Listen to this post

Key point: In response to the increasing number of state data privacy laws and to address a wave of claims under state wiretap laws, most businesses have spent the last several years posting online privacy notices, consent banners, marketing preference centers, and opt-out mechanisms. But the challenge today is no longer providing consumers with a way to exercise privacy rights. The challenge is to ensure those rights actually work.

State privacy laws increasingly require businesses to provide consumers with the ability to opt out of targeted advertising, certain data-sharing activities, and the sale of personal information. Privacy links, preference centers, cookie banners, and similar tools have become standard components of modern compliance programs. So, many organizations have already addressed whether their websites need to provide opt-out mechanisms.

What receives less attention is whether those choices are being honored.

For many businesses, the greatest privacy risk is no longer a missing disclosure in a privacy notice.

It is the gap between what the business says happens when a consumer opts out and what its systems, vendors, and technologies do afterward. Recent litigation and enforcement activity has repeatedly focused on situations where opt-out mechanisms existed on paper, but allegedly failed to stop the underlying collection, sharing, or advertising activities. Regulators are increasingly evaluating website functionality, not simply website disclosures.

But opt-out failures are not solely a regulatory concern. Plaintiffs continue targeting the use of tracking technologies, pixels, session replay tools, SDKs, and similar technologies through a variety of litigation theories, including state wiretap and privacy statutes like the California Invasion of Privacy Act, Florida Security of Communications Act, and similar laws. In many cases, the same operational failures that create regulatory risk can also provide the foundation for litigation. Proper notice, consent and opt-out management are therefore no longer just a privacy compliance issue, but a broader business risk issue.

As enforcement activity and plaintiff claims continue to rise, organizations should be asking a simple question: if a consumer opts out today, what will change tomorrow?

Privacy as an operational challenge

A business may have updated its website privacy notice, deployed a consent management platform, and implemented consumer-rights workflows. But over time, both websites and their back-end systems evolve. Marketing teams introduce new tools. Vendors change. Advertising technologies are added. Analytics configurations are updated. Mobile applications and other digital properties expand. As a result, a company’s actual data practices can drift away from what was originally reviewed and approved.

Businesses should not assume that implementing a consent banner or preference center means that their obligations have been met. Independent audits continue to identify situations where websites continue to collect or share information after website visitors have exercised their privacy or choices regarding the use of website tracking tools. This is often because tracking technologies, vendor integrations, or consent management configurations are not operating as intended. These findings serve as an important reminder that opt-out compliance should be continuously validated rather than assumed.

Increased use of Universal Opt-out Mechanisms (UOOMs)

As of January 1, 2026, 12 state privacy laws now require businesses to recognize UOOMs, such as the Global Privacy Control (GPC), which allow consumers to communicate privacy preferences automatically through their browsers or devices. Businesses that have not tested how these signals are received, interpreted, and implemented across their digital ecosystem may find that their compliance assumptions do not align with reality.

For that reason, organizations should view opt-out compliance as a cross-functional responsibility rather than a privacy policy exercise. Legal, privacy, information technology, marketing, procurement, and vendor-management teams all play a role in ensuring that consumer choices are received, communicated, implemented, and verified.

Risk considerations

A few practical questions can help assess risk:

  • Does your business know which tracking technologies are operating across its websites and mobile applications?
  • Are opt-out requests communicated to all relevant systems and third-party service providers, such as website hosting and analytics providers?
  • Does your business recognize and appropriately respond to UOOMs where required?
  • Has your business tested whether targeted advertising, analytics, and other data-sharing activities stop when a valid opt-out request is received?
  • Do the actual technological activities align with the commitments described in your business’ privacy notice and consumer-rights disclosures?

The answers to those questions often reveal that the largest privacy risks are not legal ambiguities, but rather operational gaps.

The bottom line is simple: an opt-out right is not merely a website feature or a disclosure. It is an operational obligation. As privacy-related enforcement activity continues to evolve and litigation involving tracking technologies remains active, businesses should focus not only on offering privacy rights, but also on verifying that those rights can truly be exercised by website visitors, including customers and potential customers.

The question is not whether consumers can opt out. It is whether the opt-out actually works.

Contact us

If you have questions regarding your website’s opt out mechanisms or have other privacy compliance concerns, contact Shannon Kapadia, Heidi Salow, Anokhy Desai or your Husch Blackwell attorney.