What happens if you don't give consent?
What happens if you don't give consent? Learn how opt-in and opt-out laws like GDPR and CCPA treat your data — and why most opt-outs get ignored.

What happens if you don't give consent?
Key Facts
- 76 of the top 100 US websites ignore CPRA opt-out signals, industry research finds
- 30% of tested retailers still served retargeted ads after explicit opt-out requests, a Wesleyan/Consumer Reports study found
- GDPR violations cost up to €20 million or 4% of global turnover, per Osano's privacy guide
- The EU issued €2.1 billion in GDPR fines in 2024 alone, pushing cumulative penalties past €4 billion
- 48% of consumers have stopped buying from a company over privacy concerns, consumer research shows
- 144 countries now hold data protection laws covering 79% of the global population, according to privacy statistics
- A CCPA-style opt-out model becomes a GDPR violation the moment it touches an EU resident, consent analysts warn
What 'No Consent' Actually Means Depends on Where You Are
Silence is not neutral. Whether "no answer" means "no data" or "collect everything anyway" depends entirely on which consent model governs your jurisdiction — and most people have no idea which one applies to them.
Under opt-in regimes like the EU's GDPR, the default is no. Nothing gets collected until you affirmatively say yes — no cookies, no marketing emails, no tracking. Under opt-out regimes like California's CCPA/CPRA, data is shared by default and the burden falls on you to withdraw it, as consent researchers explain. Silence means the opposite thing depending on where you live.
The landscape is more layered than a simple binary. Virginia's VCDPA takes a hybrid approach: most data can be collected without permission, but sensitive information requires opt-in, according to privacy compliance analysis. Brazil defaults to opt-in, Canada's PIPEDA allows either depending on context, and Australia permits implied consent in some situations. With 144 countries now holding data protection laws covering 79% of the global population, the same click can mean three different things in three places.
Here is what each model means for you when you say nothing:
- Opt-in (GDPR-style): No data collected, no marketing contact, no non-essential cookies until you actively agree.
- Opt-out (CCPA-style): Your data is collected and shared by default; you must act to stop it.
- Hybrid (Virginia-style): General data collected by default, but sensitive data like health or financial details requires explicit opt-in.
The opt-out model has a serious catch: your withdrawal is frequently ignored. According to industry research, 76 of the top 100 US websites do not honor CPRA opt-out signals, and 75% share user data with third parties even after users opt out. A Wesleyan/Consumer Reports study found 30% of tested retailers still served retargeted ads despite receiving explicit opt-out requests.
This is why, when evaluating a growth partner, you should ask which consent model their funnel follows — on both the inbound and outbound sides. A provider whose booking process requires an explicit "I agree to be contacted" checkbox, the way Worqd's does, is operating opt-in by design regardless of jurisdiction. That distinction matters: as consent strategy analysis warns, a model built for CCPA's opt-out floor becomes a GDPR violation the moment it touches an EU resident.
Knowing which model governs your data tells you exactly what your silence — or your "no" — actually accomplishes.
The Uncomfortable Truth: Most Opt-Outs Get Ignored
Saying "no" should end the conversation. In practice, it often doesn't — and the data on how frequently opt-out requests get ignored should change how you vet any growth or lead-gen partner.
According to research on the top 100 US websites, 76 of them do not honor CPRA opt-out signals, and 75% share user data with third parties even after users explicitly opt out. The problem isn't confined to obscure corners of the web, either — media and ecommerce sites are the biggest offenders, both at 79% noncompliant.
Academic testing tells the same story. A Wesleyan and Consumer Reports study found that 12 of 40 tested retailers — 30% — appeared to serve retargeted ads despite receiving Global Privacy Control opt-out requests. As Consumer Reports policy analyst Matt Schwartz put it, without strong enforcement, companies can "simply ignore these laws with impunity."
Why this matters when you're choosing a provider: a partner's privacy policy is a piece of paper. What counts is whether their systems — ad integrations, retargeting pixels, follow-up sequences — actually respect a "no" once it's given. If they don't, the legal and reputational exposure lands on you, not just on them.
Before signing with any growth or lead-gen provider, ask specific questions:
- Do your systems detect and honor opt-out signals like Global Privacy Control automatically?
- What happens to a lead's data after they opt out — is it actually purged from ad audiences and outreach lists?
- Do you capture explicit consent on inbound forms (e.g., an "I agree to be contacted" checkbox) rather than relying on silence?
- How do you keep sensitive form fields out of ad targeting and public analytics?
The stakes are not theoretical. Privacy mishandling now carries real financial consequences — Amazon was fined $888 million in Europe for targeting users without proper consent, and at least 10 US companies have been fined since 2022 for privacy noncompliance, per the same industry analysis. California, Colorado, and Connecticut have even launched joint investigations into businesses that ignored GPC signals.
There's a trust dividend on the other side, too: consumer research shows 48% of people have stopped buying from a company over privacy concerns, while 83% are more inclined to shop with sites that are transparent about privacy. At Worqd, that's why our outreach is built to be permission-aware and personalized rather than a template blast — respecting consent is both the compliant choice and the higher-converting one.
When you evaluate a provider, treat their answer on opt-outs as seriously as their answer on lead volume. A "no" that gets ignored is worse than no consent system at all — it's a liability quietly compounding inside your funnel.
What Ignoring Consent Costs the Companies You Hire
When you hire a growth partner to generate and follow up with leads, their compliance failures don't stay theirs. Regulators and plaintiffs' attorneys increasingly treat consent violations as a shared liability — and the fines are climbing fast.
Under GDPR, mishandling consent can cost up to €20 million or 4% of global annual turnover, whichever is higher, according to Osano's marketing data privacy guide. In California, the CCPA imposes $7,500 per intentional violation — a number that multiplies quickly when each affected consumer counts separately.
These aren't theoretical caps. The EU issued €2.1 billion in GDPR fines in 2024 alone, pushing cumulative penalties past €4 billion since 2018. Amazon's $888 million fine for targeting users without proper consent shows regulators will pursue even the largest players, as Marketing Dive reports.
The exposure now extends well beyond regulators. Private litigation has become a second front:
- Session-replay class actions surged after Javier v. Assurance IQ and Popa v. Harriet Carter Gifts, with claims upheld against Nike, Lululemon, and Prudential, per an IAPP analysis by privacy attorneys.
- The FCC has tightened TCPA consent requirements for lead generators, plus a texting Do-Not-Call mechanism — meaning your partner must document valid consent for every lead they text on your behalf.
- California, Colorado, and Connecticut have jointly investigated businesses that ignore opt-out signals like Global Privacy Control.
Here's the uncomfortable part: noncompliance is the norm, not the exception. Research cited by Marketing Dive found 76 of the top 100 US websites ignore CPRA opt-out signals, and 75% share data with third parties even after users opt out. A Wesleyan and Consumer Reports study caught 30% of tested retailers serving retargeted ads to people who had explicitly opted out.
That creates a direct risk transfer problem. As Privado.ai's CEO warns, "even if a marketing team doesn't plan to use their audience data for retargeting, just sharing the data without proper consent puts the advertiser at risk." If your provider's tracking pixels, follow-up sequences, or lead lists mishandle consent, your brand name is on the complaint — and on the headline.
The reputational math is just as stark. Usercentrics' data privacy statistics show 48% of consumers have stopped buying from a company over privacy concerns, while 83% are more inclined to shop with sites that are transparent about their practices.
This is why consent handling belongs on your provider checklist before you sign anything. Worqd builds explicit consent into its own booking funnel — a plain "I agree to be contacted about my request" — and keeps sensitive form fields out of public analytics, because permission-aware outreach is the opposite of a template blast. Ask any partner you're vetting to show you the same discipline in writing.
Consent Done Right Is a Conversion Advantage, Not Just a Legal Checkbox
Most companies still treat consent as a compliance hurdle — a checkbox to tick before the real work begins. But the data tells a different story: the people who raise their hand and share their information are signaling genuine interest, and that intent translates directly into performance.
Osano notes that opt-in audiences convert at higher rates because they actually want to hear from you. Meanwhile, consumer research shows that 48% of people have stopped buying from a company over privacy concerns, while 83% are more inclined to shop with sites that are transparent about data practices. Trust isn't abstract — 60% say they'll spend more with brands they trust to handle data responsibly.
The contrast is stark. Three-quarters of the most-visited U.S. and European websites fail to honor opt-out signals, and 75% share data with third parties even after users say no. That gap between stated policy and actual behavior is exactly where prospects lose confidence — and where providers who respect consent stand out.
- Explicit, opt-in consent creates a smaller but far more engaged audience
- Permission-aware outreach beats template blasts because relevance earns replies
- Honoring opt-outs fully — including universal signals like Global Privacy Control — protects both compliance and conversion
- Keeping sensitive data out of ad targeting and analytics reduces risk without sacrificing performance
This is why Worqd builds consent into every touchpoint — from the booking funnel that requires an explicit "I agree to be contacted" confirmation to AI SDR outreach that's personalized, permission-aware, and the opposite of a template blast. When follow-up respects the prospect's choice, it doesn't just avoid fines. It converts.
Five Questions to Ask Any Provider Before You Sign
Most providers will say "yes, we're compliant" when you ask. The real test is whether they can show you exactly how consent is captured, tracked, and honored — before you sign anything.
With 75% of top websites noncompliant with CPRA and GDPR, you can't afford to take that answer on faith. Here are five questions that separate providers who treat consent as a legal checkbox from those who treat it as a practice.
1. Do they capture explicit opt-in consent on inbound forms? GDPR requires "express, affirmative, specific, informed and voluntary opt-in consent" — pre-ticked boxes and silence don't count, per consent experts. Look for an unchecked "I agree to be contacted" box and a plain statement of how the data will be used. Worqd's own booking funnel works this way: explicit agreement, with details used only to prepare for the call.
2. How do they document consent for outbound outreach? The FCC has tightened TCPA consent requirements for lead generators, so your partner must trace valid consent back to each individual lead. If they can't show where a contact came from and what that person agreed to, that lead is a liability — not an asset.
3. Do they honor opt-outs fully, including the 12-month rule? California requires businesses to honor opt-outs for at least 12 months before asking users to opt back in, and opt-out confirmation becomes mandatory in 2026. Yet a Wesleyan/Consumer Reports study found 30% of tested retailers still served retargeted ads after receiving opt-out requests. Ask how opt-out signals are processed — and how quickly.
4. Is sensitive data kept out of ad targeting and analytics? Many companies now treat sensitive data as "off limits" for advertising, given CCPA, Colorado, and Washington requirements, according to IAPP legal analysts. A compliant provider keeps sensitive form fields — health, financial, biometric — out of public analytics and ad platforms entirely.
5. Can they show consent tracked per lead? The strongest sign of a compliant partner is visibility:
- Per-lead consent records with timestamps and source
- Documented opt-out handling across every channel
- Clear answers about what data flows to which tools
Consent quality isn't just risk management. Research shows 48% of consumers have stopped buying over privacy concerns, while 83% are more inclined to buy from transparent brands. A growth partner who respects consent protects your pipeline — and your reputation.
Frequently Asked Questions
What actually happens to my data if I don't give consent?
Is staying silent the same as saying no?
If I opt out, will companies actually stop using my data?
Can companies get fined for ignoring my refusal to consent?
What should I ask a growth or lead-gen provider about consent before hiring them?
Does requiring consent hurt lead generation results?
The Bottom Line: A 'No' Only Works If Someone Honors It
What happens when you don't give consent? It depends on where you live — under opt-in laws like GDPR, silence means no; under opt-out laws like CCPA, silence means yes until you say otherwise. But the bigger lesson is that a 'no' is only as strong as the systems behind it. With 76 of the top 100 US websites ignoring opt-out signals and fines climbing into the hundreds of millions, a provider's consent practices are now a business risk you inherit the moment you hire them. The good news: consent done right isn't just safer — it converts better, because people who raise their hand actually want to hear from you. So before you sign with any growth partner, ask the five questions: how consent is captured, how it's documented per lead, how opt-outs are honored, and where sensitive data goes. If you'd rather skip the vetting, Worqd builds explicit opt-in consent and permission-aware follow-up into every funnel we run — book a free growth call and see how it works.
Want help putting this into action?
Book a Growth Call