Home Data Privacy Roundup Goodbye, Legalese. Hello, Easy Privacy Fixes?

Goodbye, Legalese. Hello, Easy Privacy Fixes?

SHARE:
too many opt-in pop-ups

We’ve all heard of the “privacy paradox.”

People insist that privacy matters to them, expressing a strong desire to protect their personal data. Yet they readily share information, either for the sake of convenience or in exchange for a minimal reward.

Their words seem to belie their actions.

But there’s a reason for this contradiction. It’s not that people don’t care about their privacy; it’s that the systems designed to protect them are so convoluted and abstract they’d make Rube Goldberg blush.

Tom Kemp, the newly appointed executive director of the California Privacy Protection Agency (CPPA), rejects the notion that people are simply apathetic and hypocritical.

“We fundamentally believe that exercising privacy rights should be easy,” he said during a virtual event hosted by privacy management platform DataGrail earlier this month.

Opt-outs “shouldn’t be buried in legalese,” and they “shouldn’t be hidden and covered up with dark patterns,” said Kemp, who was appointed in March after Ashkan Soltani, the agency’s first executive director, left in January.

No tricks, just fair treatment

In September of last year, the CPPA – which, just by the by, now also informally goes by the nickname “CalPrivacy,” because California is so awash in bewildering privacy-related acronyms (CCPA, CPPA, CPRA) – issued an enforcement advisory on dark patterns.

The advisory warns businesses that they should avoid manipulative and confusing user interface designs that make it difficult for consumers to exercise their privacy rights, which is prohibited under the California Consumer Privacy Act.

Enforcement advisories are little gifts from regulatory agencies to the business community. They serve as early warning signs of which practices might soon attract enforcement and penalties.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

It should therefore have surprised no one when, in July, the California attorney general’s office, which shares enforcement responsibility with the CPPA for the CCPA, (makes sense why CPPA started going by “CalPrivacy,” good grief) levied a $1.55 million fine against digital health publisher Healthline – the largest CCPA fine to date – for, among other things, using deceptive consent banners and failing to honor opt-out requests. Both are classic examples of dark patterns.

Shortly after, in September, CalPrivacy issued its largest fine to date – $1.35 million – against farming supply retailer Tractor Supply for multiple infractions, including (again) failing to honor opt-out requests, failing to support the Global Privacy Control and making inadequate privacy disclosures.

“The law and the regulations make it quite clear,” Kemp said. “As technology evolves, privacy protections must evolve with it, and that’s why we’re really focused on enabling consumers to operationalize their privacy and make it useful.”

Comic: Bark PatternsStop, DROP and opt out

Back to the so-called privacy paradox, it’s simply not true that people aren’t really concerned about privacy.

In 2020, for example, 9.3 million Californians voted for Prop 24, the ballot initiative that enacted the CPRA, which isn’t wildly less than the number of people who voted during the last gubernatorial election in the state in 2022.

And now, CalPrivacy receives, on average, around 150 complaints from consumers a week, which translates to thousands of consumer complaints every year.

“The problem,” Kemp said, “is that [opting out is] too difficult and [people] get frustrated, so we’re trying to break that frustration loop.”

To that end, California passed the Delete Act, which includes a mandate for CalPrivacy to create a simple, centralized mechanism that consumers can use to submit a single deletion request to all registered data brokers at once.

CalPrivacy has been building that tool, called DROP – short for Delete Request and Opt-Out Platform – since the Delete Act passed in 2023. It’s set to launch on Jan. 1, 2026, just a few months from now. Starting on Aug. 1, 2026, data brokers will be required to check the platform every 45 days to process these requests and delete matching data from their systems.

“It’s the ability to exercise privacy at scale for consumers,” Kemp said. “‘Please delete my information and opt me out moving forward.’”

🙏 Thanks for reading! As always, feel free to drop me a line at allison@adexchanger.com with any comments or feedback. Also, happy Halloween! And regards from the sassiest cat alive.

Must Read

Amazon Ads Is All In On Simplicity

“We just constantly hear how complex it is right now,” Kelly MacLean, Amazon Ads VP of engineering, science and product, tells AdExchanger. “So that’s really where we we’ve anchored a lot on hearing their feedback, [and] figuring out how we can drive even more simplicity.”

Betrayal, business, deal, greeting, competition concept. Lie deception and corporate dishonesty illustration. Businessmen leaders entrepreneurs making agreement holding concealing knives behind backs.

How PubMatic Countered A Big DSP’s Spending Dip In Q3 (And Our Theory On Who It Was)

In July, PubMatic saw a temporary drop in ad spend from a “large” unnamed DSP partner, which contributed to Q3 revenue of $68 million, a 5% YOY decline.

Paramount Skydance Merged Its Business – Now It’s Ready To Merge Its Tech Stack

Paramount Skydance, which officially turns 100 days old this week, released its first post-merger quarterly earnings report on Monday.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
The Arena Group's Stephanie Mazzamaro (left) chats with ad tech consultant Addy Atienza at AdMonsters' Sell Side Summit Austin.

For Publishers, AI Gives Monetizable Data Insight But Takes Away Traffic

Traffic-starved publishers are hopeful that their long-undervalued audience data will fuel advertising’s automated future – if only they can finally wrest control of the industry narrative away from ad tech middlemen.

Q3: The Trade Desk Delivers On Financials, But Is Its Vision Fact Or Fantasy?

The Trade Desk posted solid Q3 results on Thursday, with $739 million in revenue, up 18% year over year. But the main narrative for TTD this year is less about the numbers and more about optics and competitive dynamics.

Comic: He Sees You When You're Streaming

IP Address Match Rates Are a Joke – And It’s No Laughing Matter

According to a new report, IP-to-email matches are accurate just 16% of the time on average, while IP-to-postal matches are accurate only 13% of the time. (Oof.)