Privacy Horror Stories: What I've Seen Go Wrong Behind the Scenes
Posted
October 9, 2026

Writen by:
Christine Desrosiers, CIPP/E, CIPP/US, CIPM, FIP

Healthy on paper, haunted in production
Most privacy programs look great on paper. There's a consent management platform, a cookie policy, a vendor inventory, a DSAR process and a team that takes all of it seriously.
Then you open a browser, opt out the way a real consumer would, and watch what actually happens - that's where the horror stories start.
None of the stories below involve bad actors or careless teams. They involve good programs, real investment and a gap between what the controls say and what the browser does. Details are anonymized, but every number is real.
What we've seen
The opt-out that barely changed anything
A large auto manufacturer wanted to confirm its opt-out worked. We tested it the way regulators increasingly do: as real visitors from California, Colorado and Texas, across a large sample of critical, must-be-correct pages of the site.
After opt-out, 184 of 221 ad tech and martech tags were still active, as were 362 of 594 cookies. Some of the data still flowing to an audience platform included device-fingerprinting and mobile identifier signals – exactly the kind of data the opt-out was supposed to stop.
The CMP was configured, the banner displayed correctly, the consumer clicked the right button, but two things broke underneath. Opting out didn't refresh the page, so every tag that had already loaded kept running. And the browser-level opt-out signal, Global Privacy Control, only switched off some of the targeting vendors. From the privacy team’s dashboard, this program looked compliant. From the browser, the opt-out was mostly decorative.
Two consent banners and a vendor that wouldn't leave
A consumer rewards site had its consent platform in place, owned and managed by the privacy team. When we loaded the site, visitors were shown two consent experiences: the one the team owned, and a second one from a different vendor that nobody could fully explain.
After a Connecticut visitor opted out, Google Ads tags and cookies kept dropping, a Pinterest cookie stayed, and a Meta SDK remained active, even though the team had classified Meta as a "sale of information" vendor that should be shut off on opt-out.
The part that stuck with me wasn't the technical failure, it was that the privacy team already knew something was wrong. They had escalated it to the technical owners more than once and still hadn't gotten a complete fix. They could see the problem, they just couldn't make it anyone's job to solve it.
Fifty-one sites, fifty-one problems
A publisher network asked us to check consent behavior across its portfolio. Every one of its 51 sites had tags or cookies misfiring against IAB consent signals.
On one news site, more than 400 ad tech tags and cookies were still active after a visitor opted out. On another, the consent signal wasn't reaching the ad partners at all, so ads kept being served as if the visitor had never said no.
And the failure ran the other way too. On 49 of the 51 sites, tags weren't firing after a visitor opted in. That's a privacy problem and a revenue problem from the same root cause.
The team's question wasn't "is this broken?" It was "how do we find the common cause and fix it across 51 properties without triaging each one by hand?" – a very different problem from fixing one website.
Why these problems persist
When I look across these stories, the root causes repeat.
- Configuration isn't validation. A CMP shows what you told it to do. It can't show what data a browser actually sent, and to whom, after a real person opted out. Story 1 passed every configuration check.
- Fragmented ownership. Privacy owns the policy. Marketing owns the tags. A developer or agency owns the implementation. In Story 2, everyone could see the issue and no one owned the fix.
- Vendor chains nobody fully maps. Tags load other tags. A second CMP shows up. A partner script pulls in vendors that never appear in your inventory.
- Constant change at scale. Every campaign, agency and site update is a chance for drift. Multiply that by 51 properties and manual checks can't keep up.
What privacy teams tell us
The questions I hear from privacy leaders are remarkably consistent:
- My CMP says we're fine. How do I actually know?
- I've escalated this three times. Who's supposed to fix it?
- How do I fix this across 50 sites without checking each one by hand?
- I didn't know that vendor was on our site until it showed up in a scan.
What these have in common is that they aren't questions about policy. Privacy teams know what should happen. They're asking how to prove what did happen.
The bigger problem
Privacy teams are increasingly accountable for environments they can't fully see or control. More vendors, more properties, more automated marketing systems making changes nobody approved line by line.
The question is shifting from "is our program well designed?" to "could we prove what happened to one consumer's data after they said no?" For most organizations I talk to, the honest answer is "not easily."
The closing question
So here's what I'd ask you: what's happening in your digital ecosystem right now that you can't independently verify?
Over the next five weeks, I'll share more of these stories, from tags that come back after you remove them to privacy tools that give you two different answers - I'd love to hear yours! And if you'll be at the CPO Forum in Miami next month, we're turning this into a candid working session. Bring your story.
Frequently asked questions
Everything you need to know about Boltive, our technology, and how we help reduce digital risk.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.
We verify that your privacy and ad security controls actually work in production. On the privacy side, we simulate real consumer behavior to test whether consent is honored across your websites, apps, and ad ecosystem. On the ad security side, we detect and block malicious, non-compliant, and unwanted ads in real time before they reach Byour users.