0 cumulative citations
View corpus contextConsent in data protection law undermines privacy rather than securing it, because it institutionalises disclosures that produce negative externalities and free‑riding; the article argues policymakers should abolish consent as a legal basis and pursue collective, rights‑based alternatives.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
0 cumulative citations
View corpus contextAbstract Consent in data protection law is highly contentious. Critics argue that enabling people to make their own decisions is not feasible, as people are generally poor decision-makers. However, proponents insist on the value of consent as a tool of empowerment. This Article challenges the foundational assumptions of this debate: that consent is conducive to privacy; that the decision to share one’s data concerns mainly the person sharing them; and that if we were to bridge the gap between the layperson and the ideal decision-maker, we would achieve an optimal level of data privacy protection. Setting aside these false assumptions, this Article aims to resituate the consent debate in a framework that rests on more solid theoretical ground. First, it connects the economic concept of data externalities with the philosophical idea of the harm principle. This highlights how unilaterally imposing burdens on others, without consideration of their interests, is morally unjustifiable, thereby depriving consent of its normative justification. Second, it examines privacy as a public good, demonstrating that even rational decision-makers are bound to freeride on each other’s data privacy and make everyone worse-off, thereby rendering consent undesirable. Therefore, this Article concludes that we should abolish consent, while retaining individual control over data through data privacy rights.
Summary
Main Finding
The Article argues that consent as a legal basis in data protection should be abolished. Consent intrinsically enables disclosures and thus reduces privacy; because data processing is relational and generates negative externalities and public‑goods problems, even perfectly informed, rational consenters (the “ideal” decision‑makers) will produce collective outcomes that are welfare‑reducing. By tying economic externalities to the philosophical harm principle, the author concludes consent lacks a sufficient normative justification. Instead of consent, privacy should be regulated through individual data‑privacy rights and collective/structural governance that address relational harms.
Key Points
- Consent facilitates disclosure. Consent’s primary legal function is to authorize collection/processing; therefore it tends to diminish, not enhance, privacy. At best withholding consent preserves the status quo; at worst consent enables information flows that reduce others’ privacy.
- The dominant framing that consent can be fixed by better information or user empowerment is misguided. Even if people behaved as homo economicus (fully rational, fully informed), the relational nature of data creates negative information externalities and public‑goods problems that produce inefficient equilibria (over‑disclosure/free‑riding).
- Data externalities: one person’s disclosure often imposes costs on others (reduction of their privacy, predictive inferences, increased profiling). These are classic negative externalities that markets and individualized consent fail to internalize.
- Public‑goods logic: privacy (or aspects of it) behaves like a public/aggregate good. Rational agents will free‑ride on others’ privacy choices, causing everyone to be worse off; individualized consent cannot solve this coordination failure.
- Normative framing: linking externalities to the harm principle shows why some disclosures can be morally unjustifiable even if consented to by the discloser—unilateral imposition of burdens on others without regard to their interests is wrongful.
- Legal theory implications: informational self‑determination (ISD) and control‑based accounts of privacy are insufficient responses because they do not address relational harms. Abolishing consent does not mean removing individual control—data privacy rights (limits on collection/use, rights to deletion, purpose limits, etc.) should be retained and restructured.
- The Article surveys alternatives and objections and argues that reforming consent or improving notice is not an adequate fix; the problem is structural and requires shifting away from consent as the central tool.
Data & Methods
- Methodology: conceptual, doctrinal and normative analysis. The Article combines legal doctrinal work (analysis of GDPR and EU legal concepts such as informational self‑determination), economic theory (externalities, public goods, Coasean insights), and philosophical argument (harm principle).
- Evidence base: literature synthesis and theoretical argumentation rather than original empirical data. The author grounds claims in economics/legal scholarship (e.g., work on data externalities, privacy as a public good, critiques of notice‑and‑consent) and uses thought experiments (the Alex vignette and a homo economicus counterfactual) to illustrate failures of consent.
- Analytical moves: (1) reframe consent as an enabling mechanism for disclosure rather than as empowerment; (2) map economic externality theory onto privacy harms and invoke the harm principle to yield normative constraints; (3) use public‑goods logic to show why individual consent leads to collective inefficiency even under idealized assumptions.
Implications for AI Economics
- Market failure in data supply: Consent‑centric regimes will systematically underprice or fail to internalize negative third‑party effects from data use (inferences, re‑identification, spillovers). This can lead to over‑collection of data that improves model performance but imposes unpriced social costs (privacy loss, discrimination, informational harms).
- Rethinking legal baselines changes incentives for firms and data markets. Abolishing consent as the primary legal basis would push regulators toward:
- stronger categorical or purpose‑based prohibitions on some data uses,
- ex ante restrictions and mandatory limits (rather than user approvals) that constrain what datasets firms may assemble,
- rights‑based controls (deletion, portability, access limits) and structural remedies (data minimization, purpose limitation, data provenance). These shifts alter the supply of usable training data and thus the estimated social value of AI applications; economists modeling AI production functions must account for regulatory constraints that reduce raw data availability.
- Internalizing externalities requires collective or regulatory instruments. Economic tools that could be explored or redesigned include:
- Pigouvian taxes or fees on data practices that generate measurable externalities,
- mandated liability/compensation schemes for demonstrable downstream harms,
- market institutions for collective bargaining or collective consent (data trusts, commons governance) that can negotiate on behalf of groups affected by relational disclosures,
- public provisioning of privacy‑safe datasets (synthetic or DP‑noised) to substitute for unrestricted data access.
- Design and mechanism consequences: mechanism design for data markets must move beyond bilateral consent pricing to multi‑party incentive structures—contracts, side payments, or regulation that internalize cross‑person externalities. Standard market designs (per‑user opt‑in pricing) are insufficient.
- Technical mitigations and cost‑tradeoffs: privacy‑preserving ML methods (differential privacy, federated learning, secure aggregation) become more attractive policy complements, but they also change model quality and economic trade‑offs. AI economists should quantify welfare trade‑offs between model accuracy and privacy guarantees when consent is not the main governance lever.
- Empirical research agenda: quantify the magnitude of data externalities (how much one person’s disclosure improves model accuracy vs. social privacy loss); estimate welfare implications of different governance regimes (consent‑based vs rights/collective‑governance); simulate market responses by platforms and intermediaries to abolition of consent.
- Transitional and international considerations: abolishing consent in one jurisdiction will affect global data flows and market equilibria—cross‑border regulatory arbitrage, shifts in corporate data strategies, and compliance costs must be modeled. Comparative institutional responses (EU style rights vs. U.S. sectoral rules) will produce different economic outcomes for AI ecosystems.
- Policy trade‑offs to model: reduced data availability may slow some AI deployment or raise costs, but eliminating consent avoids systematic under‑internalization of harms and could increase aggregate welfare if collective harms are large. AI economics models must incorporate the distributional effects (who bears costs, which firms gain/lose, effects on innovation and competition).
Suggested priorities for AI economists responding to this argument: - Build formal models of multi‑agent externalities from individual data disclosures and simulate equilibria under (a) consent‑centric regimes and (b) rights/collective regimes. - Estimate externality magnitudes empirically (how much a marginal disclosure changes risk to others or model performance). - Evaluate policy instruments (taxes, liabilities, data trusts, mandatory limits, technical constraints) for welfare, incentives, and feasibility. - Study how changes to the legal basis for data (abolishing consent) would affect platform business models, market entry, and competitive dynamics.
Overall, the Article reframes the problem from fixing consent to addressing structural externalities and collective governance—an agenda that requires AI economics to move beyond individual willingness‑to‑sell/willingness‑to‑accept models and to incorporate multi‑party harms, public‑goods logic, and new regulatory instruments.
Assessment
Claims (7)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| Even if individuals made fully informed and rational data-sharing decisions, consent would still fail to produce optimal data privacy protection. Governance And Regulation | negative | Level and effectiveness of data privacy protection under consent-based governance |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Consent is antithetical to privacy because its function is to facilitate the disclosure, collection, and processing of information. Governance And Regulation | negative | Privacy protection, understood as limiting access to information about data subjects |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Consent to disclose personal data can impose privacy costs on third parties who are not parties to the data-sharing transaction. Governance And Regulation | negative | Third-party privacy and exposure to data-related harms |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Because privacy has public-good characteristics, individuals can rationally free ride on one another’s privacy, producing an inefficient outcome in which everyone is worse off. Governance And Regulation | negative | Collective privacy protection and efficiency of individual consent decisions |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The central problem with consent-based privacy governance is not merely that individuals lack information or rationality; even an ideal version of the model would fail to protect privacy optimally. Governance And Regulation | negative | Optimality of privacy protection under individual consent and privacy self-management |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Consent can at best preserve the level of privacy that would exist without consent as a legal basis for processing, while at worst it enables disclosures that increase what others know about the data subject and potentially about other people. Governance And Regulation | negative | Privacy level resulting from granting or withholding consent |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The article argues that consent in data privacy law should be abolished while individual control over data should be retained through data privacy rights. Governance And Regulation | positive | Effectiveness of the proposed data privacy governance framework |
Reading fidelity
high
Study strength
speculative
|
not reported
|