Those Do Not Sell Links Actually Do Something Now

Those Do Not Sell Links Actually Do Something Now

Tech News california ccpa data-brokers privacy regulation

So this past Wednesday, July 1st, was the date California's Attorney General started actually enforcing the CCPA. Not the law going into effect, that happened back in January. This was the "ok now we're serious" date, the one where Xavier Becerra's office can actually come after companies for ignoring it. I'd honestly half forgotten it was coming until I saw a tweet about it Tuesday night and thought, huh, I should go check whether any of this stuff actually works.

Quick refresher for anyone who wasnt paying attention: if youre a California resident, businesses over a certain size have to give you a way to tell them not to sell your data, and they have to actually honor it. Thats the whole "Do Not Sell My Personal Information" link that started showing up in site footers earlier this year, usually in tiny gray text down near the copyright notice where nobody looks.

I spent about an hour Wednesday night clicking through a bunch of them, mostly out of curiosity and partly because I was avoiding actual work. Some results:

  • Spokeo's opt-out form worked fine, took maybe two minutes, no games.
  • One of the smaller data broker sites (wont name it, dont want to give it more traffic) made me create an account just to submit an opt-out request. An account. To ask them to stop selling my data they already have without my permission. The irony was not lost on me.
  • A couple of the bigger ad-tech adjacent sites had the link but it just dumped you into a generic "contact us" form with no confirmation of anything, which feels like exactly the kind of malicious compliance the law was supposed to prevent and is apparently still legal enough that nobody's fixed it yet.

None of this is surprising if youve watched how companies handle GDPR requests either. The pattern is always the same: do the absolute minimum to have a defensible paper trail, make the actual process annoying enough that most people give up halfway through. I dont think thats some grand conspiracy, I think its just what happens when compliance gets handed to whichever team has the least incentive to make it pleasant.

The bigger question, and the one Im actually curious about, is whether the AG's office is going to go after anyone meaningfully in the next few months or whether this ends up like a lot of privacy enforcement, mostly theoretical until a big enough breach forces the issue. Becerras office has said they'll prioritize complaints and cant possibly audit every company with a website, which, fair, thats an impossible task for any state AG regardless of budget. But it does mean the actual deterrent effect right now is more vibes than teeth.

In loosely related news this week: India banned 59 Chinese apps on the 29th, TikTok and UC Browser and a bunch of others, citing data security concerns tied to the border standoff with China. Different continent, different legal mechanism entirely, a straight ban instead of an opt-out regime, but its the same underlying anxiety driving both stories. Governments are figuring out, unevenly and a few years too late, that "an app is quietly extracting your data and doing whatever it wants with it" is actually a policy problem and not just a EULA nobody reads. I dont think either approach is obviously the right one. An outright ban is blunt and probably has more to do with geopolitics than genuine privacy concern in Indias case. But at least it does something immediately, instead of leaning on a form that dumps you into a contact-us box.

Anyway. If youre in California and youve got five minutes, its worth actually clicking through a few of those footer links instead of scrolling past them like Ive done for six months. Half of them still dont work right, and now, technically, that's supposed to matter.