← Latest papers
💻 computer science

Remarks on the Relevance of Privacy Expectations for Default Opt-out Settings

The paper argues that universal opt-out mechanisms should be permitted as default settings on pre-installed privacy-protective software because their use inherently reflects consumers' reasonable privacy expectations and constitutes a valid affirmative choice, thereby resolving conflicts between state privacy laws and FTC prohibitions on deceptive practices.

Original authors: Sebastian Zimmeck

Published 2026-03-18
📖 5 min read🧠 Deep dive

Original authors: Sebastian Zimmeck

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The "Privacy Switch" Problem

Imagine you buy a new car. You want it to be safe, so you buy a model advertised as having "State-of-the-Art Safety Features." You expect the airbags to be ready to go the moment you turn the key. You don't expect to have to crawl under the dashboard, find a tiny switch, and manually flip it to "ON" just to get the safety you paid for.

This paper is about a similar situation in the digital world.

We are talking about Universal Opt-Out Mechanisms (UOOMs). Think of these as a giant "Do Not Sell My Data" switch. When this switch is flipped, websites and advertisers are legally told: "Stop tracking me and stop selling my personal information."

The Conflict: The "Pre-installed" Rule

Currently, many US states (like Colorado) have passed laws saying:

"If a piece of software comes pre-installed on a device (like the Safari browser on an iPhone), the manufacturer cannot flip the 'Do Not Sell' switch to 'ON' by default. The user must find the setting and flip it themselves."

The logic behind this rule is that a "default" setting isn't a real choice. If the switch is already on, the company made the choice for you, not the user.

The Problem:
This rule creates a weird situation.

  • If you download a privacy browser yourself, the company can turn the switch on for you.
  • If you buy a phone with that same browser already on it, the company cannot turn the switch on for you, even if they promised in their ads that the phone is super private.

The author, Sebastian Zimmeck, argues this is unfair and confusing.

The Core Argument: Expectations vs. Buttons

The paper argues that we need to stop looking at how software is installed (pre-installed vs. downloaded) and start looking at what the consumer expects.

The Apple Analogy

Imagine Apple markets its products with the slogan: "Privacy. That's Apple."
They tell you, "We protect your data. We don't track you."

If you buy an iPhone because you trust this promise, you have a reasonable expectation that your data is safe.

  • The Author's View: If Apple tells you "We protect your privacy," and then they make you manually flip a switch to actually start protecting your privacy, they are being deceptive. It's like a car company saying, "This car has the best brakes," but then making you manually install the brake pads before you can drive.
  • The Legal Risk: If Apple forces you to flip the switch, they might be breaking federal laws against "deceptive practices." They are promising privacy but hiding the mechanism to get it.

The "Choice" Redefinition

The law says a "choice" must be "affirmative and unambiguous." Usually, we think this means clicking a button.

  • The Paper's Twist: The author says choosing the product IS the choice.
    • If you buy a "Privacy-First" browser, your choice to buy it is your signal that you want privacy.
    • Turning on the "Do Not Sell" switch by default isn't a "default setting" in this case; it's the inherent nature of the product you bought.
    • It's like buying a "No-Noise" apartment. You don't expect to have to sign a form to get silence; the silence is part of the deal.

Why the Old Rules Don't Work (The "Do Not Track" Lesson)

The paper looks back at a failed attempt called "Do Not Track" (DNT) from 10 years ago.

  • What happened: Microsoft turned on "Do Not Track" by default in their browser.
  • The Reaction: Ad companies got angry. They said, "You can't decide for us! The user must click the button!"
  • The Result: Because the ad industry refused to listen to the "default" signal, the whole system failed. Nobody got protected.

The Lesson: We learned that self-regulation (letting companies decide what to do) doesn't work. We need laws that force companies to respect privacy. But the current laws are so strict about "defaults" that they actually hurt the companies trying to be private.

The Solution: Let Privacy-Protective Companies Compete

The author suggests a new way to look at the rules:

  1. If a company promises privacy: They should be allowed to turn the "Do Not Sell" switch ON by default. This matches what the customer expects. It stops them from being "deceptive."
  2. If a company relies on selling data: They should NOT be allowed to turn the switch on by default. If they do, it would be a shock to the user and a violation of expectations.

The Takeaway

The paper concludes that we need to stop worrying about whether software was "pre-installed" or "downloaded." Instead, we should ask: "What did the consumer reasonably expect?"

If you pay a premium for a product because it promises to be private, you should get that privacy automatically. Making you jump through hoops to get the privacy you were promised is bad for consumers, bad for competition, and potentially illegal.

In short: If you buy a "Privacy Shield," it should be on by default. If you have to go find the switch to turn it on, the shield wasn't really there to begin with.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →