A data subject orientated approach to auditing consent: an Aristotelean Smithian Lockean approach to data subject orientated online consent

Breen, Stephen (2024) A data subject orientated approach to auditing consent: an Aristotelean Smithian Lockean approach to data subject orientated online consent. Doctoral thesis, London Metropolitan University.

Abstract

The focus of this research is the relationship between a company who is requesting consent to process online personal data from Data Subjects and how the consent can be audited to determine complaince to regulations such as the GDPR (European Union, 2016). It looks at the issues relating to requests for consent and how Data Subjects experience this request with the context of the GDPR and how consent in particular is addressed by companies. Leading on from the literature review and other data, a consent audit was developed based on the analysis and findings from qualitative and quantitative data, which then influenced the development of an audit verification process.

The literature review highlighted an imbalance in the relationship between an organization and a Data Subject. An approach was developed for this research based on Greenwood (Greenwood, 2007) who highlights the importance of rebalancing the relationship between companies and businesses. The philosophical underpinning of this research is taken from Aristotelean (Aristotle, 1981) philosophy and expanded on with views on consent from Adam Smith (Smith, 1993) and John Locke (Locke, 1988). This approach aligns with the GDPR which reorientates the relationship between a company and a Data Subject, which is describe by this research a Data Subject orientation. The literature review also showed that there is a significant gap between data governance, international standards and a Data Subject orientation. It has also shown that there is no philosophical foundation for online consent in relation to online personal data and an absence of a consent audit in relation to the GDPR. This research aims at resolving this problem by proposing an Aristotelean, Lockean, Smithian approach to Data Subject oriented consent. The research methodology had three distinct stages. Firstly, the development of a conceptual model based on findings taken from an understanding of consent taken from the literature review and an analysis of themes taken from the GDPR and ISO standards. This phase of the methodology provided insight into the problems and issues related to online consent and lead to the development of the research hypotheses:

H1: Compliance with Articles 6, 7, 8, 9, 13, 17, 20, 22, 40, 49, of the GDPR, in relation to consent, is only possible if the data security model has a Data Subject orientation.

H2: An GDPR-ISO audit model will provide increased assurance that Articles 6, 7, 8, 9, 13, 17, 20, 22, 40, 49 relating to consent in the GDPR are compliant and that it provides validation for a Data Subject oriented data security model.

Secondly, qualitative and quantitative data collection, a case study and analysis, providing themes against which consent compliance can be measured from the Data Subject's perspective, which lead into the final aspect of this methodology. Thirdly, the development of a GDPR-ISO DSO Audit verification process used to verify H1 and H2.

The research shows that the themes developed from the qualitative data analysis provided a detailed understanding of how Data Subjects experience the requesting and giving of consent. Following on from this, the output of the data analysis led to the development of a GDPR-ISO DSO audit verification process, with the results from the GDPR-ISO DSO audit verification process showing that the audit model is robust and showing that H1 and H2 have been verified.

The contribution to knowledge from this research includes a philosophical approach to understanding consent within a Data Subject orientation, based on Aristotelean philosophy and expanded on with views on consent from Adam Smith and John Locke. A Data Subject oriented approach to a data security model, which is new and attempts to rebalance the relationship between companies and Data Subjects. A mixed methods data collection and analysis using two iterations, which fed into each other resulting in detailed findings and the development of consent themes. A GDPR-ISO DSO Audit Model Verification Process, with the development of three filters, one of which is based on themes taken from the mixed methods data collection and analysis.

Details
Record
View Item View Item