The gap between your privacy policy and your data practices is where regulators live

Enforcement actions rarely start with a bad privacy policy. They start with systems that drifted away from one. Annual audits catch that gap months late. Always-on risk management compares obligations, policies, and live configurations continuously, and flags contradictions as they appear.

JC
Jack CarvelHead of Legal & Data Protection Officer
Read time
7 min read
Last
Updated

Summarize this article with

Privacy enforcement actions often originate from gaps between what a company's privacy policy states and what its data workflows and systems actually reflect. Annual audits and point-in-time risk assessments miss these gaps because they capture single moments, while system configurations and vendor contracts keep changing. Always-on risk management closes the gap by continuously comparing regulatory obligations, documented policies, and live system configurations, flagging contradictions in real time and routing them for remediation.

Every major privacy enforcement action of the past three years has a similar origin story.

A company had a privacy policy. The policy said something clear and reasonable about how personal data would be handled: when it would be deleted, which vendors would receive it, and how consumers could opt out. The policy wasn't wrong; the systems just didn't match it.

That gap, between what a privacy policy commits to and what the technology stack actually does, is where regulators live. It's also the gap that a survey-based risk assessment, conducted annually and manually by a team armed only with spreadsheets, was never built to find.

Let's talk about that gap: what causes it, why it's getting wider, and what a modern privacy program does to close it continuously rather than discover it after the fact.

The gap is structural, not intentional

Nobody writes a privacy policy intending to misrepresent their practices. Gaps form because privacy policies and system configurations evolve on different timelines and are managed by different teams with different incentives.

A privacy policy is updated when a lawyer reviews it, typically at intervals. A system configuration changes when an engineer ships a feature, a vendor updates their integration, or a new tool gets added to the stack. The policy review cycle and the engineering deployment cycle have never been synchronized.

The result is drift. A policy commits to 12-month data retention, while a vendor's default setting is indefinite. A policy says consumer opt-out requests are processed within 15 days, but a new system added to the stack wasn't included in the data subject rights (DSR) workflow. A policy says no sensitive data is shared with advertising platforms, yet a session replay tool added six months ago captures form inputs that include health information and sends them to a third-party dashboard.

None of these gaps were created deliberately, but all of them are an enforcement risk.

What recent enforcement actions actually show

The California Privacy Protection Agency (CalPrivacy) issued a $632,000 enforcement action against Honda in 2024. The finding: excessive verification barriers and asymmetrical opt-out processes, where consumers could opt into data sharing with one click but faced multiple steps to opt out. Honda's privacy policy almost certainly didn't describe this asymmetry. The system created it.

The CNIL fined Orange €50 million for continuing to read cookies after users withdrew consent. The systems failed to enforce consent changes in real time, even though the policy said consent would be respected.

The California AG settled with Healthline Media for $1.55 million for sharing sensitive health-adjacent browsing data with advertisers. The data use violated purpose limitation commitments in the privacy policy: the systems were doing something the policy said they wouldn't.

The pattern is consistent. Regulators are not primarily finding bad policies. They're finding good policies that systems don't follow.

Company Regulator Fine Sector Root cause
Honda California Privacy Protection Agency $632,000 Automotive Excessive verification barriers and asymmetrical opt-out processes: consumers could opt in with one click but faced multiple steps to opt out
Orange CNIL (France) €50 million Telecommunications Continued reading cookies after users withdrew consent; systems failed to enforce consent changes in real time
Healthline Media California Attorney General $1.55 million Communications/media Shared sensitive health-adjacent browsing data with advertisers, violating purpose limitation commitments in the privacy policy

Why annual assessments don't catch drift

The conventional response to this problem is the annual privacy audit: a structured review of systems, policies, and vendor contracts designed to identify gaps and produce a remediation roadmap.

Annual audits are better than nothing, but they're not good enough, especially at the speed of business today.

An annual audit is a snapshot. It captures the state of the program on the day the audit was conducted. Six weeks later, a vendor updates their subprocessor list. Three months later, a new analytics tool gets added to the website. Four months later, a new state privacy law takes effect, requiring a configuration change your consent management platform hasn't made yet.

The audit report is sitting in a shared drive. Nobody has connected it to what happened in the engineering backlog last Tuesday.

Risk assessments have the same limitation, and carry an additional one. The traditional Data Protection Impact Assessment (DPIA) or Privacy Impact Assessment (PIA) begins with a blank template and depends on humans answering questions about systems they may not have full visibility into. The quality of the assessment is a direct function of the institutional knowledge of the people filling it out. When those people leave, the knowledge walks out with them.

One of the Ketch product team's most direct observations about this problem: "A lot of times in privacy we talk about risk assessments, which, let's be honest, they're adorable surveys." Adorable surveys that 30% of the time, nobody fills out completely.

The three questions a modern risk program answers continuously

A privacy risk program built to close the gap between policy and practice answers three questions, not once a year, but continuously:

What are we required to do?

This means monitoring regulations, enforcement actions, and regulatory guidance in real time, rather than reading a newsletter weekly. It means ingesting the regulatory environment as it changes and cross-referencing it against your current configurations and commitments.

What do we say we do?

This means maintaining a live, synthesized view of your privacy policies, vendor DPAs, subprocessor agreements, and internal data processing commitments, not a folder of PDFs that gets reviewed annually.

What are we actually doing?

This means connecting to your live systems, your consent management platform configurations, your DSR workflows, your data repositories, and your access controls, to know what they're doing with personal data right now rather than what they were doing when the last audit ran.

The gaps between those three answers are your risk inventory. The moment a gap appears, whether it's a new enforcement action that implicates your current configuration, a vendor contract missing a term required by a law that went into effect last month, or a system configuration that contradicts a policy commitment, a modern risk program surfaces it, prioritizes it, and routes it for remediation.

What "always-on" risk management looks like in practice

The Ketch Agent Network performs this reconciliation continuously. It ingests regulatory feeds, synthesizes policy documents, and connects to live system configurations, comparing all three simultaneously and flagging the daylight between them.

When a new settlement surfaces that relates to your current practices, it flags the issue with the specific regulatory citation and proposes remediation steps. When your DPA with a vendor is missing a required term, such as a required CCPA term, it surfaces the gap with a recommended fix and an assignable action item.

When a completed assessment contains a contradiction against your own data policies, such as indefinite retention documented in a vendor agreement against a 6-month policy commitment, it catches the contradiction before submission, not after.

Your team approves the fix, and Ketch executes it.

The shift this creates is significant. Instead of gathering context by reading contracts, running queries, and chasing system owners, the privacy team reviews prioritized, actionable findings with the regulatory citations already attached. The time spent on context drops while the time spent on decisions and execution goes up, which is a different job, and a more defensible one.

What to do before your next audit

Closing the policy-practice gap doesn't require a platform change on day one. It requires a clear-eyed view of where your current program leaves you exposed.

Start with these three questions:

  • If a regulator asked you today to prove your data practices match your privacy policy, how long would that take to pull together? If the answer is longer than a week, the gap is real.
  • When was the last time you reconciled your data map against what's actually running in your systems? If the answer is more than three months ago, the map is stale.
  • How do you currently know when a new state law or enforcement action affects your current configurations? If the answer involves a newsletter and a calendar reminder to review manually, the gap is growing faster than you're closing it.

These aren't hypothetical risks. They're the documented origin stories of enforcement actions that have cost companies $632,000 to $1.55 million in the U.S., and up to €50 million in the EU. The work of closing them is the work of a modern privacy program.

The Ketch Agent Network does that work continuously, not as an annual project, but as infrastructure.

FAQs

Next step

Confident AI innovation starts with permissioned data

Book a demo of AI Sentry and the Ketch Agent Network, the two products that make AI governance an operational program.

Get Started Free

Get started in less than 5 min