Privacy Mistakes Your Business is Likely Making

(and How to Fix Them)

7/22/2026

The Common Mistakes

During our many independent external reviews over the past two years, we see the same public-facing privacy compliance mistakes* that are easy for both consumers and regulators to identify:

1) Third party cookies, pixel, and tracking technology loading despite consent revocation.

Anyone with the ability to click on their browser settings and pull up developer tools can see a myriad of tracking technologies deployed that are actively collecting and disclosing information. In fact, this is one of the first assessment tools we utilize during our privacy audits. While some technical expertise may be needed to decode what is being shown, it isn’t hard for someone to see that a cookie belongs to, say, LinkedIn when they are on an ecommerce shopping site.

In some cases, this tech still loads despite a GPC signal being sent. For others, it’s happening even when cookie preferences are used in an attempt to disable tracking.

Disclosing information to a third party when a consumer has explicitly communicated they do not consent to such sharing is an egregious compliance violation. Is it the worst thing we see? Not by a long shot BUT the public visibility exposes any organization to increased litigation and regulatory noncompliance risk—all out in the open for anyone with the know-how to see.

2) In the “this probably doesn’t surprise anyone” category: Inaccurate or outdated privacy notices.

Based on our external review over the past two years, the list of companies is extensive, but a few examples across sectors: Boeing, Edward Jones, Bumble, HelloFresh, Feeding America, and…even LinkedIn. Categories include:

  • Broken links are the most consistent issue across any business we reviewed.

  • Outdated policies referencing old technology

  • Policies that don’t reflect publicly verifiable processing activities (see #1 above).

3) Data Subject Access Requests that are unfulfilled, not responded to timely, ask for more information to verify, or are just incorrect.

There can be valid, compliant reasons for these actions (or lack thereof). For example, no regulatory requirement to fulfill due to resident location or data subject type, inability to verify an individual, or incorrect data being provided to the company.

When it becomes noncompliance is situational, but a few examples of what we found companies doing during external reviews that would qualify:

  • Asking for more information, and in some cases sensitive information, to verify identity when sufficient information was required and provided on initial intake form.

  • Rejecting or disallowing requests due to residency even though a state privacy law does exist for that resident (usually found when new laws are rolled out).

  • Not providing a reason or explanation for rejecting the request.

  • Providing blank data when access request is submitted through a logged-in account that must have data associated in order to exist, at all.

  • Requiring identify verification to submit an opt-out of selling/sharing request.

  • Not being aware of or able to respond to requests for specific third parties with which data is shared.

Privacy compliance can be extremely complex, yet we often see companies forgetting the importance of the basics: ensuring accuracy of external communication and, just as critical, that what is implemented reflects what is being communicated.

What You Can Do About It

If I could encourage any company to do one thing right now in their privacy compliance journey, it would be to review their privacy program and truly test it. Here’s what that might look like:

  • Poke holes in external and internal policies by verifying what is actually happening, not just what is written.

  • Validate data processing activities on not just your main web domain, but also on all sub domains.

  • Have someone test your data subject rights process to ensure it works as designed.

  • Ask other departments for clarity on what specific processing is executed upon consumer request.

  • Establish an inventory of all of the third parties with which you share data. The list is likely larger than you expect. Assess the practices of those third parties that process data with high privacy risk.

  • Engage your internal audit team (if you have one) to help test internal controls.

These steps are what we do when we do audits, and it’s something any company can do themselves to ensure compliance. And, of course, for this or more in-depth privacy assessments, you can reach out to Cadence and we’d be happy to help!

*The term “mistake” here is being represented as unintended, unknown, or misaligned functionality. It is not intended to represent cases where a company has actively accepted privacy risk and associated noncompliance (which also happens in every business).

As with all of our written blog content, AI was not involved in the creation, editing, or review of this material.

privacy; GDPR; cadence; CCPA, data
privacy; GDPR; cadence; CCPA, data

Cadence Privacy