BeyondSingularity

← Data Privacy, Ethics and Society outline

Module 03 / 14  ·  Phase 2 — Architecture: law, technology, and the human cost

3. Consent, collection, and the limits of agreement

This week in the arc

Coming from

Week 2 gave you four lenses and ran them on a case at rest. Now they meet something live.

Going to

Week 4 — the technology sold as the fix: anonymization and privacy-enhancing tools, and where they fail the people they promise to protect.

Core

Almost everything in privacy rests on one small sentence: I agree. Terms of service, cookie banners, the box you tick, the screen you tap to drive off the lot — all of it is load-bearing, and all of it assumes you made a real choice.

This week we test that assumption and watch it come apart from two directions. Consider what “consent” has to mean to be worth anything — that you understood it, that you could have refused, that it still describes what’s happening to your data now — and then hold that against how it actually works:

  • The app — you didn’t read it, and if you had, you could not have understood it.
  • The car — you didn’t know there was an agreement at all; surveillance came bundled inside a thing you bought.
  • Both — you agreed once, to one purpose, and the data has been flowing to others ever since.

Consent is a snapshot. Data flow is a river. That gap is the subject of the night. By the end you should distrust “I agree” as a solution to anything — which matters, because nearly every harm in the rest of this course involves something you nominally agreed to. And there’s a second reason it matters: there are laws built to fix exactly what you just watched break — and knowing what they promise lets you measure the distance between the promise and the room you’re sitting in.

Two philosophies split the world. Europe’s GDPR treats your data as an extension of you: processing is forbidden by default and permitted only on a specific legal basis, and where that basis is consent, the consent must be “freely given, specific, informed, and unambiguous.” It is opt-in, rights-based, and it applies across the whole economy. The United States has no such law. It regulates in patches — health here, finance there, children somewhere else — and defaults to opt-out: the collection is allowed; the most you usually get is the right to ask them to stop. California’s CCPA/CPRA is the furthest the US has gone, and it is still a consumer-protection statute, not a declaration that the data is yours.

Now do the thing this course does. Hold GDPR’s standard — freely given, specific, informed, unambiguous — against the cookie banner you clicked this morning, or the agreement you never read. The standard is crystal clear. The practice violates it nearly universally. That gap is the point, and it is not because the law is stupid: it is because the ethical problem outruns the instrument built to contain it. From here on, every harm we study carries a second question alongside the lenses and the lifecycle: which law would touch this — and exactly where does it fail?

Cases — tagged by category, name the kind before you react

The agreement you didn't read the consent fiction — you pick the platform

We take a real agreement from a platform you name in the room — the one in your pocket — and trace a single click to what actually gets collected, combined, and inferred. Your app, your click, your data.

The car you didn't know was watching surveillance you never agreed to

You bought a car — a physical object — and surveillance came baked in. Where you go, when, how fast, how hard you brake, what time you get home. The “agreement” was a tap on a setup screen, or a clause in a sales contract you were never handed. Most buyers never registered a consent moment at all.

Reading

Required Obar & Oeldorf-Hirsch, “The Biggest Lie on the Internet” Information, Communication & Society, 2020
Recommended EFF, on how Meta tracks you across the web and how to limit it Electronic Frontier Foundation, 2025
Recommended Mozilla, *Privacy Not Included — cars — and Kashmir Hill’s NYT reporting on carmakers selling driving data

Discussion

  • You've clicked 'I agree' thousands of times. Name one thing you're confident you actually agreed to — and how you know.
  • You tapped 'Agree' on a car's setup screen to use navigation. Did that authorize selling your driving profile to your insurer? If not, what did your tap actually consent to?
  • If refusing means you can't do your job, reach your friends, or drive the car you bought — is a 'yes' still consent?