While many state comprehensive data privacy laws require that data controllers honor universal opt-out mechanisms such as Global Privacy Control (GPC) signals, California, Colorado and Connecticut have launched a joint enforcement effort targeting noncompliance with these requirements. This is not the first time these attorneys general have cooperated on data privacy law efforts and may signal a broader trend of cooperation across states.
What are universal opt-out mechanisms?
Universal opt-out mechanisms are a browser setting or extension that sends a signal to a website that a consumer is opting out of the selling or sharing of their personal information and targeted advertising. The website should respond to that signal by automatically opting out the consumer of such selling or sharing. This enables consumers to easily opt-out on each website they visit rather than having to submit an opt-out request on an individual basis at each website.
To date, privacy laws in California, Colorado, Connecticut, Delaware, Minnesota, Montana, Nebraska, New Jersey, New Hampshire, Oregon and Texas require business to detect and process these out-out signals. Maryland’s requirement takes effect on Oct. 1.
Implementation was delayed but is now an enforcement priority
While the requirement to recognize GPC signals is not new, enforcement has not been a top priority. However, the three-state coalition is now contacting businesses suspected of violating this requirement and requesting that those businesses cure noncompliance.
Noncompliance can be costly
Businesses that fail to honor GPC requests face multiple enforcement risks. In addition to the potential for class action litigation and reputational damages, states can directly impose fines for noncompliance with their privacy laws:
- California: Fines up to $7,500 per violation
- Colorado: Penalties up to $20,000 per violation
- Connecticut: Fines up to $5,000 per violation
In addition, privacy regulators are becoming more active and are working closely across state lines. In addition to this investigatory sweep, Delaware, Indiana, New Jersey and Oregon have joined California, Colorado and Connecticut as part of a broader group of regulators that share priorities and sometimes run investigations together as part of the Consortium of Privacy Regulators.
When a regulator starts asking questions, it can be costly and risky for a business. California, Colorado and Connecticut can pass along what they find in this sweep to regulators in the Consortium and in other states. Regulators often request detailed information about how a company handles data, including technical setups and recordkeeping. If they discover issues, they may expand their investigation to look for other problems.
Because of this, it is time to review your websites and verify that your data practices align with the universal opt-out mechanism requirements.
We’re here to help.
If you have any questions about how these principles may impact your company, please reach out to Kelly Hollingsworth, Nate Steed, Sam Poortenga or your Warner attorney.
