Can ‘Autonomous Consent’ Redefine GDPR? A Landmark UK Court Ruling Explained
14th August 2025
A recent High Court ruling has introduced a new framework for assessing consent to data processing, raising critical questions about how organisations handle personal data under the UK GDPR, especially where vulnerable individuals are involved. This potential ambiguity in the law could cause problems regarding the future of consent and put extra pressure on organisations that collect third-party cookies for advertising purposes.
Case Details
The claimant, anonymised as RTM, brought a case against Bonne Terre Ltd and Hestview Ltd, the operators of the Sky Betting and Gaming (SBG) platform. He alleged that they breached his data protection rights by unlawfully collecting and processing his personal data. RTM also sought damages for harm, distress, and financial loss.
SBG, like many other online gaming platforms, collects data on customers’ activities, including wins and losses, the games they played, and what marketing they responded to. This is not unusual and is covered by the GDPR and PECR, provided that the user gives explicit consent for the collection and processing of their data for marketing purposes.
The plaintiff, RTM, is a reformed gambling addict who claims that his compulsive gambling behaviour impaired his autonomy and rendered his consent invalid. He further claims that the platform exacerbated his compulsive behaviour through direct marketing communications. The High Court ruled in his favour on 23rd January 2025, saying that the mechanisms through which consent was obtained were not sufficient to establish consent.
The judgment stated that:
“He clicked through without reading any privacy notice, simply to get rid of the messages on his screen and get on with gambling. He had not informed himself of the nature and use of cookies to obtain and use raw data for ultimate marketing purposes…he just wanted to get on and gamble” – RTM [2025] EWHC 111 (KB), para.162.
Furthermore, Justice Collins Rice introduced a novel three-part framework for assessing consent, including:
- Subjective
This relates to the state of mind of the individual when giving consent.
- Autonomous
Referring to the individual’s ability to make an informed and uncoerced decision.
- Evidential
The data controller must demonstrate that valid consent was obtained.
This test is not currently codified in legislation but may influence future regulatory or judicial interpretation of consent under the GDPR.
Ambiguity and Lack of Guidance
The court found that RTM was a ‘vulnerable individual’ whose compulsive gambling behaviour impaired his ability to provide autonomous consent. This appears to contradict current legal guidance and could undermine existing compliance frameworks. The Court did not provide any way for controllers to determine an individual’s state of mind when they consent to data collection, or how organisations can apply the Court’s analysis to other situations. This case has introduced another troubling idea – that individuals will have to provide even more personal data to controllers for their consent to be considered valid, which could violate Article 5 of the GDPR and the wider principle of data minimisation.
The Court’s judgment did not address the subject of damages other than to find in favour of RTM, and the case is currently being appealed with no hearing date set at the time of writing (August 2025).
Similar Cases
This case is unique in that the plaintiff could be considered a high-risk data subject given his gambling addiction, and the sophistication and level of targeting that SBG used in their marketing campaigns. There have been similar cases where plaintiffs with a history of gambling problems have tried to claim remedies based on breach of contract, breaches of statutory duty under the gambling regulation regime, and negligence (breach of duty of care), such as Calvert v William Hill [2008] EWHC 454 (Ch). In this case, William Hill failed to honour self‑exclusion requests made by Graham Calvert, a pathological gambler. The court found William Hill breaching its duty of care, but refused compensation for his losses on the ground that he would have gambled elsewhere regardless. This case doesn’t address data protection consent or profiling; rather, it concerns the bookmaker’s own self‑exclusion policies and negligence.
The case introduces new uncertainty to data protection laws and regulations. Without clear ICO guidance or legislative amendments, data controllers are left to interpret how subjective or autonomous consent can be reliably identified, monitored, or evidenced, especially in contexts involving vulnerability or addiction. This decision raises critical questions for any data controller relying on consent as a lawful basis for processing. While the facts are highly specific, the ruling could prompt greater scrutiny of how consent is gathered, particularly in sectors involving behavioural targeting. That said, it does not automatically require every organisation using cookies or direct marketing to overhaul their processes, but it does signal a potential shift in judicial thinking around vulnerability and autonomy.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources
BAILII