Proof

Brand, technology and AI, with the working shown.

No. 03 Consent

Permission is a design material

India’s data protection rules arrive in phases, accessibility becomes a market rule in Europe, and agents need a way to ask before they act. Consent, designed in rather than bolted on.

Read
4 min
Stories
4
Get Proof by email
A brass letterbox on a dark blue door, with a small sign above it that reads “No junk mail”.
Photograph: Miguel A Amutio / Unsplash

From the editor

Consent used to live in a checkbox and a privacy policy. It is turning into something closer to a product surface: a notice a person can understand, a choice they can change, a record a regulator can inspect and, for AI agents, a moment where someone says yes before anything happens.

This issue looks at four places where permission is being designed, including the sign-up form for this newsletter, which we built to the same rules.

On the web version of this issue, from the studio: field guides to DPDP consent and to WCAG 2.2, how we design agents that ask before they act, and an onboarding flow that keeps every disclosure in plain sight.

The Xterra Edze studio

Story 1 of 4, Martech: Consent you can prove

India’s Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). They give effect to the DPDP Act, 2023, with an eighteen-month period for phased compliance. Every Data Fiduciary must give a separate consent notice that is clear and easy to understand, and that explains the specific purpose for which personal data is collected and used.

The Act also sets the standard for leaving. Where consent is the basis for processing, a person may withdraw it at any time, “with the ease of doing so being comparable to the ease with which such consent was given.”

The DPDP Rules, 2025 were notified
14 Nov 2025
The period for phased compliance
18 months
To answer a request to access, correct or erase personal data
90 days

Source: Press Information Bureau, Government of India, 17 November 2025.

What we check: that a CRM can answer three questions about any contact: what they agreed to, when, and through which notice. And that unsubscribing takes no more steps than signing up did.

Story 2 of 4, Product: Accessibility, now a market rule

The European Accessibility Act has applied since 28 June 2025. Products and services in its scope, among them e-commerce, banking services, e-books, computers, smartphones and ticketing machines, must meet its accessibility requirements to be sold in the EU, with transition periods for some services already in use.

In practice, teams work to WCAG: the European standard EN 301 549 (V3.2.1) builds its requirements for web content on WCAG 2.1 level AA, and a revision built on WCAG 2.2 is in preparation.

What we check: consent itself. Cookie banners, preference centres and sign-up forms are among the least accessible parts of most sites, and a choice a person cannot operate is not a choice.

Story 3 of 4, AI: Ask before acting

An agent that can send, buy, book or delete is making decisions on someone’s behalf. OWASP calls the failure Excessive Agency (LLM06:2025) and traces it to three root causes: excessive functionality, excessive permissions and excessive autonomy.

  1. Sort every tool an agent can call into read, reversible and irreversible.
  2. Let read and reversible actions run, and log them.
  3. Put a named person in front of every irreversible one, with the agent’s reasoning and the data it used on screen.

The record matters as much as the gate. Every approval, refusal and override should be logged with who made it and what they saw, so a decision can be explained later to the customer it affected.

What we check: that the approval step shows enough for a person to say no. An approve button with nothing behind it is a rubber stamp, not oversight.

Story 4 of 4, Brand: The unsubscribe is a brand moment

The last thing a reader sees from a brand is often its unsubscribe page. Gmail expects one-click unsubscribe from bulk senders, and RFC 8058 defines how a mail client can unsubscribe someone with a single request, sent as an HTTPS POST so a link scanner cannot do it by accident.

We built this newsletter’s way in and way out to the same standard: a confirmation email before anything else is sent, topics you choose rather than boxes ticked for you, one-click unsubscribe in the mail apps that support it and a link in every issue, and a page that confirms you have left without asking you to explain.

What we check: that leaving is as well designed as joining. People remember both.

Worth reading. The sources behind this issue.

From the studio. Related work and writing.

Proof

Get the next issue. Free, monthly, easy to leave.

One issue a month in your inbox, after you confirm by email. Choose topics if you like, or none for every story.

Choose topics (optional)

We keep your address, any topics you choose, this page and when you agreed, with your IP address and browser as the record of that agreement. Privacy notice

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced