
Most businesses tick the consent box and move on. A pre-ticked checkbox here, a privacy policy link there. It feels handled. But consent is no longer that simple — and the difference between opt in and opt out now carries real legal weight.
Getting it wrong is not a technical oversight. It is a compliance failure with financial consequences attached.
Opt In vs Opt Out: What Is the Difference?
Opt in requires a person to actively agree before a business collects or uses their data. Opt out allows the business to collect data by default unless the person takes action to stop it.
One word apart. Worlds apart in terms of compliance.
Valid consent must meet four standards:
- Voluntary — the person makes a genuine choice, free from pressure
- Informed — they understand what they are agreeing to in plain language
- Current — businesses cannot assume consent from a past interaction
- Specific — a blanket agreement does not cover every use of personal data
Pre-ticked boxes, vague opt out language and buried privacy settings fail that standard. Passive consent is not consent at all.
Why Businesses Get Consent Wrong
Most businesses do not set out to mislead their customers. The problem is that they built consent models for convenience, not compliance.
A pre-ticked newsletter subscription. A cookie banner that makes opting out harder than opting in. An app that assumes permission because a customer created an account.
Tracking consent at scale adds another layer of complexity. Businesses must record who consented, to what, and when — across every touchpoint where they collect personal data. Without the right processes in place, that becomes unmanageable as the business grows.
What Good Consent Looks Like in 2026
Good consent is clear, honest and gives the person a genuine choice:
- Plain English explanations of what data is being collected and why
- An active opt in rather than a pre-selected default
- A straightforward way to withdraw consent at any time
- A record of when and how consent was obtained
The upcoming December 2026 Privacy Act amendments and the OAIC are raising the bar significantly. When a customer submits an Individual Rights request, consent records are often the first thing that comes into question.
Consent is not a one-time checkbox. It is an ongoing relationship between a business and the people whose data it holds.





