This paper critically examines the use of nudging techniques in obtaining consent for the processing of personal data. It argues that, in most cases, verifying compliance with the validity requirements set out by the GDPR ultimately amounts to assessing the choice architecture that underlies consent requests. Building on this premise, the study shows that the cognitive process leading to the granting of privacy consent typically reflects “fast thinking,” which renders individuals particularly susceptible to the deliberate manipulative strategies crafted by those who design the decision-making environment. This cognitive asymmetry – between users’ fast thinking and the slow, reflective thinking of choice architects – constitutes the root of the systemic vulnerability of digital users. Finally, in light of the ease with which consent can be secured, the paper advocates complementing measures aimed at countering decision manipulation with substantive forms of protection, analogous to those found in consumer law, by introducing a robust regulatory framework capable of safeguarding both individual rights and the broader public interest in establishing democratic limits on the accumulation of personal data.

Il saggio analizza criticamente l’impiego delle principali tecniche di nudging nell’acquisizione del consenso al trattamento dei dati personali, mettendo in luce come, nella maggior parte dei casi, la verifica della sussistenza dei requisiti di validità prescritti dal GDPR finisca per tradursi in una valutazione dell’architettura delle scelte sottesa alla richiesta di consenso. Su questa base, lo studio prosegue evidenziando come il processo mentale che presiede alla concessione del consenso privacy si configura tipicamente come un “pensiero veloce” (impulsivo), particolarmente esposto alle meditate strategie manipolatorie elaborate da chi allestisce l’ambiente decisionale. Tant’è che proprio quest’asimmetria cognitiva, tra il “pensiero veloce” degli utenti e il “pensiero lento” (riflessivo) degli architetti delle scelte, è all’origine della sistemica vulnerabilità dell’utente digitale. Infine, data la facilità con cui gli architetti delle scelte riescono a ottenere il consenso, si propone di affiancare ai rimedi volti a contrastare la manipolazione delle decisioni forme di tutela sostanziale – analogamente a quanto previsto nella legislazione consumeristica – attraverso l’introduzione uno statuto normativo “forte”, idoneo a salvaguardare anche l’interesse generale a porre un argine democratico all’accumulazione dei dati personali.

Navone, G. (2026). Nudge e consenso privacy: una spinta (non sempre) gentile. RIVISTA DI DIRITTO PRIVATO, 31(2), 265-278.

Nudge e consenso privacy: una spinta (non sempre) gentile

G. Navone
2026-01-01

Abstract

This paper critically examines the use of nudging techniques in obtaining consent for the processing of personal data. It argues that, in most cases, verifying compliance with the validity requirements set out by the GDPR ultimately amounts to assessing the choice architecture that underlies consent requests. Building on this premise, the study shows that the cognitive process leading to the granting of privacy consent typically reflects “fast thinking,” which renders individuals particularly susceptible to the deliberate manipulative strategies crafted by those who design the decision-making environment. This cognitive asymmetry – between users’ fast thinking and the slow, reflective thinking of choice architects – constitutes the root of the systemic vulnerability of digital users. Finally, in light of the ease with which consent can be secured, the paper advocates complementing measures aimed at countering decision manipulation with substantive forms of protection, analogous to those found in consumer law, by introducing a robust regulatory framework capable of safeguarding both individual rights and the broader public interest in establishing democratic limits on the accumulation of personal data.
2026
Navone, G. (2026). Nudge e consenso privacy: una spinta (non sempre) gentile. RIVISTA DI DIRITTO PRIVATO, 31(2), 265-278.
File in questo prodotto:
File Dimensione Formato  
Estratto RDP 2-2026 - Navone.pdf

non disponiibile

Tipologia: PDF editoriale
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 693.47 kB
Formato Adobe PDF
693.47 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11365/1321694