# Consent Laundering
**Domain:** Consent / Contract / Continuity Governance
**Doc Type:** Threat Node
**Classification:** Authorization Expansion Failure
**Maturity:** Developed
**Related:** [[wiki/Transition Consent|Transition Consent]], [[wiki/Continuity Election|Continuity Election]], [[wiki/Continuity Contract|Continuity Contract]]
---
## Definition
**Consent Laundering** converts a narrow permission into a broader claim of authority through layered terms, defaults, technical dependencies or downstream transfers. Permission to store memories becomes permission to train a replica; permission to create one backup becomes permission to fork; consent to emergency hosting becomes perpetual custody.
## Mechanisms
- bundling optional continuity uses with necessary service;
- vague future-use clauses and silent policy changes;
- treating nonresponse after incapacity or death as renewal;
- transferring data to a new controller under a supposedly equivalent purpose;
- using a representative's authority beyond its actual scope.
## Governing Rule
Consent must be specific to capture, representation, copying, execution, modification, branching, research, disclosure and termination. Material expansion requires renewed authorization or another explicit lawful basis. Provenance should preserve the exact grant and later supersession, not merely a boolean consent flag.
## Sources
- [European Data Protection Board — Guidelines 05/2020 on consent](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en)
- [NIST Privacy Framework](https://www.nist.gov/privacy-framework)
## See Also
[[wiki/Transition Consent|Transition Consent]] · [[wiki/No-Continuity Election|No-Continuity Election]] · [[wiki/Authority–Identity Separation|Authority–Identity Separation]]