There is, somewhere in the modern corporation, a place where the word ‘no’ goes to die. Nobody knows exactly where it is. The lawyers insist they have never seen it, Marketing says it must be somewhere in Technology, Technology produces a ticket showing that the preference was successfully updated, and Compliance, arriving late with a spreadsheet and an expression of ancestral exhaustion, discovers that the customer who said no on Monday was contacted again on Thursday. By then the organisation has already performed the ancient corporate miracle of transforming a refusal into a workflow, the workflow into a data field, and the data field into something everyone can see but nobody appears obliged to obey.
We have made consent unnecessarily mystical. We speak about lawful bases, consent-management platforms, preference centres, suppression lists, orchestration layers and audit trails until the simple human act beneath all this machinery disappears. Someone was asked a question and gave an answer. That answer was no. Or perhaps it was yes yesterday and no today, which is entirely their right because consent that cannot change its mind is not consent at all. Yet corporations sometimes behave as though withdrawal were an administrative inconvenience, a small rebellion by the data subject that must be acknowledged ceremonially before business continues with its afternoon.
This is where I wear two hats, one as a DPO and another as a director, and neither permits me the luxury of calling this merely a privacy issue. The DPO sees the obvious legal question: was the individual’s choice respected, and can the organisation demonstrate it? The director should see something more disturbing: if our systems cannot reliably execute a simple instruction from a customer, what exactly does that say about our control environment? A board that receives beautiful dashboards showing consent rates while customers continue experiencing communications contrary to their recorded preferences is not looking at good governance. It is looking at a painting of good governance.
The UK GDPR makes withdrawal of consent conceptually straightforward, and PECR brings particular discipline to electronic direct marketing, but legislation cannot rescue an organisation from architecture it does not understand. A customer preference may begin its journey in one system, travel through another, encounter an ancient CRM nobody wishes to retire, pass a marketing platform acquired three procurement cycles ago, meet an API whose original developer has departed for Australia, and finally emerge at the other end miraculously transformed into permission. Every system reports itself healthy. Every control has an owner. Every owner has a PowerPoint slide. The customer, meanwhile, is still being contacted.
Then comes the linguistic sorcery. Marketing becomes “engagement”. Promotion becomes “customer experience”. A commercial communication acquires a paragraph of administrative information and is suddenly introduced to the organisation as a service message. This is where privacy professionals must become suspicious of nouns, because the purpose of a communication is not determined by whatever somebody typed into the campaign description. Calling a wolf Customer Relationship Management does not improve the prospects of the sheep. We must examine substance, purpose and effect, particularly where an individual has already expressed a preference that the organisation would rather not hear.
For directors, the questions should therefore become considerably less comfortable. Do withdrawals propagate across the entire relevant technology estate, and how do we know? Can downstream platforms override them? Do newly implemented systems inherit historical preferences? Are suppression controls tested after migrations and releases? Can third parties continue processing against an obsolete signal? Most importantly, does management information measure whether choices are actually honoured, rather than merely counting how many choices have been captured? There is an enormous difference between recording a command and executing it, although corporate dashboards have developed an impressive talent for making the two appear identical.
Consent is ultimately a test of organisational character because it becomes meaningful precisely when the answer is inconvenient. Any company can respect the customer who says yes. The real governance test arrives when the customer says no to profiling, no to cookies, no to marketing, or simply, after years of saying yes, not anymore. At that moment the organisation discovers whether privacy was genuinely engineered into its operations or merely written into its promises. Trust is not created when we ask permission beautifully. Trust is created when the answer costs us something and we honour it anyway.
Perhaps that is why the future of privacy will depend less upon producing longer notices and more upon building organisations capable of remembering what people told them. The technology will become more complicated, the data flows more invisible and the temptation to reinterpret inconvenient choices more sophisticated. Yet beneath all that complexity remains an embarrassingly primitive proposition, one understood long before anyone invented cookies, CRM systems or the GDPR: when you ask a human being for permission, you inherit an obligation to respect the answer. Otherwise consent becomes corporate theatre, the curtain rises, the dashboards glow green, everybody applauds the controls, and somewhere beyond the boardroom a customer who already said no is being asked, once again, whether perhaps they really meant yes.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke






NGX political wrong call in showcasing reforms’ success