Regulators spent 2025 and 2026 fining companies for compliance gaps that touch ordinary users directly. According to a new compliance roundup from Kanerika, the list of 10 commonly missed gaps runs from ignored opt-out signals to AI profiling that people were never told about. That matters to you as much as to the businesses involved, because each gap is a right you may be able to use. This GDPR CCPA opt-out rights guide explains what you are entitled to, how to ask for it, and where VPNs and browser settings help or fall short.

What GDPR and CCPA Actually Give You as an Individual

The two laws work differently, and the difference shapes what you do.

The EU's GDPR is an opt-in style regime. Organizations generally need a lawful basis, such as consent, before processing your personal data. Your rights include access to the data a company holds on you, correction, erasure, objection to certain processing, and protections around decisions made purely by automated means. For a deeper background, see our GDPR explainer.

California's CCPA, as amended by the CPRA, leans on opt-out. Businesses can collect personal information by default, but you can tell them to stop selling or sharing it. California residents can also ask what is collected, request deletion or correction, and limit the use of sensitive data. The California Attorney General's page describes the right to opt out as a request that businesses stop selling or sharing your personal information.

The practical takeaway: under GDPR you often challenge processing, while under CCPA you usually have to speak up first.

Why Ignored Opt-Out Signals Like Global Privacy Control Matter

One of the gaps regulators penalized in 2025-2026, per the source roundup, is businesses ignoring opt-out signals. The best-known example is Global Privacy Control (GPC), a setting in your browser or extension that automatically tells every site you visit that you do not want your data sold or shared.

The idea is simple. Without GPC, you would have to find a "Do Not Sell or Share My Personal Information" link on every website and click it one by one. With GPC, your browser sends the request for you. Under California rules, a business is expected to treat that signal as a valid opt-out request. When a site ignores it, the opt-out right exists only on paper.

The same roundup flags AI profiling as another enforcement area. If a company uses your data to build automated profiles without telling you, you lose the chance to object. Our guide on how AI chatbots track your data shows how much information these tools can collect, which is useful context before you decide what to request.

Enforcement is also growing in scale. Cumulative penalties have been climbing, as covered in our report on GDPR fines topping 4 billion as 137 nations adopt privacy laws. Regulators are clearly willing to act, but that does not replace you checking your own settings.

How to File Opt-Out, Deletion, and Data-Access Requests

You do not need a lawyer. A few steps cover most cases:

  1. Find the right channel. Look in the privacy policy for a privacy contact, web form, or the "Do Not Sell or Share" link. Many companies name a data protection officer or privacy team.
  2. Be specific. State which law you are relying on (GDPR or CCPA), which right you are using (access, deletion, opt-out), and the email or account identifiers needed to find your records.
  3. Expect identity checks. Companies may ask you to confirm who you are before releasing or deleting data. That is normal.
  4. Keep a record. Save screenshots and copies of your request with the date. If the company misses its deadline or refuses without good reason, you have evidence for a complaint.
  5. Escalate if needed. In the EU, you can complain to your national data protection authority. California residents can report problems to the state's privacy regulators.

One detail worth knowing: according to Clarip's summary of the CCPA, once you opt out, a business must honor that choice for 12 months before it asks you to opt back in to the sale of your information.

Data brokers are the hardest part, since there are many of them and most people never deal with them directly. Automating the process can save time; our Incogni review looks at one service that submits opt-out and deletion requests to brokers on a user's behalf.

Where VPNs and Browser Settings Fit (and Where They Don't)

A VPN hides your IP address from the sites you visit and encrypts traffic between your device and the VPN server. That is valuable, but it is not a legal opt-out. A VPN does not tell a company to stop selling your data, and it does nothing about information you have already handed over through accounts, purchases, or logins.

There is also a possible downside. Privacy rights often depend on where a business thinks you live. Connecting through a server in another country could change which notices or options a site shows you. If you want to exercise California or EU rights, it is usually safer to make requests from your real location, or to state your residency clearly in the request.

Browser settings are the better complement:

  • Turn on Global Privacy Control in a browser or extension that supports it.
  • Block third-party cookies and review site permissions regularly.
  • Use separate browser profiles to limit cross-site tracking.

Think of it as layers: a VPN reduces what is exposed at the network level, GPC and browser controls send your legal preferences automatically, and formal requests deal with data already collected.

What This Means For You

The 2025-2026 fines show that opt-out rights are enforceable, but enforcement happens after the fact. Your best protection is to use the rights now rather than assume companies are handling them correctly. If a site ignores your GPC signal or hides its opt-out link, that is worth documenting and reporting.

Key Takeaways

  • Enable Global Privacy Control in your browser today so opt-outs are sent automatically.
  • Send a data-access request to services you use heavily to see what they hold, then request deletion for anything you do not need them to keep.
  • Keep copies of every request and response in case you need to file a complaint.
  • Do not treat a VPN as an opt-out tool; use it alongside formal requests, not instead of them.
  • Consider automating broker removals, and read our GDPR explainer for more on the rights behind them.

Use this GDPR CCPA opt-out rights guide as a checklist: turn on GPC, send your first request this week, and revisit the process every few months.