A consumer opts out on your website. Does your mobile app know? Does your email platform know?
For most organizations, the honest answer is: not reliably.
This is the consent fragmentation problem, and it has become one of the most pressing compliance challenges facing brands that operate across multiple digital channels. Regulators have made clear that honoring a consumer’s opt-out on a single device or a single channel is not enough. When a consumer says “no,” that preference must follow them everywhere your brand can reach them.
The gap between what regulators expect and what most tech stacks can actually deliver is wide. Up until this point, organizations have built channel specific opt-out workflows that do not pass opt-out signals between one another. The expectation is now one unified opt-out experience – propagated across all of your channels. Closing the gap requires rethinking how identity, consent, and preference management work together across your entire ecosystem.
The regulatory pressure is real, and growing
Today’s customer journey spans web, mobile app, email, and SMS, often within the same session. And the technology powering that journey has gotten remarkably good at following the consumer across all of it. Identity graphs stitch together email addresses, device IDs, advertising identifiers, and login credentials to build unified profiles that fuel cross-channel targeting, personalization, and monetization.
The regulatory evolution we are seeing in 2026 is a direct response to consent fragmentation challenges that are becoming impossible to ignore: companies built the infrastructure to recognize a consumer everywhere, but did not build the infrastructure to honor that consumer’s choices everywhere. Opt-in recognition operated systemwide. Opt-out recognition was built at the device or channel where the request was made, and remained siloed to that channel.
Regulators are now closing that gap with a simple principle. In its $2.75 million settlement with Disney for failing to honor consumers’ requests to opt-out across Disney accounts, California Attorney General Rob Bonta articulated it most clearly: “if a business can associate a consumer’s devices with the consumer for advertising purposes, it can and must associate those devices with the consumer for purposes of honoring the consumer’s opt-out rights.”
That expectation is becoming the standard across jurisdictions. If a company’s identity architecture can track a consumer across channels for advertising or engagement, regulators expect that same architecture to propagate and enforce the consumer’s opt-out.
At the same time, there is an equal push to make it easier for consumers to exercise those rights. Global Privacy Control (GPC), a browser-level signal that automatically tells every website a consumer visits to stop selling or sharing their personal information, is now legally required in eleven states. California’s Opt Me Out Act (AB 566), effective January 1, 2027, will require every browser to offer this functionality as a built-in setting. The result: opt-out signal volume is about to increase significantly, and businesses need infrastructure that can absorb and enforce those signals across every channel automatically.
The enforcement actions and regulatory developments below reflect this principle in practice.
The Disney / California AG settlement (February 2026)
The California Attorney General secured a $2.75 million CCPA penalty against Disney for failing to propagate consumer opt-out signals across devices and streaming services. Disney honored Global Privacy Control (GPC) signals only on the specific device that sent the signal, not across the logged-in user’s account ecosystem. The settlement also found that Disney’s TV apps lacked in-app opt-out mechanisms and that opt-out signals were not passed to advertising partners.
CNIL multi-device consent guidance (December 2025 / January 2026)
France’s data protection authority published recommendations establishing that consent given via a logged-in account may carry to other devices, but refusal or withdrawal must travel the same way. Users must be notified on each new device, and identifiers shared with vendors must be pseudonymized. CNIL has signaled it will begin work in 2026 on “multi-property” consent, enabling a single consent signal to apply across multiple websites or brands within the same corporate group.
Multi-State GPC enforcement sweep (September 2025)
The California Privacy Protection Agency, the Colorado AG, and the Connecticut AG jointly announced a coordinated investigative sweep targeting companies that fail to honor GPC-based opt-out requests. Businesses that appeared noncompliant received letters demanding immediate compliance. This was the first cross-state coordinated enforcement action focused on a specific privacy-technical issue, and it followed the formation of the Consortium of Privacy Regulators in April 2025.
Eleven states now have active universal opt-out mechanism requirements, including California, Colorado, Connecticut, Delaware, Montana, Nebraska, Texas, Oregon, New Jersey, Minnesota, and Maryland.
California’s Opt Me Out Act (AB 566)
Governor Newsom signed AB 566 in October 2025, making California the first state to require browsers to include built-in opt-out preference signal functionality. Under the existing CCPA, businesses are already required to honor those signals. The practical effect, when the law takes effect on January 1, 2027, is a dramatic increase in the volume of opt-out signals brands will receive from California users.
Why this is still so hard
This is not an easy problem to solve, with unique consent unification challenges for different enterprises. These problems make cross-channel opt-out compliance difficult to operationalize.
1. The propagation problem
Each consent tool is typically built with a 1:1 relationship to the consumer. Consent preferences surface via the tool, and remain tied to that user specific on the channel. The shift into propagating opt-outs across channels requires building out complicated technical workflows to unify these systems. If one of those systems cannot receive, store, share, or honor a preference signal, the workflow breaks.
Verification adds another layer of complexity. Some consumer preference requests require verification, some don’t. Businesses will need to provide an audit trail that the proper verification mechanisms were in place alongside the downstream signal propagation.
2. The identity problem
Consent should follow the person, not the device. The emerging standard, endorsed by both the California AG and France’s CNIL, is that the logged-in account should be the single source of truth for consent. When a consumer opts out while logged in, that preference should apply everywhere they interact with your brand.
But most organizations are not there yet. The boundary between authenticated and unauthenticated sessions creates a gap. If a user opts out while logged in and then visits your site logged out, the opt-out may not hold. The inverse is also true. If a consumer opts out during an unauthenticated session, but the organization has the means to tie that session to a known account, the preference should apply to that account. The principle works in both directions: wherever you can connect the dots between a session and an identity, the consumer’s choice should follow. Shared devices and multiple accounts per household add another layer of complexity.
And identity resolution for marketing often runs on a different graph than identity resolution for suppression. The identifiers that tie a person together for targeting purposes (email, hashed email, IP address, device ID, mobile advertising ID, cookies) need to be equally accessible for opt-out propagation. If your opt-out logic does not have full access to the same identity graph your marketing uses, there is a gap between who you can target and who you can suppress.
What to look for in your tech stack
Not every tool in your martech stack can participate in cross-channel preference propagation. Some consent management platforms can manage consent at the point of collection, but cannot propagate or enforce an opt-out downstream. The distinction matters.
When evaluating whether a vendor can actually participate in a unified preference management architecture, look for:
- API and webhook support for real-time preference signal ingestion and distribution
- Identity key acceptance, so the vendor can receive and act on a preference tied to a unified user identifier rather than a device-level cookie or session
- Audit trail capabilities that log when a signal was received, when it was applied, and what action was taken
- Cross-channel reach, so a single preference update can propagate across push, email, SMS, in-app, and web simultaneously
How Airship approaches cross-channel consent
The consent fragmentation problem persists because most organizations built their messaging infrastructure one channel at a time. The email platform came first. Then push notifications. Then SMS. Then a CMP for cookie consent on the web. Each system manages its own opt-in and opt-out logic independently. Each one has a different concept of who the user is.
The result is predictable: a consumer opts out of email marketing, but the SMS platform has no idea. A GPC signal fires on the website, but the mobile app cannot see it. A customer calls support and asks to stop receiving messages, and an agent logs the request in a CRM field that no downstream system reads.
Airship approaches this differently. Instead of trying to reconcile consent across disconnected systems after the fact, Airship treats the person as the unit of consent from the start.
One identity, one preference state. Every contact method a consumer uses, whether it is an email address, phone number, or app install, maps to a single Named User ID. That identifier is the anchor. It does not matter whether the consumer interacts with your brand through your mobile app on their phone, your website on their laptop, or an SMS reply from a different device. Airship recognizes them as the same person.
This is the architectural shift that matters. When identity lives at the account level rather than the device level, preference propagation stops being an integration challenge and becomes a default behavior. An opt-out registered on one channel is immediately reflected across every channel tied to that Named User, because they all read from the same source.
Granular control that keeps consumers engaged. Most legacy consent flows offer a binary choice: receive everything, or receive nothing. That forces consumers who are frustrated with one type of message to unsubscribe from all of them. It is a lose-lose outcome: the brand loses a reachable customer, and the consumer loses access to messages they actually wanted.
Airship’s Preference Centers let consumers make precise choices: which channels, which message categories, and how often. A customer who wants real-time order updates via push but only a weekly email digest of promotions can set exactly that. This “opt-down instead of opt-out” model preserves the relationship and generates zero-party data, explicit preferences the consumer chose to share, that is more accurate and more durable than anything inferred from tracking behavior.
Effectuation, not just collection. There is a meaningful difference between a platform that collects a consent signal and one that enforces it. A CMP that records a cookie preference on your website has done one job. But if that preference does not reach your email platform, your SMS gateway, and your push notification system, the consumer’s choice has not been honored.
When a preference updates anywhere in Airship, it is tracked at the Named User level per channel type. Your messaging strategy respects that choice across the consumer’s entire profile automatically. There is no batch sync overnight. No middleware to maintain. No manual reconciliation between systems.
Privacy controls built into the SDK. Airship’s SDK Privacy Manager gives teams feature-specific flags that control exactly what data is collected for each use case, from push notifications to analytics. You collect what you need for the experience you are delivering, nothing more. And customer data is never used to train AI models.
An audit trail that can answer a regulator’s question. After the Disney settlement, demonstrating compliance means more than having the right policies. It means showing the work: when a preference was received, how it propagated, and what changed as a result. Airship’s unified preference history per Named User provides that record in one place, rather than requiring your team to piece together logs from five separate systems.
The net effect is that the propagation problem, the identity problem, and the verification problem described earlier in this post are addressed by the same architectural decision: anchoring consent to the person, managing it in one place, and enforcing it everywhere simultaneously.
Building a program that scales
Technology is necessary but not sufficient. Cross-channel opt-out compliance also requires organizational alignment.
Scope and staff the problem. Inventory every channel, vendor, and identifier in your ecosystem. Decide whether identity resolution is in scope or out. Name one accountable owner. Cross-channel preference management typically requires seats at the table from privacy, product, engineering, and marketing.
Build the business case beyond fines. The investment case for unified preference management is not limited to regulatory risk. Better preference management means more relevant content, higher engagement, and fewer unsubscribes. When consumers control their preferences and trust how their data is used, they engage more. If your organization has measured the upside of personalization powered by zero-party data, the compliance investment is the same investment.
Prepare for what is coming. New consent surfaces are emerging: in-car interfaces, gaming consoles, wearables, retail media networks. Each one is a new channel that needs to accept and propagate preferences. And AI agents, both consumer-facing and company-side, will begin exercising and honoring privacy rights at scale on behalf of users. Platforms that can absorb these new surfaces into an existing unified preference architecture will be better positioned than those that need to build a new solution every time a new channel appears.
The bottom line
The regulatory trajectory is heading in one direction: more enforcement modeled on the Disney template, more coordinated multi-state action on GPC signals, and more guidance like CNIL’s that treats the logged-in account as the consent anchor. The brands that treat cross-channel opt-out compliance as a product and engineering priority, not just a legal checkbox, will be the ones best positioned to navigate what comes next.
Ready to see how Airship can help unify consent and preference management across your channels? Book a meeting with our team.



