Consent management is closely tied to data privacy and relates to what users have agreed to in terms of if and how their data can be used. This can be to receive communication, for tracking behaviour and creating profiles that drive AI interaction. There is a legal dimension when it comes to consent management and there is a psychological dimension. The former is more widely known and applied. The latter is less understood and attended to, yet the psychological aspects of consent mechanisms can make or break customer trust and loyalty.
From a legal perspective, the GDPR[i] specifies the measures data controllers must take to ensure that users are giving informed consent to their data sharing. In Article 4(11) it specifies that “consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”. These terms, while clear, are open to interpretation. However, “freely given” should be understood as ruling out coercion or bundling by making consent a condition of using a service that doesn’t actually require the data. “Specific” would rule out catch-all consents such as cookie banners that make Accept All a single click and Reject a six-step process. “Informed” requires the person to actually understand what they are agreeing to, knowing what the consequences are, in plain language. And consent must be as easy to withdraw as it is to give. Furthermore, companies need to get new consent from data subjects if they plan to process their data for further purposes. Many other AI frameworks and polices such as the OECD AI Principles[ii], NIST AI RMF 1.0[iii], ASEAN Guide on AI Governance and Ethics[iv], and the African Union Continental AI Strategy[v] indirectly address consent-related measures through their protection of human rights, privacy, and autonomy. And, while not specifically consent focused, Article 50 of the EU AI Act[vi] does propound transparency obligations whereby users who are exposed to AI outputs, through sharing their data, are made aware that they are interacting with AI. These policies are in addition to the many consumer protection acts to consider.
With such governance frameworks in place, it may seem like people’s data and privacy and freedom of choice are sufficiently protected. Unfortunately, formal consent can be lawfully obtained without being acquired through ethical means. For example, someone who is cognitively overloaded by too many options or legal jargon, manipulated by deceptive patterns such as default bias and framing effects, or simply unable to comprehend the downstream consequences of their click, may give formal consent but not genuinely agree with what they are consenting to. Deceptive or dark patterns are defined in the EU’s Digital Services Act (2022)[vii] as “practices that materially distort or impair, either purposefully or in effect, the ability of recipients of the service to make autonomous and informed choices or decisions”. The Act prohibits dark patterns from creating confusing or misleading consent prompts. Yet, dark patterns have been found to be quite pervasive in cookie consent notifications[viii] [ix]. (A very useful site to visit for more guideline on deceptive or dark patterns is https://www.deceptive.design).
Subjective consent on the other hand is when someone has the cognitive bandwidth, the emotional state and realistic alternatives needed to make the choice meaningful to them. Subjective consent speaks to autonomy which is becoming a key concern in AI safety frameworks such as the Council of Europe AI Treaty[x] and Unesco’s Recommendation on the Ethics of AI[xi] because of its impact on well-being and human rights. (Read an article by Professor Vanessa K. Bohns on the broader psychology of subjective consent).
The challenge for marketers is to get a user’s consent to optimize commercial practices without undermining their subjective consent. While personalisation, segmentation and lifecycle marketing can benefit consumers, getting the balance between driving conversion rates, sales, engagement, data collection and ethical consent management can be tricky. Studies indicate that getting it wrong reduces brand affinity and discourages continuous engagement. Getting it right increases customer trust and loyalty which are the bedrock of long-term growth.
- Thales 2025 Digital Trust Index[xii] found that privacy fears are becoming a major factor in consumer decisions to abandon brands, with 82% doing so in 2024.
- Thales 2026 Index[xiii] indicates that consumers (66%) trust companies more when consent management systems provide clear choices, easy-to-find controls, and simple ways to update preferences.
- 46% of organisations surveyed in Cisco’s 2026 Data and Privacy Benchmark[xiv] study identified clear communication about data use as the most effective action to build customer confidence.
- According to Usercentrics 2025 State of Digital Trust Report[xv], consumers (65%) are still happy for brands to collect data but they’re rejecting vague terms, overly complex choices and unclear value.
As policies become more enforceable, marketing leaders will need to find new ways to gain users’ consent while complying with laws and ethical principles. Below are some recommendations to move away from consent as a tick-box compliance exercise, to the beginning of a solid customer relationship.
- Separate the consents, and only ask for what you actually use
The single biggest cause of consent failure is bundling where one universal “Accept All” covers data collection, profiling, marketing communications, third-party sharing and AI training, with just one click.
Instead, present granular, separable choices with each one saying what data is being used, for what purpose, and with what consequence. Each can be accepted or declined independently, and the user should be able to change any of them later without affecting the others.
- Make sure the value exchange is explicit and proportionate
Subjective consent requires that the user can form a clear mental picture of what they’re trading for and what they’re getting. “We use your data to improve your experience” is not a value exchange, it’s a platitude. Rather use, “If you share your purchase history, we’ll recommend complementary products instead of generic ones and we’ll stop showing you items you’ve already bought”.
Marketers should be able to articulate the user’s benefit in one sentence, in the user’s language.
- Layer the information, don’t bury it
Avoid privacy notices that are buried beneath volumes of legalese, presented when the user is trying to do something else, which undercuts subjective consent. Rather use layered disclosure, for example, at the moment of consent, show a short, summary (50 words) in plain language in terms of what data is being used, for what purpose and how to reverse choices.
Make the full, legal text a click away for the small percentage of users who want to read it.
- Make rejection as easy as acceptance, and be sincere
Symmetry of friction, where each choice is as easy or difficult to action, is the single most diagnostic test for whether a consent flow is genuine and not manipulative. Every consent UI should have a button of equal, visual weight, equal click cost, equal placement, equal styling. So, no confirmshaming on the reject button, and no pre-ticked boxes.
This is where most marketing teams fail when decisions are based purely on A/B testing because asymmetric friction converts better. The ethical decision is to avoid that optimization on principle.
- Use progressive consent over time, instead of maximizing consent upfront
The tendency is to get all the necessary consents as soon as you have the user’s attention. The result is consent fatigue, and a relationship that starts with dissatisfaction. Progressive consent prevents this from happening. At sign-up ask for the minimum amount of information required to deliver the core experience. Then, as the user uses the service and the benefit of personalization becomes clear, ask for additional permissions in context.
Each ask is small and contextual, and tied to a specific benefit the user can see. Acceptance rates per ask are typically higher than the equivalent upfront ask, and the consent is genuinely informed because the user has the experience to evaluate it.
- Give the user a real, persistent control surface
Most consent flows are designed to be navigated once and then forgotten. The user never sees the consent settings again unless they hunt for them. This violates the GDPR requirement that consent must be as easy to withdraw as it is to give.
The fix is a visible, accessible preference centre which is ideally through one click on any page as a single screen that shows every consent the user has given with active toggles.
- Be honest about sharing data by naming the partners and purposes
The vaguest part of most consent flows is third-party sharing. Subjective consent requires that the user can form a mental model of which partners and what the sharing accomplishes. Best practice is to name the categories of partners whether they are analytics providers, advertising platforms, retail-media networks, or email delivery platforms. Name the major partners themselves and link to a current list rather than a static reference in a privacy policy.
Each data-sharing arrangement must be via separate consents in order to comply with the DSA, and the EU AI Act expectations.
The most sophisticated marketing teams are starting to treat consent itself as a meaningful behavioural signal. Where compliance teams mostly focus on consent rates, and marketing teams mostly focus on acceptance rates, those teams that focus on subjective consent will see higher engagement per consented user, lower unsubscribe rates, fewer regulatory exposures and a first-party data asset that retains its value.
Marketing teams pursuing acceptance-rate maximization are running a strategy that worked before but is becoming defunct. The leaders investing in subjective consent are building a relationship architecture that will continue to show returns into the future.
[i] https://gdpr-info.eu/art-4-gdpr/
[ii] https://www.oecd.org/en/topics/sub-issues/ai-principles.html
[iii] https://www.nist.gov/itl/ai-risk-management-framework
[iv] https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf
[v] https://au.int/en/documents/20240809/continental-artificial-intelligence-strategy
[vi] https://artificialintelligenceact.eu/article/50/
[vii] https://www.eu-digital-services-act.com
[viii] https://www.oecd.org/content/dam/oecd/en/publications/reports/2022/10/dark-commercial-patterns_9f6169cd/44f5e846-en.pdf
[ix] https://www.sciencedirect.com/science/article/pii/S2199853125000551?ref=pdf_download&fr=RR-2&rr=a02d7e08bf41df1a
[x] https://www.coe.int/en/web/artificial-intelligence/the-framework-convention-on-artificial-intelligence
[xi] https://www.unesco.org/en/articles/recommendation-ethics-artificial-intelligence
[xii] https://cpl.thalesgroup.com/about-us/newsroom/digital-trust-index-2025
[xiii] https://www.thalesgroup.com/en/news-centre/press-releases/thales-digital-trust-index-2026-ai-adoption-grows-when-enhancing
[xiv] https://www.cisco.com/c/en/us/about/trust-center/data-privacy-benchmark-study.html
[xv] https://usercentrics.com/resources/state-of-digital-trust-report/



