As the EU’s AI Act and Digital Services Act reshape digital governance, traditional privacy consent models face unprecedented scrutiny. In Reflections upon ’The Privacy Fallacy’ by Ignacio Cofone (2025), Salvatore Orlando, an expert in Italian data law, examines Ignacio Cofone’s The Privacy Fallacy (Cambridge UP 2024) to propose a paradigm shift in EU data protection. This commentary previews how Orlando reframes consent from a procedural checkbox to a substantive normative filter, blending behavioural economics with GDPR principles.
Consent Beyond Contract
Orlando persuasively critiques Cofone’s core challenge to privacy law’s contractual consent model, which assumes rational, informed choices in digital environments. He dismantles two myths: the myth of rationality (users as perfectly informed decision-makers) and the myth of apathy (users’ indifference to privacy). As Orlando notes, ”European data protection law—and the GDPR in particular—cannot be understood purely through procedural compliance” but must account for platform design and economic incentives.
Key takeaways:
-
GDPR Art 6(1)(a) consent falters amid cognitive biases.
-
Shift to socio-legal constructs integrating real-world behaviour.
This raises questions: How might national courts apply these insights variably across the EU?
Behavioural Distortions and Consumer Law
Behavioural distortions emerge as a legally actionable harm, with Orlando linking privacy to the Unfair Commercial Practices Directive (UCPD, Directive 2005/29/EC). Platforms exploiting biases undermine consent, mirroring UCPD prohibitions on manipulative practices. By analogy, privacy law should treat such dynamics as vitiating factors, not mere user errors.
Key takeaways:
-
UCPD remedies (e.g., blacklisting dark patterns) extend to data consent.
-
Cognitive vulnerabilities demand proactive regulatory design.
Critically, this integration risks blurring consumer and data protection remits—does it empower or overburden enforcers?
Substantive Legality of Purposes
Orlando innovates by anchoring consent validity to GDPR Art 5(1)(b)’s purpose limitation, arguing that illicit processing (e.g., discriminatory targeting) renders consent invalid ab initio. No procedural perfection salvages substantively unlawful aims, expanding review beyond form to content. Traditionally, consent focuses on GDPR Art 6(1)(a) validity and procedural elements like being informed and specific, as seen in cookie banners; Orlando’s substantive test, however, pivots to Art 5(1)(b) legitimacy and purpose lawfulness, exemplified by prohibited profiling.
This test invites scrutiny: Might it chill legitimate innovation, or fortify against Big Tech overreach?
Relational Dimensions of Data
Building on Cofone, Orlando embraces personal data’s relational nature, where profiling harms ripple beyond individuals to societal biases and collective autonomy. Algorithmic ecosystems demand holistic jurisprudence, aligning with debates on data governance’s public interest turn.
Key takeaways:
-
Individual consent ignores externalities like echo chambers.
-
Relational lens supports collective remedies under DSA.
Compared to US FTC enforcement, Orlando’s approach foregrounds EU-style purposivism—yet empirics on consent fatigue remain underexplored.
Toward a Renewed Paradigm
Orlando synthesises these threads into an interpretive overhaul: infuse GDPR with behavioural insights, UCPD tools, and purpose legality to normativise consent amid digital markets. This enriches discourse on regulatory pluralism, urging interdisciplinary empirics to test relational privacy’s viability. Can EU law enforce such shifts against Big Tech lobbying? Future scholarship might probe national divergences or AI Act synergies.
Read Salvatore Orlando’s full publication here: https://universitypress.unisob.na.it/ojs/index.php/ejplt/article/view/2199/1745
