The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

Consent in data protection law undermines privacy rather than securing it, because it institutionalises disclosures that produce negative externalities and free‑riding; the article argues policymakers should abolish consent as a legal basis and pursue collective, rights‑based alternatives.

The Case for Abolishing Consent in Data Privacy Law
Emmanouil Bougiakiotis · August 11, 2026 · German Law Journal
openalex theoretical n/a evidence 7/10 relevance Full text usable extracted full text DOI Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

OpenAlex

Latest observation:

  1. Emmanouil Bougiakiotis provider ID

Semantic Scholar

Latest observation:

  1. Emmanouil Bougiakiotis provider ID
The paper argues that consent should be abolished as a legal basis in data protection because consent inherently enables disclosures, creates negative externalities and public‑good problems that cannot be resolved by improving individual decision‑making, and should be replaced by rights-based and collective governance approaches.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Abstract Consent in data protection law is highly contentious. Critics argue that enabling people to make their own decisions is not feasible, as people are generally poor decision-makers. However, proponents insist on the value of consent as a tool of empowerment. This Article challenges the foundational assumptions of this debate: that consent is conducive to privacy; that the decision to share one’s data concerns mainly the person sharing them; and that if we were to bridge the gap between the layperson and the ideal decision-maker, we would achieve an optimal level of data privacy protection. Setting aside these false assumptions, this Article aims to resituate the consent debate in a framework that rests on more solid theoretical ground. First, it connects the economic concept of data externalities with the philosophical idea of the harm principle. This highlights how unilaterally imposing burdens on others, without consideration of their interests, is morally unjustifiable, thereby depriving consent of its normative justification. Second, it examines privacy as a public good, demonstrating that even rational decision-makers are bound to freeride on each other’s data privacy and make everyone worse-off, thereby rendering consent undesirable. Therefore, this Article concludes that we should abolish consent, while retaining individual control over data through data privacy rights.

Summary

Main Finding

The Article argues that consent as a legal basis in data protection should be abolished. Consent intrinsically enables disclosures and thus reduces privacy; because data processing is relational and generates negative externalities and public‑goods problems, even perfectly informed, rational consenters (the “ideal” decision‑makers) will produce collective outcomes that are welfare‑reducing. By tying economic externalities to the philosophical harm principle, the author concludes consent lacks a sufficient normative justification. Instead of consent, privacy should be regulated through individual data‑privacy rights and collective/structural governance that address relational harms.

Key Points

  • Consent facilitates disclosure. Consent’s primary legal function is to authorize collection/processing; therefore it tends to diminish, not enhance, privacy. At best withholding consent preserves the status quo; at worst consent enables information flows that reduce others’ privacy.
  • The dominant framing that consent can be fixed by better information or user empowerment is misguided. Even if people behaved as homo economicus (fully rational, fully informed), the relational nature of data creates negative information externalities and public‑goods problems that produce inefficient equilibria (over‑disclosure/free‑riding).
  • Data externalities: one person’s disclosure often imposes costs on others (reduction of their privacy, predictive inferences, increased profiling). These are classic negative externalities that markets and individualized consent fail to internalize.
  • Public‑goods logic: privacy (or aspects of it) behaves like a public/aggregate good. Rational agents will free‑ride on others’ privacy choices, causing everyone to be worse off; individualized consent cannot solve this coordination failure.
  • Normative framing: linking externalities to the harm principle shows why some disclosures can be morally unjustifiable even if consented to by the discloser—unilateral imposition of burdens on others without regard to their interests is wrongful.
  • Legal theory implications: informational self‑determination (ISD) and control‑based accounts of privacy are insufficient responses because they do not address relational harms. Abolishing consent does not mean removing individual control—data privacy rights (limits on collection/use, rights to deletion, purpose limits, etc.) should be retained and restructured.
  • The Article surveys alternatives and objections and argues that reforming consent or improving notice is not an adequate fix; the problem is structural and requires shifting away from consent as the central tool.

Data & Methods

  • Methodology: conceptual, doctrinal and normative analysis. The Article combines legal doctrinal work (analysis of GDPR and EU legal concepts such as informational self‑determination), economic theory (externalities, public goods, Coasean insights), and philosophical argument (harm principle).
  • Evidence base: literature synthesis and theoretical argumentation rather than original empirical data. The author grounds claims in economics/legal scholarship (e.g., work on data externalities, privacy as a public good, critiques of notice‑and‑consent) and uses thought experiments (the Alex vignette and a homo economicus counterfactual) to illustrate failures of consent.
  • Analytical moves: (1) reframe consent as an enabling mechanism for disclosure rather than as empowerment; (2) map economic externality theory onto privacy harms and invoke the harm principle to yield normative constraints; (3) use public‑goods logic to show why individual consent leads to collective inefficiency even under idealized assumptions.

Implications for AI Economics

  • Market failure in data supply: Consent‑centric regimes will systematically underprice or fail to internalize negative third‑party effects from data use (inferences, re‑identification, spillovers). This can lead to over‑collection of data that improves model performance but imposes unpriced social costs (privacy loss, discrimination, informational harms).
  • Rethinking legal baselines changes incentives for firms and data markets. Abolishing consent as the primary legal basis would push regulators toward:
    • stronger categorical or purpose‑based prohibitions on some data uses,
    • ex ante restrictions and mandatory limits (rather than user approvals) that constrain what datasets firms may assemble,
    • rights‑based controls (deletion, portability, access limits) and structural remedies (data minimization, purpose limitation, data provenance). These shifts alter the supply of usable training data and thus the estimated social value of AI applications; economists modeling AI production functions must account for regulatory constraints that reduce raw data availability.
  • Internalizing externalities requires collective or regulatory instruments. Economic tools that could be explored or redesigned include:
    • Pigouvian taxes or fees on data practices that generate measurable externalities,
    • mandated liability/compensation schemes for demonstrable downstream harms,
    • market institutions for collective bargaining or collective consent (data trusts, commons governance) that can negotiate on behalf of groups affected by relational disclosures,
    • public provisioning of privacy‑safe datasets (synthetic or DP‑noised) to substitute for unrestricted data access.
  • Design and mechanism consequences: mechanism design for data markets must move beyond bilateral consent pricing to multi‑party incentive structures—contracts, side payments, or regulation that internalize cross‑person externalities. Standard market designs (per‑user opt‑in pricing) are insufficient.
  • Technical mitigations and cost‑tradeoffs: privacy‑preserving ML methods (differential privacy, federated learning, secure aggregation) become more attractive policy complements, but they also change model quality and economic trade‑offs. AI economists should quantify welfare trade‑offs between model accuracy and privacy guarantees when consent is not the main governance lever.
  • Empirical research agenda: quantify the magnitude of data externalities (how much one person’s disclosure improves model accuracy vs. social privacy loss); estimate welfare implications of different governance regimes (consent‑based vs rights/collective‑governance); simulate market responses by platforms and intermediaries to abolition of consent.
  • Transitional and international considerations: abolishing consent in one jurisdiction will affect global data flows and market equilibria—cross‑border regulatory arbitrage, shifts in corporate data strategies, and compliance costs must be modeled. Comparative institutional responses (EU style rights vs. U.S. sectoral rules) will produce different economic outcomes for AI ecosystems.
  • Policy trade‑offs to model: reduced data availability may slow some AI deployment or raise costs, but eliminating consent avoids systematic under‑internalization of harms and could increase aggregate welfare if collective harms are large. AI economics models must incorporate the distributional effects (who bears costs, which firms gain/lose, effects on innovation and competition).

Suggested priorities for AI economists responding to this argument: - Build formal models of multi‑agent externalities from individual data disclosures and simulate equilibria under (a) consent‑centric regimes and (b) rights/collective regimes. - Estimate externality magnitudes empirically (how much a marginal disclosure changes risk to others or model performance). - Evaluate policy instruments (taxes, liabilities, data trusts, mandatory limits, technical constraints) for welfare, incentives, and feasibility. - Study how changes to the legal basis for data (abolishing consent) would affect platform business models, market entry, and competitive dynamics.

Overall, the Article reframes the problem from fixing consent to addressing structural externalities and collective governance—an agenda that requires AI economics to move beyond individual willingness‑to‑sell/willingness‑to‑accept models and to incorporate multi‑party harms, public‑goods logic, and new regulatory instruments.

Assessment

Paper Typetheoretical Evidence Strengthn/a — This is a normative/theoretical legal- philosophical article that develops an argument against consent using conceptual analysis, economic theory (externalities/public goods) and the harm principle rather than original empirical or causal identification. Methods Rigormedium — The paper mounts a careful, well-referenced conceptual and normative argument, synthesizing law, economics and philosophy and engaging prior literature; however it lacks empirical testing, formal modeling, or quantitative validation of key claims about magnitudes or real-world effects. SampleNo empirical sample or dataset; the paper uses doctrinal analysis, literature synthesis (economics, legal scholarship, philosophy), thought experiments (e.g. 'Alex') and normative argumentation. Themesgovernance adoption GeneralizabilityArgument is normative/theoretical and not empirically validated in specific jurisdictions or industries., Applicability may vary by legal system (EU vs US vs others) given different rights frameworks and regulatory institutions., Does not quantify the size or distribution of data externalities across sectors or populations, so policy implications may differ in practice., Practical implementation, enforcement costs, and political feasibility are not empirically assessed., Technological specifics of AI systems (models, data architectures) are discussed conceptually but not empirically modeled, limiting technical generalizability.

Claims (7)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Even if individuals made fully informed and rational data-sharing decisions, consent would still fail to produce optimal data privacy protection. Governance And Regulation negative Level and effectiveness of data privacy protection under consent-based governance
Reading fidelity high
Study strength medium
not reported
0.12
Consent is antithetical to privacy because its function is to facilitate the disclosure, collection, and processing of information. Governance And Regulation negative Privacy protection, understood as limiting access to information about data subjects
Reading fidelity high
Study strength medium
not reported
0.12
Consent to disclose personal data can impose privacy costs on third parties who are not parties to the data-sharing transaction. Governance And Regulation negative Third-party privacy and exposure to data-related harms
Reading fidelity high
Study strength medium
not reported
0.12
Because privacy has public-good characteristics, individuals can rationally free ride on one another’s privacy, producing an inefficient outcome in which everyone is worse off. Governance And Regulation negative Collective privacy protection and efficiency of individual consent decisions
Reading fidelity high
Study strength medium
not reported
0.12
The central problem with consent-based privacy governance is not merely that individuals lack information or rationality; even an ideal version of the model would fail to protect privacy optimally. Governance And Regulation negative Optimality of privacy protection under individual consent and privacy self-management
Reading fidelity high
Study strength medium
not reported
0.12
Consent can at best preserve the level of privacy that would exist without consent as a legal basis for processing, while at worst it enables disclosures that increase what others know about the data subject and potentially about other people. Governance And Regulation negative Privacy level resulting from granting or withholding consent
Reading fidelity high
Study strength medium
not reported
0.12
The article argues that consent in data privacy law should be abolished while individual control over data should be retained through data privacy rights. Governance And Regulation positive Effectiveness of the proposed data privacy governance framework
Reading fidelity high
Study strength speculative
not reported
0.02

Notes