Consent has always struck me as one of privacy’s strangest inventions. We have spent years building systems designed to ask human beings questions they do not particularly want to answer, usually at the precise moment they are trying to do something else. A customer wants to read an article, check an investment, transfer money or buy a shirt, yet a rectangle appears asking them to participate in a miniature referendum on advertising technology.
Behind that rectangle sits an extraordinary machine. Consent management platforms, SDKs, advertising identifiers, pixels, preference centres, vendor lists and databases wait for the customer’s finger to make a decision. Somewhere, a privacy professional has spent weeks debating whether “Accept All” is too prominent, whether rejection requires another click, and whether an analytics technology is genuinely necessary or merely wearing the clothes of necessity.
This is why Global Privacy Control interests me far beyond cookies. GPC presents a deceptively simple proposition: what if an individual could express a privacy choice through their browser or device and organisations were expected to listen? If European authorities mapped that signal decisively to refusal or withdrawal of consent and objection to certain forms of advertising, something fundamental would change. The internet might finally begin remembering that privacy belongs to the person rather than the website.
From a Privacy Director’s chair, however, the interesting question begins after the lawyers have finished interpreting the law. A meaningful GPC regime would turn what appears to be a browser setting into a substantial governance obligation. Organisations would need to understand how that signal travels through their technology estate, how it interacts with consent previously collected, what happens downstream and whether the customer’s choice survives across websites, applications, devices and subsequent sessions.
That is where consent reveals its true character. Consent is not a banner, a configuration, a beautifully drafted paragraph or a green tick sitting peacefully inside an audit report. It is a lifecycle that requires an organisation to demonstrate what somebody agreed to, when they agreed, what processing followed and, critically, what happened when that person changed their mind.
Withdrawal is where many elegant frameworks meet reality. The customer withdraws at 10:03, and the interface faithfully records the instruction, yet somewhere deeper inside the organisation an SDK continues firing, an advertising audience remains populated or yesterday’s consent status survives inside another system. The front door says no while several rooms at the back of the house continue saying yes, and that contradiction tells us more about privacy maturity than a hundred pages of policy.
Then my thoughts travel to Africa, where this conversation cannot simply arrive in a suitcase from Brussels. Nigeria now has the Nigeria Data Protection Act 2023 and an increasingly important regulatory institution in the Nigeria Data Protection Commission, but legislation is only the architecture of the house. The harder question is whether rights can actually live inside it.
Nigeria presents a fascinating test because its digital economy is intensely mobile. Banking apps, fintechs, telecommunications providers, social platforms, e-commerce businesses and global technology companies increasingly sit between Nigerians and ordinary economic life. Consent governance therefore cannot become an imported ritual in which African businesses reproduce Europe’s forests of cookie banners while congratulating themselves for achieving compliance.
Imagine a customer sitting in Lagos who has already communicated that she does not want her behaviour tracked for targeted advertising. Why should she explain herself again to fifty websites, several apps and an assortment of invisible advertising intermediaries? If the technology remembers her password, transaction history, device identifier, viewing behaviour and shopping preferences, it becomes increasingly difficult to explain why the same technology develops amnesia when asked to remember her privacy preference.
This is where Africa has an opportunity to be more ambitious. European authorities may determine what GPC means within European law, while American states continue developing their own approaches to universal opt-out mechanisms. African regulators should study those developments without assuming that regulatory maturity requires copying them word for word. Nigeria can ask what machine-readable privacy preferences should mean within its own legal framework, digital economy and rapidly expanding technology ecosystem.
There is a commercial argument here too. Privacy professionals sometimes talk about consent as though the objective were to construct the perfect legal mechanism, but customers experience something much simpler: friction or trust. A business that remembers a customer’s privacy choices demonstrates something remarkably powerful about its governance. It tells the customer that the organisation can hear the word “no” without requiring it to be repeated at every digital doorway.
For boards, that changes the conversation considerably. Directors should be asking whether customer preferences propagate through the organisation, whether third parties honour them, whether withdrawal works technically rather than theoretically, and whether evidence exists to demonstrate that the machinery obeys the promise made on the screen. Privacy engineering, marketing, procurement, product, technology and data governance therefore belong at the same table because consent failure rarely respects organisational charts.
Perhaps that is what GPC ultimately represents: not another acronym for privacy professionals to debate, but the beginning of a different relationship between people and digital systems. Europe has an opportunity to define what that relationship means within its borders, while Nigeria and the wider African continent have an opportunity to shape their own interpretation rather than inherit somebody else’s mistakes.
Consent will remain important because autonomy remains important, but repetition should never be confused with meaningful choice. A person should not have to spend a lifetime telling machines the same thing simply because organisations have designed themselves not to remember. The future of consent governance may therefore depend on a remarkably human principle: when someone has spoken clearly, good governance begins by listening, and great governance remembers what they said.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke







Friend-raising: The overlooked discipline behind every breakthrough