ABSTRACT / INTRODUCTION
The cookie banner is modest, but it rests on a very old jurisprudential question: what can it possibly mean that a person ‘consents’ to something that she does not understand, that she cannot effectively refuse (having encountered it dozens of times that day) and that she may encounter again and again? In this short article I do not seek to tackle, on a site-to-site basis, whether any given banner is lawful. This article’s scope is more limited, but arguably a more profound: to use the third-party cookie as a case study in the theory of consent itself, as a legal fiction, as a behavioural artefact and as a battleground of contestation between autonomy-centred and welfare-centred justifications for data protection.
The enquiry takes its starting point from the following premise: Consent doctrine, whatever form it takes in positive law, assumes a rational, sufficiently informed actor that is able to make a credible choice. Arguably, the third-party cookie regime was intended for precisely the opposite world one in which friction, opacity and repetition would lead to a rubber-stamp of approval in the absence of otherwise present preference. That the paradigms of the user prescribed by one body of doctrinal material (GDPR, the ePrivacy framework, comparative US and Indian law, and the prominent CJEU decisions) is the immediate focus of the essay, and it is here taken less as a rulebook to be applied than as evidence in a larger debate.
Three conceptual lenses structure the analysis. The autonomy lens central to philosophical/normative writings conceptualizes the consent requirement as a recognition of a person ‘s right to control her own body, which is valuable in itself, whether or not it leads to the best outcome. The market failure lens sometimes called the ‘meta-model’ conceptualizes the consent requirement as a correction for the market failure caused by information asymmetry between platform and user, which is instrumentally valuable to the extent that it leads to the most efficient, welfare-maximising outcome. The fundamental rights lens the dominant approach in the EU and Indian constitutional doctrine conceives of data protection as upholding human dignity against the totalizing power of the market and the state, which cannot be understood fully in terms of either individual autonomy or optimal welfare.
BACKGROUND / LEGAL FRAMEWORK
CONSENT AS LEGAL FICTION
The definition of consent maintained by positive law ‘a freely given, specific, informed, and unambiguous indication of wishes’[1] (in the EU) can best be understood not as a statement about what actually happens when a user clicks on a banner, but as a regulatory ideal against which the adequacy of the click can be judged. Importantly, the disparity between the ideal and the phenomenon it claims to regulate is also a site of theoretical interest: it implies that the function of consent doctrine is not to describe our ‘psychological reality’ but rather to allocate the burden of justification onto anyone who desires to deviate from the privacy-protective default.
Article 5(3) of the ePrivacy[2] Directive provides the definitive presumption: information stored or accessed on a user‟s terminal equipment requires the informed, freely given consent of the user, unless it is strictly necessary for the provision of a service explicitly requested by the user. Theoretically however, the strict-necessity carve-out does more than it appears to, as the exception at this point is where the law concedes that information software so integral to the service requested by the user that the notion of consent cannot otherwise be reconciled with the request, tending instead to implied authorisation.
THE CONDITIONALITY PROBLEM
Article 7(4) GDPR which states that consent is not freely given if it is based on an offer made a condition of another enjoyment prefers the autonomous explanation.[3] It presupposes that making a decision under a threat of deprivation from a service that-service, especially on the basis of a no-good-choices alternative-is not really making a decision. Such a presupposition can be challenged. Under contract theory, a “take-what-you-get” scenario would normally constitute an infringement of the freedom of contract but Article 7(4) merely introduces a substantive fairness requirement more characteristic of the doctrine of unconscionability or consumer jurisdiction than of traditional contract law: with the latter, data protection theory reveals a strange mixture.
DIGNITY AS AN INDEPENDENT VALUE
First, as demonstrated by the Charter of Fundamental Rights, Article 8 makes a clear textual distinction between the protection of personal data, and the right to respect for private life and family under Article 7.[4] Like many formal distinctions in European law that balance the scope of different rights, this may be of more than just theoretical significance: it touches upon the presuppositions and limitations of informational self-determination, and marks out Informational self-determination Not just as a version of the privacy-as-seclusion paradigm, but also as an autonomous conception of human dignity as such, too.
India ‘s constitutional jurisprudence draws an equally follows a different path, culminating in the same end. Puttaswamy cantered privacy in the right to life and personal liberty protected by Article 21, effectively submerging informational privacy as a species of profound right and not a standalone, transactional right to the individual.[5] Though qualified by markedly different doctrinal foundations a written article versus a broad interpretation of ‘life and personal liberty’ the European and Indian views agree.
THE MARKET-FAILURE ACCOUNT
A competing framework more popular in the United States (where state privacy law ultimately allowed opt-outs), as well as in the European Union (which essentially mandates opt-ins) treats any leniency in default already chosen as an instrumental tool, not an end in itself, in correcting the informational imbalance between platform and user. Under that analysis, opt-out default is not an inferior type of protection, but instead a different and arguably more beneficial instrument, for rectifying the same problem (namely, that limiting transaction costs by requiring action on the part of users prematurely under an opt-in model) by shifting the consumer‘s decision-making costs from the point of initial engagement to the point at which the user actually takes a specific exception. It remains to be seen whether this cost-shifting is theoretically justified, as a matter of economics, or solely a matter of market efficiency; the material comparison in Part III undermines the argument either way.
MAIN ANALYSIS & CASE STUDIES
PLANET49 AND THE REJECTION OF INERTIA
In Planet49, the CJEU determined that a pre-ticked box could not constitute consent under the above definition, since consent must be given through obvious, express action.[6] More generally, this ruling can be interpreted as a strong argument against relying on default-based reasoning as a basis for legitimacy: the Court refused to treat inertia simply not unchecking a box as an expression of will. This is essential to this line of argument for reasons beyond the Court ‘s formal conclusion, as it explicitly repudiates the market-failure account ‘s acceptance of default-based mechanisms. If defaults could stand in for preference, the opt-out cookie protocol would be valid under the GDPR; Planet49 dismisses this conclusion with respect to consent-based processing, solidifying the autonomy framework in statutory law, not simply policy opinion.
FASHION ID AND THE DIFFUSION OF RESPONSIBILITY
Fashion ID‘s conclusion that the embedding site was a joint controller of data transmitted by a third-party plug-in[7] might, in the eyes of some, be a structural rather than theoretical answer to one such challenge: that the modern web, not a bilateral affair between publisher and user but a web of publishers, ad tech intermediaries and data-brokers, all further separated by an octopus-like web of contacts, and all with its functions and respective responsibilities largely invisible, an entire tree-node of which is available only at click (fashion ID, and the browser)won‘t do it again. By refusing the web publisher jurisdiction to offload responsibility to the mysterious third-party, the Court, as seemingly pragmatic in avoidance as it is in judgment, pegs work-forcing the consent pre-condition to the visible web (the, ‘thing available for the user to view and manipulate’) and not the amorphous series of invisible sub-corporates.
THE CNIL FINES AS A THEORY OF FRICTION
The French Conseil d’état’s partial annulment of permissive CNIL guidance[8] and the CNIL‘s subsequent fining of Google and Facebook for asymmetric click-depth measurement between acceptance and refusal[9] all model what we might call a friction theory of consent: that the number of discrete deeds demanded of us in order to exercise a preference is not a value-neutral design decision, but is in fact constitutive of whether that preference actually constitutes a valid sign of consent. This behaviourally rich insight underpins formal legal doctrine: that autonomy as a matter of law cannot be divorced from the choice architecture which in fact convoys it.
THE TCF DECISION AND THE LIMITS OF SELF-REGULATION
The analogous ruling of the Belgian data protection authority that IAB Europe‘s TCF[10] itself was illegal uncovers an even more fundamental fault line: that an industry-wide technical standard putting sustainable legal consent into effect scaled up more or less automatically tended to reproduce the asymmetries it was looking to address by treating consent as a data point for archiving and communicating rather than as a normative relation for preserving. The incident suggests that standardising the act of consenting and making it into a uniform string of bits has the risk of substituting the structural control that was initially desired with simple compliance with a procedure.
THE AMERICAN COUNTER-MODEL
The opt-out architecture[11] of the CCPA is the most comprehensive legislative embodiment of the market-failure narrative. It does not require that a particular case of tracking was consented to in the most philosophically rigorous sense, only that there was a way for the consumer to opt-out that was given to the consumer and that the consumer could use free of charge. Relative to the autonomy narrative this seems to be a weaker form of protection; compared with a purely welfarist paradigm it is perhaps a more proportionate one, since it takes into account the utility gained from decision costs incurred to users of routine, unincentivized tracking while still providing a (mild) incentive to those users to opt-out.
INDIA’S UNSETTLED THEORETICAL POSITION
India ‘s DPDPA has implementing consent language[12] that is textually closer to that of the EU than to the American default position but at the very moment it wraps said text in a constitutional wrapping Puttaswamy ‘s dignitarian reading of Article 21 that has yet to be put to the test vis-a-vis the actual problem of tracking. It arrives theoretically at an uncompromising crossroads: a rights-based constitutional starting point, a consent-based statutory text, and, as of yet, no interpretive doctrine capable of determining which of the three frames identified in Part I will ultimately determine India ‘s cookie jurisprudence.
CRITICAL ANALYSIS & EVALUATION
THE INCOHERENCE OF LAYERED FRAMES
The circumstances examined above indicate that none of the three doctrinal frames offers a comprehensive explanation for existing cookie doctrine. The GDPR‘s welfarist balancing frame is represented by Article 7(4) conditionality, the Guide welfare-based plan of the Article 7(4) rule of the EDPB excising is lmpowerment that permits legitimate interest as an alternative ground for certain types of processing is a sign of a somewhat more welfarist compliance monitor authoritarian welfarism, enabling a welfarist balancing test to be interpreted flexibly, whereas the more welfarist welfare frame of the Charter‘s Article 8 dignity rights framing quotes both, unwilling to be co-opted by either of them. The resulting cookie doctrine is something of a symbiosis, not a synthesis, of these three frames, with litigants (including regulators) free to interpret and rely on whichever constitutes the most expedient framing strategy for a particular case: an instance of theoretical arbitrage.
THE REGULATORY-GUIDANCE/BINDING-LAW DISTINCTION AS THEORETICAL SYMPTOM
It is also important to remember that most of the bridge linking this abstract statutory principle to their concrete instantiation including the EDPB ‘s business and ‘cookie walls’ are presumptively null is only interpretative guidance, not law[13]. This is a fundamentally revealing observation: it indicates that legislatures have either refused or failed to resolve the autonomy/welfare tension in primary law, thereby forcing regulators to predominate with soft law that apes the language of autonomy but does not carry the constitutional authority to which it would otherwise be entitled.
PROCEDURALISATION AS A RECURRING FAILURE MODE
What is clear across every jurisdiction in common though is the consistent overlay that consent is not ‘per se’ unwanted, it is administratively too fragile that it seems inevitable that every effort to roll it out to the masses Pré ticked, the TCF, opt-out signals- ultimately seems to knock it into a formal mechanic, a tick box, divorced from the real content that it was supposed to be doing its job protecting. And this ultimately speaks to a (structural, not drafting)overriding fault of the theory, rather than the way in which it is applied the core issue with consent in this case is that it might just simply be non-scalable in the transaction volume of the modern web without diluting its content enough to undermine its raison d’être.
- A SPECULATIVE REFRAMING
Rejecting the friction and proceduralisation imperatives would appear to lead to a slightly different, and perhaps more compelling, theoretical conclusion: that the best response is to give up on the transactional consent regulation of third-party tracking altogether, and replace it with–or perhaps just supplement it with–ex ante, structural, common-sense limits on what may be transmitted and to whom. That is, the legitimacy would move from the individual click to the system and would be grantee to the minimum platform architecture instead of the individual transaction abstraction. This fifth can be seen to adhere least to the first three frames discussed in Part I, and to tend more toward a fourth, paternalist-structuralist paradigm.
CONCLUSION
In this article, the third-party cookie has functioned not merely as a narrowly technical compliance issue but also as a vehicle for comparing debates about many notions of consent that are drifting apart in the rapid waters of regulation. The autonomy frame, lay most bare in Planet49 and Article 7(4) of the GDPR, says that if a choice is made under the duress of not-buying, then it is no choice at all. The market-failure frame, as it were, within the CCPA ‘s opt-out architecture, reads consent instrumentally, as a stopgap not a prerequisite. The fundamental-rights frame, pioneered by the EU Charter and embraced by the Puttaswamy touchstone in India, stands in opposition to the equation of data protection with either filing system, by requiring dignity be acknowledged as an independent limitation.
None of the three frames, considered independently, provides a fully satisfying explanation as to why cookie consent so reliably collapses into ritual. Its persistent collapse by jurisdiction-level phenomena dark patterns in the EU, opt-out fatigue in the US, doctrinal neglect in India points to the more general failure not of any one frame but of the very concept of maintaining any transactional theory of consent at the large scale the contemporary internet requires. Whether the law ‘s next move will be toward an increasingly rigorous transactional model, or away from the transaction entirely in favor of structural, default-setting regulation, is the key unresolved question left open by this article for future doctrinal and theoretical inquiry.
BIBLIOGRAPHY
Legislation
- Charter of Fundamental Rights of the European Union [2012] OJ C 326/391.
- Digital Personal Data Protection Act 2023 (India).
- Directive 2002/58/EC (ePrivacy Directive) [2002] OJ L 201/37.
- Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L 119/1.
- California Consumer Privacy Act 2018 (CCPA), as amended by the California Privacy Rights Act 2020.
Cases
- Fashion ID GmbH & Co KG v Verbraucherzentrale NRW eV (Case C-40/17) EU:C: 2019:629.
- Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
- Planet49 GmbH v Bundesverband der Verbraucherzentralen (Case C-673/17) EU:C: 2019:801.
- Conseil d’État No 434684 (19 June 2020).
Official Materials
- Belgian Data Protection Authority, Decision 21/2022.
- CNIL, Deliberation Nos SAN-2021-023 and SAN-2021-024 (2022).
- European Data Protection Board, Guidelines 05/2020 on Consent under Regulation (EU) 2016/679.
[1] GDPR, Regulation (EU) 2016/679, art 4(11).
[2] ePrivacy Directive 2002/58/EC, art 5(3), as amended by Directive 2009/136/EC.
[3] GDPR, art 7(4).
[4] Charter of Fundamental Rights of the EU, arts 7–8.
[5] Justice K.S. Puttaswamy (Retd.) v Union of India, (2017) 10 SCC 1.
[6] Planet49 GmbH v Bundesverband der Verbraucherzentralen [2019]
[7] Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV [2019]
[8] Conseil d’État, 19 June 2020, No. 434684.
[9] CNIL, Deliberation No. SAN-2021-023/024 (Google/Facebook, Jan 2022).
[10] Belgian DPA, Decision 21/2022 (IAB Europe TCF).
[11] Cal. Civ. Code §§ 1798.100 et seq. (CCPA, as amended by CPRA).
[12] Digital Personal Data Protection Act, 2023 (India), § 6.
[13] EDPB, Guidelines 05/2020 on Consent, paras 27–33.