Navigating Global Privacy Control’s Not-So-Simple Implementation

Soon, nine states will require websites to honor consumers’ broadcasted requests to opt out of all sharing of their personal data with the global privacy control (GPC) or a similar universal opt-out mechanism. GPC, a browser-based setting for consumers to automatically opt out, is said to be simple for consumers to use, simple for companies to implement and simple for regulators to check. But it turns out to have several complexities for companies, underscored by a new study of 11,000 sites revealing that many of them did not translate GPC into opt-out signals. This article goes behind the findings and looks at the GPC’s pitfalls, including misconfigurations, privacy signal system glitches, the ease of consent fraud and issues in due diligence, with insights from an original developer of GPC and experts at Moritt Hock, Neal Gerber & Eisenberg, the Network Advertising Initiative, Orrick and Raptive. See “Why Companies Unintentionally Fail to Honor Opt-Outs” (Aug. 16, 2023).

To read the full article

Continue reading your article with a CSLR subscription.