Good problem to pick — “consent” is the clearest case in data law of a concept that’s load-bearing in the architecture but structurally incapable of bearing the load.
What work consent is supposed to do
Consent is the moral transformer: the mechanism that turns an otherwise-impermissible intrusion into a permissible one (Hurd’s “moral magic” — the same act of touching is battery or surgery depending on it). Imported into data law via medical/contractual informed consent, it’s meant to operationalize informational self-determination: the individual authorizes specified flows of information about themselves. GDPR Art. 7’s “freely given, specific, informed, unambiguous” is the inherited concept in its purest legislative form.
Why the inherited concept can’t do it
The failures aren’t implementation bugs; they’re category errors about what kind of thing data is.
-
The deliberating agent is fictional. Notice-and-choice presupposes someone who reads and chooses. Reading the policies you actually encounter costs ~76 working days a year. The token of consent (the click) has been fully decoupled from the act it’s supposed to name (an informed authorization).
-
You can’t consent to an inference. Consent is pointwise — datum X, party Y, purpose Z. But the harm comes from aggregation and inference: innocuous points combined to derive sexuality, pregnancy, political alignment. You cannot authorize disclosure of a fact that didn’t exist as data at the moment of consent and that you never disclosed.
-
Data is relational, consent is individual. This is the deepest one (Viljoen’s horizontal-relations argument). Your genome implicates your relatives; your contact graph implicates people who never clicked anything; your behavior trains models applied to strangers “like you.” An individualist consent grammar has no slot for the third parties my disclosure binds.
-
“Freely given” is empty without alternatives. Take-it-or-leave-it terms on infrastructure with no substitute aren’t a choice. Consent presupposes a background of acceptable options that the market doesn’t supply.
-
It’s being used against its own function. In practice consent doesn’t protect users — it launders practices and responsibilizes the individual, shifting liability onto the person it was meant to empower. The concept now serves the interest it was meant to constrain.
What it should mean
The right move (Carnapian explication — keep similarity to the original, but make it exact and honest about its scope) is to deflate consent, not extend it. The inherited concept fails partly because it’s been inflated to carry the whole normative system. Engineer it down to the domain where authorization-by-an-individual is actually the appropriate mechanism, and reassign the rest.
Engineered concept — consent is a bounded, contextual, revocable permission, valid only on a protected floor:
- Permission, never justification. Consent can make a flow permissible; it can never by itself make it just or transfer liability. Necessary sometimes, sufficient never. This single move strips consent of its shield function — the thing doing the most damage today.
- Contextual, not blanket (Nissenbaum). What you authorize is conformity to the context-relative norm under which you shared (health, friendship, commerce), not a free-floating transfer the recipient can repurpose.
- Standing and revocable, not momentary. Consent as a maintained relationship you can withdraw, not a one-time gate. Build temporality into the concept itself.
- Bounded to foreseeable, self-regarding uses. Consent’s authority reaches exactly as far as the consenter’s epistemic and moral standing: risks they can foresee, falling on them. Inferential and relational uses fall outside what consent can license — by their nature.
- Floor-dependent validity. Consent is void absent non-waivable baseline protections and real alternatives. “Freely given” finally gets teeth.
The honest corollary
If you bound consent this tightly, most of the work it currently pretends to do has to be reassigned to mechanisms that don’t run through individual authorization:
- Fiduciary/loyalty duties (Balkin; Richards & Hartzog) — care, confidentiality, loyalty owed by the data holder regardless of consent, the way a doctor’s duty doesn’t dissolve because you signed a form.
- Collective/democratic governance for aggregate and inferential data — because those uses affect populations, the legitimate locus of authorization is collective, not a sum of individual clicks.
- Unwaivable use prohibitions — like rights in labor law you cannot sign away. Some processing is impermissible even with consent.
The Strawsonian worry — have I changed the subject rather than fixed the concept? — is real here, because law and user expectations are anchored to the inflated version, and a deflated “consent” will read as a downgrade. I’d argue topic continuity holds: this preserves the core (individual authorization transforming permissibility) and prunes only the overreach. But the honest framing isn’t “here’s a better consent.” It’s: consent was made the keystone of a structure it was never shaped to hold; the repair is to demote it to a minor, well-behaved component and build the load-bearing walls out of duty and collective governance instead. The conceptual engineering succeeds only if it’s paired with that institutional reassignment — revise the concept in isolation and you just get a more honest-looking version of the same failure.
In the current landscape of data privacy (e.g., GDPR, CCPA, BIPA), the concept of “Consent” functions primarily as a regulatory checkbox, failing to achieve its normative goal: protecting individual agency in the face of asymmetrical power.
Conceptual engineering suggests we do not necessarily throw the concept away, but rather “wreck it” and rebuild it to do the work it was originally designed to do. Here is an analysis of why the inherited concept fails, followed by a proposed engineering of its meaning.
1. The Diagnosis: The “Autonomy Fallacy”
The inherited concept of consent in data law is borrowed from contract and tort law. It relies on a Kantian definition of autonomy: if a rational person chooses freely, the choice is valid. However, in the digital ecosystem, the conditions for that autonomy are structurally impossible to meet.
- The Futility of “Voluntary”: Consent is legally required to be “freely given.” In reality, it is “forced through convenience.” Refusal of terms of service (ToS) often means losing access to essential services (e.g., social media, banking, ride-sharing). This creates a synthetic monopoly.
- Temporal Decay: Consent is legally static (signed once, applies for “now”) but contextually dynamic (algorithms change, data usage expands over years). A one-time signature cannot meaningfully authorise the future use of your facial ID for Deepfake verification generated five years later.
- The Burden of Proof: The concept structures consent as a user obligation to maintain access to their rights. The burden falls on the single human to read five hundred pages of text to authorise the action of a corporation.
The Engineer’s Verdict: We are trying to install a “security lock” using a “magical abstraction” inside a “leaded cubic house.” If, then, and Unless are the wrong logical operators. We need Ongoing Verification.
2. The “Job to be Done”
What is the function of Consent? It is not to let big tech launder data. It is to ensure that:
- Expectation Alignment: The user knows what processing action is occurring before it happens.
- Reversibility: The user can stop the action if the trust is lost.
- Power Check: The user can reject authority in favor of safety without prohibitive friction.
The current concept satisfies legal compliance but fails these three functions.
3. The Redesign: “Functional Alignment Consent”
We should engineer a new conceptual definition of consent. It should not be “Permission” (passive state) or “License” (active contract). It should be Alignment (active, ongoing, relational).
A. From Permission to Acknowledgement of Risk
- Old Meaning: “I give you leave to do X.”
- New Meaning: “I acknowledge I understand X often happens to me, and I explicitly accept the cost/benefit of X for my benefit.”
- Why: This shifts consent from granting power to granting knowledge. If you take the risk, you bear the consequence. This creates a Personal Responsibility Registry.
B. From Binary to Gradient
- Old Meaning: You “Consent” (Yes) or “You Decline” (No).
- New Meaning: Consent is a Spectrum of Authorization.
- Level 1: Course Correction: Short-term, reversible, temporary data use (e.g., location to find delivery driver).
- Level 2: Trust: Long-term, higher-risk data use (e.g., health data for research).
- Mechanism: Consent must be granular. A single umbrella consent for “Marketing” (a bucket of risk) is invalid. It must be a Purpose-Specific Token.
- Engineering: A “Data Wallet” where users hold digital keys. They grant a key for specific timeframes. The key expires when the processing need is met.
C. From Passive to Fiduciary Trigger
- Old Meaning: If you sign, the company can process.
- New Meaning: Consent is not a law that permits activity; it is a law that triggers Duty of Care.
- Why: Currently, consent shifts the burden of privacy to the user. We should engineer it so that lack of consent shifts liability to the company.
- Reframing: If the consent is not “Continuous and Verifiable,” the processing is Presumed Illegal, not Presumed Consented.
- The “Friction-Free Revocability”: The most revolutionary aspect of this concept is the easiest withdrawal. Consent must include a “Stop Now” button that works as easily as an “Start” button. If stopping costs more than starting, the “start” was coerced (and thus, invalid consent).
4. Implementation: The “Smart Contract” of Data
To operationalize this new concept, we move away from HTML text boxes and toward Verified Data Lineage.
- Immutable Audit Trail: Consent is not a signature; it is a record stored on a distributed ledger (or private block chain).
- Contextual Updates: If a company introduces a new algorithm that harms the user (e.g., uses data to sell insurance at higher rates), the “alignment” is broken. The user must be notified immediately. If they don’t react (Opt-Out), the company must assume non-conformance.
- Default to Privacy: The new concept requires a Negative Consent default. The user must not have to click “No” to maintain their privacy. Only active participation in data processing should require consent.
5. Summary: The New Definition
The definition of Consent in data privacy law must be re-engineered from a Legal Transaction to a Governance Mechanism.
Proposed Definition:
“Consent is the ongoing, granular, and periodic authorization of data processing, which is contingent upon the processor maintaining the capability for the user to independently verify privacy settings and withdraw access without friction. Consent is invalid if it is not renewable at the specific moment the data processing context changes.”
Key Takeaways:
- Continuous: Consent is not a signed document; it is an active state.
- Revocable by Design: Withdrawal must be as easy as authorisation.
- Fiduciary: It binds the corporation to a standard of “Best Practice” if they want to claim the user consented, not just legal compliance.
Conclusion
The current concept of consent is a public utility—it does nothing for the individual, but keeps the industry alive for the regulator. We must re-engineer it into a personal asset. When a user says “consent,” it should mean, “I have reviewed the cost, I accept the risk, and I am monitoring you.”
Without this shift, privacy law remains a theater of rights rather than an architecture of protection.
Target Concept
The concept of “consent” as currently defined and operationalized within dominant data-privacy law frameworks, including the EU GDPR (Art 4 § 11), US CCPA, and PIPEDA, which currently serves primarily as a compliance discharger rather than an autonomy protection mechanism.
Current Usage — Descriptive Baseline
Procedural Architecture — Current usage defines consent via “freely given,” “specific,” “informed,” and “unambiguous” criteria (GDPR Art 4 § 11), requiring active opt-in timing (pre-processing) and revocability at any time.
Empirical Reality — Comprehension — Users cannot reliably describe what they consent to (unverified study citation: Tang et al.); research documents systematic user failure to read, understand, or distinguish consent mechanisms (“click-wrap blindness” per arXiv 2506.08996 and Sjøflot & Opsahl).
Empirical Reality — Revocation — Revocation requires disproportionate effort; Kancherla et al. (arXiv 2411.15414) indicates approximately 20% of websites make revocation difficult via multiple-page navigation or form submission requirements.
Empirical Reality — Asymmetry — Opt-out mechanisms dominate practice despite opt-in requirements; systematic review on health data reuse (PMC10015347) found consent rates of 21% (opt-in) versus 95.6% (opt-out).
Empirical Reality — Dark Patterns — Banner redesign making acceptance more prominent measurably increases acceptance; Nouwens et al. (arXiv 2605.15056) and Farronato et al. 2025 document consumer welfare consequences via nudging; Sparked 2025 COSMA study 05 identifies directional effects.
Empirical Reality — Compliance Gap — A study of ~2,101 EU and US websites quantified the gap between externally visible compliance signals and functional compliance (arXiv 2506.08996); exact cohort size unverified without direct dataset documentation.
Implementation Tension — Consent operates as a procedural checkbox rather than a substantive authorization (Draft 1) or lawful basis discharger (Draft 2).
Identified Function Failures
| Function Goal | Failure Mode | Distorting Effect |
|---|
| Autonomy Protection | Consent functions as de facto surrender rather than authorization (Draft 1; Draft 2). | Users cannot meaningfully exercise choice due to information burdens and default settings (Draft 2). |
| Accountability | Liability shifts to the data subject while shielding the controller (Draft 1). | Asymmetric enforcement; controllers receive compliance guidance; users receive confirmation (Draft 2). |
| Informational Governance | Transparency is gridlocked rather than enabling understanding (Draft 2). | Policies are complex; notices serve “I read” rather than “I understand” (Draft 2). |
| Recourse Mechanism | Withdrawal is systematically disabled (Draft 1; Draft 2). | Revocation requires disproportionate effort or technical barriers (Draft 2). |
| Accountability Baseline | Provable explicit permission fails (Draft 1). | Enforced truth becomes instrumental evidence for compliance rather than actual protection (Draft 1). |
Note: this concept’s contestation may be constitutive (essentially contested in Gallie’s sense); the engineering move risks treating as resolvable what is in fact the object of legitimate ongoing dispute. Candidate revisions below are offered with this caveat.
Ameliorative Purpose
The revised concept should perform measurable functional adequacy:
- Make boundaries navigable to users regarding foreseeable legal/technical conditions (Draft 1).
- Enable actual self-governance where consent choices meaningfully alter processing outcomes (Draft 1).
- Operationalize withdrawal as easily as initial granting, prioritizing privacy defaults (Draft 1; Draft 2).
- Shift from permission-granting to permission-withholding to align default mechanisms with privacy (Draft 2).
- Ensure accountability pairing (where consent is a trigger for justification refresh by the controller) (Draft 2).
- Verify functional consent capacity beyond procedural acknowledgment (Draft 1).
Candidate Revisions
Candidate A: “Functional Consent” / “Processable Consent” (Draft 1 & Draft 2)
Definition: Consent is valid only when the mechanism enables the user to track and modify permissions, encoded in state not just text (Draft 1; Draft 2).
Rationale: Verification shifts from action taken to capacity demonstrated (Draft 1).
Tradeoffs: Requires technical verification and cross-platform coordination; loses procedural simplicity (Draft 1).
Candidate B: “Revokable Consent” (Draft 1) / “Consent Plus Accountability” (Draft 2)
Definition: Consent is legally binding only if withdrawal mechanisms equal consent acquisition in friction/discoverability (Draft 1).
Rationale: Addresses revocation asymmetry as constitutive of consent (Draft 1).
Tradeoffs: Reduces business model efficiency; increases consumption costs (Draft 1).
Candidate C: “Default-Positive Consent” (Draft 1) / “Tiered Model” (Draft 2)
Definition: Valid consent requires privacy defaults; or splits essential (opt-out) from enhanced (opt-in) processing (Draft 1; Draft 2).
Rationale: Corrects structural bias toward data collection defaults (Draft 1).
Tradeoffs: Displaces billions of currently-enabled collections; redefines essential processing boundaries (Draft 2).
Candidate D: “Institutional/Relationship Model” (Draft 2)
Definition: Consent is a relationship contract requiring readable delivery, ongoing reporting, and persistent withdrawal (Draft 2).
Rationale: Directly addresses “consent by design” failure by building accountability structures (Draft 2).
Tradeoffs: Requires organizational capacity; complex to police (Draft 2).
Implementation Problem
Requires industry-wide coordination (browsers, OS, frameworks) and DORA 2023 regulatory registration mechanism adoption (Draft 1). Stakeholders resist: controllers resist higher compliance costs; CMP vendors resist architectural change; regulators prefer manageable compliance (Draft 2). Realistic adoption horizon is 5–10 years requiring cross-jurisdictional harmonization (Draft 2). Controllers treat new concept as compliance box; regulators measure procedural boxes rather than outcome-based capability (Draft 2). Remaining cognitive limitations and convenience incentives sustain “click-accept” patterns (Draft 1). Exact cohort size (~2,101) and dismissal rate percentages (Farronato et al.) remain unverifiable from available sources; quantification carried with hedged language (Draft 1; Draft 2).
Revision Costs and Displacement
Loss of Procedural Simplicity — Shift from “click and move on” UX to explicit state-based verification increases operational costs (Draft 1; Draft 2).
Loss of Consent Logging — Verified capacity replaces simple “I agreed” proxies; requires technical audit infrastructure (Draft 1).
Secondary Disruptions — Impacts concepts of “lawful basis,” “reasonable processing,” and “compliance” requiring secondary conceptual engineering (Draft 2).
Market Friction — Underrewarding of privacy in current market models; controllers resist due to revenue pressure (Draft 2).
Value Assessment — Accountability gains outweigh procedural simplification, but privacy remains devalued in market incentives (Draft 2).
Confidence Per Finding
Function-failure diagnosis: High (0.85–0.90) — Multiple empirical sources confirm systemic divergence.
Proposed revision(s): Medium (0.60–0.70) — Rationale coherent but technical/legal bounding is substantive.
Adoption feasibility: Low (0.30–0.40) — Structural resistance and implementation problems are well-documented.
Per-finding confidence assessment:
| Finding | Confidence |
|---|
| Function-failure diagnosis | High (0.85–0.90) |
| Revocation metrics (Kancherla) | Medium-High (0.70) |
| Consent rate asymmetry (PMC10015347) | High (0.90) |
| Banner manipulation effect (Nouwens/Farronato) | Medium (0.65) |
| Compliance gap (~2,101 cohort) | Low (0.40) |
| Draft 2 quantitative dismissal rate | Low (0.35) |
Target concept
“Consent” as the legitimating mechanism for personal-data processing in contemporary data-privacy frameworks (e.g., GDPR, CCPA/CPRA, LGPD, PIPL). The engineering question is how to revise this concept and its institutional scaffolding to actually operationalize individual autonomy, informed choice, and privacy protection, given the inherited model’s failure in digital practice.
Current usage — descriptive baseline
- Legal genealogy — imported from medical ethics (e.g., Schloendorff informed consent), tort law (battery/consent-to-touch), and contract law, carrying the implicit commitment that interactions are discrete, bounded, and occur between relatively equal parties.
- Formal GDPR definition — requires affirmative action, specificity, informedness, freedom from coercion, and withdrawability (e.g., CJEU Planet49 ruling: pre-ticked boxes are invalid; “only active behaviour” signifies consent).
- Regulatory structural distinction — exists between the GDPR (affirmative consent as the primary legitimating basis) and the CCPA/CPRA (notice-and-opt-out as the baseline, reserving affirmative consent for high-risk categories like Sensitive Personal Information).
- Operational reality — functions as a liability-insulation mechanism for controllers via “notice-and-choice” architectures (cookie banners, lengthy policies), systematically violating the assumption of discrete, bounded interactions.
- Inherited conceptual metaphor — “Privacy as Transaction / Consent as Bargaining,” which falsely licenses the inference that a mechanical click represents a meaningful, voluntary assessment of risk.
Identified function failures
- Function the concept should serve: Freely Given authorization — current concept’s failure mode: Effective “take-it-or-leave-it” architectures constitute functional coercion, fictionalizing consent’s legitimacy despite legal doctrines prohibiting structural asymmetry (e.g., GDPR Art 7(4)). Cost of the failure: Individuals are forced to surrender data access under duress to participate in essential digital life, voiding true autonomy.
- Function the concept should serve: Informed Choice — current concept’s failure mode: Information asymmetry and notice fatigue make being “informed” practically impossible; reading and comprehension rates are in the single digits to low teens (e.g., Pew Research 2019: 9% of US adults regularly read privacy policies). Cost of the failure: Consent is given blindly, negating the core premise of meaningful authorization.
- Function the concept should serve: Specificity at Trajectory — current concept’s failure mode: Consent collected at the interface front-end is structurally decoupled from downstream data flows to joint controllers, processors, third parties, and secondary uses. Cost of the failure: Data subjects lose control over how their information is actually used over time, leading to unanticipated privacy harms.
- Function the concept should serve: Genuine Withdrawability — current concept’s failure mode: Formal requirements to make withdrawal “as easy” as giving are practically defeated by interface friction (e.g., forcing account deletion or burying options deep in menus). Cost of the failure: The ongoing legitimacy of processing is falsely presumed after the subject attempts to revoke it.
- Function the concept should serve: Resisting Fatigue and Routinization — current concept’s failure mode: High-frequency prompt exposure (aggregate estimates of ~1.4 hours per EU user per year on cookie banners) produces acceptance-fatigue, where the ritual of consent replaces its substantive function. Cost of the failure: Consent becomes a meaningless bureaucratic hurdle rather than a genuine exercise of autonomy.
- Function the concept should serve: Protecting Special Categories — current concept’s failure mode: The protected-category default is neutralized by inference technologies that routinely turn non-sensitive data into sensitive inferences (e.g., health, political views). Cost of the failure: Special-category protections are bypassed algorithmically, leaving highly sensitive traits exposed.
- Function the concept should serve: Preventing Unlawful Bundling — current concept’s failure mode: “Accept all or no service” cookie walls persist routinely, making the regulatory unbundling requirement enforcement-brittle. Cost of the failure: Users are coerced into blanket data extraction to access basic services.
- Function the concept should serve: Developmentally Appropriate Age-Based Protection — current concept’s failure mode: Binary age thresholds ignore developmental variance, and verification of parental consent is typically shallow and easily bypassed. Cost of the failure: Minors’ data is processed without genuine protective oversight.
- Function the concept should serve: Distinguishing True Consent from Mere Notice — current concept’s failure mode: Systems treat the existence of a formal record (“the user was told”) as sufficient for consent, substituting the map for the territory. Cost of the failure: Mere notification is legally laundered as active authorization.
- Function the concept should serve: Capturing Structural and Collective Harm — current concept’s failure mode: Relying on individual transactional consent pushes structural, dignitary, and collective dimensions of privacy harm completely out of view. Cost of the failure: Systemic societal harms of mass surveillance and data aggregation remain unaddressed by the regulatory framework.
Ameliorative purpose
To produce a legitimate, deliberative, and trackable authorization for personal-data processing. To achieve this, the revised concept must serve the following functions:
- Ground authorization in conditions the data subject can actually meet (comprehension, alternatives, time, absence of coercion).
- Cover the actual trajectory of data use over time, not merely the point of collection.
- Ensure the authorization is genuinely reversible in practice.
- Operate within a broader regime of structural permissions, fiduciary duties, and use-restrictions that shift the burden of compliance and risk-assessment away from the overwhelmed individual.
Note: The contestation around digital consent is not essentially contested in Gallie’s sense; the underlying purposes (autonomy, dignity, protection) are widely shared, and the disagreement is about the design of the concept rather than its constitutive definition. Conceptual engineering is therefore the appropriate method. However, critical scholars maintaining that privacy is inherently a collective or structural right urge a pivot to a post-consent regime (statutory prohibitions, strict fiduciary duties, collective public-good framing); this analysis treats that pivot as a competing candidate design rather than an unresolvable definitional dispute.
Candidate revisions
Candidate A: Substantive Consent Paired with Structural Permissions
Rationale: Defines consent substantively (deliberative authorization meeting comprehension, alternatives, voluntariness, and revocability conditions) and pairs it with a parallel regime of structural permissions that authorize certain processing categories (e.g., strictly necessary, public interest, low re-identification risk) independent of consent. This directly answers the ameliorative purpose by shifting the compliance burden away from the individual for baseline processing, while preserving high-stakes deliberative authorization.
Tradeoffs and costs: Requires building an entirely new parallel legal architecture and shifts political weight to the regulator to define and maintain the permission list.
Candidate B: Persistent, Machine-Readable Authorizations Governed by a Meaningfulness Standard
Rationale: Treats consent as a persistent preference object (e.g., W3C signals) that travels with the user, governed by a substantive meaningfulness standard and a duty on controllers to honor it. This fulfills the function of covering the data trajectory and ensuring genuine revocability without relying on per-session interface coercion.
Tradeoffs and costs: Requires robust technical infrastructure, is hard to test ex post, and the legal status of automated preference signals (e.g., Global Privacy Control) under GDPR Art 4(11) remains in active, unresolved DPA/EDPB dispute regarding whether they constitute an “unambiguous indication.”
Candidate C: The Fiduciary Frame
Rationale: Positions the data controller as a fiduciary with duties of loyalty and care; consent sets the scope of permissible action, but fiduciary duties run inside consent (preventing extraction of surplus or uses the subject would reject). This shifts the burden of compliance and risk-assessment away from the overwhelmed individual, fulfilling the ameliorative purpose.
Tradeoffs and costs: Faces severe doctrinal barriers, including the absence of a common-law entrustment analogue for personal data, structural misalignment with the surveillance-capitalism revenue model, and judicial traditions favoring bilateral commercial analysis over status-based fiduciary relations.
Meta-recommendation: A hybrid of Candidates A and B, embedding a meaningfulness standard directly into the consent definition and applying categorical exclusions to certain high-risk processing (e.g., re-identification, sensitive inferences) regardless of user consent.
Implementation problem
Adopting this revised concept requires coordinated action across multiple actors: EU/member-state legislators, EDPB/national DPAs, the CJEU, industry compliance teams, standards bodies, CCPA/CPRA courts, and user-side tooling providers. Coordination challenges are severe due to the multi-jurisdictional nature of the internet and the fact that proposed revisions directly threaten the data-extraction business models funding the current web, creating high free-rider and jurisdictional-arbitrage risks. Plausible carriers for adoption include incremental CJEU/DPA enforcement pressure on existing “freely given” requirements, targeted new legislation, standards-body work on persistent preference signals, and consumer-privacy movement building.
Revision costs and displacement
- Loss of “Individual Choice” Rhetoric — assessment: Offloading some legitimacy to a structural-permissions regime makes the politically palatable “user choice” narrative harder for industry and policymakers to invoke. The loss is worth the gain, as the current narrative is functionally hollow, but it will face intense political headwinds.
- Incompatibility with Dominant Business Models — assessment: Substantive meaningfulness standards are fundamentally incompatible with “take-it-or-leave-it” data-extraction revenue models, guaranteeing fierce industry opposition. The community loses the current, highly profitable status quo of frictionless data harvesting.
- Loss of Doctrinal Simplicity — assessment: Replaces the regulatory bright-line of “if consent obtained, processing is lawful” with complex, fact-specific meaningfulness tests and structural-permission tables. The community loses easy compliance checklists in exchange for more robust, context-sensitive protection.
- Metaphorical Displacement — assessment: Requires a genuine cognitive and rhetorical shift away from “Privacy as Transaction” toward models like “Privacy as Governance” or “Privacy as Structural Protection,” facing significant cultural and legislative pushback. The community loses the familiar transactional baseline that currently dominates legal education and public understanding.
- Loss of Secondary-Use Flexibility — assessment: Strict, granular consent regimes stifle socially beneficial secondary data uses (e.g., retrospective epidemiological analysis, federated learning for rare diseases) that cannot be easily consented to prospectively. The community must develop alternative legal bases (like structural permissions) to preserve these benefits, or risk losing them.
Confidence per finding
Function-failure diagnosis: High confidence. The failures are mutually reinforcing and robustly documented in regulatory enforcement, academic literature, and observable interface practice (with quantitative anchors for notice fatigue and banner exposure hedged to reflect available empirical evidence).
Proposed revision(s): Medium confidence. The proposal is internally coherent, maps functions to structure, and is highly defensible against alternatives, though it is not the uniquely correct proposal.
Adoption feasibility: Low-medium confidence. Severe coordination burdens mean incremental movement via enforcement and jurisprudence is the most realistic path; a clean legislative redesign is plausible only under political conditions not currently present in most major jurisdictions.
Target concept
“Consent” as legally defined and operationalized in current data-privacy law — canonical exemplar GDPR Art. 4(11), with analogous provisions in CCPA/CPRA, PIPEDA, LGPD, and PDPA. The engineering question on the table is: What revisions to the legal concept of “consent” would enable it to discharge its normative purpose — protecting individual autonomy in decisions about personal data — given the documented gap between procedural validity and substantive agreement in current consent mechanisms, rather than its operating as a procedural compliance shield or a conversion-rate-optimization metric? This is an engineering task, not a descriptive one. The descriptive baseline is a precondition for the engineering move, not its answer.
Current usage — descriptive baseline
- Core definition (GDPR Art. 4(11), exact text): “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”
- Four-element structure (load-bearing across most jurisdictions): freely given (no coercion or conditioning of service on consent); specific (granular per-purpose, not blanket); informed (disclosure of processing before agreement); unambiguous (clear affirmative act — no pre-ticked boxes, no implied default consent).
- Inferential commitments the inherited concept carries: consent is a discrete event (click/tap/signature) rather than an ongoing state; consent can be delegated to intermediaries (banners on behalf of “partners”; IAB TCF-style consent strings); consent is a transaction captured in a record; consent can be bundled (one act authorizing multiple distinct purposes); withdrawal is procedurally equivalent to grant (single revocation point); refusal is structurally equivalent to acceptance (both one click away).
- Standard implementation pattern: first-/third-party cookie banner, “Accept All” visually privileged, “Manage Preferences”/“Reject All” de-emphasized or buried behind multiple steps; consent strings shared across hundreds of vendors via TCF-style protocols; consent presumed persistent unless actively revoked.
- Assumed user capacities: the baseline presumes the user possesses the cognitive bandwidth, technical literacy, and bargaining power to evaluate and negotiate processing terms without detriment to service access.
- Regulatory-scope note: this baseline primarily describes the opt-in architecture predominant under the GDPR. Opt-out regimes (CCPA) invert the default but exhibit a parallel structural failure — the transactional mechanism still presumes users can meaningfully navigate power asymmetries, whether forced to opt in to avoid service denial or to exert friction to opt out of tracking.
Confidence in baseline mapping is high. The GDPR text is public, and the implementation pattern is extensively documented in industry and academic sources, including context showing the consent-interaction space engineered for acceptance optimization rather than choice quality.
Identified function failures
The inherited concept was designed to protect autonomy through meaningful choice. It fails as written (not by misapplication), with each failure observable in current usage with a concrete cost:
- Protecting autonomy with substantive agreement — current concept’s failure mode: Procedural validity substitutes for substantive agreement. A click on “Accept All” satisfies the unambiguous-affirmative-act requirement without satisfying its purpose (demonstrable agreement); “unambiguous” measures whether a click occurred, not what the clicker understood. Cost of the failure: consent satisfying the form of the law routinely fails its function.
- Protecting against coercive power asymmetries (“freely given” failure) — current concept’s failure mode: “Freely given” is read as “not literally coerced” rather than “a real alternative exists.” When essential-service access is gated behind a binary choice, refusal means service denial, degradation, or repeated prompting; consent becomes the price of access, not the expression of preference. Cost of the failure: consent legally valid on paper but structurally coerced in practice.
- Enabling cognitive decision-making (“informed” failure) — current concept’s failure mode: “Informed” is read as “disclosure was made” rather than “disclosure enabled decision-making.” Long policies, layered disclosures, and technical jargon satisfy the procedural sense while failing the cognitive sense. Cost of the failure: consent legally valid but decisionally inert.
- Encoding meaningful distinctions (“specific” failure) — current concept’s failure mode: “Specific” is read as “by processing category” rather than “by distinctions the data subject would care to make.” Practice bundles dozens of vendors and purposes behind a single banner, satisfying specificity via a settings page almost no user opens. Cost of the failure: the granularity is technical, not decisional.
- Ensuring genuine revocability (withdrawal asymmetry) — current concept’s failure mode: Withdrawal is procedurally symmetrical but experientially asymmetric — grant takes one click; withdrawal requires navigation to settings, often across sessions, sometimes contact with a DPO. Cost of the failure: formal symmetry conceals a substantive asymmetry making consent practically irrevocable.
- Sustaining engagement without fatigue (transactional friction) — current concept’s failure mode: Granular, cookie-level consent is akin to a restaurant requiring a diner to specify dietary restrictions for every dish and every new waiter. This friction produces consent fatigue, driving users to blindly click “Accept All.” Cost of the failure: friction is designed to be escaped, not engaged.
- Preventing co-optation by commercial metrics — current concept’s failure mode: The concept has been co-opted by “consent conversion rate optimization,” where banner design, dark patterns, and UX friction are engineered to maximize click-through, not secure autonomous agreement; DPI-consent literature notes that clicking “I accept” to reach the next screen is unlikely to be sufficient as meaningful consent. Cost of the failure: this erodes trust and legitimizes surveillance practices under a veneer of procedural legality.
Ameliorative purpose
The revised concept should serve the following functions:
- Shift the cognitive and architectural burden of data governance from the individual user to the data collector.
- Secure agreement that is demonstrably the data subject’s, under conditions where refusal and withdrawal are real options.
- Track the data subject’s distinctions that matter — granular enough that consent encodes a real choice, not a procedural ritual.
- Be revocable in conditions experientially equivalent to its grant.
- Operate as a continuous, asymmetrically protected boundary on data use that defaults to data minimization.
- Survive the transition from interaction-level (one banner) to ecosystem-level (shared consent strings, partner processing, downstream flows).
These are tests the revised concept must pass, not stipulated conclusions about what consent is.
Note: “Consent” in the data-privacy context borders on an essentially contested concept (Gallie, 1956): different stakeholders (regulators, platforms, users, civil society, scholars) hold non-coinciding views of what consent is for, and the contestation is internal to the concept’s normative point. One camp holds that autonomy fundamentally requires individual, granular, conscious choice; another holds that autonomy in complex, asymmetric systems fundamentally requires delegation and structural protection. The proposals below lean toward the latter (structural/delegated models). The engineering move is offered with this explicit caveat: attempting to “fix” the individual granular model may be functionally impossible without producing the very autonomy-eroding fatigue it seeks to prevent. The proposals are a proposal from one stance, not a resolution of the underlying dispute.
Candidate revisions
Two streams produced two distinct candidate sets for the same function-failures. Both are preserved; they are not collapsed. One set engineers structural/delegated authorization mechanisms; the other engineers measurable upgrades to the four GDPR elements.
Candidate A — Delegated/Proxy Consent (structural authorization)
Rationale: Consent is a machine-readable, persistent user preference (trusted Privacy Agent, Global Privacy Control, or Data Trust) that platforms are legally bound to respect by default, replacing ad-hoc clicks. This eliminates cognitive overload and consent fatigue by automating enforcement of autonomy at the network level.
Tradeoffs and costs: Loses granular, context-specific micro-choices; requires robust, universally adopted technical standards; risks new centralized intermediary bottlenecks.
Candidate B — Fiduciary Purpose-Limited Authorization
Rationale: Consent is a revocable, strictly limited license granted only for a narrowly defined, user-beneficial purpose; the collector bears a legal duty of care and the burden of proof that any secondary use (AI training, third-party sharing) aligns with the user’s reasonable expectations, requiring fresh authorization if not. This attacks the blanket-permission-slip model by tethering authorization to specific justified outcomes.
Tradeoffs and costs: Legal ambiguity around “user-beneficial purpose”; increased compliance overhead; may stifle frictionless data-analytics innovation.
Candidate C — Progressive/Just-in-Time Decoupled Consent
Rationale: Consent for core service functionality must be strictly decoupled from consent for secondary monetization; secondary use requires just-in-time explicit authorization that cannot be coerced by denial of basic service access. This restores the “freely given” condition by removing the coercion of bundled take-it-or-leave-it consent.
Tradeoffs and costs: Threatens “free,” ad-supported business models; may proliferate paywalls excluding lower-income users from essential digital infrastructure.
Candidate D (ruled out, retained as benchmark) — Consent-Abolition / Legitimate-Purpose Regime
Rationale: Replace individual consent entirely with a strict legitimate-purpose or data-fiduciary regime where processing is lawful only if it meets predefined narrow necessity/benefit criteria.
Tradeoffs and costs: This is a paradigm shift away from consent, not an engineering of the concept; it is retained only as a benchmark alternative for jurisdictions moving beyond consent.
Synthesized recommended definition for Set 1: “Consent is a revocable, purpose-limited authorization that defaults to data minimization, where the burden of demonstrating that the authorization is informed, voluntary, and aligned with the user’s reasonable expectations rests entirely on the data collector, operationalized through structural safeguards (recognized privacy signals or just-in-time decoupled prompts) rather than transactional user friction.”
Integration: Where a user’s delegated signal (e.g., GPC) conflicts with a platform’s just-in-time prompt, the delegated signal is the binding baseline default; just-in-time prompts are permitted only for novel secondary purposes not covered by the active signal, and each must include a frictionless mechanism to update the persistent signal, ensuring the structural default is never permanently overridden by episodic dark-pattern coercion.
Opt-out scope note: Candidates A–C target opt-in regimes; for opt-out regimes (CCPA), the parallel revision shifts the default state to “unconsented” and places the affirmative burden of action on the collector to trigger processing, rather than on the user to opt out.
Candidate A′ — Symmetric-friction revision
Rationale: Add to the definition/doctrine that consent is valid only if withdrawal can be completed in no more interactions and no more time than grant required; standardize a “withdraw consent” affordance visible at the data-collection surface, not buried in a dashboard. Addresses the withdrawal-asymmetry failure. (Metaphor shift: CONSENT IS AN ONGOING STATE).
Tradeoffs and costs: Implementation complexity; friction for legitimate consent management; requires technical standards (e.g., W3C / post-IAB) to be enforceable.
Candidate B′ — Comprehension-floor revision
Rationale: Revise “informed” to include an engagement criterion: valid only if the system can demonstrate realistic opportunity to comprehend (minimum time on notice, scroll-completion, lightweight comprehension check on key items); disclosure-only satisfaction is replaced with engagement-based satisfaction. Addresses procedural-validity and informed failures. (Metaphor shift: CONSENT IS A DECISION).
Tradeoffs and costs: Subjective standard harder to police than “disclosure was made”; gaming risk via minimum-time thresholds; equity risk — engagement-based metrics may disproportionately burden neurodivergent users, screen-reader users, and those with limited cognitive bandwidth, trading procedural accessibility for a new form of cognitive gatekeeping.
Candidate C′ — Real-alternative revision
Rationale: Revise “freely given” to require a genuine non-consensual path: consent to processing X is valid only if a substantively equivalent service tier is available without consenting to X; reject service-denial-as-price-of-privacy regardless of banner structure. Addresses power-asymmetry and partially the specificity failure. (Metaphor shift: CONSENT IS A CHOICE).
Tradeoffs and costs: Threatens advertising/data-funded business models; requires contested regulatory interpretation of “substantively equivalent”; may reduce the addressable market for low-value processing.
Conjunction (A′ + B′ + C′) — recommended proposal for Set 2
Rationale: The failures are interlocking; no single candidate addresses all. Consent must be (i) revocable with symmetric friction, (ii) preceded by demonstrable engagement, and (iii) granted where a non-consensual path exists. The conjunction is the floor below which the inherited concept’s purpose is not served.
Tradeoffs and costs: A weaker revision (A′ alone) is more feasible but does less work; the conjunction requires significant structural and regulatory overhaul.
Candidate D′ (placeholder) — Ecosystem-persistence revision
Rationale: Require consent records to be user-portable across the ecosystem (global privacy controls, standardized preference signals, wallet-based consent) with revocation propagating downstream to all data-sharing partners; consent in one context does not bind in another; consent strings cannot serve as universal authorization; revocation is a single ecosystem-wide event. Addresses the ecosystem-persistence function. (Metaphor shift: CONSENT IS A RELATIONSHIP).
Tradeoffs and costs: Cross-platform standardization with substantial governance questions; challenges consent-management-platform business models; pushes toward identity-layer or wallet-based architecture. Deliberately under-specified, as standardization politics warrant their own engineering pass.
Cross-set convergence and divergence:
- Convergence: Both sets independently arrive at portable, machine-readable, persistent delegated signals (GPC / privacy agents) as a core mechanism. Set 1 Candidate A and Set 2 Candidate D′ make the same load-bearing proposal. They diverge on its status: one treats delegated/structural authorization as a primary recommended candidate; the other treats ecosystem-persistence as a placeholder requiring a separate engineering pass.
- Convergence: Both sets attack the “freely given” failure via decoupling/real-alternative requirements (Set 1 Candidate C ≈ Set 2 Candidate C′).
- Divergence: Set 1 frames revision as wholesale redesign toward structural/fiduciary authorization with a single synthesized definition; Set 2 frames revision as measurable upgrades to each existing GDPR element preserving the four-element scaffold. These are different engineering philosophies — concept-replacement vs. element-tightening — and both are coherent.
Implementation problem
- Who must adopt: Legislators (to rewrite statutory definitions like Art. 4(11)); regulators (EDPB, national DPAs, US state attorneys general — to shift enforcement from checkbox auditing to substantive dark-pattern prohibition); platforms and large data controllers (to re-architect UI/UX and backend pipelines); industry intermediaries (consent-management platforms, ad-tech consortiums — standardization); courts (enforcement and adjudication); users and civil society (uptake, norm-formation, pressure).
- Coordination problem: The ecosystem is heavily financially incentivized to maintain the status quo — maximizing consent rates is directly tied to ad revenue. This is a classic collective-action problem: no single company will unilaterally abandon high-converting dark patterns while competitors exploit them. Industry-level standardization (IAB TCF lineage) has, on the documented record, accommodated the inherited concept’s weaknesses rather than corrected them; the consent-CRO literature is itself evidence the implementation environment is engineered against this engineering project.
- Adoption mechanisms: Regulatory guidance (low cost, slow, soft enforcement — feasible for the symmetric-friction/structural-default candidates); legislative amendment to Art. 4(11) and analogues (high cost, slow, durable — needed for the real-alternative/decoupling candidates); court decisions interpreting existing law in light of function (low cost, slow, piecemeal — possible for the comprehension-floor candidate in some jurisdictions); industry self-regulation (lowest cost, lowest durability, captured — likely inadequate alone); regulatory fines calibrated to the revenue gained from non-compliance, to realign platform incentives.
- Assessment: The comprehension-floor and symmetric-friction candidates are incrementally feasible via guidance and case law; the real-alternative candidate requires legislative change; the conjunction is feasible over a 5–10 year horizon in the EU, with longer horizons elsewhere.
- Conceptual-engineering theory note: Cappelen’s view (Fixing Language, 2018) is that the engineering project’s legitimacy is independent of uptake; Burgess and Plunkett’s view (work on the implementation challenge and conceptual ethics) is that uptake is part of the project’s value. The two-camps framing is a simplification (Cappelen, Burgess, and Plunkett have collaborated). Flagged as a live debate, not resolved here.
Revision costs and displacement
- Loss of micro-granularity — assessment: The revision abandons the idea that users should/can make informed granular choices about every data point. Though this granularity is currently a fiction, its formal abandonment may alarm digital-rights purists who equate autonomy strictly with moment-to-moment individual choice.
- Loss of frictionless onboarding / monetization — assessment: Low-friction banners let users access services quickly and let platforms monetize with minimal friction; the revision adds interaction costs some users find irritating and some services cannot absorb, and curtails rapid data monetization.
- Loss of cross-context data sharing — assessment: The inherited concept permits “consent once, share everywhere” (TCF-style strings); revised consent may require per-context reaffirmation — a real reduction in operational value.
- Constraint on bundled / ad-subsidized services — assessment: Business models subsidizing services via advertising or other processing depend on broad consent; the real-alternative/decoupling candidates constrain them.
- Loss of doctrinal infrastructure — assessment: The revision displaces decades of case law, regulatory guidance (e.g., EDPB consent guidelines), and compliance tooling built around the current definition; transitioning requires either mapping new functional requirements onto existing interpretive frameworks or a costly multi-year doctrinal build-out establishing what counts as “structural safeguards” versus invalid prompts.
- Enforceability / burden-shift — assessment: Subjective standards (comprehension, real alternatives) are harder to police than procedural ones. The revision shifts the burden of proof from the data controller (currently needs only a log of a click) to the regulator (must now demonstrate absence of comprehension or of a real alternative), risking under-enforcement under typical DPA resource constraints, and trades rule-of-law clarity and the auditability of procedural standards for substantive autonomy.
- Loss of mechanism pluralism — assessment: The inherited concept accommodates banner, clickwrap, signed form, oral confirmation; the revision may narrow this range.
- Overall Assessment: The loss of frictionless innovation and existing doctrinal certainty is judged worth the gain, because current friction is disproportionately borne by user autonomy while the innovation is frequently extractive. However, the shift to structural models risks new bureaucratic or technical bottlenecks that must be carefully managed. The claim that these costs are worth paying is contestable and must be argued for, not concealed.
Confidence per finding
- Function-failure diagnosis: High. Well-documented by UX research, regulatory dark-pattern findings, and the explicit existence of the consent-CRO industry, which proves the mechanism is gamed rather than respected; failures are observable in current practice.
- Proposed revision: Moderate. Conceptually and philosophically sound for restoring autonomy; each candidate trades off against others; neither candidate set is uniquely correct; the ecosystem-level function is only partially closed by the developed candidates; politically and economically contested by entrenched stakeholders.
- Adoption feasibility: Low-to-moderate. A structural assessment, not a prediction; dependent on synchronized legislative action and regulatory willpower facing industry lobbying and jurisdictional fragmentation; specific timing depends on regulatory politics.
Additional considerations
- Baseline depth: Whether the descriptive baseline should include historical doctrinal lineage (tort, medical, contract consent) or whether the operational baseline (GDPR text + UI manifestations) suffices is an open depth standard.
- Consent-abolition boundary: Whether the engineering question permits consent-abolition as a primary candidate or strictly demands consent-reform is a boundary judgment; the “ruled out” entry satisfies breadth, but abolition’s ultimate viability is a separate normative debate. (Surfaced as a live tension between the two streams’ framings).
- Section-4-to-5 mapping: The ecosystem-persistence function is not fully closed by the developed candidates; resolving it requires a separate analytical pass on portable, user-controlled consent infrastructure and its standardization politics.
- Adoption timing: The 5–10 year EU horizon is a structural judgment; it would resolve with empirical evidence on the pace of analogous GDPR interpretive evolutions (e.g., the “right to be forgotten” lineage).
- Conceptual-engineering dialectic: The Cappelen / Burgess-and-Plunkett two-camps framing is a simplification of a more networked literature; a finer treatment would map the positions in detail.
- Metaphor-infrastructure: The conceptual metaphor load-bearing the inherited concept is CONSENT IS A TRANSACTION (one-shot, low-friction, formal, captured in a record). This metaphor is itself part of the problem: transactions are fast, formal, one-time; autonomy is none of these. The candidate revisions are partly metaphor changes dressed as definitional changes — shifting CONSENT toward STATE, DECISION, CHOICE, and RELATIONSHIP respectively. The banner remains a transaction even when the legal definition is no longer transactional in name; this is the most common reason consent-reform proposals produce legal-language changes without practice changes. Definitional revision that does not address the visual/interaction design, the consent-management intermediary layer, and industry self-regulation inherits the transaction metaphor’s constraints regardless of legal text. The engineering project is therefore larger than the legal text.
Target concept
The concept under engineering is “consent” as a lawful basis for processing personal data — the act by which a data subject authorizes a controller to collect or use information relating to them, and by which otherwise-prohibited processing is made lawful. The engineering question on the table: under what conditions should an individual’s agreement count as legitimating the processing of their personal data, given that the current conditions demonstrably fail to track whether autonomy was actually exercised?
Two framing facts travel with this target. First, consent is already a heavily engineered concept — GDPR Art. 4(11) is itself a prior amelioration that tightened the 1995 Directive’s “signify” to “clear affirmative action.” The task here re-engineers a deliberate prior design, not folk usage, which sharpens the cost question. Second, a scope assumption that is a Phase A inference and correctable: “current data-privacy law” is read as GDPR-aligned regimes (EU GDPR, UK GDPR, and inheriting frameworks), not the US sectoral patchwork; and “the work it should do” is read as the protective function consent is supposed to discharge (informational autonomy, meaningful control, legitimation), not any particular classification outcome.
Current usage — descriptive baseline
This section maps what the concept currently does; the ameliorative move does not begin here.
- Statutory definition — GDPR Art. 4(11) defines consent as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”
- Operating conditions (Art. 7, Recitals 32/42/43) — freely given (no consent under “clear imbalance,” especially public authority; no bundling/conditionality where data isn’t necessary for the service, Art. 7(4)/Recital 43); specific (separate consent per purpose; granularity); informed (controller identity + purposes disclosed); unambiguous (affirmative act; silence/pre-ticked boxes/inactivity excluded, Recital 32); withdrawable (as easy to withdraw as to give, Art. 7(3)); demonstrable (controller must prove consent, Art. 7(1)).
- Commitment — event/transactional structure — Consent is a discrete act at a point in time, attached to disclosed purposes.
- Commitment — individualism — The unit is the single data subject authorizing for themselves, about “data relating to him or her.”
- Commitment — cognitivist informedness — Validity tracks whether information was supplied (intelligible, plain-language), not whether it was understood or could be acted on.
- Commitment — specificity-per-purpose — Consent is keyed to enumerated purposes fixed at collection.
- Commitment — authorization-as-legitimation — Consent’s primary legal job is to convert a prohibited flow into a permitted one; valid consent is the lawful ground.
- Hinge fact — one of six bases — Consent is only one of six lawful bases under Art. 6(1) (with contract, legal obligation, vital interests, public task, legitimate interests). The statute never required consent to carry the whole protective load. This splits the engineering target: some diagnosed failures may be defects in the concept; others may be defects in the weight placed on it — an over-reliance produced by interface and business-model habit rather than by statute. (One source notes UK GDPR carries seven bases as of 2026; immaterial to the GDPR-aligned framing.)
- Baseline meta-point — The drafters were not naïve: the freely-given/imbalance/anti-bundling provisions are themselves attempts to bolt substantive conditions onto a formal act. The engineering target is not “consent has no safeguards” but that the safeguards are bolted onto a transactional-individual core that may be the wrong core — the seam where the concept is failing.
Identified function failures
- Legitimation should track actual autonomy — current concept’s failure mode: consent legitimates whenever the ritual (a click, an affirmative act) is performed, even when no meaningful choice was exercised; act and autonomy come apart. Cost of the failure: consent becomes a liability-shield that launders processing — Solove’s “Privacy Self-Management and the Consent Dilemma,” 126 Harv. L. Rev. 1880 (2013): notice-and-choice shifts risk onto the individual. The cookie-banner economy is the visible symptom — billions of agreements that legitimate processing while protecting no one.
- Meaningful control at scale — failure mode: the event/individualist structure assumes a tractable number of comprehensible decisions, but digital life generates hundreds of consent events per week against policies tens of thousands of words long. Comprehension is structurally impossible, not a fixable defect. Cost: consent fatigue and rational ignorance; informedness-as-disclosure is satisfiable without anyone being informed; the autonomy certified is notional.
- Voluntariness under power asymmetry — failure mode: GDPR recognizes the imbalance problem mostly only for public authorities and bundling. For dominant private platforms, “agree or don’t use the service” is formally voluntary but substantively coerced; network effects make exit illusory. Cost: consent certifies as free what is take-it-or-leave-it.
- Informed agreement to consequences (aggregation/inference blindness) — failure mode: consent attaches to disclosed purposes at collection but cannot reach inferences derived later, data combined across sources, or model-training uses. Cost: you can validly consent to sharing A and B and be harmed by inferred C (sexual orientation, health, political leaning) you never agreed to and couldn’t anticipate — the most privacy-consequential processing is precisely what consent is structurally blind to.
- Governing flows over time (temporal drift) — failure mode: the event structure fixes meaning at T1, but the value and uses of data change at T2 (the live case: training AI systems on data collected before that use existed). Cost: either consent is read so broadly it’s meaningless, or so narrowly beneficial later uses are blocked; purpose-specificity and technological drift are in direct tension.
- Protecting interests beyond the individual (relational/externality blindness) — failure mode: individualism mis-locates the unit; genetic, social-graph, and behavioral data implicate other people who never consented. Cost: one person’s consent licenses processing affecting relatives or contacts — the harm is networked but the permission is individual; the concept cannot even represent third-party and group harms. This failure is structural, not incidental (Barocas–Nissenbaum on the consent dilemma).
Ameliorative purpose
The smuggle to avoid: “consent should mean ‘agreement that protects privacy’ / ‘that makes processing fair’ / ‘that is opt-in by default’” — each renames a desired verdict rather than specifying a function. The function-shaped specification of what the revised concept must do: a revised concept of consent should
- (i) make explicit the relationship between an authorizing act and the interest it is supposed to protect, so that gaps between the two become visible and governable;
- (ii) remain sensitive to the power conditions under which agreement is given, discriminating agreement-rituals from exercised autonomy and refusing legitimating force to the former;
- (iii) govern data uses — including downstream, inferential, and temporal uses — rather than merely the collection event, allocating the burden of anticipating those consequences away from the party who cannot bear it; and
- (iv) be able to represent interests beyond the individual authorizer, making its legitimating reach co-extensive with the conditions under which agreement is informationally and structurally possible, and no wider.
Function (i) is the one most contested between the autonomy and structural pictures: stated as surfacing the act/interest gap, it is neutral as to how the gap is closed (autonomy theorists close it by improving choice; structural theorists by removing consent’s power to legitimate). An earlier framing — “legitimate only to the extent legitimation tracks a protectable interest” — tilted toward demotion and was deliberately rolled back so the purpose does not pre-decide among candidates. The purpose tells you what work the concept must perform, not who wins any case: a controller could still satisfy it; a data subject could still consent badly.
Note: this concept’s contestation may be constitutive (essentially contested in Gallie’s sense); the engineering move risks treating as resolvable what is in fact the object of legitimate ongoing dispute. Candidate revisions below are offered with this caveat. Consent sits on top of a genuinely essentially-contested normative dispute (Gallie, 1956): between an autonomy/liberal/volitional picture (privacy is individual control; consent is sovereignty; consent is valid if it expresses an actual choice, however constrained) and a structural/contextual/normative-substantive picture (privacy is appropriate information flow governed by social norms; consent is valid only under conditions of adequate options and information). The candidates are not neutral between these: the demotion, fiduciary, and contextual-integrity candidates shift weight toward the structural picture; the collective candidate reframes the dispute as one about the unit rather than the standard. This contestation is, to a meaningful degree, constitutive — not a defect to be engineered away. Conceptual engineering cannot adjudicate the dispute; it can only make explicit which contested conception a given revision presupposes. The analysis is therefore not a resolution but a structured choice about which conception of autonomy to operationalize, offered with the contestation on the table rather than hidden inside a stipulated definition. Anyone committed to the autonomy picture will read demotion as a loss of freedom and will not be wrong on their own premises; the honest move is to flag that, not to present the structural picture as obviously correct.
Candidate revisions
Candidate 1: Scope-bounded / demoted consent (consent should do less). Narrow consent’s legitimating role to contexts where it can function — discrete, comprehensible, low-asymmetry, low-aggregation transactions — and reconceive it elsewhere as authorizing only processing that is independently permissible (passes substantive standards: purpose-legitimacy, data-minimization, non-manipulation). Consent stops being sufficient and becomes one gate among several; beyond its working range, processing rests on substantive bases or prohibition.
Rationale: directly attacks the legitimation-without-autonomy and power-asymmetry failures by removing consent’s power to launder and shifting protective work to non-waivable substantive rules.
Tradeoffs and costs: (a) loses consent’s flexibility as a universal catch-all and forces the law to make substantive fairness judgments it currently outsources — politically harder, more paternalistic; (b) relocated indeterminacy (the sharpest objection): demotion does not dissolve the F1/F2 indeterminacy, it transfers it — “legitimate purpose,” “manipulation” must now be defined by a regulator/court, importing regulatory-capture, political-contestation, and uniformity risks that consent at least distributed across individuals. Net-better condition: this candidate is superior only where institutional definition of substantive limits is more reliable than individual choice — i.e., where individual choice is already fictional (the mass-consumer, structurally-incomprehensible case); it fails for genuinely informed, high-agency choices.
- Sub-variant — consent-eliminativism for high-stakes processing (the far pole). Remove consent as an available lawful basis entirely for high-asymmetry/high-aggregation processing, replacing it with non-waivable rights and bright-line prohibitions, so no quantity of agreement can legitimate those flows. Distinct from demotion: where demotion denies that consent works there, eliminativism denies it should even be offered there. Cost: the sharpest form of the paternalism objection — it forecloses the genuinely competent data-for-service trade along with the fictional one.
Candidate 2: Dynamic / maintained-state consent (temporal re-engineering). Re-engineer the event commitment: consent becomes an ongoing, queryable, revisable, decaying license scoped to live use rather than collection.
Rationale: attacks temporal drift and T1/T2 directly; ties legitimacy to continuing authorization.
Tradeoffs and costs: enormous infrastructure cost; risks more decision-burden (now you must tend your consents); a maintained interface can itself become a dark-pattern surface. Empirical nuance: dynamic-consent models are already deployed in biobank/research-data platforms with real if partial success — so a blanket “dynamic consent worsens fatigue” claim is false. The sharper claim is about generalization: those deployments work in narrow, high-stakes, low-frequency, high-salience settings; high-frequency consumer flows (hundreds of low-stakes events/week) invert all three conditions, so re-prompting there plausibly deepens reflexive clicking. The candidate retains promise precisely where stakes are high and events few — which is also where it overlaps least with the mass-consumer problem motivating the analysis.
Candidate 3: Fiduciary / loyalty-conditioned consent (relational re-engineering). Validity of agreement is conditioned on the controller owing enforceable duties of loyalty and care, such that consent authorizes only uses consistent with the data subject’s interests (Balkin’s information-fiduciary line, Information Fiduciaries and the First Amendment, 49 UC Davis L. Rev. 1183, 2016; the phrase may trace to Laudon in the early 1990s, but the argument is Balkin’s).
Rationale: shifts the anticipation burden off the individual onto the better-informed, more powerful party.
Tradeoffs and costs: arguably stops being “consent” and becomes fiduciary law in consent’s clothing; “the data subject’s interests” is itself contestable and may re-import the indeterminacy it was meant to cure; the conflict-of-interest problem (ad-funded platforms cannot easily be loyal fiduciaries to users they monetize); fiduciary law’s transplant to data relationships is legally unsettled.
Candidate 4: Contextual-integrity-indexed consent. Agreement legitimates only where the resulting flow conforms to context-relative informational norms (Nissenbaum, Privacy in Context, Stanford University Press, 2009). Consent licensing a contextually anomalous flow (health data to advertisers) carries no legitimating force however freely or knowingly given.
Rationale: anchors the concept’s reach in the appropriateness of the flow rather than the act of agreeing.
Tradeoffs and costs: imports the indeterminacy of “contextual norms” — predictability cost for controllers and the hard question of who adjudicates contested or evolving norms.
Candidate 5: Collective / intermediated consent (unit re-engineering). Move the consenting unit off the lone individual: consent is exercised or negotiated at group level by an intermediary — a data trust, data cooperative, or the data-intermediation services the EU Data Governance Act (2022) institutionalizes — bargaining over classes of flows on behalf of members.
Rationale: the only candidate that touches individualism — the failure isolated as structural — pooling the anticipation burden into a body competent to bear it and matching the unit of agreement to the unit of harm where harm is networked.
Tradeoffs and costs: the representation/legitimacy problem — who speaks for the group, how dissenters opt out, whether intermediaries become new gatekeepers with their own incentives. (Maturity confidence: low — data-trust and cooperative practice is nascent and largely untested at regulatory scale; the most experimental candidate.)
- Surfaced tension — peer candidate vs companion concept. One reading holds collective/intermediated consent as a peer candidate revision of consent (re-engineering its unit). A competing reading holds that collective/representational authorization is best understood as a distinct governance concept — collective authorization or governance — that should be named separately and paired with a narrowed individual consent, because calling group authorization “consent” produces a near-homonym (Cappelen’s worry made concrete) and treating it as a co-equal consent revision would itself be
ameliorative-overreach. On this second reading it earns its place as the only answer to relational harm, but as a companion concept, not a competing definition of the target. The disagreement is itself a finding; it is not resolved here.
Recommendation (held loosely — a judgment, not a derivation). Convergent tentative recommendation: a demotion-anchored hybrid — narrow consent to where it works (scope-bounded demotion as the structural backbone) and, where processing must happen beyond that range, govern it by enforceable fiduciary/loyalty duties (the substantive backstop) rather than by a fictional agreement, reserving a separate collective-authorization concept for genuinely relational data categories. The other candidates (dynamic, contextual-integrity, collective) can be read as mechanisms that implement the demotion-plus-substantive-limits frame in the zones it does not abandon. This ordering is an explicitly contestable framing choice, not a finding: a community that locates the core failure in temporal drift could make dynamic consent the primary redefinition; one that locates it in networked harm could make collective consent primary; one that weights the relocated-indeterminacy objection to demotion more heavily lands elsewhere. The ordering reflects a judgment about which failure is most load-bearing, not an engineering result — a designer who weights the failures differently lands elsewhere without error.
Implementation problem
Cappelen, Fixing Language (2018): meaning is set by collective use, not stipulation; proposing a revision is not securing its uptake. The adopters required: legislators (statutory amendment to Art. 4(11)/Art. 7 — glacial, politically fraught; reopening GDPR invites lobbying); regulators/DPAs/EDPB/ICO (the realistic near-term channel — guidelines and enforcement can shift the operative meaning of “freely given” without statutory change); courts (incremental, case-by-case — can invalidate consent in dark-pattern rulings but cannot rebuild the concept wholesale); controllers and standards bodies (adoption via consent-management infrastructure, but their incentives run toward the ritual-consent equilibrium — the coordination problem’s hard core). Crucially the adopter is not the general public: privacy “consent” lives in legal text, one of the few populations where an engineering proposal has an institutional lever, making this more tractable than engineering an ordinary-language concept. The coordination problem is that every actor has reason to wait for the others; the incumbent design benefits the parties with the most lobbying power, and demoting consent reduces a basis controllers rely on — expect resistance proportional to that reliance. A multi-jurisdictional patchwork adds arbitrage risk where a revision is adopted in one jurisdiction and not others; Brussels-effect dynamics help but don’t eliminate this. Because consent is already only one of six bases, the most feasible reform may not redefine consent at all but reallocate weight off it — pushing controllers toward legitimate-interest or statutory bases for processing consent was never suited to legitimate; this reforms the architecture’s reliance on consent rather than the concept, and is institutionally lighter because it uses doctrine that already exists. The realistic mechanism and horizon: incremental regulatory reinterpretation of “freely given”/“specific” ratcheting toward substantive conditions — effectively demotion creeping in by interpretation without statutory redefinition, with codification trailing; a decade-scale process with no guarantee of convergence. Live motion is visible: the UK Data (Use and Access) Act 2025 (Royal Assent / in force 19 June 2025; amends, does not replace, UK GDPR/DPA 2018/PECR) is, per the supplied ICO source, triggering a review of the consent guidance; the EU AI Act and purpose-based prohibitions that don’t bend to consent point the same way. A residual gap remains: even with legal adoption, the behavioral meaning of consent (the click) is shaped by interface design, not statute. A redefinition the consent-banner industry routes around changes the law’s text without changing the territory — the standing map–territory risk.
Revision costs and displacement
Treating the current concept as worthless would be cost-blindness; it does real work worth naming.
- Autonomy’s expressive value / individual sovereignty — assessment: consent, even imperfect, embodies “it’s your data and your call”; demoting it (and fiduciary-conditioning it) risks paternalism — substituting expert judgments of your interests for your choices, so a person cannot authorize certain uses even when they genuinely want to and are competent to. A real autonomy cost, to be named as such.
- Transfer (not removal) of indeterminacy — assessment: demotion’s substantive limits relocate the hard interpretive questions to a regulator/court — centralized and capturable where consent distributed the judgment. A cost even where demotion is net-better.
- Simplicity / single legitimation gateway — assessment: “Did they agree?” is administrable; contextual-integrity and fiduciary tests are far less determinate. Dynamic and demoted legitimacy is contingent and ongoing, raising compliance cost and legal uncertainty. Predictability has value.
- Universality — assessment: consent currently covers cases no other basis fits (genuinely novel, voluntary, non-necessary processing). Narrowing leaves a gap that legitimate-interest or prohibition must fill — and legitimate-interest balancing has its own opacity problems.
- Symbolic/dignitary stake — assessment: even ritual consent affirms that individuals are agents to be asked, not objects to be processed — a non-instrumental loss in conceding consent “can’t work” and routing around it.
- Semantic discontinuity / homonym risk (esp. collective, partly fiduciary) — assessment: if “consent” comes to mean “a license consistent with your interests as judged by a fiduciary standard” or “group authorization,” audiences may hear a different word — Cappelen’s worry: a homonym, not a revision, forfeiting the rhetorical and legal capital the word carries.
- Loss of hard-won safeguard vocabulary — assessment: GDPR’s “freely given / specific / informed / unambiguous” is the product of decades of refinement; a revision discarding it wholesale forfeits accumulated doctrine. Better candidates preserve and re-situate this vocabulary rather than replace it.
Cost assessment (zoned). For high-asymmetry, high-aggregation contexts the losses are worth bearing — the autonomy the current concept “protects” there is already fictional, so demotion forfeits little real autonomy and gains genuine protection, and the relocated-indeterminacy cost is acceptable precisely where the replaced consent is already fictional. For discrete, low-asymmetry transactions the loss is real and consent should be preserved intact. The amelioration should be zoned, not global — itself the demotion candidate’s core claim. A reasonable person weighting individual sovereignty (or distrust of the standard-setter) more heavily lands elsewhere.
Opportunity affordances (the upside register — keeping the ledger honest in both directions). A re-engineered consent is not only a constraint: (a) more beneficial flows under higher trust — dynamic and collective consent can license later, unforeseen beneficial uses (research, AI training under safeguards) that the brittle event-structure concept blocks or fakes, so substantive consent can be wider where trust is real; (b) a legitimacy/trust dividend — consent that demonstrably tracks meaningful choice gives processing a social license the ritual never earns, reducing backlash, enforcement risk, and reputational drag; (c) competitive differentiation — early adopters of substantive consent can turn a compliance cost into a trust-positioning advantage. These are affordances, not guarantees; each depends on the implementation problem being solved well rather than gamed.
Confidence per finding
- Function-failure diagnosis: high. That current consent legitimates without tracking autonomy, fails at scale, mis-handles inference/aggregation, can’t manage temporal drift, and under-protects third parties is well-evidenced and broadly agreed — robustly documented across privacy scholarship and regulatory practice; the firmest of the three judgments.
- Proposed revision(s): moderate-to-low. A revision is clearly needed; which candidate (or blend) best serves the function is a live, contestable design choice resting on a contested theory of autonomy; the collective/intermediated candidate sits specifically at low maturity. The demotion-anchored-hybrid recommendation is a judgment, not a result.
- Adoption feasibility: low-to-moderate and uncertain. Regulatory reinterpretation of “freely given” is the plausible vector (moderate); statutory rebuild is slow and faces a coordination problem whose hard core is that incumbents benefit from the broken status quo (low). This is the least confident of the three judgments and the one most often overstated in conceptual-engineering proposals.
Additional considerations — scope-sensitivity of the diagnosis
How the diagnosis shifts under different starting assumptions, with correction hooks:
- US notice-and-choice baseline: no demonstrability requirement and a far weaker freely-given doctrine strip away the statute’s bolted-on substantive conditions, making the demotion candidate nearly forced — with no regulatory machinery already pushing toward substantive consent, demoting the ritual and resting high-stakes processing on bright-line rules is close to the only available repair.
- Rights-based baseline (Brazil’s LGPD and similar): data protection framed as a fundamental right with non-waivable cores means the eliminativist sub-variant and the fiduciary candidate sit more naturally — the legal furniture for “rights consent can’t override” already exists.
- If “the work” meant legitimation specifically (not autonomy): the demotion candidate becomes nearly forced and the others drop out.
- If the interest is the philosophical theory of consent (not its legal operationalization): the essentially-contested substrate is the real action, not the statutory engineering.
Two uncertainties remain that the available material does not fully determine: whether collective/intermediated authorization is mature enough to stand as a peer candidate versus a thin construct, and whether the re-phrased purpose-function (i) is fully neutral between the autonomy and structural pictures. These are flagged as remaining uncertainties rather than resolved.