Interesting.  But you are relying on a UI in a UA to make this meaningful to the average person.  What about putting some burden on the company by requiring that consent be presumed to expire after X days unless the user reaffirms  under the same standard?

>> Again, for each interaction with a user that has an out-of-band consent, the response/well-known header will:
>> - remind the user of this fact (if they have DNT:1 set)
>> - provide a resource (link) to alter this consent AT ANY TIME

