Analysis

You Never Read It. That Was the Plan

How privacy policies became the perfect crime — and what we can do about it.

By Giovanni Battista Caria


You clicked “I Agree.” You always do. So does everyone else.

The average privacy policy in 2026 takes between 18 and 34 minutes to read. The average user spends less than 15 seconds on it before scrolling to the bottom and accepting. No one reads them — and the companies that write them know this better than anyone. They designed it that way.

This is not a conspiracy theory. It is a business model.

Over the past two years, in the course of security research, incident response, and advisory work across multiple jurisdictions, I have analyzed dozens of privacy policies for clients ranging from gaming operators to healthcare platforms to public institutions. What I found is not a collection of occasional oversights. It is a systematic, engineered gap between what companies declare and what they actually do — a gap so consistent, so structurally reproducible, that it can only be the result of deliberate design.

This article is an attempt to make that gap visible. Not for lawyers. Not for DPOs. For everyone.


Part 1: The Document Is Not Designed to Inform You

Let us start with an uncomfortable observation.

A privacy policy is, legally speaking, an information notice. Its purpose — as defined by Articles 13 and 14 of the GDPR — is to inform the data subject clearly and transparently about what data is collected, why, for how long, by whom, and what rights the subject holds over that data.

In practice, privacy policies are legal shields. They exist to protect the company, not the user. Every vague clause, every buried opt-out, every reference to a separate document that is never linked — these are not accidents of poor writing. They are outputs of a legal optimization process whose objective is maximum data collection with minimum enforceable commitment.

The language is the first tell. Phrases like “we may collect,” “in certain circumstances,” “including but not limited to,” “legitimate business purposes,” and “trusted partners” appear in virtually every major privacy policy. None of these phrases means anything specific. All of them are designed to mean nothing specific. “We may collect” means we collect. “Trusted partners” means advertising networks you have never heard of and whose servers are in jurisdictions you have no relationship with.

The structure is the second tell. Critical information — the legal basis for processing, the list of third parties who receive your data, the retention period — is systematically buried. Consent mechanisms are front-loaded with large green “Accept All” buttons and small grey “Manage Preferences” links that require three additional screens to navigate. This is not UX design. It is behavioral engineering applied to legal compliance.

The length is the third tell. The longer the document, the less likely any user reads it, and the more room there is to hide consequential clauses in the middle of section 14, subsection 3, paragraph (f). Amazon’s privacy policy is over 4,000 words. Google’s is longer. The FTC’s own privacy notice — a US government document — would violate GDPR in at least six distinct ways if applied to EU users.


Part 2: The Gap Between What They Say and What They Do

The most important concept in privacy policy analysis is not violation detection. It is delta detection — the measurement of the distance between what a document declares and what the backend actually does.

This distinction matters enormously, and it is almost completely absent from standard compliance frameworks.

Consider three real-world patterns that appear constantly in the policies I have analyzed.

The legitimate interest fabrication. Article 6(1)(f) of the GDPR permits processing personal data when the controller has a “legitimate interest” that is not overridden by the rights of the data subject. This provision requires a documented balancing test — a Legitimate Interest Assessment — that weighs the company’s interest against the individual’s rights. In practice, “legitimate interest” has become a magic phrase that companies paste into policies to avoid asking for consent. Google Analytics is cited as legitimate interest. PayPal transaction data is cited as legitimate interest. Behavioral advertising profiles built from cross-site tracking are cited as legitimate interest. None of these pass the actual balancing test required by GDPR. The EDPB has said so repeatedly. Companies continue to do it because enforcement is slow, fines are rare, and the legal team’s job is to minimize consent requirements, not maximize user protection.

The third-party opacity wall. Almost every privacy policy mentions “third-party services,” “trusted partners,” or “affiliates.” Almost none of them name these parties specifically. This is a direct violation of Article 13(1)(e), which requires identification of recipients or categories of recipients of personal data. “Trusted partners” is not a category. It is a placeholder for a list that, if published, would reveal the full extent of the data economy the company participates in — advertising networks, data brokers, analytics platforms, credit scoring services, and in some cases intelligence-adjacent data aggregators. The opacity is not incidental. It is the product.

The AI training silence. This is the vector that is most underregulated in 2026 and most consequential for the future. A service collects your data legitimately — to provide you with the service you signed up for. In the backend, that data is extracted, partially pseudonymized, and used to train machine learning models. Those models are then used for behavioral targeting, content recommendation, pricing optimization, or sold as AI services to other companies. None of this appears in the privacy policy. There is no cookie involved. There is no SDK to detect. There is no visible transfer. The processing happens silently, at the infrastructure level, declared nowhere except perhaps under “we use data to improve our services” — a clause so broad it covers virtually anything.

This is not hypothetical. It is the operating model of most large platform companies in 2026. The absence of disclosure is not an oversight. It is a deliberate exploitation of the gap between what GDPR requires in principle and what it can detect in practice.


Part 3: The Transatlantic Contradiction That Cannot Be Solved

Here is something that should be front-page news but rarely gets discussed outside specialist circles.

The GDPR and US law are structurally incompatible. Not philosophically. Not in spirit. Legally, operationally, irreconcilably incompatible — and no political agreement has resolved this, because no political agreement can.

The GDPR is built on the premise that personal data belongs, fundamentally, to the individual. Processing it requires a legal basis. Transferring it outside the EU requires guarantees that the destination country provides equivalent protection. The system is designed to give individuals control over their data regardless of where the company processing it is located.

US law operates on a different premise. Under FISA Section 702, the US government can compel American companies to provide access to data on non-US persons stored anywhere in the world — including on servers physically located in Europe — without notification to the individual and without any mechanism for judicial challenge accessible to EU citizens. Under the CLOUD Act, US law enforcement can demand data from US-based providers regardless of where that data is physically stored.

These two systems cannot coexist without one overriding the other. An American company operating under both legal regimes simultaneously cannot fully comply with both. When US authorities issue a lawful order under FISA 702, the company must comply. GDPR says that transfer is illegal without adequate protections. The company cannot tell you about the order because it is classified. You have no legal recourse in a US court because you are not a US person. The European DPA cannot enforce against what it cannot see.

The Court of Justice of the European Union has reached this conclusion twice. In Schrems I (2015), it invalidated the Safe Harbor agreement. In Schrems II (2020), it invalidated the Privacy Shield framework. The EU-US Data Privacy Framework of 2023 — the current attempt at a solution — is already under legal challenge for the same structural reasons. The problem is not the name of the agreement. The problem is that FISA 702 exists and has not been reformed.

What this means practically: if you are an EU citizen using any service provided by a US company — any cloud storage, any SaaS platform, any application that calls home to American servers — your data is accessible to US intelligence agencies under conditions that are illegal under GDPR and invisible to you. This is not a theoretical risk. It is the default state of the transatlantic data economy.

When you accept a privacy policy from an American company operating under US law, you are not consenting to something that can be governed by GDPR. You are operating in a legal grey zone where the protections you are promised are unenforceable against the most consequential actors.


Part 4: How to Read a Privacy Policy in Ten Minutes

Despite everything above, there are things you can look for. The following are the highest-signal indicators that a privacy policy is either non-compliant with GDPR or designed to obscure what the service actually does with your data.

Red flags — stop and investigate:

The policy invokes “legitimate interest” without specifying what that interest is and how it was balanced against your rights. If you see this phrase without a link to a Legitimate Interest Assessment, treat it as a consent workaround.

The policy names no specific third parties — only categories like “partners,” “affiliates,” or “service providers.” Ask yourself: why won’t they name them?

There is no retention period, or the retention period is “as long as necessary.” GDPR requires a specific period or the criteria for determining it. Vague retention language means indefinite retention.

The policy is governed by laws of a non-EU jurisdiction (US, UK post-Brexit in some cases) and offers no EU-specific provisions. If the company offers services to EU users, GDPR applies regardless.

The policy mentions “third-party services” or “analytics tools” without naming them and without reference to Standard Contractual Clauses or an adequacy decision for data transfers. Your data is going somewhere outside the EU with no disclosed legal basis.

The service offers AI-powered features — recommendations, personalization, automated responses — but the privacy policy does not mention model training, AI processing, or automated decision-making. This is the clearest signal of undisclosed backend AI training.

Yellow flags — read carefully:

Retention periods exist but are tied to account activity with no maximum. “We retain your data for as long as your account is active” can mean decades.

The policy references a separate cookie policy, a separate data processing agreement, or a separate terms of service without linking to them directly. Each separate document is an opportunity to bury critical information.

The right to erasure is acknowledged but surrounded by so many exceptions that it is practically unusable. Read the exceptions carefully — if they cover “legal obligations,” “legitimate interests,” or “statistical purposes,” the right is effectively hollow.

The company is headquartered in the US but claims compliance with GDPR through a subsidiary or representative. Check whether the subsidiary actually controls the processing or is a legal fiction designed to create EU jurisdiction on paper while operations remain under US law.


Part 5: The Consent You Never Gave

There is a word for a contract where one party cannot understand the terms, cannot negotiate them, cannot refuse them without losing access to essential services, and has no practical recourse when the other party violates them.

It is not “consent.” Consent requires information, freedom, and the genuine possibility of refusal.

What you click when you accept a privacy policy is not consent. It is the simulation of consent — a legal formality that protects companies from liability while transferring to you all the risk of a data relationship you did not choose and cannot exit.

The GDPR was meant to change this. In many ways it has — it created enforcement mechanisms, it established rights, it raised the cost of the most egregious violations. But it did not change the fundamental incentive structure: companies profit from collecting data, and the cost of not collecting it is higher than the cost of occasional regulatory fines.

That is the only lever that has ever worked at scale: making the invisible visible. When violations are visible, they become politically costly. When users can read what they are signing, they can make real choices. When the gap between declaration and practice can be measured and named, the gap becomes harder to maintain.

None of that requires new legislation, international agreements, or years of litigation. It requires only that people know what they are looking at.


The views expressed in this article are the author’s own and do not constitute legal advice.