Popular Posts

Consent Finally Gets a Memory: No More Endless Pop-Ups

When Consent Finally Learns to Remember: A New Chapter for Digital Privacy

Why the future of privacy isn’t about more pop-ups—it’s about systems that actually listen


The Problem with Today’s "Consent"

Imagine walking into a store to buy a shirt. Before you can even look at the merchandise, a clerk jumps in front of you with a clipboard: "Excuse me! Would you like to participate in a survey about which advertisers can track your every move in this store and every other store you visit?"

You just want the shirt. But the clerk insists. This is exactly what happens online every single day.

Current consent systems are broken because:

  • They interrupt you when you’re trying to do something else
  • They ask confusing questions about "advertising technology" and "legitimate interest"
  • They make "Accept All" big and bright, while "Reject All" hides in tiny gray text
  • Behind every popup sits a massive machine: tracking pixels, advertising IDs, vendor lists, and databases—all waiting for your click

Important Point
Consent today is a performance, not a choice. Companies spend weeks debating button colors and wording, but the real question—does this respect the human?—gets lost.


Enter Global Privacy Control (GPC): A Simple Idea With Big Implications

What if your browser could just tell websites your privacy preferences automatically?

That’s Global Privacy Control (GPC). Think of it like a "Do Not Disturb" sign you hang on your hotel door—except it’s a technical signal sent by your browser or phone that says: "This person doesn’t want to be tracked for advertising."

Why GPC Matters

Old Way GPC Way
You click "Reject" on 50 different websites You set it once in your browser
Every site asks you the same questions Sites listen to your existing choice
Your "no" gets lost in each company’s system Your preference travels with you

If European regulators decide GPC legally counts as saying "no" to tracking, the internet would finally remember that privacy belongs to the person, not the website.


Consent Is a Lifecycle, Not a Banner

From a Privacy Director’s chair, the real work starts after the lawyers finish reading the law.

Consent isn’t:

  • A cookie banner
  • A configuration setting
  • A pretty paragraph in a privacy policy
  • A green checkmark in an audit report

Consent IS:

  • A lifecycle that requires proving:
    1. What someone agreed to
    2. When they agreed
    3. What data processing followed
    4. What happened when they changed their mind

The Withdrawal Gap: Where Good Intentions Fail

Here’s where reality hits hard.

Scenario: A customer withdraws consent at 10:03 AM. The website records it perfectly.

But behind the scenes:

  • An SDK (software toolkit) keeps firing data to advertisers
  • An advertising audience list still includes them
  • Yesterday’s "yes" survives in another system

The front door says "NO" while the back rooms keep saying "YES."

This contradiction reveals more about a company’s privacy maturity than 100 pages of policy documents ever could.

Important Point
Technical withdrawal is what matters. If your systems don’t actually stop processing data when someone says "stop," your consent mechanism is theater.


Nigeria’s Moment: Don’t Copy Europe—Lead Differently

Nigeria has the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Commission (NDPC). But laws are just the blueprint. The harder question: Can rights actually live inside the house?

Why Nigeria Is a Fascinating Test Case

Nigeria’s digital economy is intensely mobile:

  • Banking apps and fintechs
  • Telecommunications providers
  • Social platforms
  • E-commerce businesses
  • Global tech companies

All sit between Nigerians and everyday economic life.

The trap: Copying Europe’s "forests of cookie banners" and calling it compliance.

The opportunity: Build something better from the start.

The Lagos Example

Imagine a customer in Lagos who has already told her browser: "Don’t track me for ads."

  • She visits 50 websites
  • Uses several apps
  • Encounters dozens of invisible advertising middlemen

Why should she explain herself 50+ times?

If technology remembers her:

  • Password
  • Transaction history
  • Device identifier
  • Viewing behavior
  • Shopping preferences

Why does it get amnesia when asked to remember her privacy choice?


Africa’s Chance to Be More Ambitious

Europe will define GPC for Europe. US states will build their own opt-out rules. African regulators should study these—but not copy them word-for-word.

Nigeria Can Ask Its Own Questions:

  1. What should machine-readable privacy preferences mean under Nigerian law?
  2. How do they work in a mobile-first economy?
  3. What fits Nigeria’s rapidly expanding tech ecosystem?
  4. How do we protect informal sector workers and first-time internet users?

This isn’t about catching up. It’s about leapfrogging to a better model.


The Business Case: Trust Beats Friction

Privacy pros often treat consent like a legal puzzle. Customers experience it as friction or trust.

Two Paths:

Path A: Friction Path B: Trust
"Accept cookies" on every site Browser setting respected everywhere
"We need your permission… again" "We heard you the first time"
Customer feels hunted Customer feels respected

A business that remembers your privacy choices demonstrates powerful governance. It says: "We can hear ‘no’ without making you shout it at every digital doorway."


What Boards Should Be Asking

Directors need to move beyond "Are we compliant?" to:

  1. Do customer preferences actually propagate through our entire organization?
  2. Do our third-party vendors honor those preferences?
  3. Does withdrawal work technically—not just in theory?
  4. Can we prove our machinery obeys the promise on the screen?

This Requires Breaking Silos

Consent failure doesn’t respect org charts. These teams must sit at the same table:

  • Privacy Engineering
  • Marketing
  • Procurement
  • Product
  • Technology
  • Data Governance

The Bigger Picture: A New Relationship Between People and Systems

GPC isn’t just another acronym. It’s the beginning of a different deal between humans and digital systems.

  • Europe can define what this means within its borders
  • Nigeria and Africa can shape their own interpretation—inheriting wisdom, not mistakes

Summary: The Human Principle at the Core

Consent will always matter because autonomy matters.

But repetition is not meaningful choice.

A person shouldn’t spend a lifetime telling machines the same thing because organizations designed themselves not to remember.

The future of consent governance depends on a remarkably human principle:

When someone has spoken clearly, good governance begins by listening. Great governance remembers what they said.


FAQ

1. What exactly is Global Privacy Control (GPC)?

GPC is a technical signal your browser or device can send to websites automatically, telling them your privacy preference (like "don’t sell my data" or "don’t track me for ads"). You set it once in your browser settings, and it travels with you across the web—no popups needed.

2. Is GPC legally binding?

It depends on where you are. In California (under CCPA), businesses must honor GPC as a valid "do not sell" request. In Europe, regulators are increasingly treating it as a valid withdrawal of consent. Nigeria’s NDPC has not yet issued specific guidance, but the NDPA 2023’s principles support machine-readable consent mechanisms.

3. Why can’t I just use "Incognito Mode" or a VPN?

Incognito and VPNs hide your activity from your local device or network—but they don’t tell websites your privacy preferences. Websites can still track you via fingerprinting, login status, or first-party cookies. GPC is about communicating your choice, not just hiding.

4. What’s the "withdrawal gap" the article mentions?

It’s when a company’s frontend (website/app) records your "no," but their backend systems keep processing your data anyway. For example: you reject cookies, but an embedded advertising SDK still sends your data to 50 companies. This is alarmingly common.

5. How can Nigerian businesses start implementing this today?

Start with an audit: Map where consent is collected, where it’s stored, and—critically—where it isn’t propagated. Invest in consent management platforms that support GPC signals. Build privacy engineering into product roadmaps, not as a legal afterthought. And test withdrawal end-to-end—not just the UI.


Michael Irene, CIPM, CIPP(E), is a data and information governance practitioner based in London, UK. He is a Fellow of the Higher Education Academy and can be reached at moshoke@yahoo.com or @moshoke on Twitter.

This article originally appeared in Business a.m. The publication welcomes reactions and comments at comment@businessamlive.com

Leave a Reply

Your email address will not be published. Required fields are marked *