ConsentPixel – Privacy · Verified

Privacy · Plain-English Pillar · 2026

Data and Privacy Explained: Rights, Risks & Rules

Everyone talks about data and privacy, but the words get used loosely — privacy, security, compliance, consent all blur together. This guide draws the lines clearly: what data privacy actually is, how it differs from security, the rights you have, the rules that apply in 2026, and what really happens when privacy is violated.

By ConsentPixel TeamUpdated August 202618 min readInformation, not legal advice
20 states
US states with comprehensive privacy laws in force as of 2026 — up from one in 2020
12 states
Where a single browser signal (GPC) is now a legally binding opt-out
$2.75M
Largest US state privacy settlement to date (Disney/ABC, Feb 2026)
The short answer

What is data privacy? Data privacy (also called information privacy) is your right to control how your personal information is collected, used, shared, and kept. It's about who gets to know what about you, and whether you had a real say in it.

It's often confused with data security, but they're different: security is about protecting data from attackers; privacy is about using data appropriately and honoring people's choices — even when the data is perfectly secure. This guide is general information, not legal advice.

"Data and privacy" is one of those phrases everyone nods along to and few can define precisely. That vagueness is a problem, because privacy, security, and compliance are genuinely different things — and confusing them is how businesses end up secure but sued, or compliant on paper but not in practice. Let's build the concept up cleanly, from the definition to the rules, with real 2026 examples along the way.

What does privacy mean when we talk about data?

Start with the definition, because "privacy" gets used to mean everything from window blinds to encryption.

Data privacy

The right of an individual to control how their personal information is collected, used, shared, retained, and deleted — and the obligation of organizations to handle that information fairly, transparently, and only with a proper basis (like consent). Also called information privacy.

Notice what that definition centers on: control and appropriate use, not secrecy. Privacy isn't about hiding — it's about agency. When people ask "what is privacy" or "what does privacy primarily refer to," the most accurate answer is that it refers to a person's ability to determine what happens to information about them. A company can hold your data perfectly securely and still violate your privacy by using it in ways you never agreed to.

To define personal privacy simply: it's your reasonable expectation that information about you — where you go, what you buy, what health conditions you search — won't be collected and traded without your knowledge. Individual privacy is the same idea applied to a single person's data across every service they touch. That expectation is exactly what data-privacy laws exist to protect.

Privacy vs data security: the difference that trips everyone up

This is the single most useful distinction to get straight, because the two are constantly confused — and the difference between privacy and security of data has real consequences.

Data privacy

About appropriate use and control: what data you collect, why, whether you had a legal basis, and whether the person had a real choice.

"Should we be using this data at all — and did they agree?"

Data security

About protection: keeping data safe from breaches, theft, and unauthorized access through encryption, access controls, and monitoring.

"Is this data locked down and safe from attackers?"

Here's the punchline: you can have perfect security and still fail on privacy. A company that encrypts its database flawlessly, then quietly sells that data to advertisers without consent, is secure but not private. Conversely, sloppy security creates a privacy problem when it leads to a breach. The two overlap — database privacy and security work best together — but they answer different questions. Security asks "is it safe?" Privacy asks "should we even have it, and does the person have a say?"

A simple way to remember it

Security protects data from people who shouldn't have it. Privacy protects people from inappropriate uses of their data — including by the company that legitimately holds it. Compliance is a third thing again: proving to a regulator that you're doing both.

Information privacy, personal data, and what actually counts

When laws talk about privacy, they're usually talking about personal data (or "personal information") — and the definition is broader than most people expect. It's not just your name and credit card. Under modern privacy laws, personal data includes anything that can identify you directly or indirectly:

  • Obvious identifiers — name, email, phone, address, government IDs.
  • Online identifiers — IP address, device IDs, cookie IDs, advertising IDs.
  • Behavioral data — the pages you visit, what you search, how you move through a site.
  • Sensitive data — health, biometrics, precise location, race, sexual orientation, and (newly, in California) neural data.
  • Inferences — profiles a company builds about you from all of the above.

That last category matters most for the modern web. What compromises your digital privacy usually isn't a single leaked password — it's the quiet accumulation of behavioral data into a profile. Privacy concerns around the collection and use of data about individuals are really concerns about profiling: the way ordinary browsing gets stitched into a detailed picture of who you are, often by companies you've never heard of.

Your privacy rights and choices

The good news: you have more concrete, enforceable rights over your data than ever. Depending on where you live, privacy laws now give individuals a consistent set of rights — and the "your privacy choices" links you see on websites are how you exercise several of them.

  • The right to know what data is collected about you and how it's used.
  • The right to access a copy of your data, and to correct or delete it.
  • The right to opt out of the sale or sharing of your data for targeted advertising.
  • The right to limit use of sensitive information.
  • The right to non-discrimination for exercising any of these — a company can't cut off service because you said no.

In the US, these come from state laws like the California Consumer Privacy Act (CCPA/CPRA) and its counterparts. In the EU and UK, they come from the GDPR — see our GDPR guide for the opt-in model that governs there. The single most important practical difference: the EU is opt-in (nothing non-essential until you agree), while US states are mostly opt-out (they can collect by default, but must let you stop it).

Global Privacy Control: one signal, twelve states

If there's one privacy development worth understanding in 2026, it's Global Privacy Control (GPC) — because it turns a browser setting into a legal instruction.

Global Privacy Control

A standardized browser signal (technically an Sec-GPC: 1 header) that automatically tells every website you visit: "do not sell or share my personal data." Instead of clicking "opt out" on each site, you set it once and it applies everywhere.

What makes GPC matter is that it's not just a polite request. As of 2026, roughly twelve US states legally require businesses to honor GPC (or a similar universal opt-out) as a valid opt-out of data sale and sharing. Ignoring it is a violation. California's very first CCPA enforcement action — the $1.2 million Sephora settlement in 2022 — was, in part, about failing to honor GPC signals.

GPC support varies by browser. Firefox, Brave, and DuckDuckGo have it built in (in Firefox and Brave it's a simple setting; DuckDuckGo sends it by default). Chrome, Safari, and Edge don't yet include native GPC — for now, users add it through an extension. But that's about to change: California's AB 566, signed in October 2025, will require major browsers to build in a GPC setting by January 1, 2027. Once Chrome and Safari ship it, the volume of opt-out signals hitting websites will jump enormously — which is why smart businesses are learning to honor GPC now.

See it on your own site

Which trackers fire before anyone consents?

Data privacy gets concrete at one specific moment: when a tracker sends a visitor's data to a third party before they've agreed. Run a free scan to see exactly which trackers and cookies fire before consent on any site — in about 10 seconds, no account needed.

No account needed for the scan · no credit card · information, not legal advice

Privacy by design and privacy by default

For anyone building a product or website, two principles have moved from "nice to have" to "written into law": privacy by design and privacy by default.

Privacy by design

Building privacy protections into a product or process from the very start — as a default architectural choice — rather than bolting them on after launch. The concept, developed by Dr. Ann Cavoukian, is now embedded in the GDPR (Article 25).

The framework rests on seven foundational privacy-by-design principles — the ones most worth knowing are that privacy should be proactive not reactive, the default setting (no action required by the user to be protected), and end-to-end across the whole data lifecycle. When people ask "when should privacy by design be implemented," the answer the principles give is blunt: from the first design decision, not after the breach.

Privacy by default is the most consumer-visible piece: it means the most privacy-protective setting is the one that's on before anyone touches a control. A signup form that leaves marketing consent unchecked by default is practicing privacy by default; one that pre-checks it (a classic dark pattern sometimes called "privacy zuckering") is doing the opposite. A privacy-by-design example on the web is a consent banner that blocks tracking until the visitor opts in — protection is the default state, not something the user has to go hunting for.

Privacy frameworks, principles, and certifications

Beyond individual laws, a set of shared frameworks shapes how privacy is practiced worldwide — useful to recognize whether you're evaluating a vendor or building a program.

  • The OECD Privacy Principles (1980, updated 2013) — the original eight principles (collection limitation, purpose specification, use limitation, and so on) that most modern laws still echo.
  • Fair Information Practice Principles (FIPPs) — the US lineage of the same ideas, underpinning many sectoral rules.
  • The NIST Privacy Framework — a voluntary US framework for managing privacy risk, often paired with NIST's cybersecurity framework.
  • ISO/IEC 27701 — an international standard for a privacy information management system, extending the ISO 27001 security standard.
  • Australia's Privacy Principles (APPs) and similar national principle sets — regional expressions of the same core ideas.

On the people side, privacy has become a genuine profession. The IAPP (International Association of Privacy Professionals) offers the most recognized privacy certifications — the Certified Information Privacy Professional (CIPP), along with the CIPM (management) and CIPT (technologist) credentials. When a vendor says its team includes certified privacy professionals, these IAPP certifications are usually what they mean.

Privacy violations: what they look like in the real world

Abstract definitions get real the moment privacy is violated. So what is a breach of privacy, and what does a violation of privacy actually look like?

Privacy violation

Collecting, using, sharing, or exposing someone's personal data in a way they didn't agree to and wouldn't reasonably expect — whether through a deliberate practice, a careless default, or a failure to honor a choice they made. (Distinct from a data breach, which is specifically unauthorized access — one type of privacy violation, not the only one.)

Real privacy-invasion examples are more mundane — and more common — than dramatic hacks:

  • Ignoring an opt-out. A visitor clicks "do not sell my data" (or sends a GPC signal) and the site keeps sharing it anyway. California fined Ford $375,000 in 2026 for creating "unnecessary friction" in its opt-out process.
  • Tracking before consent. Analytics, ad pixels, or session-replay tools firing the moment a page loads, before the visitor agrees — the basis of a large wave of US lawsuits.
  • Selling data you shouldn't. California fined Tractor Supply $1.35 million and reached a $2.75 million settlement with Disney/ABC (its largest to date) over alleged failures around consumer opt-out and data sharing.
  • Dark patterns. Designing consent flows so "accept" is easy and "reject" is buried — a violation of the "symmetry in choice" many laws now require.

In the US, one specific flavor of violation has become its own litigation wave: under the California Invasion of Privacy Act (CIPA), plaintiffs argue that trackers capturing a visitor's activity before consent amount to unlawful interception — with statutory damages of $5,000 per violation under California Penal Code §637.2. You can see the scale of it in our CIPA Lawsuit Tracker. The lesson across all of these: most privacy violations aren't hacks — they're ordinary data practices that never asked, or never listened.

The 2026 data privacy rules that actually matter

The regulatory picture changes fast, so here's where data privacy stands in 2026 — the parts that affect real websites.

RegimeModelWhat it governs
EU / UK GDPROpt-inNo non-essential data collection or tracking until the user consents. The strictest baseline.
US state laws (20+ states)Opt-outCollection allowed by default, but consumers must be able to opt out of sale/sharing and access/delete their data.
California (CCPA/CPRA)Opt-out+The strictest US state; enforced by a dedicated agency (CalPrivacy) with real fines and mandatory GPC honoring.
ePrivacy Directive (EU)Opt-inArticle 5(3) requires consent before storing or accessing anything on a user's device — the basis of cookie and pixel consent.
Canada (PIPEDA) & othersConsentConsent-based frameworks; Canada's privacy legislation is being modernized, and 80+ countries now have comprehensive laws.

Two 2026 developments are worth flagging specifically. First, California's privacy agency rebranded to "CalPrivacy" and turned notably more aggressive — new rules on risk assessments and automated decision-making took effect January 1, 2026, and staff have said hundreds of investigations are underway. Second, and counterintuitively: Google shut down its Privacy Sandbox project on October 17, 2025, and Chrome is now keeping third-party cookies indefinitely. The "cookieless future" everyone planned for didn't arrive — which means the consent obligations around third-party tracking aren't going away; if anything they're the main event again. (Curious how that affects cookies specifically? See our guides on what cookies are and cookie consent.)

Why is privacy so important?

It's fair to ask why any of this matters — especially if you feel you have "nothing to hide." The importance of privacy runs deeper than hiding secrets:

  • Privacy is about power, not secrecy. Who knows what about you shapes what you're shown, what you're charged, and what opportunities you're offered. Losing control of that is losing a kind of autonomy.
  • Profiles are permanent and portable. Data collected today can resurface years later, in contexts you never imagined — a health search, a location trail, a purchase history — sold between companies you never chose.
  • The harms are real. Discrimination in pricing and hiring, manipulation through targeting, exposure of sensitive conditions, identity theft — these flow from ordinary data collection, not just breaches.
  • Trust is a business asset. For companies, respecting privacy isn't just compliance — it's the difference between customers who trust you with their data and customers who don't.

That's why digital privacy is important even for people who "have nothing to hide": privacy isn't the opposite of transparency, it's the foundation of consent. Without it, you're not choosing to share — the choice is being made for you.

Privacy for your business: turning the concept into practice

If you run a website, all of the above lands on one practical question: is what my site actually does consistent with what privacy law and my own privacy policy promise? The gap between those two is where risk lives. Making privacy real in a business comes down to a few concrete moves:

  1. Know what you collect. You can't govern data you can't see. Most exposure comes from third-party trackers a site owner didn't know were running — so start by scanning your own site to inventory what actually fires, and when.
  2. Get the timing right. For EU visitors, block non-essential trackers until opt-in. For US visitors, honor opt-out signals including GPC. The when — before or after consent — is the whole game.
  3. Practice privacy by default. Make the protective setting the starting state; no pre-checked boxes, no buried "reject."
  4. Keep proof. A timestamped record of each consent decision is what turns "we respect privacy" into something you can actually demonstrate to a regulator.
  5. Write the policy from reality. Your privacy policy should describe what your site truly does — generated from a real scan, not a generic template.

This is exactly the gap ConsentPixel — Privacy · Verified is built to close. From a single pixel, it blocks third-party trackers until a visitor consents, honors opt-out and GPC signals, continuously scans what fires across your pages, and logs each decision as evidence — so your privacy practice matches your privacy promise. It's a consent-management and detection tool, not legal advice, and not a substitute for counsel on your specific obligations.

Key takeaways

  • Data privacy is about control and appropriate use — who gets to know what about you, and whether you had a real say. It's not the same as secrecy.
  • Privacy ≠ security. Security protects data from attackers; privacy protects people from inappropriate use — you can have one without the other.
  • You have real, enforceable rights — to know, access, correct, delete, and opt out — plus browser-level tools like GPC to exercise them at scale.
  • GPC is now legally binding in ~12 states, and California's AB 566 will put it in every major browser by January 1, 2027.
  • Privacy by design and by default mean building protection in from the start and making it the out-of-the-box state.
  • Most privacy violations aren't hacks — they're ordinary practices that never asked for consent or never honored an opt-out.

The bottom line

Data and privacy stop being fuzzy the moment you separate the ideas: privacy is control over your personal information, security is protection of it, and compliance is proving you do both. In 2026 the rules behind those ideas have real teeth — a dedicated California agency issuing million-dollar fines, a browser signal that carries legal weight in a dozen states, and a litigation wave built on trackers that fire before anyone says yes.

For individuals, the takeaway is empowering: you have more control than you think, and tools like GPC make it easier to use. For businesses, it's clarifying: the goal isn't a perfect privacy policy, it's a site whose behavior matches it. Both start the same way — by seeing what's actually being collected.

See your site's real privacy picture in 10 seconds

The fastest way to move from privacy in theory to privacy in practice is to see what your own site does. Scan free to find every third-party tracker and cookie firing before consent — then close the gap with a single prevention-first pixel that blocks trackers, honors GPC, and logs the proof.

Scan your site free →
No account for the scan · then a 14-day free trial, no credit card, from $8.99/mo · or explore the privacy laws · information, not legal advice
CP
The ConsentPixel Team

ConsentPixel — Privacy · Verified helps website owners and agencies make privacy real — blocking third-party trackers until a visitor genuinely consents, honoring opt-out and Global Privacy Control signals, continuously scanning what fires, and logging each decision as evidence. This article is general educational information, not legal advice. ConsentPixel is not a law firm.

Frequently asked questions

What is data privacy in simple terms?

Data privacy — also called information privacy — is your right to control how your personal information is collected, used, shared, and kept. In plain terms, it's about who gets to know what about you, and whether you had a real say in it. It's distinct from data security: security is about protecting data from attackers and breaches, while privacy is about using data appropriately and honoring people's choices, even when the data is perfectly secure. A company can hold your information safely and still violate your privacy by using it in ways you never agreed to. This is general information, not legal advice.

What's the difference between data privacy and data security?

They answer different questions. Data security is about protection — keeping data safe from breaches, theft, and unauthorized access using tools like encryption and access controls. Data privacy is about appropriate use and control — what data an organization collects, why, whether it had a legal basis, and whether the person had a genuine choice. The key insight is that you can have one without the other: a company can secure its database flawlessly and still violate privacy by selling that data without consent. Security asks "is it safe?" Privacy asks "should we have it, and did they agree?" Compliance is a third thing: proving to a regulator that you do both.

What is Global Privacy Control (GPC)?

Global Privacy Control is a standardized browser signal that automatically tells every website you visit not to sell or share your personal data. Instead of clicking "opt out" on each site individually, you enable it once and it applies everywhere. What makes it powerful is that it's legally binding: as of 2026, roughly twelve US states require businesses to honor GPC as a valid opt-out of data sale and sharing, and ignoring it is a violation. Firefox, Brave, and DuckDuckGo support GPC natively; Chrome, Safari, and Edge currently need an extension, but California's AB 566 will require all major browsers to build it in by January 1, 2027.

What is privacy by design?

Privacy by design means building privacy protections into a product or process from the very start, as a default architectural choice, rather than adding them after launch. The concept, developed by Dr. Ann Cavoukian, is now written into the GDPR (Article 25). Its principles emphasize being proactive rather than reactive, making privacy the default setting so users are protected without having to take action, and covering the full data lifecycle end to end. A practical privacy-by-design example on the web is a consent banner that blocks tracking until the visitor opts in — protection is the default state, not something the user has to hunt for. The related idea, privacy by default, means the most privacy-protective option is the one that's already on before anyone changes a setting.

What counts as a privacy violation?

A privacy violation is collecting, using, sharing, or exposing someone's personal data in a way they didn't agree to and wouldn't reasonably expect. That's broader than a data breach — a breach (unauthorized access) is just one type. Common real-world examples include ignoring a consumer's opt-out or GPC signal, firing tracking pixels before a visitor consents, selling data without a proper basis, and using dark patterns that make "reject" far harder than "accept." Recent enforcement shows these are taken seriously: California fined Ford $375,000 over opt-out friction, fined Tractor Supply $1.35 million, and reached a $2.75 million settlement with Disney/ABC. Most violations aren't dramatic hacks — they're ordinary data practices that never asked or never listened.

Why is data privacy important if I have nothing to hide?

Because privacy is about control and power, not secrecy. Who knows what about you shapes what you're shown, what you're charged, and what opportunities you're offered — so losing control of your data means losing a form of autonomy, whether or not you have anything to "hide." Data collected today is permanent and portable: it can resurface years later in contexts you never imagined, sold between companies you never chose. The harms are concrete — price and hiring discrimination, manipulation through targeting, exposure of sensitive information. Privacy isn't the opposite of transparency; it's the foundation of consent. Without it, you're not choosing to share — the choice is being made for you.

Information, not legal advice. This article is general educational information about data privacy concepts, laws, and enforcement and does not constitute legal advice or create an attorney–client relationship. Privacy laws vary by jurisdiction and change frequently; specific obligations depend on your facts, data, and location. Enforcement figures and settlement amounts are as publicly reported as of August 2026 and may change; the $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Verify your specific obligations with qualified counsel. ConsentPixel — Privacy · Verified is a consent-management and detection tool, not a law firm.
Scroll to Top