The most-sent privacy request in the world
A US newspaper publishes, as its state's law requires, a count of the privacy requests it received in a year. Deletion requests: 842. Access requests: 113. Requests to stop the selling and sharing of personal information: 13,426,237.
Sit with the ratio. For every person who asked that publisher what it held, roughly a hundred and twenty thousand refusals arrived telling it to stop trading them.
That number is not a groundswell. It is a browser setting called Global Privacy Control: an opt-out preference signal sent automatically to every site you visit. Somewhere in the last few years the opt-out stopped being something a person does and became something software does on their behalf, once per site, forever, silently. It is the single most-exercised privacy right in history and almost nobody exercising it knows they are.
We have written before about what those switches actually switch off: that they work forward only, that each one covers one use at one company, and that the formal version resolves to the company's own word. All of that still holds. This is the part we did not know then, because the number had not been published.
A signal has no reply, and that is the point
Here is what makes thirteen million possible. The signal is not addressed to anyone. No inbox receives it, no case is opened, no person reads it, and nothing comes back. It is a flag on a request header. The site either acts on it or does not, and either way your side of the exchange ends the moment it is sent.
That is a genuine achievement. Any mechanism requiring a human at the other end would collapse under a fraction of that volume, which is precisely why the older rights sit at 842 and 113. Automation is the only reason the number runs to millions.
But look at what was traded away to get there. A deletion request produces a reply, however evasive. An access request produces a file, however partial. The opt-out produces nothing at all. There is no dated document, no named sender, no sentence in their words, no record that it happened. You have exercised a right and the only evidence is a setting in your own browser, which proves what you asked for and nothing whatsoever about what they did.
Nobody checks
So how would you ever know?
Not by watching the advertising. Ads getting less relevant proves nothing, ads staying relevant proves nothing, and the profile can carry on being assembled while the targeting changes. The processing you objected to is invisible from outside by construction. That is not a conspiracy, it is just what server-side data handling is.
Not from the company either. There is no acknowledgement, no confirmation, no compliance report naming you. The publisher above disclosed 13,426,237 signals received. It disclosed no figure at all for how many were honoured, and no law required it to.
Which leaves the regulators, and they have looked once in a way worth reporting. In its first enforcement action under the state's privacy law, California's attorney general found a retailer whose site was not configured to detect or process global opt-out signals at all, while its policy told visitors it did not sell personal information. The settlement was $1.2 million, with reporting obligations attached about its efforts to honour the signal going forward.
That is one company, checked once, four years ago. It failed. We have no basis for saying it is representative and we are not going to pretend otherwise. The honest statement is narrower and worse: the most-sent privacy request in the world has almost never been independently checked, and the one documented look found it was not working.
The ground underneath has collapsed
While the signal was scaling into the millions, something else was happening to the thing it objects to.
In late 2024 an EU regulator examined behavioural analysis and targeted advertising on a professional network and worked through every legal basis the company offered. Consent was found not to be freely given, sufficiently informed, specific or unambiguous. Legitimate interests were found to be overridden by the rights of the people involved. Contractual necessity was found invalid. All three failed, and the fine was 310 million euros.
Around that sits a hardening floor. Europe's platform regulation flatly bans ad profiling that uses sensitive categories, and bans it entirely for users a platform knows are minors. A US regulator took $150 million off a platform for feeding phone numbers and email addresses collected for account security into its ad targeting, a practice it said affected more than 140 million people. And the regulators' own guidance holds that offering a bare choice between consenting to profiling and paying a fee is, in most cases, not valid consent either.
Read those together. This is not a right that companies have a good argument against. It is a right whose every attempted justification has been tested at scale and lost.
Which means a written objection here is harder to refuse than almost anything else you could send them. Not because they are frightened of you, but because the lawful grounds for saying no have been examined one by one and found not to exist.
What a written answer does that a signal cannot
The signal and the letter ask for the same thing. Only one of them leaves a trace.
It dates the claim. A reply is a company's own statement, on a day, about what it stopped doing. If its behaviour later contradicts that sentence, the sentence is still there, and it did not come from you.
It names the scope. A switch says "personalised advertising: off". It does not say whether the profile is still being built, only used differently. A written answer has to address what you actually asked.
It survives the relationship. Settings die with accounts. A migration, a redesign, a change of default, an acquisition, and the toggle's history is gone. The reply is not on their system. It is in your inbox.
Silence counts too. A switch cannot produce a non-answer. A request can, and a company that will not put in writing what its own interface already claims has told you something worth keeping.
None of that requires believing them. We do not verify what a company says and neither should you. The point is not that the written answer is true. The point is that it exists, it is dated, and it is theirs.
Send both
Flip every switch you can find, and turn on the browser signal if you have not. It costs nothing, it works at a scale no letter ever will, and on the evidence above the companies have no lawful footing to ignore it.
Then send the objection in writing to the handful of companies that actually matter to you, and keep what comes back. Not because the letter is stronger. Because it is the only version of the request that leaves anything behind.
Thirteen million refusals went out from one publisher's readers in a year, and not one of those people can show you a thing. That is the gap, and closing it costs one email.
DÆTRAX keeps the ledger: which company, which request, which date, and what came back. We do not send it for you and we do not store their reply. The reply belongs in your inbox, where it is yours. Start your record →