Ask most privacy teams how their opt-out program handles logged-out users, and you’ll usually hear some version of the same thing: it’s covered, but only at the browser level, a cookie or local flag tied to that one device and that one session. On the face of it, that seems like enough. And for as long as consent management has existed as a discipline, that assumption went largely untested. A consumer who was signed in had a choice that could, in principle, follow their account across every device tied to it. One who wasn’t signed in wasn’t ignored, but their opt-out stayed exactly where they made it: that browser, and nothing more.
At least, that was the case before recent U.S. privacy enforcement cases, like the California AG’s settlement with Disney (at $2.75 million, the largest the regulation has produced). U.S. regulators are now writing a new chapter in consumer privacy enforcement. In the Disney case, the underlying complaint laid out four distinct technical challenges: opt-outs that stayed pinned to the browser and never followed logged-out users any further, opt-out tools that were not connected to one another, opt-outs that did not carry across the separate brands sharing a single advertising operation, and no working opt-out at all on apps and connected TV.
Three of those four are, fundamentally, engineering challenges. The opt-out existed in principle but didn’t work in practice: systems weren’t connected, requests never passed from one brand to the next, or a control that worked in a browser had no equivalent on an app or a TV. The first challenge is different. It isn’t about whether the mechanism worked. It’s about whether it reached far enough.
The argument here is simple. If a business can connect a person’s devices to advertise to them, it can make the same connection to honor their opt-out, and so it must.
Post-Disney settlement, a new precedent has been set. Your obligation now hinges on how you monetize people, not on the coverage of the software you bought to manage consent. Those two things can vary wildly in scale, and the settlement is, at its core, about what happens when they do.
Two meanings of the word “identify”
The force of that argument depends on what “identify” actually means, because the everyday meaning and the working meaning have come apart. When a privacy team says it can’t identify a logged-out user, it usually means it lacks that person’s name, email, or account. But that isn’t how advertising recognizes people. Advertising works off a profile: a stable identifier tied to a device or browser, built from a record of behavior, matched across a phone, a laptop, and a TV as one person. No name required, at any point. The profile does the work a name would do, precisely enough to follow someone from screen to screen and put an ad in front of them on that basis.
The settlement treats that kind of recognition as real enough to create an obligation. An opt-out has to reach any profile a business connects to a given device, including the “pseudonymous profiles” it keeps for selling, sharing, or targeting ads. If your systems can turn an anonymous signal into a profile precise enough to advertise against, you’ve identified that person in every sense the law cares about. A business that can recognize you well enough to sell you something can recognize you well enough to honor your opt-out. It’s the same system doing both jobs. You don’t get to use it for one and disown it for the other.
This is not one regulator reading the statute unusually broadly in a single case. The same enforcement logic was already visible a few months earlier in California’s settlement with Sling TV, part of the same enforcement wave targeting streaming services. Two actions pointing the same direction is a pattern, not a fluke, and it’s the standard the next company under review will be measured against.
The requirement is harder to meet than it sounds, because the ability to recognize people doesn’t have to belong to you. Most cross-device recognition in the market is bought, not built. A business running campaigns through Google or Meta, or matching people in a data clean room, is relying on someone else’s ability to track that person across devices. You can outsource the recognition. You can’t outsource the responsibility. If a partner is doing the identity matching on your behalf, their systems are the ones that have to receive your opt-outs too.
This is where most programs discover a gap they didn’t know they had, and it’s usually a symptom of how consent tools were built, not carelessness. Many CMP vendors can collect opt-outs from logged-out visitors, but only at the browser level: a cookie or local preference, tied to that one device and that one session. Once a person logs in, that browser-level choice and their account-level identity live in two separate records, one in a cookie, one in a database, with nothing connecting them. An opt-out submitted while logged out doesn’t necessarily follow the person once they’re recognized elsewhere. An opt-out submitted while logged in doesn’t necessarily reach back down to their anonymous browser state. The gap isn’t between people who were covered and people who were ignored. It’s between two disconnected records of the same person.
That gap shows up in practice, not just in theory. A consent record can log a clean opt-out while the systems downstream of it, the ones actually moving data to ad-tech partners, were never told anything changed. The request stops at the layer where it was made, because that’s the only layer built to receive it.
Marketing Technology News: MarTech Interview with Mark Listes, CEO @ Pendulum Intelligence
An engineering project, not a legal exercise
Closing that gap is ongoing engineering work, not a legal task you finish once. It means pointing the opt-out at the same profile your advertising systems already use, so one request suppresses every version of that person, not just the one tied to their login. It means passing that suppression to every partner holding a profile of them, notifying each one when an opt-out happens instead of assuming a blocked tag on your own site covers it. And it means being able to show, after the fact, that the suppression actually reached the systems collecting the data. None of this happens inside a typical consent management tool by default. It’s built to record a choice, at the browser or the account level, not to unify the two or enforce that choice across every system it doesn’t directly control.
It would be a mistake to treat this as a one-time fix. The rule underneath it is that your obligation follows your capability: if you can do something with a person’s identity, you’re answerable for it. Treat this as a box you check once a year, and you’ll keep failing it every time the box comes back around. Treat it as infrastructure, built to unify what you know about a person whether they’re logged in or not, and you’re covered now and ready for whatever comes next.
What the Disney settlement really establishes isn’t a list of one company’s mistakes. It’s a clearer line under where obligations start: wherever a business, or anyone acting for it, can recognize a person well enough to advertise to them. Companies that don’t internalize that are likely candidates for the next headline in the suits that follow.
About The Author Of This Article
Max Anderson is co-founder at Ketch
About Ketch
The Ketch Platform is the new layer of business technology that helps brands collect, control, and activate clean, permissioned, AI-ready and privacy-safe data across every device, system, and third-party app.
Marketing Technology News: How MarTech Is Enabling Autonomous Brand Engagement Across Channels?










