When Your Product’s Requests for Consent Frighten Your Users

Do your user consent procedures drive your users away?

When a product deals with personally identifiable information (PII), the product vendor is nornmally required to obtain one or more types of consent from their users: consent to process the data, consent to store the data, consent to use the data in algorithmic traijing, and possibly others.

When the consent notice appears on the user’s screen, they will react in one of two ways:

  1. They will provide the requested consent without hesitation.
  2. Something about the consent request frightens them so much that they uit the process right then and there.
By Tim Reckmann from Hamm, Deutschland – Einkaufswagen, CC BY 2.0, https://commons.wikimedia.org/w/index.php?curid=83154898.

It’s yet another example of the abandoned shopping cart problem, where people stop shopping (or in this case consenting) and the seller loses money from a lost sale.

How can you get the first group to 100% and the second group to 0%?

By avoiding these three mistakes.

Mistake 1: your consent request is too vague

What if you ask your users for consent to use their data, but don’t explain how you’re going to use it?

Now some people will sign the consent form anyway, thinking that your company would never do evil things…until they do,

But more discerning people will become immediately suspicious and start asking questions…or just not bother to ask questions and abandon your process.

Mistake 2: your consent request is too detailed

To protect themselves legally, compliance teams often insist on dense, intimidating language full of terms like immutable identifiers, third-party processors, and permanent data storage retention protocols.

Now some people will sign dense documentation even if the fine print requires them to hand over their first born. Others won’t.

If you’re required to talk about immutable identifiers due to some regulation or another, add a preface that explains what immutable identifiers are.

Mistake 3: your consent request doesn’t have a time limit

Some privacy regulations require that companies managing data only keep the data for a specified amount of time. Your consent request should comply with these regulations. If you don’t, you’re in trouble.

But even if your local regulations don’t mandate a time limit for storing data, impose one anyway.

Think about the practicality of it. Let’s say you’re requesting resumes for job applications, and I submit one. How useful is that resume going to be to you ten years in the future?

Conclusion

Don’t frighten your users. Ensure that your consent process is easily understandable, not overwhelming, and explains what the users need to know.

Leave a Comment