
Introduction
The Executive Regulations of the Personal Data Protection Law were issued in November 2025 by a decree of the Minister of Communications and Information Technology. While the Regulations constitute an important step toward giving effect to the Law and clarifying its implementation mechanisms, certain provisions raise questions regarding their enforceability and the way they reinterpreted several fundamental concepts upon which the Law is established, most notably the concept of consent to the collection of personal data.
The Personal Data Protection Law established a rule to protect individual privacy by stipulating that personal data may not be collected, processed, disclosed, or disseminated except with the explicit consent of the data subject, or in cases permitted by law.
The significance of this formulation lies in the fact that it renders consent a constraint on the authority of the entity collecting the data, rather than a mere procedural formality. However, the Executive Regulations have adopted a different formulation. Article 2 of the Regulations provides that a natural person’s provision of their personal data in order to obtain a service or carry out a lawful transaction constitutes consent to the collection and processing of this data for that purpose. Under this formulation, consent is no longer an explicit, unambiguous act; rather, it has become inferable from the conduct of the data subject themselves.
The problem here lies in transforming consent into a presumptive matter. In a system that protects personal data, consent must precede the collection process, be explicit, informed, and accompanied by a genuine ability of refusal. If consent is treated as an automatic consequence of requesting a service, it loses a significant aspect of its function, because the individual may provide their data out of necessity for the service, rather than as an expression of their freely given agreement to all forms of data collection and processing. This is even more evident in the digital environment, where most individuals cannot negotiate terms, modify how platforms operate, or easily access viable alternatives.
From this perspective, Article 2 of the Executive Regulations appears to reduce the protection established by the Law as it opens the door to confusion between processing that is truly necessary for the provision of the service and processing that goes beyond that for other purposes, such as behavioral analysis, tracking, marketing, or data sharing. The Regulations should have set a clear distinction between what is required for the performance of the service—which is subject to a specific legal basis—and any additional collection or processing, which should be based on explicit, separate consent or a clear legal basis.
The same Regulations require explicit written consent in certain cases, such as with sensitive personal data, children’s data, and some forms of direct online marketing. This indicates that consent inferred from behavior is not sufficient in all cases. However, this stricter standard has not been extended to the general rule regarding the collection of data related to daily services and transactions.
This paper examines the impact of the discrepancy in the formulation of the concept of consent between the Law and the Executive Regulations on the legal position of the data subject and their actual ability to exercise control over their data. The shift from requiring explicit consent under the Law to presuming consent in application broadens the authority of the data collector. It weakens the individual’s ability to object to its collection or determine the scope of its processing. The paper’s central argument is that data protection should not be based on the presumption of an individual’s consent merely because they request a service, but rather on establishing clear limits on what may be collected and processed from the outset.
The Legal Framework for Data Collection Consent in the Personal Data Protection Law
Understanding the issue of implied consent to data collection begins with the Personal Data Protection Law itself, rather than the Executive Regulations, as it is the binding general rule that takes precedence over the Regulations. The Law did not leave the regulation of consent to data collection to the Executive Regulations as a merely procedural matter; rather, it placed it within the framework of legal legitimacy. Article 2 of the Law provides that personal data may not be collected, processed, disclosed, or disseminated by any means except with the explicit consent of the data subject, or in cases permitted by law.
This wording reveals that the fundamental principle of the Law is to restrict the discretion of the data controller to collect personal data from the outset. The Law does not grant the authority to collect data unless the individual objects, nor does it treat the mere use of a service as sufficient to infer the individual’s consent. Instead, it establishes a clear rule: personal data may not be collected or processed unless the data subject has given explicit consent or where another legal basis specifically authorizes such collection or processing.
The significance of conditioning explicit consent lies in the Law’s distinction between clear and direct consent and presumed consent. The Law does not regard an individual’s awareness or lack of objection as sufficient, nor does it permit consent to be inferred from general conduct. Rather, it requires that consent be given clearly and directly. By using the term “explicit,” this legislative choice raises the level of protection and places the burden of proof on the party seeking to collect or process the data.
It is not enough for the entity to claim that the person used the platform, provided their data, or completed the transaction. Rather, it must provide proof of the individual’s consent to the processing of their data as specified. Accordingly, the Law places the protection of individuals and the limitation of the powers of entities that collect and process personal data ahead of facilitating the collection and circulation of such data.
However, the text does not make explicit consent the sole basis for the lawfulness of data collection. Article 2 uses the phrase “or in cases authorized by law,” which means that some forms of processing may be lawful without consent, provided they are based on a clear legal provision or framework. This distinction prevents confusion between two different situations: the existence of an alternative legal basis to consent, such as the necessity of fulfilling a legal or contractual obligation in cases permitted by law; and diluting consent requirements so that it can be inferred from any ordinary behavior conducted by the individual. The first situation may be lawful when the legal basis is specific and narrowly defined. In contrast, the second situation weakens the consent requirement itself rather than adding an independent legal basis for processing.
The Law’s regulation of consent in this Article is built upon two interrelated principles. The first is that the processing of personal data is not a neutral technical procedure, as it affects the legal position, privacy, and freedom of the individual, and must therefore be subject to legal constraints. The second is that the basis for collecting and processing data must be clear: either explicit consent or a case permitted by law. In both instances, the text does not permit the assumption of consent from the individual’s mere daily interaction with the service.
In addition, Article 2 of the Personal Data Protection Law links explicit consent to specific rights of the data subject. It grants the data subject the right to be informed of their personal data held by any data holder, possessor or controller; to view, access, or obtain it; to withdraw prior consent to the retention or processing of their data; to rectify, modify, erase, add to, or update their data; to restrict processing to a specified scope; and to be informed of any breach or violation of their personal data.
These rights complement the requirement of explicit consent and ensure that an individual’s control over their data is not limited to the moment of initial consent. The structure of the Law provides individuals with ongoing legal control over their data, rather than losing it merely by clicking a button or completing a form.
Nevertheless, the framework established by Article 2 remains general. It does not, on its own, clarify when consent is sufficiently explicit, what the specific conditions for its validity are, or how to distinguish in practice between processing necessary for the provision of the service and additional processing that requires separate consent. The Executive Regulations were supposed to clarify these issues in a way that enhances protection and limits the discretion of data controllers; however, they have instead tended to broaden the scope for inferring consent from a person’s behavior.
Transformation of Data Collection Consent from Explicit to Behavioral in the Executive Regulations
The Personal Data Protection Law establishes explicit consent as the general rule preceding the collection, processing, or disclosure of personal data. However, the Executive Regulations have reformulated consent in a manner that weakens its practical effect. This contradicts the principle that the Executive Regulations are, by their very nature, intended to elaborate on what the Law has outlined in general terms and to facilitate its implementation, not to alter its underlying logic or reduce the level of protection it provides.
Nevertheless, the Regulations have, with respect to consent to data collection, adopted a formulation that treats the daily conduct of the individual as sufficient grounds for inferring their consent, rather than moving towards a more rigorous approach in defining consent and regulating its conditions.
Article 2 of the Executive Regulations of the Personal Data Protection Law stipulates, at the outset, that personal data may not be collected unless the consent of the data subject has been obtained and the purpose of the collection has been clearly disclosed to them. This provision appears superficially consistent with the Law, although it does not describe consent as “explicit”.
The article then adds that the provision of personal data by a natural person for the purpose of receiving services or carrying out lawful transactions shall be deemed consent to the collection and processing of such data for that purpose. Under this formulation, consent is no longer a clear legal expression preceding processing; rather, it becomes a conclusion that may be inferred merely from an individual’s entry of their data as part of the procedures for obtaining a service.
There is a legal and practical difference between requiring explicit consent and considering the submission of data during a service request to be sufficient consent. In the first case, the burden of proving that the individual has given clear and direct consent falls on the entity collecting the data.
In the second case, however, it is sufficient for the entity to rely on the fact that the individual completed the procedure, used the platform, or submitted the required data. Thus, consent transforms from an independent legal safeguard into an effect linked to the service request, and its basis becomes behavior that can be interpreted as acceptance, rather than a clear expression of will.
This transformation occurs within a digital environment characterized by an imbalance of power between individuals and service providers. Individuals seeking digital services typically do not negotiate with service providers over the data requested, determine whether each category of data is genuinely necessary, or set conditions for its processing. In most cases, they have no choice but to accept the interface and terms presented to them to access the service.
Therefore, data entry does not necessarily reflect a free will to consent to its processing, but rather a need for the service. Furthermore, this need does not imply acceptance of all forms of processing that may result from data collection, such as storage, analysis, or subsequent use. Consequently, the distinction between data necessary for service provision and data collected to serve additional interests of the collecting entity becomes blurred.
This conflation could have been avoided by relying on the wording adopted by the Law itself. The Law permits processing “in cases authorized by law”, thereby distinguishing between processing based on consent and processing based on another legal basis. Accordingly, the Executive Regulations could have clarified that certain data may be necessary for the provision of a service or the completion of a transaction, and that its collection and processing in such cases would be grounded in a specific and limited legal basis, rather than presumed consent. However, the Regulations did not adopt this distinction.
This formulation reveals that the Executive Regulations approach consent to data collection from an administrative perspective rather than from the perspective of the data subject’s rights. This is reflected in their emphasis on electronic records, the recording of the date and form of consent, and the mechanisms adopted by the Personal Data Protection Center. While these requirements may serve important evidentiary and oversight purposes, they do not resolve questions concerning the validity of consent itself, including whether consent was freely given, whether the individual can refuse without being denied access to the service, and whether consent is specific to each processing purpose or instead broad and open-ended. An existing record proving that an individual submitted their personal data does not substitute for the absence of answers to these questions.
This regulatory approach undermines the practical value of the phrase “explicit consent” as used in the Law. Rather than signifying a clear and separate expression by the individual, it becomes possible to rely on their conduct to claim that they have consented. In this way, the Regulations permit the application of a broader standard than that established by the Law, thereby diminishing the protection associated with the conditional requirement of explicit consent.
Confusing the Necessity of Service Provision with the Freedom to Consent to Data Collection and Processing
Article 2 of the Executive Regulations conflates two distinct issues that must remain separate if the objective is to protect personal data rather than merely regulate its circulation. The first concerns the necessity of collecting certain data to provide a service or complete a lawful transaction. The second concerns the data subject’s freely given and explicit consent to the collection and processing of their personal data.
Although these two grounds are legally and practically distinct, the Executive Regulations treat the submission of personal data for the purpose of obtaining a service or completing a transaction as consent to the collection and processing of that data for that purpose. In doing so, they fail to clearly distinguish between data that are necessary for service provision and data that the individual has freely consented to have processed, effectively substituting the individual’s need for the service for their freely given consent.
This paradox is closely linked to the nature of the relationship between the individual and the service provider. In most digital environments, the individual does not negotiate with the provider over the type of data required or the terms of its processing. Individuals may not know why each category of data is requested, and they are generally unable to deselect certain fields while continuing to use the service. They may also fail to find a practical alternative if they refuse to provide the data.
Therefore, providing data does not necessarily mean that the individual has made a free decision regarding its processing. Rather, it may simply reflect the individual’s need to access the service, complete a transaction they cannot forgo, or cope with the absence of a realistic alternative. In such cases, consent becomes contingent upon the need for the service, rather than an independent expression of the individual’s will.
This confusion also affects the logic adopted by the Personal Data Protection Law. The Law does not consider a person to have consented merely by requesting a service. Rather, it stipulates that personal data may not be collected, processed, disclosed, or disseminated except with the explicit consent of the data subject, or in cases permitted by law. This formulation distinguishes between two bases for the lawfulness of processing: explicit consent, and cases in which the law permits processing based on a specific legal interest or necessity. This distinction prevents the data controller from treating everything requested within the service pathway as necessary, or from expanding the scope of data collection and processing based on additional interests not directly related to the provision of the service.
The Regulations could have regulated this matter more clearly and consistently with the Law. They could have provided that the processing of personal data strictly necessary for the provision of a specific service is justified by the necessity of providing that service, provided that the processing is limited to the minimum data required. Conversely, they could have required separate explicit consent for any additional collection or processing not directly and necessarily related to the provision of the service.
However, the Regulations did not distinguish between the two areas, assuming that anyone requesting the service and submitting their data had already consented to its collection and processing. Thus, the Regulations used the necessity of providing the service as a basis for presuming consent.
This confusion has practical implications concerning the scope of data that entities may request. An entity may include in its service form categories of data that are not all necessary for providing the service, and then rely on the fact that the individual voluntarily submitted those data as evidence of consent to their processing. At that point, the discussion shifts from the necessity of each category of data to merely proving that the individual provided it. The first approach places on the entity the burden of justifying each field and the purpose of its collection, whereas the second shifts this burden to the individual and treats the provision of data as sufficient to conclude the discussion on its lawfulness.
This approach also undermines the principle of data minimization. This principle requires that the entity request only the data necessary for the specific purpose and justify the need to collect each category of data within a narrow scope. However, considering the need for the service as evidence of consent places the individual before two options: accepting the entire set of requested data or forgoing the service altogether. In this case, consent ceases to function as a constraint on data collection and instead becomes a mechanism for legitimizing what the entity has already predetermined to collect.
The implications of this regulatory approach extend further when collected data is used for analysis, classification, service improvement, behavioral profiling, marketing, or sharing within the same corporate group. Article 2 of the Executive Regulations stipulates that the submission of personal data constitutes consent to their collection and processing “for that purpose”. However, the broad or complex wording of the purpose may make it difficult to distinguish between processing necessary for the service and additional processing.
For example, an entity might consider analyzing user behavior to be part of service improvement, describe the retention of data for extended periods as an operational requirement, or deem the sharing of certain data with a third party necessary to enhance service efficiency. In such cases, a single purpose could encompass multiple forms of processing, even though the individual has only expressed a desire to receive the service.
This critique does not deny service providers’ need to collect certain data necessary for the operation of services and the completion of digital transactions. However, this necessity must remain specific and reviewable, and must be limited to what is required to achieve the direct purpose of the service. It should not be used to justify the presumption of consent to all forms of collection and processing associated with it.
Therefore, maintaining the distinction between the necessity of providing the service and the freedom to consent preserves the individual’s ability to make an independent decision regarding their data, and prevents their need for the service from being used as a basis for consent that was not freely and explicitly given.
From Prior Consent to Subsequent Objection: The Executive Regulations’ Shift in Data Protection
The impact of the Executive Regulations extends beyond diluting the meaning of consent to data collection. It does not only dilute the essence of consent to data collection, but also shifts the focus of protection from the pre‑collection stage to a later one, at which the individual must object after their data has been collected or processed. This shift affects the nature of protection itself.
In a model framework most consistent with data protection, the entity does not begin collecting or processing data until legal requirements are met, foremost among which is obtaining explicit consent when consent is the legal basis for processing. However, the model adopted by the Regulations permits the initiation of collection and processing on a broad scale, and then subsequently grants the individual the right to object, rectify, or request erasure.
The first model protects the individual before processing begins or expands. In contrast, the second confronts the individual with the consequences of processing that has already begun and requires them to take subsequent steps to mitigate those consequences.
The Personal Data Protection Law, in its overall structure, does not place the individual in this defensive position from the outset. It makes explicit consent a prerequisite to the collection, processing, or disclosure of data, and links it to the individual’s rights to be informed, access their personal data, withdraw consent, request rectification, erasure, restriction of processing, and updating. This reflects the Law’s recognition that individuals’ rights must be respected before any processing of their data.
However, by accepting that providing data to receive a service constitutes consent to its collection and processing, the Executive Regulations shift part of the protection to a subsequent stage. Instead of focusing on whether the legal conditions are met before collection, the focus shifts to how the individual may exercise their rights after their data has been collected.
This shift is reflected in Article 3 of the Executive Regulations, which requires controllers to establish a mechanism, approved by the Personal Data Protection Center, enabling data subjects to submit a request to: access and review their personal data; withdraw prior consent to its retention; rectify or modify their data; restrict its processing to a specific scope; or object to any processing thereof.
This provision establishes important rights. However, at the same time, it reflects a sequence in which processing begins before these rights are exercised. Consent is presumed to have been given, the data already collected, and their processing may have already commenced, with subsequent means then made available to the individual for objection, rectification, or restriction. Thus, protection against unlawful processing is limited to the individual’s ability to mitigate its effects after it has already begun.
This sequence shifts part of the burden from the entity collecting the data to the data subject, because the exercise of subsequent rights does not take place automatically. The individual must first be aware that their data has been collected, understand how it is being used, identify the entity responsible for its processing, and access the approved mechanism for submitting their request. The individual must then formulate the request, follow up on the response, and ascertain what has happened to their data if it has been transferred to third parties or retained for multiple purposes.
Many individuals lack the time, knowledge, or technical and legal capacities necessary to pursue this course of action. Therefore, shifting protection to this stage does not merely delay it; it may render its exercise less effective and more difficult to access.
This framework also places individuals and controllers in unequal positions. The entity has already obtained, recorded, and stored the data, and may have begun analyzing it, linking it to other data, or using it within broader systems. The individual, however, only begins to exercise their rights after these steps have occurred.
Even if they later object, withdraw their consent, or request erasure, some effects of the collection and processing may have already taken place. The data may have been copied, incorporated into internal analyses, used to build a profile of them, or transferred to another system. For this reason, subsequent rights are not equivalent to the protection that would have been afforded by requiring legal conditions to be met before collection. These rights remain necessary, but they do not compensate for the protection that would have been afforded by requiring legal conditions to be met before processing.
This distinction is particularly important because the harm caused by data processing is not always apparent or immediate. Introducing data into an extensive processing cycle can make it difficult for an individual to regain full control. Even if the controller subsequently responds to a request for erasure or rectification, the data may have already been used or may have influenced other decisions or analyses. Therefore, data protection regulations must begin with establishing restrictions that prevent unjustified expansion from the outset, rather than relying solely on the individual to discover what has happened and then use objection mechanisms.
Criticizing implied consent is not intended to diminish the value of the rights of withdrawal, access, rectification, erasure, and objection. These rights are essential for protecting the data subject. However, the problem lies in treating them as sufficient to compensate for weak consent at the outset of data collection and processing.
Subsequent rights complement, rather than replace, prior restrictions on processing. If they are used to compensate for the absence or weakness of explicit consent, they become a delayed defense mechanism rather than an additional safeguard alongside prior protection.
Inconsistent Consent Standards
The problems with the Executive Regulations extend to their internal inconsistency in regulating consent. The Regulations do not adopt a single, clear standard, but rather establish two different levels of protection without providing a clear legal basis for this disparity.
This is evident in Article 2, which deems a person’s provision of their data to receive a service or carry out a lawful transaction as consent to the collection and processing of that data for that purpose. By contrast, other provisions in the Regulations require explicit written consent when it comes to sensitive personal data, children’s data, or direct electronic marketing. This disparity reflects differing assessments of the risks associated with collecting and processing personal data within the Regulations themselves.
Article 14, regulating sensitive personal data, stipulates that explicit written consent—whether on paper or electronically—must be obtained from the data subject or, in the case of children’s data, from their legal guardian, except in cases authorized by law. This wording does not suffice with general consent, nor does it allow consent to be inferred from mere conduct; rather, it requires a clear and specific expression of consent.
Article 15 adopts a similar standard for children’s data. For children under the age of 15, it mandates prior written, explicit consent from the legal guardian before data collection and processing. It also mandates that such consent must specify the time period covered. For children between the ages of 15 and 18, the Regulations remain stricter than the rule outlined in Article 2, as they require parental consent depending on the circumstances.
Article 18, which regulates direct electronic marketing, makes the sending of marketing communications conditional upon the data subject’s explicit consent. It further prohibits personal data collected for that purpose from being used for any other purpose unless new explicit consent has been obtained. These provisions demonstrate that the Executive Regulations apply a more stringent consent standard where they consider the nature of the processing to require a higher level of protection.
Article 2, which governs the general rule for the collection and processing of personal data, does not provide such a higher level of protection. The article does not require explicit or written consent; rather, it allows the provision of data by an individual while receiving a service to be considered sufficient consent. This results in a disparity within the Regulations between explicit, documented consent for certain types of processing and consent inferred from conduct under the general rule.
If the Regulations stipulate that certain types of processing may only be based on explicit, direct, and documented consent, they could have adopted this as the default standard while narrowly defining the exceptions in which processing may rely on another lawful basis.
This disparity may be grounded in the fact that sensitive data, children’s data, and direct marketing are associated with higher risks. However, the nature of data at the point of collection is not the sole factor determining the level of risk in the digital environment. Additional risks may arise from the aggregation, linking, and analysis of personal data, even where each category of data appears non-sensitive when considered in isolation.
Data that do not appear sensitive when collected separately may, once combined with other data and analyzed, reveal sensitive information about an individual’s behavior, relationships, location, habits, consumption patterns, and interests, and may even disclose their health status, religious beliefs, political opinions, social circumstances, or sexual orientation.
Therefore, basing protection on separating between sensitive and non-sensitive data—without taking into account the effects of aggregation, linking, and analysis—does not cover all risks arising from processing. This makes the adoption of a weaker standard in the general rule for data collection something that requires clearer justification, as this rule serves as the starting point for various forms of subsequent processing.
This disparity also weakens the basis that could be relied upon to justify Article 2. If everyday transactions and digital services require a degree of flexibility, the standard of explicit consent could have been retained, at the very least, in cases where the necessity of collecting all the requested data is not established. If the Regulations consider that consent inferred from conduct is insufficient for direct marketing, accepting it at the stage of initial data collection raises a problem, because this stage may precede the use of data for marketing, analysis, or classification.
Thus, the Regulations require clearer consent for certain forms of subsequent use, while applying a less stringent standard at the stage of collecting data that may later be used for these very activities. This regulatory approach ensures a higher degree of protection for some stages of processing, while maintaining a less stringent standard at the stage where the data collection cycle begins.
This inconsistency demonstrates that the Executive Regulations do not adopt a coherent conception of consent. In some Articles, consent is treated as a legal expression of will that must be explicit, documented, and specific. In Article 2, however, consent is treated as something that may be inferred from an individual’s use of a service.
This disparity also grants the data controller broader scope in collecting and processing data under the general rule, while requiring compliance with a stricter standard only in the cases explicitly specified by the Regulations. Thus, the entity may apply the explicit requirements for sensitive data, children’s data, and direct marketing, while benefiting from a weaker standard for all other forms of data collection and processing.
This disparity also confirms that requiring clearer consent is not legally or technically impracticable. The Regulations themselves have regulated explicit, written consent and specified certain cases in which it is required. Yet they did not adopt this standard as the starting point for the collection of ordinary personal data, even though such collection affects a far greater number of individuals in their everyday interactions.
The weaker consent standard in Article 2 therefore reflects a regulatory choice rather than a consequence of the impossibility of applying explicit consent in the digital environment. As a result, it weakens individuals’ ability to control the collection and processing of their data.
Moreover, this disparity demonstrates that the Executive Regulations did not establish a coherent standard for protecting individuals’ freedom to consent to the processing of their personal data. They raise the level of protection where the risks are associated with particular categories of data or specific processing activities, but do not apply the same standard to the collection of data that appears ordinary, even though its aggregation, linking, and analysis may give rise to comparable risks.
Conclusion
This paper concludes that the shortcomings in regulating consent within the Executive Regulations stem from the approach they adopted. Rather than building upon the explicit consent requirement established by the Personal Data Protection Law, and clarifying its conditions, limits, and effects in a manner that enhances the protection of the data subject, the Regulations have adopted a framework based on a less protective standard. This is evident in the fact that a person’s provision of their data when requesting a service or conducting a transaction is considered consent to the collection and processing of that data for that purpose.
This approach weakens the consent standard established by the law by allowing consent to be inferred from an individual’s conduct rather than requiring it to be given explicitly. It also shifts part of the burden of data protection from the entity collecting the data to the individual seeking to obtain a service.
As a result, the subsequent exercise of rights, such as the right to object, request erasure, or seek rectification, becomes a means of addressing the consequences of data collection after it has already occurred, rather than ensuring that explicit consent serves as a prerequisite for the collection and processing of personal data.