Feb 24 2026
Privacy Risk: The Illusion of Choice
A briefing on why cookie consent banners may be creating more legal exposure than they prevent, and why risk managers need to look beyond cyber coverage.
TL;DR
A briefing for risk managers on cookie consent banners where tracking technologies have already fired before the user can act on a Reject All option. Sets out US and European enforcement during 2025 (Honda, Todd Snyder, Healthline, Tractor Supply, SHEIN, Conde Nast), the legal shift from privacy violation toward fraud and CIPA interception claims, common cyber insurance exclusions where reasonable steps are not in place, and a checklist of web, opt-out, vendor, and evidence controls.
We include privacy auditing as part of our service, extending compliance auditing not just to cover ADA, but also privacy. As with ADA and accessibility, risk managers should be aware of likely exposure.
Cyber coverage has limitations, especially where clients have not taken reasonable steps to minimize exposure, and where criminal intent is alleged (see below) then you could be without coverage.
It may seem extreme to talk about criminal intent, but so many websites have popups and include "reject all" as an option, and an undertone unknown to many is that a considerable amount of data has already been collected before that button is ever presented. In essence, you have deceived the visitor with the illusion of choice, and taken data.
An important point is the direction lawyers are now taking. Claims are no longer limited to ADA violations. Plaintiffs' counsel are seeking to use fraud, defined as taking without consent, to ensure that claims carry greater value and are treated as a more substantial threat. At the extreme end of this spectrum, this can mean personal liability for officers, or imprisonment.
The "Illusion of Choice"
The phrase comes directly from how regulators and courts are now describing a common pattern: a website displays a cookie banner offering a "Reject" option, but tracking technologies (cookies, pixels, SDKs, third-party requests) have already fired before the user has any opportunity to act. The reject button is decorative. The data has already been collected and, in many cases, disclosed to third parties.
Even in opt-out regimes (as opposed to prior-consent regimes in the EU), this design pattern creates enforceable concerns. If targeted advertising trackers fire before the rejection can take effect, the opt-out mechanism is not controlling processing at the relevant time. If personal data is disclosed to ad networks before rejection, the consumer right is frustrated because the disclosure has already occurred. These are not theoretical issues. They are the basis of current enforcement actions and settlements.

Targeted Advertising/Profiling Opt-Out Rights
State-by-state breakdown of US consumer privacy laws, with the "illusion of choice" risk pattern and enforcement authority by jurisdiction.
Content is for informational purposes only and does not constitute legal advice.
Enforcement Is Accelerating
During 2025, multiple enforcement actions resulted in significant penalties. The pattern is clear: regulators are no longer issuing warnings. They are issuing fines.
California
- American Honda Motor Co. (March 2025): $632,500 for CCPA breaches including an online privacy management tool that failed to offer Californians their privacy choices in a symmetrical or equal way. The tool allowed opt-in via one click but required multiple steps to decline.
- Todd Snyder (May 2025): $345,178 for failure to configure and then monitor a cookie consent platform, which was non-functional for 40 days, preventing users from opting out.
- Healthline Media (July 2025): $1.55 million settlement for CCPA breaches including failing to opt consumers out of sharing personal information for targeted advertising. Healthline was found to have "deceived" consumers through a consent banner that failed to disable tracking cookies.
- Tractor Supply Company (October 2025): $1.35 million fine for CCPA breaches including failure to recognize opt-out preferences on its website, and a form that enabled people to indicate they did not want their personal information sold but then failed to enact this via third-party tracking technologies.
- Conde Nast (ongoing): Facing a class-action privacy lawsuit in California alleging that trackers were installed on websites including The New Yorker and Wired without valid user consent, in violation of the California Invasion of Privacy Act (CIPA). A judge has allowed the case to proceed.
Other US States
In April 2025, the Michigan Attorney General filed a lawsuit against Roku for collecting and sharing sensitive data relating to children, including via tracking pixels and cookies. The Texas Attorney General has also taken action against General Motors and Google for sharing information without consent. The Attorneys General of Colorado, Connecticut, and California announced a joint investigation into whether businesses are properly honoring requests to opt out of having their data sold and receiving targeted advertising indicated through Global Privacy Control (GPC).
Europe
In parallel, enforcement in Europe is tightening:
- SHEIN (September 2025): CNIL, the French data protection authority, fined retailer SHEIN €150 million for privacy breaches relating to cookies, including failing to obtain consent, displaying incomplete cookie banners, and placing new cookies even after a user refused all cookies.
- Conde Nast (November 2025): Fined €750,000 by CNIL for failing to obtain user consent before placing cookies on one of its French sites.
- UK (ongoing): The Information Commissioner's Office (ICO) has started more actively monitoring the UK's top 1,000 websites while dramatically increasing the potential fines for non-compliance.
The Legal Direction: From Privacy Violation to Fraud
The legal landscape is shifting. Presenting a "Reject" option that does not prevent initial tracking creates a strong argument that the interface is misleading. Under state unfair or deceptive acts and practices regimes (UDAP), this can be characterized as a deceptive practice, even where the privacy statute itself is framed around opt-out rights.
Under California's Invasion of Privacy Act (CIPA), plaintiffs are arguing that deploying third-party tracking code that captures and transmits user interaction data to a third party without valid consent constitutes unlawful "interception" or "eavesdropping" under California Penal Code § 631(a). Separately, some web-tracking claims allege that certain tracker configurations operate like a "pen register" or "trap and trace" device, violating California Penal Code § 638.51(a) when implemented without legally required authorization.
The Conde Nast tracker complaint explicitly pleads CIPA § 638.51(a) in connection with installing and using trackers without prior consent or authorization.
This matters because the characterization of data collection without meaningful consent as fraud, rather than a technical privacy breach, changes the risk profile for organizations and their officers. Claims framed as fraud carry greater remedies, attract more attention, and in criminal contexts can result in personal liability or imprisonment for officers. This is not a distant hypothetical. It is the direction that enforcement and litigation are heading.
Cyber Coverage May Not Protect You
Many organizations assume their cyber insurance will respond to privacy claims. That assumption has limits. Most cyber policies contain exclusions for situations where the insured has not taken reasonable steps to minimize exposure. Where an organization has deployed a consent banner that does not function as presented, and tracking has proceeded regardless, an insurer may argue the organization failed to take reasonable precautions.
Where criminal intent is alleged, coverage exclusions are common. If a court or regulator characterizes the deployment of a non-functional reject button as intentional deception, or if a claim is brought under a criminal statute such as CIPA, the organization may find itself without coverage at the point it is needed most.
What Risk Managers Should Do
The following controls are drawn from a practical compliance checklist covering web/adtech governance, opt-out implementation, vendor management, and evidence retention:
Web and AdTech Controls
- Configure tag manager to prevent pre-rejection marketing tag firing.
- No third-party calls (pixels, SDKs) before opt-out state is applied.
- Maintain and update cookie classification regularly.
- Review SDKs for mobile equivalents.
Opt-Out Implementation
- Provide a clear opt-out method for targeted advertising.
- Ensure opt-out applies across devices where technically feasible.
- Confirm opt-out applies to downstream adtech partners where contractually required.
- Implement and test universal opt-out signals where applicable.
Vendor and Processor Controls
- Contracts must include opt-out honoring obligations.
- Third-party adtech disclosures and restrictions documented.
- Processors must support suppression lists and opt-out propagation where applicable.
Evidence and Governance
- Automated scans demonstrating tag firing order.
- Records showing opt-out preference signal detection and application.
- Audit logs of consumer opt-out processing.
- Maintain a tag inventory and vendor list with mapped purposes.
- Implement change control for tag additions (ticketing and approvals).
Sources and References
The following links provide primary statute references, regulator guidance, and enforcement materials referenced in this article and the accompanying whitepaper.


