MarketingMarketing Analytics

The consent illusion: why privacy ethics demand more than a cookie banner

Most marketing organisations treat consent as a compliance checkbox rather than a strategic asset. The companies that understand the difference are building durable customer relationships while their competitors race toward regulatory cliffs.

🎙️

Listen to the podcast

4 min

Privacy has become one of the loudest topics in marketing circles. GDPR turned ten in 2028, but its real legacy is visible right now: every major platform, every data broker, every adtech vendor is repositioning itself as a "privacy-first" solution. California's CPRA reshaped data handling practices across North American operations. Google's deprecation of third-party cookies, after years of delays, finally forced the industry's hand. CMOs who were slow to adapt are now paying consultants to explain concepts their legal teams flagged half a decade ago.

The conversation is everywhere. And the consensus view that has crystallised around it is, on the surface, entirely reasonable.

The consensus view

The dominant position goes roughly like this: the era of surveillance-based marketing is closing. Regulation is tightening globally. Consumers are more aware of how their data is used, and they care more than they used to. The smart move is to invest in first-party data, build clean consent frameworks, and use that foundation to deliver personalised experiences within clear ethical boundaries. Trust is the new currency. Privacy is a competitive advantage.

This view is supported by credible evidence. Research from Edelman's Trust Barometer has consistently shown that data misuse ranks among consumers' top concerns with brands. Boston Consulting Group found that companies perceived as trustworthy in their data practices generate significantly higher returns on marketing spend. Even on the commercial side, vendors like Salesforce and Adobe have built substantial product lines around consent management and first-party data activation, though those figures should be weighed knowing they have direct commercial incentives to emphasise the opportunity.

There is nothing wrong with this framing as far as it goes. It reflects genuine shifts in regulation and genuine consumer sentiment. A CMO who ignores it is making a serious error.

Where it breaks down

The problem is not that the consensus is false. The problem is that it has been absorbed into marketing culture as a technical challenge rather than an ethical one, and that distinction has significant second-order effects.

Most organisations have responded by building consent management platforms, refreshing cookie banners, and publishing updated privacy policies. That is compliance, not ethics. It is worth being precise about what "consent" actually means in practice today. A user clicking "Accept all" on a banner they cannot be bothered to read is not meaningfully consenting to anything. Research from the Norwegian Consumer Council documented how consent interfaces are routinely designed to make rejection difficult, time-consuming, and cognitively exhausting. The name for this practice is dark patterns, and it is widespread. The fact that it is technically lawful in many jurisdictions does not make it ethical, and the distinction matters for CMOs who are thinking beyond the next quarter.

There is also a deeper structural problem. The "first-party data as a solution" framing assumes that companies can replicate the targeting precision they lost from third-party cookies simply by accumulating more direct data from their own users. This is partially true, but it misses something. The reason surveillance-based targeting was so powerful is precisely because it tracked behaviour users were not aware was being tracked. First-party data collection, done honestly, is actually less comprehensive. That gap cannot be closed by clever consent UX. A genuinely privacy-respecting first-party data strategy means accepting some loss of targeting precision. Very few marketing strategy documents acknowledge this trade-off explicitly.

The second blind spot is about demographics. The populations that most actively engage with privacy settings are not representative of the broader customer base. Highly educated, higher-income users in Western markets are significantly more likely to opt out, use ad blockers, or read privacy settings. If your consent architecture effectively skews your first-party data toward users who are least sensitive to targeted advertising, your models are training on a biased sample. This is a measurement problem that sits underneath the ethics conversation, and almost no one is talking about it seriously.

Finally, the "trust as competitive advantage" framing invites a cynical version of the strategy: perform trustworthiness rather than practise it. Amazon, Meta, and Google all have sophisticated privacy dashboards and consent interfaces. They also face ongoing enforcement actions across the EU, the UK, and multiple US states. The infrastructure of transparency can exist entirely independently of genuine respect for user autonomy. A CMO who builds a sophisticated consent management platform while continuing to exploit every technical grey area is not ahead of the curve. That organisation is building regulatory and reputational exposure, not competitive advantage.

What a sharp operator should actually do

The CMOs who are getting this right are treating privacy as a design constraint rather than a communications strategy. That is a meaningful distinction.

Concretely: build your targeting architecture as if the most aggressive interpretation of current regulation is already in force everywhere you operate. The direction of travel in the EU, UK, Brazil (LGPD), India (DPDP Act), and the patchwork of US state laws is consistent. The question is not whether stricter rules are coming but when and in what form. Companies that build toward the stricter frontier now avoid costly system rebuilds later.

Invest in contextual targeting competence. The industry's response to cookie deprecation has been heavily weighted toward identity resolution, data clean rooms, and other mechanisms that try to reconstruct individual-level targeting. These are not inherently problematic, but the assumption that you need individual-level precision for effective marketing is itself worth challenging. The evidence on contextual advertising, particularly from independent academic work and from publishers who have studied their own inventory, suggests that relevance at the content level drives meaningful engagement without requiring individual tracking.

On consent design, the standard should not be "technically compliant" but "would this interface embarrass us if a regulator or a journalist described it in detail." That is a more reliable test than a legal review.

The organisations building durable positions here are not the ones with the most sophisticated adtech stack. They are the ones where the CMO has a direct relationship with the privacy governance function and where customer data practices are reviewed against ethical standards, not just legal ones. Patagonia's approach to customer data, for instance, has been shaped by its broader brand values in ways that go well beyond regulatory requirements. That kind of coherence is hard to copy and harder to undermine.

Privacy ethics in marketing is not a solved problem because you have deployed a consent management platform. The companies treating it that way will find out the hard way, probably in the form of an enforcement action or a media cycle that damages brand equity in ways that take years to repair.

Finished reading?

Validate your read to earn XP and feed your radar.