Consent: What You Can Measure When People Say No
Refusal rates vary enormously and are not random. What that does to your data, what modelling actually fills in, and what survives regardless.
Consent is usually discussed as a legal problem. It is also a measurement problem, and the measurement consequences are larger and less understood than the compliance ones. In workplace settings, the same consent and proportionality questions apply to employee monitoring software, especially when individual activity is collected.
This article is about what consent does to your data. The legal requirements differ by jurisdiction, change frequently, and need current specialist advice rather than an article — including this one.
The measurement problem is selection, not volume
If 40% of visitors refuse tracking, the obvious framing is that you lost 40% of your data.
The real problem is that you did not lose a random 40%.
People who refuse differ systematically from people who accept. They skew by device, by browser, by age, by technical confidence, by country, and by how the prompt was designed. Every one of those correlates with commercial behaviour.
So the visible portion of your data is a biased sample, and every rate computed from it — conversion rate, channel share, device split — is a rate for the consenting population rather than for your customers.
That is a different and worse problem than missing volume. Missing volume you can scale up. Bias you cannot, unless you know its shape.
What varies, and by how much
Refusal rates are not a fixed industry number, and any article quoting one should be treated with suspicion.
They vary by:
Jurisdiction and regime. Whether consent is required at all, and whether refusal is as easy as acceptance.
Prompt design. A banner where "reject all" is one click and one where it takes three produce very different rates. This is also where compliance and measurement pull in opposite directions, and where a lot of quiet non-compliance lives.
Audience. Technical audiences refuse more. Older audiences accept more. Mobile differs from desktop.
Brand trust and context.
Measure your own. The number that matters is your refusal rate, by segment, and how it has moved. An industry average tells you nothing about your bias.
What modelling actually does
Platforms offer to model the conversions you cannot observe. Understanding what this is and is not:
It is an estimate produced by observing the consented population and extrapolating to the unconsented one.
It assumes the two populations behave similarly, conditional on whatever the model can see. That is the assumption doing all the work, and it is exactly the assumption that selection bias violates.
It is produced by the party being evaluated, using a method you cannot inspect, with a definition of conversion they control.
It may still be the best available estimate. The objection is not that modelling is illegitimate — it is that a modelled number and an observed number are different kinds of thing and are usually presented in the same column of the same table.
Practical instruction: find out what proportion of your reported conversions are modelled, per platform. The platforms disclose this. The proportion is usually higher than people assume, and it should change how much weight the number carries.
What survives consent entirely
The underrated part, and it is the same list as the one that survived cookie erosion.
Server-side records of what actually happened. Orders, revenue, sign-ups. Your own transactional data does not depend on anyone's consent to tracking, because it is the record of a transaction you were party to.
This is the ground truth, and it is frequently the least-used dataset in the building. If analytics says 400 conversions and the order table says 340, the order table is right.
Aggregate methods. Geo experiments, holdout tests and marketing mix modelling operate on totals. They do not need to identify anyone, so consent does not degrade them at all. See incrementality.
Which is the strategic point: as user-level observation degrades, the relative value of experimental methods rises. Organisations that built their measurement on aggregate causal methods have been largely unaffected by the last six years. Organisations that built it on user-level path reconstruction have been rebuilding continuously.
Working with a biased sample
You will still use the consented data. Doing it honestly:
Report rates with the denominator stated. "Conversion rate among tracked users" is a different metric from "conversion rate," and the difference is not pedantry — it moves when your consent rate moves.
Watch for consent rate changes masquerading as performance changes. A cookie banner redesign that reduces acceptance by ten points will move every metric on every dashboard, and it will be attributed to marketing. Log banner changes on the same timeline as campaign changes, or you will spend a week explaining a drop that had nothing to do with you.
Reconcile against ground truth regularly. Tracked conversions against actual orders, monthly, per channel. The ratio is your visibility rate, and its movement is more informative than most dashboards.
Use the tracked data for relative comparisons within a period, and the transactional data for absolute numbers.
Do not compare tracked metrics across periods where consent rates differed. This is the most common silent error in this whole area.
Questions worth asking about your own setup
What is our refusal rate, and how has it moved? Most organisations do not measure this, which means they cannot detect when it changes.
Does refusal correlate with anything commercial? Compare consented and non-consented traffic on whatever you can see server-side — landing page, referrer, device, geography. If they differ, you have quantified your bias, which is more than most people have.
What proportion of reported conversions are modelled?
Does our tracked conversion count reconcile with orders? And has that ratio drifted?
When did the banner last change, and is that change on the same timeline as the metrics?
The framing worth using with stakeholders
The temptation is to present modelled and tracked numbers as one figure, because a single number is what was asked for.
The better version separates them: "We observed 340 orders. Analytics reports 400 conversions, of which some proportion is modelled. The gap is our visibility, not our performance."
Then the follow-up question — "so which is right?" — has a clean answer: the order table is what happened; analytics tells you where it plausibly came from, for the portion it can see.
See explaining uncertainty to someone who wants a number.
The summary
Consent removes a biased slice, not a random one, and that is the harder problem.
Modelling extrapolates from the consenting population, which is exactly the population that differs.
Your transactional data is the ground truth and it does not depend on consent.
Aggregate causal methods are unaffected, which is why their relative value keeps rising.
And log your banner changes next to your campaign changes, because otherwise a consent shift will be read as a performance shift, and someone will act on it. For current legal guidance, consult the ICO guidance on consent.