Abstract
We will argue that clarifying the “moral core” of consent offers a common metric by which we can evaluate how well different legal frameworks are able to protect the central moral rights and interests at stake. We begin by revisiting how legal frameworks for digital consent developed in order to see where there may be common moral ground and where these different cultures diverge on the issue of protection of personal information. We then turn to ethics to clarify the central interests and rights at stake in morally transformative consent, in order to provide a common basis for evaluating the different legal frameworks. Ultimately, we seek the moral core of digital consent in order to reimagine its role in international conflicts.
Introduction
In contemporary society, our lives are mediated through digital technologies that offer services in exchange for our data. This has been justified by the use of privacy policies and terms of service that users agree to by virtue of using the site or service—the digital version of notice and choice. Users thereby “consent” to invasive data collection, analysis, and sharing, but this consent falls short of most normative standards of morally transformative consent.
As a moral concept, consent is significant because it plays a morally transformative role in interpersonal interactions. Valid consent can render permissible an otherwise impermissible action. It transforms the specific relations between the consenter and consentee about a clearly defined action. We can consent to sexual relations, borrowing a car, surgery, and the use of personal information. Without consent, the same actions can become sexual assault, theft, battery, and an invasion of privacy. Consent for information exchange is based on a notice and choice regime wherein a user is notified of information collected and used, and provided a choice of whether to continue with the information exchange. But what is the proper scope and terms of valid consent in the digital realm? What are we authorizing when we permit use of our personal data? What is required to achieve morally transformative consent to digital transactions?
We shall refer to consent as it relates to computing, which includes the collection, processing, sharing, and use of personal information, as digital consent. Despite differences in the development of consent in data protection laws, 1 consent has become central to international privacy disputes and transnational innovation. 2 Consent is often seen as the primary mechanism for protecting users’ control over their personal information. Yet the efficacy of consent in protecting individual privacy has been widely questioned. Most privacy scholarship on consent either discards the practice as unworkable 3 or seeks to improve existing procedures. 4
In this article, we take a different approach. We revisit how legal frameworks for digital consent developed, in order to understand the deeper motivations underlying these laws. Our aim is to see whether these systems are different interpretations of the same fundamental moral right or if there is a deeper disagreement about why consent should play a role in the protection of personal information.
Many privacy scholars have argued that international data protection should be handled in a to-each-her-own or agree-to-disagree manner (see e.g. Malcomson, 2016; Schwartz and Peifer, 2017). This reflects the current policy landscape in which we see different legal cultures and justifications in different jurisdictions (Goldsmith and Wu, 2006; Kohl, 2007; Malcomson, 2016). However understandable it may be as a legal matter. for there to be so much variability between jurisdictions, the question remains: how well do these various legal notions of consent meet moral standards?
We want to draw attention to two different senses of consent (Faden and Beauchamp, 1986). First, consent is a moral concept. In the broadest sense, an individual’s consent involves an effective communication of an intentional transfer of rights and obligations between parties. Consent thereby transforms the moral landscape between two parties rendering permissible otherwise impermissible actions. Second, consent has become enshrined in the law. Consent can be legally binding, as long as the transaction has met certain legal requirements or institutional standards defining the scope of consent. The legal notion of consent is built on the moral notion; however, problems arise when legally binding consent fails to capture the relevant morally legitimate transference of rights and obligations.
We compare the different underpinnings to see where there may be common moral ground and where these different cultures diverge on the issue of protection of personal information. We seek to clarify the central interests and rights at stake in order to provide a common basis for evaluating the different legal frameworks. We will argue that clarifying the “moral core” of consent offers a common metric by which we can evaluate how well different legal frameworks are able to protect the central moral rights and interests at stake. Ultimately, we seek to clarify the moral core of digital consent in order to reimagine its role in international conflicts, inter alia.
The proliferation of consent in privacy and data protection
Briefly tracing the story of consent as it has developed in the West over the mid-20th century provides an insight into the roots of modern consent to computing in today’s splinternet controversies. 5 Today, consent is part of nearly all digital privacy laws and plays a more prominent role in some regimes than others, but this development, which is still ongoing, occurs later than often described. In this section, we briefly detail how consent was understood and utilized (or not) in relation to computing personal information across Western countries, which were chosen because of their prominence in international digital privacy disputes.
The legal framework of consent developed in various ways across different countries and regions. In order to ask whether these differences can be reconciled in any morally justifiable way, we must first understand how digital consent developed, evolved, and became contested in international law. We look at the United States and Europe to compare the way in which consent is utilized to authorize computing personal data. As we will show, digital consent as adopted, utilized, and applied is not a stable legal concept (Reed and Bohlander, 2017).
The United States is distinct from the European Union (EU) and other rights-based regimes that protect “data subjects,” in that it uses “marketplace discourse” to protect “privacy consumers” (Schwartz and Peifer, 2017). However, this was not always the case. In the Department of Health, Education, and Welfare (HEW), 6 the Secretary’s Advisory Committee on Automated Personal Data Systems drafted the 1973 “Records, Computers and the Rights of Citizens, Report of the Secretary’s Advisory Committee on Automated Personal Data Systems,” known as the HEW Report. In it, Americans are called “data subjects.” “Consumer” is used only in reference to the Fair Credit Reporting Act (FCRA), which passed in 1970 and is considered by some to be the world’s first data protection law. FCRA applies to credit reporting agencies, which are private entities, and makes very little use of consent but provides citizens definitive rights to transparency and correction. Consent was not part of the original five principles of the HEW, except when data were going to be used beyond its original purpose. Consent was also not a major part of the extended principles codified in the Privacy Act of 1974, which concerns citizens’ rights in relation to their government, not their rights as consumers. Agencies were not to collect, solicit, or maintain personal information unless relevant and necessary for statutory purposes. Consent was only required for further disclosure.
France passed its original data protection law in 1978, which effectively reads like a governing algorithms law. 7 The first principle holds that information technology should not infringe human rights or dignity. The second holds that no judicial decision or decision with legal (or otherwise weighty) effects can be made using automated information processing. The third holds that people have a right to know and challenge automated decisions. Section 31(1) of the 1978 Act declares that express “agreement” (accord exprès) must be given to record or store personal data related to racial origins or political, philosophical, or religious affiliations in computer memory. Importantly and unlike the US Privacy Act, the French law established a specific authority (the Commission Nationale de l’Informatique et des Libertés, or CNIL) to regulate the collection, maintenance, and dissemination of personal data. The authority determined which arrangements of computing personal information would be justified.
The United Kingdom was late to the game—legislatively speaking. The United Kingdom did not pass its Data Protection Act until 1984, but arguably led much of the international privacy debate with its early reports 8 and debates in the legislature, 9 which uniquely only applied to private sector privacy. After decades of debate, legislation finally passed and it utilized consent in a scattered way, providing procedures for disclosure in various contexts, such as payroll processing and domestic purposes. Similar to the countries above, consent was required when additional disclosures were sought.
The first country to explicitly apply consent to computing as a central piece of their data protection laws was Germany. In 1970, the first data protection law developed at the state level (Hesse) to determine what level and sector of government would be in charge of certain data banks and machinery. Consent became the central and stable form of legitimizing data processing in the Federal Data Protection Act in 1977, which applied to both the public and private sectors. The processing of personal information could not legally occur unless one of two conditions was met: processing was permitted by a law or consent was given.
With the exception of Germany, the basis of these early data protection regimes was rarely individual control or consent, but instead a focus on transparency, accuracy, and, in Europe, prohibitions on automated processing. The data collected were presumed to have been gathered and maintained with appropriate justifications. Where consent is mentioned, it is only when a third party is involved (beyond the data collecting or processing entity) that consent may be required. With the clear exception of Germany, consent did not play a major role in technology regulations in the 1970s and 1980s. Even those data protection documents produced by transnational organizations like the Organization for Economic Co-operation and Development (OECD)’s Guidelines on the Protection of Privacy and Transborder Flows of Personal Data and the Council of Europe’s Convention for the Protection of Individuals with Regard to Processing of Personal Data (“Convention 108”) did not give consent a prominent role in data practices. 10
Things changed in 1990. Concerned about market disruption deriving from conflict between national data protection regimes within the European Community, 11 the European Parliament prompted the European Commission to address the issue of the “protection of individuals in relation to the processing of personal data” (Commission of the European Communities, 1990: 1). The resulting Data Protection (DP) Directive was passed in 1995, requiring each member state to establish or adapt legislation guaranteeing certain rights and obligations in relation to processing personal data. Just as each national system had debated the application of data protection to public and/or private sectors (some of them applying to only one, others to both), the DP Directive applied to “data controllers” and “data processors” generally, with exemptions for “processing operations concerning public security, defense, State security … and areas of criminal law” (Art. 3[2]). Consent is one of six bases for legally processing personal data (Art. 7[a]), which is otherwise generally prohibited, and consent must be obtained for processing sensitive information (Art. 8[2](a)). The other five justifications for processing personal information are as follows:
To fulfill a contract with the individual;
Compliance with a legal obligation that requires the processing of personal data;
Vital interests (when processing data is necessary to protect someone’s life);
A public task (those tasks assigned to government departments, schools, hospitals, etc.);
Legitimate interests of the processor (other than public authorities), not outweighed by negative effects to the data subject’s rights and freedoms.
Significant differences remained in the national laws passed to comply with the Directive (Korff, 2002). Art. 2(h) of the Directive defines consent as “any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed.” Most countries used this language verbatim, but in Spain and Sweden consent had to be “unambiguous” and in Luxembourg it had to be “explicit” and “unambiguous.” The Italian law required consent to be in writing and the German law added that consent for a separate purpose must be “clearly distinguishable” from the initial consent given. The United Kingdom did not define consent and can be read to rely on implied (as opposed to signified) consent, depending on the situation. French law also did not define consent in their post-Directive legislation and added it to general criteria for lawful processing.
Passed in 2002 to “complement and particularise” the DP Directive, the e-Privacy Directive protects the confidentiality of electronic communications across traditional telecommunication in public networks (e.g. telephones). The 2002 e-Privacy Directive required all member states to prohibit the use of electronic networks to store or gain access to (listening, tapping, storing, and other kinds of interception or surveillance) communication and Internet traffic, unless the user was provided with “clear and comprehensive information” and offered the “right to refuse” such processing by the data controller. The European Parliament initially proposed language requiring “prior, explicit consent” but met strong opposition from advertising and technology lobbies that insisted consent would devastate the European e-commerce market (Kierkegaard, 2005). The e-Privacy Directive was amended and 2009 and Art. 5(3) now requires member states to prohibit storing or accessing communication unless the user has given consent after having been given clear and comprehensive information in accordance with the DP Directive (Kosta, 2013). National “cookie laws” that followed to comply vary dramatically. Article 32-II of the French Data Protection Act, for instance, transposes the cookie provision of the e-Privacy Directive and the CNIL provides clarification and guidance, such that cookie banners are the main source of compliance and must provide the purposes of cookies, a link to further information, a way to withdraw consent, and awareness that continued browsing constitutes consent. In Germany, legislators relied on existing provisions in the Telecommunications Act instead of passing new legislation. Sections 12 and 13 of the law require consent to collect and process personal data, but Section 15 explains that informing the user and providing means to opt-out is sufficient when information is pseudonymized, thus cookie banners and walls are often not necessary.
In the spring of 2018, the EU General Data Protection Regulation (GDPR) went into effect, harmonizing all the national legislation passed in accordance with the 1995 DP Directive. 12 The GDPR continues to rely on consent as well as the five other stated reasons to justify the collection, processing, and use of personal data. The terms for lawful consent, however, have been changed and now must be freely given, specific, informed, and unambiguous—meaning consent is provided as “clear or affirmative action” (Art. 7). Silence or inactivity (e.g. pre-checked boxes) is invalid under the regulation (Borgesius et al., 2017). The Article 29 Working Party (A29WP) released guidance on consent in the GDPR in November 2017 (European Union Article 29 and Data Protection Working Party, 2017). The A29WP explains, consent only works as a lawful basis for processing “if a data subject is offered control and … a genuine choice with regard to accepting or declining the terms offered or declining them without detriment” (European Union Article 29 and Data Protection Working Party, 2017). Consent will not be considered freely given if it is part of non-negotiable terms and determines the functionality of a site or service.
The A29WP guidelines on consent also remind controllers that consent in the GDPR, like its predecessor directive, is tied to consent under the draft e-Privacy Regulation, as most controllers are “likely to need consent under the e-Privacy instrument for most online marketing messages or marketing calls, and online tracking methods including the use of cookies or apps or other software” (European Union Article 29 and Data Protection Working Party, 2017). The e-Privacy Regulation, which is currently in draft form having been adopted by the European Parliament in October 2017 and revised by the Council in July 2018, is intended to eliminate variation between member states and contentiously applies to “over the top” services like Whatsapp, Facebook, and Google (European Commission, 2017; European Parliament Committee on Civil Liberties, Justice and Home Affairs, 2017). In drafts, unless critical to providing the service (e.g. billing), there is only one way personal data may be processed under this scheme: explicit, informed consent to use the information for the agreed-upon purpose. This measure tries to eliminate any coerced consent given when services would otherwise be withheld. It emphasizes that consent is not an exchange but a transformation of the relationship based on the autonomous willingness of one party to allow the act of the other party. The provision assumes that there is no moral justification to collect electronic communication data prior to consent.
While the United Kingdom is negotiating its data protection regime post-Brexit, it is clearly attempting to align its laws with the EU GDPR to avoid any economic or technological hurdles. Across the pond, the United States has maintained their attachment to their unique brand of consent. Unlike other national and regional data protection regimes, the United States did not pass broad data protection laws over the latter half of the 20th century nor did it create an institutional home for data protection issues. It passed issue and industry-specific regulation like the Video Privacy Protection Act of 1988 and the Healthcare Insurance Portability and Accountability Act of 1996. Over the course of the 1990s and early 2000s, the Federal Trade Commission (FTC) became the de facto privacy agency by enforcing the privacy policies (drafted and posted by companies themselves) through its authority to police unfair and deceptive trade practices, as well as its enforcement of other privacy statutes like the Children’s Online Privacy Protection Act and the now-invalidated Safe Harbor Agreement. 13 Over the decade that the FTC came into this role, the Clinton Administration issued reports through the Information Infrastructure Task Force in 1995 and 1997 that recommended a path of self-regulation for the Internet. Self-regulation meant notice and choice, which was framed as emphasizing the ability of individuals to freely choose sites whose terms of service were acceptable to them (McGeveran, 2016). The FTC is a consumer protection agency and, as such, it must define data protection as consumer privacy. Daniel Solove and Hartzog (2014) Hartzog have convincingly argued, however, that the FTC has still managed to create a stable jurisprudence and set of norms to establish meaningful privacy in the United States (pp.583–676). The norms that have developed are mostly related to security practices and are not a set of clear justifications for when consent may not be required or processing is beyond consent. It is the action and inaction of the FTC, as well as a slew of national security and law enforcement agencies and courts, that currently define the role of consent in US data protection. It continues to be based on the notice and choice regime of consumer privacy—a far cry from the rights-based, institutionally determined consent system in Europe.
The normative role of consent
Recall that consent has two importantly different senses: morally transformative consent and legally valid consent. Thus far, we have been discussing the development of consent in different legal frameworks around the world. As we have seen, the role of consent in protecting an individual’s control over their personal information did not develop until relatively recently, and the legal scope varies widely. The relativist take on the variability in the legal landscape would be to infer that because different cultures disagree on the appropriate boundaries of consent, we ought to infer there is no truth to the matter. If norms are constituted by cultural interpretations, there is no external objective stance from which to evaluate the concept independent of its culture. Often, this stance is portrayed as that of the enlightened and tolerant individual. If each should be left to their own interpretation, no one stance can or should be privileged above others. We see just such a stance seeming to underlie American technology companies’ push-back against any form of global regulation of the digital sphere in favor of more local (country or regional) regulations. Furthermore, even these local regulations are sometimes challenged in favor of self-regulation.
While this variability is understandable as a matter of law, is relativism morally defensible? Many philosophers would caution against taking a purely relativist approach about normativity. 14 We do see different cultures embed normative moral significance in practices that vary widely; however, this does not mean that every practice is on equal footing, normatively speaking. An analogy with scientific progress can illustrate why. People once held that the sun revolved around the earth, yet this difference in beliefs does nothing to undermine the truth of the matter. Many philosophers would argue a similar case applies to larger moral questions. For thousands of years slavery was not only widely practiced, it was also defended as morally acceptable. The change in beliefs and laws about the social acceptability of slavery does not reflect a change in morality. Slavery is and always was morally wrong—whether or not people applied the standard of equal respect to all human beings. What changed was broad societal recognition of this moral truth. The moral relativist would be unable to hold these claims. If the standard of moral evaluation is constituted by the cultural practices, the relativist would be committed to saying that slavery was the right thing to do in the 1700s and today it is the wrong thing to do. There is no way for the relativist to say today’s standards are better or demonstrate moral progress.
If moral relativism is off the table, we need to dig deeper into what role consent plays in our normative practices and how this could or should apply to the digital world. As a legal concept, we should expect significant variability given that laws are often written as practical negotiation of the different power dynamics, cultural interpretations, and history of a given country. The legal and institutional practices determine what qualifies as legally valid consent. If certain conditions are met, consent can be legally binding between parties.
As a moral concept, by contrast, consent functions to transform the relation between two parties. The “moral magic” of consent lies in its ability to render permissible otherwise impermissible actions (Hurd, 1996: 121–146). In the broadest sense, an individual’s consent involves an effective communication of an intentional transfer of rights and obligations between parties. 15 Valid consent transforms the specific relation between the consenter and consentee about a clearly defined action. The legal and moral conceptions of consent are connected, but problems arise when legally binding consent fails to capture the relevant morally legitimate transference of rights and obligations.
What lies at the moral core of digital consent? Herein, we outline five key features that are important to consent as a moral concept: (1) clear delineation of the background conditions for permissible and impermissible uses of one’s data; (2) a defined scope of action; (3) relevant information provided to the consentee; (4) freedom to choose among a set of viable options; and (5) the consenter should be treated fairly and should not be required to sacrifice other important rights. We first outline the background conditions since this sets the broader context within which we can understand when consent is required or not. The additional four features (2–5) specify the scope and requirements of the consent transaction, but all rely on a clear understanding of the broader context as prerequisite.
First, if the role of consent is to transform the moral landscape between parties, rendering permissible otherwise impermissible actions—this requires some common understanding of the background conditions for the default landscape. When it comes to digital consent, what is needed is a clear delineation of the background conditions for justifiable and unjustifiable terms for collecting, using, and sharing personal data. Yet, this is significantly lacking in the current context. Given the speed with which technology becomes integrated into our daily lives, often the values and expectations embedded in the technology itself become the default—whether or not we as a society have taken the time to think through the appropriate conditions for sharing personal information in exchange for access to digital services. It is easy to adopt as a given whatever terms of service are offered by the services we turn to on a daily basis. Individuals often feel powerless to negotiate these terms. Many people were not aware, until more recently, the extent of the personal information collected, used, and shared by digital companies who were providing users with “free” services (Rainie, 2016). These are problems of collective action—individual choices can do far less to establish or change the standards around acceptable and unacceptable uses of data. We should encourage inclusive discussions around the permissibility of data use in order to better set expectations concerning what the background conditions are in a given society.
Clarifying the role of consent as a moral term can help prompt us to begin these discussions around what expectations we as a society want to establish concerning the collection, use, and sharing of personal data. Only after a broad and inclusive discussion has taken place around this topic, will we be able to judge when consent should be required or not. We need to delineate what the background conditions should be for permissible use in order to know when consent is morally required.
Once we have established a clear delineation of the background conditions for permissible and impermissible uses of one’s data, there are a set of additional considerations concerning the standards that give consent its moral force. Specifying the background conditions about the standards for permissible use of personal information and when consent is morally required to go beyond that expected use is the first step of delineating a moral core of digital consent. However, more details are required for knowing when a consent transaction is morally transformative.
What is required for consent to be morally transformative? Broadly speaking, consent is the deliberate (and communicatively successful) performance of acts or omissions whose conventional or contextual point is to communicate to others the agent’s intention to undertake new obligations and/or convey to others new rights (with respect to the agent). (Simmons, 2010: 306).
Theorists disagree about precisely what constitutes deliberate and successful communication of the transfer of rights (see, e.g. Alexander, 1996, 2014; Dougherty, 2014, 2015; Wertheimer, 2003). Tom Beauchamp argues that morally transformative consent requires full autonomous authorization. He argues that consent is morally transformative if and only if an individual “with substantial understanding and in the absence of substantial control by others, intentionally authorizes [another agent] to do something” (Beauchamp, 2010: 57). By contrast, Franklin G. Miller and Alan Wertheimer argue that asking for autonomous authorization is too demanding and focuses too much on the individual who gives consent. Instead, they suggest that we should look at the context within which a consent transaction occurs. They suggest that consent is morally transformative if the consenter communicates their token of consent under conditions in which the person seeking consent has treated the consenter fairly (Miller and Wertheimer, 2010a: 94).
Yet, despite this theoretical difference concerning what makes consent morally transformative, there are significant areas where theorists overlap. It is in this overlap where we believe ethical theory can offer guidance to the complicated global legal landscape of consent. This can be thought of as a kind of overlapping consensus on key aspects of consent as a moral notion, even if theorists will reasonably disagree about the best way to specify each aspect. Following John Rawls (2005) in Political Liberalism, we think these core moral ideas can be grounded in a variety of different moral systems—each with their own account of human dignity or autonomy to show why consent is morally required. We seek to clarify the moral core of consent, while leaving it open to different theoretical approaches to illuminate why consent has this value and how it should best be instantiated in practice. 16
We here outline the remaining features of consent that contribute to its ability to be morally transformative once the background conditions for when consent is required are established. Consent is such a useful tool in our interpersonal relations because it creates “special moral justifications for conduct by others that would normally be unjustified” (Simmons, 2010: 305–306). This relates to the first key requirement we argued is important for clarifying morally transformative consent: establishing clear background conditions for permissible and impermissible uses of one’s data. Once the background conditions have been specified, we need a few other considerations to determine whether given consent transaction is morally transformative. Given its morally transformative power, consent generally requires, second, a clearly defined scope of action that you are giving permission to another person (or group) to do to you (or your data). We shall call this the scope condition. Third, an individual must also have the relevant information and sufficient understanding of this information so she knows what she consents to. We shall call this the knowledge condition. Fourth, the individual should be free to choose among a set of viable options. We shall call this the voluntariness condition. According to almost every theory of consent, coercion, manipulation, or failure to understand what the transaction involves undermines the moral force of consent. Finally, the context in which the consent transaction occurs, including the relationship between the parties, should involve each party treating the other fairly. Individuals should not be required to sacrifice other important rights. We shall call this the fairness condition.
Let us break down these general conditions. Beyond the idea that consent presumes background conditions for justifiable and unjustifiable terms for collecting, using, and sharing personal data, the moral core of consent requires the scope of the permission granted to be clearly defined (see, e.g. Beauchamp, 2010; Dougherty, 2014; Manson, 2016; Miller and Wertheimer, 2010a). For any legitimate transference of rights, we should have a clear idea of which rights we have given to another party as well as a mutual understanding of the scope and terms of the permission granted. This challenges any idea (often embedded in current terms of service) that we can consent to an unlimited scope for collection and use of personal data. Instead, there needs to be clearly defined boundaries of what permission is granted, to whom, and for how long.
This relates to the knowledge condition for consent. For parties to have a mutual understanding of the scope of the permission granted by consent, each party must have the relevant information to know what the individual has consented to share and how that information will be used. Deception and some forms of manipulation can undermine the moral force of consent by undermining the basic knowledge of the situation required for any morally valid transfer of rights (see, e.g. Beauchamp, 2010; Hyams, 2011). This knowledge requirement is at the root of why we don’t count children’s consent as either legal or morally valid—at least until they have demonstrated they have met some threshold of epistemic competence relevant to the context and proposed consent transaction. For the knowledge condition to be met, both parties need to demonstrate epistemic competence in relation to the proposed consent transaction, provision of accurate information about the transaction, and a sufficient level of understanding for the agreement to qualify as binding.
For consent to wield its moral magic, it must be freely given. This is the essence of the voluntariness condition for consent. Despite differing accounts of what voluntariness means and requires, any theory of morally transformative consent must include the provision that the consent was authentically given—free from coercive or manipulative interference. On any theory, coercion undermines consent (see, e.g. Alexander, 2014; Beauchamp, 2010; Hyams, 2011; Miller and Wertheimer, 2010a). No rights are transferred when the individual is given no alternate choice. A robber demanding “your money or your life” does not give you a sufficiently free choice. You do not give the robber a moral right to your money even if you do hand the robber your wallet. There is a salient difference between voluntary gifts and burglary. Beyond this bright line, the precise outline of when manipulation or incentives undermine the voluntariness condition can be debated. However, for all theories, the morally legitimate transfer of rights requires the transfer to be agreed to freely by the party who transfers these rights.
Finally, the consent transaction requires a fair context within which parties can choose the terms under which they are willing to exchange personal information (Miller and Wertheimer, 2010a). As a society, we should deliberate about which uses of personal information meet important social goods, which are necessary for protecting a well-functioning democratic system, and what is required to ensure individual choice of further data exchange takes place in a fair system. We would expect some variability on each of these points in different countries. Yet the standards should be able to clearly explain why the terms set are justifiable, how they establish a fair context, as well as how individual rights can be protected within the system.
The moral framework articulated herein provides a common basis for assessing whether the laws in different countries live up to robust ethical standards. If grounded in basic human rights claims or interests of privacy that would be common to all people, a philosophical approach pushes us in the direction of delineating a universal framework for digital consent. Clarifying the moral core of digital consent provides us with a common normative standard, while delineating the permissible range of variations that qualify as reasonable interpretations of this central moral core. 17 In this way, turning to a universal moral core of digital consent can set the standard by which we can evaluate differing legal interpretations of consent for their normative efficacy.
Digital consent: moral relativism or reasonable pluralism?
What do we find when we look at the comparative legal history? Are there any common appeals that can point toward a shared framework or are we stuck with relativism? In the remainder of this article, we return to the legal analysis of digital consent to investigate whether there are common themes the different legal frameworks are attempting to capture. Our aim is to see whether these systems are different interpretations of the same fundamental moral right or if there is a deeper disagreement about why consent should play a role in the protection of personal information. We will suggest that the seemingly diverse standards may in fact be an instance of reasonable pluralism 18 about consent rather than cultural relativism.
But first, what do we mean by reasonable pluralism and how does this differ from moral relativism? In any free society that protects freedom of thought and consciousness, it is inevitable that people will hold a wide plurality of moral and religious doctrines. According to John Rawls, the problem of reasonable pluralism arises because within this plurality, there will be a large subset that qualifies as reasonable. Broadly speaking, doctrines are reasonable when they meet some minimum moral and epistemic thresholds. These minimal thresholds are set by moral respect for all persons (in Rawlsian language: treating people as free and equal) and some general level of coherence of the doctrine. 19
By contrast, moral relativism holds that there are no objective moral truths because morality is tied to one’s culture. 20 While this may seem like a tolerant position, one major problem lies in the way this tends to impact the marginalized within cultures. The standards of acceptability in different cultures are generally set by the most privileged and these standards often embed existing social power dynamics. These norms can overlook (or outright harm) the marginalized within society. 21 To return to the slavery case described above, this would never qualify as reasonable because it fails on moral grounds. Slavery is simply incompatible with respect for all people as free and equal persons. Clearly, the current legal landscape surrounding digital consent has no stark cases like slavery. Nonetheless, we suggest evaluating existing standards against the normative core of morally transformative consent with particular attention to the impact on marginalized populations within a society. This will require a broadly inclusive discussion with a diverse set of stakeholders in society to ensure that all voices are adequately represented.
Despite the variability of the different legal frameworks, two dominant themes arise: a rights-based approach and one that is modeled on consumer choice. Although we can see consumer-based and rights-based data protection regimes as markedly distinct on their formulation and use of consent, Convention 108 Art. 5(a), the Data Protection Directive Art. 6(1)(a), UK’s Data Protection Act (UK Data Protection Act, 1984), and the US FTC’s charge (Hofmann, 2012) all state, in one way or another, that the primary role of data protection law is to ensure personal data is processed fairly and lawfully. Delineating fair terms of transaction echoes Miller and Wertheimer’s theory, whereas those policies that focus on individual self-determination and control (in Germany), echo in some ways Beauchamp’s theory of autonomous authorization. However, despite this variability, most laws seek to establish conditions for informed individuals to make free choices that reflect their values under fair conditions.
Cass Sunstein (2017) introduces a useful distinction in the way we can evaluate the relationship between our choices and our freedom, drawing our attention to two ways we approach technology: as citizens and as consumers. As consumers, we tend to be motivated to make choices according to our own narrow self-interest and are prone to accepting tradeoffs for more immediate gratification while ignoring our higher interests. As citizens, however, we have more aspirational aims. We can seek what would be best for society. Moreover, he suggests that we should adopt this citizenship lens as we seek to regulate the structures within which we make choices as consumers. After all, our preferences are a product of the circumstances within which we live. As citizens, we could seek to mold those institutions and expectations to conform to our higher ideals. The disconnect between our actions as consumers and our aspirations as citizens should not be taken as evidence against citizens’ support for restructuring regulations to support broader social goods. 22
Understanding the differences between these two approaches is particularly valuable in evaluating consent frameworks because the moral core of consent involves communication of our free, informed choice to transfer specific rights to (or accept obligations from) another party. This citizen rights-based versus consumer choice-based distinction roughly tracks differences between current European and American law (Schwartz and Peifer, 2017). Yet as we have seen, American law was not always so consumer focused. Early data protection regimes focused on citizen’s rights against government collection, use, and sharing of personal data. Notably, the HEW Report asks agencies not to collect, solicit, or maintain personal information unless necessary for statutory purposes. Within the framework, consent is not seen as required for government use of personal information because it is assumed that the government is justified in these practices if they stay within the appropriate statutory limits. Recall that consent is a useful tool for rendering permissible otherwise impermissible actions. The assumption behind the HEW Report is that the government is permitted to collect certain data. Thus, it is only the transfer of this data to third parties that requires explicit permission.
In the United States, the discourse has problematically shifted significantly toward consumer choice without a strong regulatory or institutional voice for the citizen seeking broader societal good. In countries with designated data protection agencies, both voices are more ably accounted for, even as privacy continues to be defined by some scholars, commentators, and laws as control of personal information. 23 “Consumer privacy” is a highly limited form of privacy but also incredibly flawed. It suggests a “marketplace” of “free choice” “exchanges,” but data collection frequently happens within free digital environments often referred to as “communities,” “networks,” or e-commerce sites (where users are actually consumers paying for goods, as opposed to users trading their data). Users can decide whether to relinquish unknown amounts and types of personal information to gain access to these services, which is an odd interpretation of “exchange.” Finally, the idea that this choice is sufficiently voluntary comes under heavy pressure when so much of our contemporary lives (including our livelihoods and access to information needed to be responsible citizens) is lived online. The notice and choice regime has come under heavy pressure for its efficacy in protecting data subjects and is largely rejected by the new GDPR. Perhaps, we are at a stage where US law should reconsider whether rights—beyond consumer rights—are infringed through the computing of personal data and ways to protect these rights, as it initially attempted to in the HEW report. A broadened US legal effectuation of consent that continues its role of protecting citizens would also be a return to US policy promoting a global Internet.
The rights-based approach in Europe has been well established as a contrast to more libertarian consumer models of contemporary American laws. The German case is particularly interesting to analyze given the merging of a strong rights-based approach to personal data protection with consent at its core, because Germany explicitly defines the computation of personal information as an infringement of individual rights. The old German national law, replaced EU DP Directive, and the now-governing GDPR all require explicit justification for any collection of personal information, but the EU-wide regimes do not presume non-consensual collection of data constitutes an infringement of rights. Instead, both the replaced DP Directive and now the GDPR allow for the legitimate interests of the processor to justify non-consensual processing of personal information, as long as it does not infringe individual rights of the data subject. It is an open question whether processing does infringe on individual rights. For Germans, any collection that was not explicitly authorized by law required individual consent to that use—without explicit consent, rights are infringed upon. In the wake of World War II abuses and the development of the distinctly European science and technology policies (Jasanoff, 2008), only a formal (legal) determination of moral justification or explicit individual consent would suffice in Germany. Today, Germany remains a leader in EU data protection and continues to support robust rights-based model of digital consent, but it remains to be seen how “legitimate interests” and “consent” justifications in the GDPR will be utilized and interpreted given the prior variation.
Let us now return to the central question at hand: is the variability purely relativistic, is there only one right approach in law, or could there be reasonable pluralism about digital consent? We think that reasonable pluralism about consent is a promising way forward. The moral core of consent ought to set the standard for what qualifies as reasonable and consent practices should be evaluated from our roles as citizens with aspirations toward higher ideals. This does not mean, however, that the global community must enforce one particular legal framework. Even looking to the moral theory, we see disagreement in what constitutes morally transformative consent. A morally justifiable international standard need not require agreement, rather it should outline a shared minimal moral threshold for digital consent.
Applying the moral core to national practices
Clearly delineating the moral core of consent—understood in the context of reasonable pluralism about digital consent—offers a promising path forward. Existing laws should be evaluated according to the widely shared standards for morally transformative consent in order to measure their effectiveness is protecting the moral interests and rights at stake.
Taking into account the early development of US law, we see a shared interest across all countries analyzed in establishing clear guidelines for when data collection, processing, and use is justified. The disagreements lie in the precise outlines of justifiable use and social necessity. This is to be expected—and will clearly turn on cultural priorities defining social good and social necessity. However, we should not simply assume that existing practices set the appropriate standards. A full and free discussion as a society is needed to outline clear boundaries for the justifiable processing of personal information and when consent is needed to go beyond these purposes.
The more recent migration to a purely consumer-choice based model in current US law strays further from the idea that collection of personal information should be constrained within clear boundaries of need. Somewhat counterintuitively, the narrow commercial focus of current notice and choice practices in the United States has led to an extremely broad interpretation of the proper justification for collection of personal data. Consumers are presumed to have unlimited freedom to choose how they wish to exchange their data with service providers. But in reality, when terms of service are non-negotiable (in contrast to GDPR interpretations by the A29WP and Borgesius et al., 2017), consumers are given the option of giving up their personal data in order to access the service offered. This may sound like a pure consent system, but actually does not provide a set of fair conditions or context under which consent occurs. Instead, the notice-choice consumer privacy system serves up boilerplate language, which is non-negotiable and limits the rights of users (Radin, 2012).
Increasingly, our society is structured in a way that imposes significant cost on those who would choose to avoid giving over one’s data because the collection and use of personal data underlie most digital service provider’s business models and the use of digital services is becoming required for participating in contemporary society. For example, most companies require some use of digital communication and the platforms and terms of service are set by one’s employer rather than being left to the individual employee. Opting out is not an option. Left unregulated, we allow the companies who collect our data to set the terms for using our data.
This is not a neutral framework. Rather, the conditions under which individuals choose (and their options) are a product of both legal regulations and social norms. 24 When we abdicate our role in deliberating about which norms we could collectively endorse in ways that protect individual rights and contribute to the public good, we allow powerful companies (who have a profit incentive to collect and use our data) to set the terms and expectations of society.
Conclusion
Clarifying the moral core of digital consent would provide us with a path forward for reintegrating a common global standard of consent, while delineating the permissible range of variations that qualify as reasonable interpretations of this central moral core. Establishing a clear moral core of consent serves practical legal ends that can help us move toward morally sound and internationally cooperative Internet jurisdiction. Internet jurisdiction and enforcement is complex and evolving. While it may be tempting to argue for an “to each her own” Internet policy and to rely on institutions and procedures to make global data go round, underlying rights and remedies related to consent may be left unaddressed. Without a clear delineation of the moral contours of consent, the background conditions governing justifiable and unjustifiable uses of personal data, and the rights of individuals as they relate to computational processing—the splinternet will continue to be an ethical and legal mess.
Resolving global debates about privacy and consent need not require a single legal system, nor does it mean anything goes. Instead, the moral core of digital consent can function as a common standard according to which we can evaluate differing legal interpretations of consent for their normative efficacy. If the differences in legal codification of rules surrounding consent appeal to a common moral basis, this provides us with a common normative standard by which we can assess the different legal frameworks. If grounded in basic human rights claims or interests of privacy that would be common to all people, a philosophical approach pushes us in the direction of delineating a universal framework for digital consent. This framework could then be interpreted and applied in different cultural contexts, while still providing clear guidelines according to which we can assess whether the laws in different countries live up to robust ethical standards. In this way, turning to a universal moral core of digital consent can set the standard by which we can evaluate differing legal interpretations of consent for their normative efficacy.
Footnotes
Acknowledgements
We would like to thank audiences at the Privacy Law Scholars Conference-Europe (2018), TPRC: Communications, Information, and Interet Policy Conference (2018), and the Eastern Division of the American Philosophical Association (2019) for helpful discussions of the ideas in this paper. Special thanks to Amg Berg, who provided detailed comments on an earlier version of this paper. This research was supported by a Complex Moral Problems Grant, awarded by Georgetown University.
Funding
The author(s) received financial support for the research, authorship, and/or publication of this article: This research was funded by a Complex Moral Problems Grant awarded by Georgetown University.
