THE GIST Young people click “I agree” hundreds of times a year. Research shows they rarely understand what they are agreeing to. This is not simply a literacy problem. It is a design problem, a policy problem, and an education problem all at once — and computing education is the obvious home for the response.
Somewhere in a server farm, there exists a legally binding agreement between a child and a corporation. The child was eleven. They clicked a button. They had no meaningful understanding of what they agreed to.
This happens millions of times a day.
I am very humbled to have contributed to IEEE standard 2089-2020 which informed by the United Nations Convention on the Rights of the Child (CRC) and the Children’s Code in the UK. Through this and other research examining young people’s experiences of privacy online across multiple countries, found consistently that young people are aware, in general terms, that platforms collect their data (Farthing et al., 2023). What they rarely understand is the scope of that collection, the ways data is used or shared, the specific meaning of terms like ‘personalised advertising’ or ‘legitimate interest,’ or what their rights are under data protection law. Awareness without comprehension is not an informed relationship with data.
The reasons for this are well documented and largely structural. Terms and conditions are written by lawyers for lawyers, or more precisely, by lawyers for regulators, since the primary function of most privacy policies is legal protection for the company, not meaningful communication with the user. They are long, abstract, and designed to be unread. Reidenberg and colleagues (2015) found that privacy policies for major online services averaged over 2,500 words and required a postgraduate reading level to comprehend. Subsequent research found that reading all the privacy policies a typical US adult encounters in a year would take approximately 76 working days (McDonald & Cranor, 2008). The numbers are not significantly different for UK users.
The interaction design of most consent flows reinforces this. Dark patterns, design choices that steer users toward outcomes that serve the platform’s interests rather than the user’s are endemic in consent interfaces. A 2022 report by the Norwegian Consumer Council documented their prevalence across major platforms, finding that ‘I agree’ was consistently presented in larger type, brighter colours, and more prominent placement than ‘manage settings’ or ‘decline’ (Forbrukerrådet, 2022). These are not accidents. They are design decisions. And they work.
Awareness without comprehension is not an informed relationship with data. Young people know platforms collect their information. What they do not understand is what that means.
It is tempting to frame this as a literacy problem and reach for an educational solution. Teach young people to read privacy policies. Teach them what cookies are, what personalised advertising means, and how data brokers operate. These are worthwhile things to teach. But the framing of individual literacy as the primary response to a structurally coercive system places an unreasonable burden on individuals and implicitly absolves system designers of responsibility.
The policy response to this recognition has been meaningful but incomplete. The ICO’s Children’s Code, enforced from 2021, introduced a set of standards for online services likely to be accessed by children, including requirements for data minimisation, restrictions on profiling, and the default use of strong privacy settings (ICO, 2021). This was a significant step. The EU’s Digital Services Act, which came into force in 2024, introduced additional transparency obligations and placed limits on targeted advertising directed at minors. But enforcement is slow, cross-border jurisdiction is complicated, and the gap between what the law requires and what platforms actually deliver remains substantial.
Research through the TrusTech4Kids project surfaced something important about how young people navigate this gap (Farthing et al., 2023). Young people are not passive. They develop workarounds by creating multiple accounts, providing false ages, using browsers in private mode. These reflect a sophisticated, if informal, understanding of how these systems work. But these workarounds shift the compliance burden onto the child and leave the structural problem intact. A thirteen-year-old who lies about their age to access a service is not demonstrating adequate consent. They are demonstrating that the system has failed them.
So where does education fit? Precisely here: not in replacing structural reform with individual responsibility, but in building the capacity to participate in the structural conversations. Young people who understand how consent design works, what business models depend on data collection, what the legal rights afforded to them actually mean, and how to exercise those rights are better placed to advocate for better systems. They are also better placed to make informed political choices about which regulatory frameworks to support and which politicians’ positions on digital rights align with their interests.
Computing education is the obvious home for this curriculum. It already covers data, algorithms, and systems. The socio-political and rights dimensions of those topics belong there too. The argument that these are ‘not technical’ topics misunderstands what computing is. Consent design is a design problem. Data brokerage is a systems problem. Regulatory compliance is a programming problem. The technical and the ethical are not separable.
Young people who understand how consent design works are better placed to advocate for better systems and to make informed political choices about digital rights.
A practical starting point would be to introduce, at secondary level, structured analysis of real terms and conditions documents. Not with the expectation that students will read every policy they encounter, that is not a reasonable expectation for anyone. But to build a structural literacy: understanding what categories of data are typically collected, what ‘legitimate interest’ means as a legal basis for processing, what rights the GDPR affords data subjects, and what the process for exercising those rights looks like in practice.
Clicking ‘I agree’ is not informed consent. It is the simulation of consent within a system designed to produce agreement. Teaching young people to recognise that simulation, to understand what genuine consent would require, is not a radical curriculum proposal.
It is basic preparation for digital life.
Thanks for reading Data in Motion
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.