Leaders in Privacy · 2026

Configured Isn't Compliant: Why Privacy Setup Alone Won't Hold Up in 2026

Buying a privacy tool and switching it on is a different thing from being compliant. In the latest Vault JS Leaders in Privacy session, the conversation turned on a single idea: regulators now test the mechanics rather than read the policy.

4,700+
wiretap lawsuits filed in the US since 2022
$2.75M
record Disney settlement over opt-out failures, Feb 2026
$1.2M
Sephora fine for ignoring opt-out signals, 2022
1,200+
cookies one CMP-equipped publisher's scan had never detected

For years, many organizations treated a consent banner and a published privacy policy as the finish line. In the latest Vault JS Leaders in Privacy session, Josh Manion sat down with Richy Glassberg, co-founder and CEO of SafeGuard Privacy and a co-founder of the IAB, to challenge that assumption directly. Their central theme: a privacy tool that is installed but never verified says very little about whether consent is actually honored in practice.

The reality is more demanding than the banner suggests. Regulators and plaintiffs have moved from reading policies to testing systems. The California Privacy Protection Agency and state attorneys general are hiring technologists and scanning sites and apps directly. Consent collected is no longer the standard. Consent enforced is, and businesses have to prove it with network evidence.

▶ Key Takeaways

What to hold onto

01

Configured was yesterday's answer. Compliant is today's. A deployed consent platform proves setup, not enforcement. Regulators now test whether opt-outs actually fire, and they expect network evidence.

02

Set-it-and-forget-it does not survive ad tech. Vendors rework their stacks, new tags appear, and configurations drift after go-live. One publisher had 1,200 cookies its scan had never detected.

03

A defensible program in 2026 is an operating practice, not a one-time project. Technical monitoring runs monthly, legal due diligence at least annually, and every claim is backed by an audit trail.

What does "configured isn't compliant" actually mean?

Configured was yesterday's answer, and compliant is today's. A consent management platform that is installed but never verified says little about whether consent is honored on the page. Most companies still sit early in this journey: they have a policy or a deployed tool, but no documented controls and no confirmation that opt-outs actually fire.

The graphic below captures the shift Josh and Richy kept returning to. The tests on the right are the ones regulators now run.

YESTERDAY Configured Turn the tool on. Ship the policy. Consent banner deployed Privacy policy published CMP installed and live Screenshot of the config TODAY Compliant Prove the mechanics, with evidence. Opt-outs actually fire Honored across every geography GPC carried end to end Network evidence on file
The bar moved from "is it installed" to "does it enforce, everywhere, provably."

Why is ad tech so hard to make compliant?

Digital advertising was built to measure and follow behavior, with tracking pixels answering whether an ad was seen, clicked, and converted. Privacy laws arrived later and were bolted onto a stack that was never designed for them. Complying fully with the way many laws are written is close to impossible: device graphs rely on persistent identifiers, and there is a real gap between forgetting a person and deleting them.

The ecosystem compounds this. Data does not stay inside one company, so a brand can do everything correctly and still be undone by a downstream partner. That is why vendor governance keeps surfacing in enforcement actions and complaints.

Why are VPPA and CIPA lawsuits targeting websites now?

A common question is why decades-old statutes are suddenly driving website litigation. The plaintiff's bar has become creative, applying the Video Privacy Protection Act of 1988 and the California Invasion of Privacy Act of 1967 to modern tracking pixels, session replay, and chat tools.

The economics explain the volume. These statutes carry fixed statutory damages per violation, which makes class actions attractive even without proof of monetary harm. Healthcare was the opening wave, and it has spread to retail, fintech, wellness, and data brokers. Because most companies are non-compliant to some degree, even brands with limited first-party data are receiving demand letters.

The litigation math

More than 4,700 wiretap suits have been filed in the US since 2022. Fixed statutory damages per violation mean a plaintiff does not need to show monetary harm for a class action to pencil out, which is why the demand letters keep landing.

Why doesn't set-it-and-forget-it work?

Ad tech changes constantly. Vendors rework their stacks, new tags appear, and configurations drift after they go live. With AI and agentic media-buying capabilities announced almost daily, technical diligence has to be ongoing rather than annual.

In the field — hidden cookies

One publisher using a major consent platform had more than 1,200 cookies its scan had never detected. The platform was in place. The site was doing something the platform could not see.

This is where Global Privacy Control matters. Honoring GPC is now required across a growing set of states, and it has to work end to end. Detecting the signal at the edge but failing to carry it through to the tag manager, server-side pipeline, and CDP counts as separate failures, each one testable by a regulator.

THE GPC SIGNAL HAS TO SURVIVE EVERY HANDOFF Browser User opts out GPC = true Edge detect signal Tag manager suppress tags Server-side pipeline honors CDP no share Stops at the edge? That is not one gap. Every stage that ignores the signal is a separate, individually testable failure.
Honoring GPC means carrying the signal through every layer, not just reading it at the door.

Cadence comes down to risk tolerance: how fast the site changes, how quickly you can remediate, and how sensitive the data is. In practice, technical monitoring runs monthly and legal due diligence at least annually.

"We don't have budget." How do privacy teams get resourced?

Privacy leaders often say they are asked to reach compliance without budget or staff, yet the money usually exists elsewhere. If a company spends heavily on advertising, the CMO controls a large ad tech budget, and a small fraction covers monitoring and the right consent platform.

There is also personal accountability. California's risk assessments are signed under penalty of perjury by executive management, which echoes how Sarbanes-Oxley forced executives to attest to financials. Enforcement is no longer theoretical.

Sephora · 2022
$1.2M

Fined by the California Attorney General for failing to honor opt-out signals, including GPC.

Disney · Feb 2026
$2.75M

Record settlement over opt-out failures across streaming. Disney must also overhaul its opt-out methods and report to the regulator for three years.

The cost of that settlement, and the three years of oversight that came with it, far exceeds the software that would have prevented the issue in the first place.

How does standardization reduce the burden?

Standards create scale. When the IAB standardized ad sizes years ago, spending grew because teams stopped resizing creative. The same logic drives the IAB Diligence Platform, powered by SafeGuard Privacy. Instead of every company writing its own assessment, companies leverage standardized assessments mapped to US state laws and obligations and digital advertising industry questionnaires, with industry role-based modules for SSPs, data suppliers, and data brokers answering only what applies. Companies report real time savings because the assessment is done before the contract.

The platform has also expanded into Europe, adding new GDPR-focused EEA versions of IAB modules, with a TCF health check on the roadmap. The consistent message from regulators is that they want to see demonstrated intent, and intent shapes how they respond. Having a comprehensive diligence plan in place can help lower the risk of investigations or fines.

What should companies actually do?

A defensible program in 2026 is an operating practice, not a one-time project.

Seven moves came out of the conversation:

1

Configure the consent platform correctly, then test it.

Verify behavior across every geography you cover, not just the market where the banner was first set up.

2

Honor GPC and other universal opt-out signals.

Confirm the opt-out propagates through the tag manager, the server-side pipeline, and the CDP, end to end.

3

Assess exposure to VPPA, CIPA, and pixel claims specifically.

Consent is only one surface. Session replay, chat tools, and tracking pixels carry their own statutory risk.

4

Keep vendor contracts and controls current.

New vendors appear constantly, and a brand can do everything right and still be undone downstream.

5

Assess vendors and conduct legal diligence at least annually.

Refresh assessments as vendors, obligations, and laws change so the program stays mapped to current requirements.

6

Run technical monitoring frequently.

Frequent technical checks catch drift as tags, cookies, and configurations change after go-live.

7

Maintain an audit trail, and ask partners for attestations.

Request them the way buyers already ask for a SOC 2. Demonstrated intent shapes how regulators respond.

The through line

Privacy compliance has become an active, evidenced, and continuous discipline rather than a configuration you complete once. The technical and legal sides move together, which is why Vault JS focuses on continuous technical monitoring while SafeGuard Privacy covers legal due diligence.

Configured describes intent. Only continuous verification describes reality, and reality is what gets enforced.

Frequently asked questions

What is the difference between configured and compliant?

Configured means a tool like a consent banner is installed. Compliant means it actually enforces consumer choices across every system and geography, with evidence to prove it. Regulators now test the mechanics, so setup alone is not compliance.

Does a consent management platform make my website compliant?

No. A CMP is a starting point, not a guarantee. Tags can fire before consent, opt-out signals can fail to propagate, and configurations drift. Compliance depends on verifying it works end to end and monitoring it over time.

What is Global Privacy Control (GPC), and do I have to honor it?

GPC is a browser-level signal that a user wants to opt out of the sale or sharing of their data. A growing set of states require businesses to detect and honor it across the whole stack, not just read it at the edge.

Why is it important to conduct legal diligence if I am managing technical diligence?

Technical diligence confirms a vendor's system does what they claim: how data flows, what is collected, where it is stored, whether the code matches the documentation. Legal diligence confirms that what the vendor does is actually permissible: whether they have a valid legal basis to collect that data, whether their contractual terms hold up, whether their practices comply with applicable privacy laws. Skipping legal diligence because technical diligence looked clean is like inspecting a car's engine and skipping the title check. The engine can run perfectly and you can still not legally own the car.

Missed the live session?

Register to watch the webinar on demand and hear the full conversation between Josh Manion and Richy Glassberg on what a defensible privacy program looks like in 2026.

Watch on demand