Generic Consents in Digital Ecosystems: Legal, Psychological, and Technical Perspectives


Steffes Bianca,Salemi Simone,Feth Denis,Groen Eduard C.


AbstractConsent is an important authorization basis for the processing of personal data. According to the General Data Protection Regulation (GDPR), consents must be as specific and unambiguous as possible. In practice, however, this leads to users being overwhelmed by the large number of consent requests, which can ultimately be detrimental to freedom of choice. What the overwhelming number of requests for consent can lead to is reflected by the so-called cookie fatigue problem: users have become accustomed to accepting cookies on websites only to get rid of cookie banners as quickly as possible. As cookies do not always lead to the collection of personal data, the cookie fatigue problem cannot be transferred entirely to the problem we would like to address in this chapter. It only serves as an example for the consequences of overloading a data subject with requests for consent. As the GDPR demands that consent be informed and given freely, the current strategy of consent handling cannot be in the spirit of the data protection legislation. In this chapter, we present our vision of how consent can be integrated in the context of digital ecosystems from three perspectives: (1) achieving legal compliance according to data protection law, (2) demonstrating technical feasibility, and (3) assuring user-friendliness by adding cognition to the equation. Our approach aims to enable “generic consents” within a clearly defined scope and context. Although generic consents that serve as a “catch-all” are generally not allowed, we leverage the specific characteristics of digital ecosystems to impose limitations that can justify their use in this particular context. We will also detail the legal implications and present implementation options.


Springer International Publishing

Reference51 articles.

1. Agrawal, R., Kiernan, J., Srikant, R., & Xu, Y. (2002). Chapter 14—Hippocratic databases. In P. A. Bernstein, Y. E. Ioannidis, R. Ramakrishnan, & D. Papadias (Eds.), VLDB ’02: Proceedings of the 28th International Conference on Very Large Databases (pp. 143–154). Morgan Kaufmann.

2. Albayrak, T., Karasakal, S., Kocabulut, O., & Dursun, A. (2020). Customer loyalty towards travel agency websites: The role of trust and hedonic value. Journal of Quality Assurance in Hospitality & Tourism, 21(1), 50–77.

3. Ali, A. S., Zaaba, Z. F., Singh, M. M., & Hussain, A. (2020). Readability of websites security privacy policies: A survey on text content and readers. International Journal of Advanced Science and Technology, 29(6s), 1661–1672.

4. Appenzeller, A., Rode, E., Krempel, E., & Beyerer, J. (2020). Enabling data sovereignty for patients through digital consent enforcement. In Proceedings of the 13th ACM International Conference on PErvasive Technologies Related to Assistive Environments, PETRA ’20. Association for Computing Machinery.

5. Assion, S. (2021). Stellungnahme als Sachverständiger zum Entwurf eines Gesetzes zur Regelung des Datenschutzes und des Schutzes der Privatsphäre in der Telekommunikation und bei Telemedien (TTDSG), BT-Drucksache 19/27441







Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3