In 2026, Disney was required to pay a fine of $2.75 million under California's Consumer Privacy Act after regulators found that users who opted out of data sharing were still being tracked on devices and platforms. The issue wasn’t that Disney did not have any privacy control; it was that these controls didn’t work consistently across its ecosystem.
Privacy regulation is not a new concept for organizations that deal with data. Frameworks such as the CCPA and the GDPR in Europe have framed data handling, including how personal data is collected, used and protected, for years. That said, these laws continue to evolve as more states and countries implement privacy laws and introduce legislation to account for large-scale cloud adoption and the introduction of AI.
Despite these shifts, many organizations still approach privacy as a routine compliance or risk-management exercise, revisiting it only when a new law comes into force or a regulatory inquiry arrives. This old approach no longer works. Today, privacy has evolved into a critical enabler of scalable growth, responsible AI adoption and lasting customer trust.
What’s holding privacy programs back
Recent enforcement actions show privacy gaps are increasingly tied to complex digital ecosystems. Disney’s recent fine of $2.75 million, for instance, exposed how cross-platform systems struggled to consistently apply user privacy choices.
AI has widened the gap further, with over 83% of organizations already using AI, but only about 25% saying they have strong governance in place, leaving privacy controls struggling to keep pace with automated decision-making and model training risks.
There are now 20 states with privacy laws compared to 2018, when there was only one. Privacy teams just can’t keep up with the rules changing so fast.
Why privacy programs fail
Privacy processes remain heavily manual
Too many hand-offs, reviews and follow-ups slow everything down.
Data subject requests continue to grow
Rising volume and complexity strain already stretched teams.
Spreadsheets and disconnected tools create inefficiencies
Silos, rework and duplicate effort lead to delays and errors.
Privacy platforms are not fully embedded into workflows
Work happens outside the flow of workflows.
Costs rise and audit risk increases as regulations tighten
Greater exposure, higher spend and tougher scrutiny.
Fragmented processes, disconnected tools, and manual workarounds create delays, increase costs, and elevate risk.
Why privacy needs a reset
The root issue is not a lack of effort or intent, but an outdated operating model. Privacy programs were designed for a slower, more predictable data environment. Today, organizations must manage data across cloud platforms, AI systems and increasingly complex ecosystems, creating demands that traditional approaches were never built to handle.
As a result, leading organizations are rethinking privacy as a continuous business capability, embedding it into how data is managed, shared and governed.
The new privacy operating model
Manage privacy as an ongoing business capability, not a compliance checkbox
Make privacy a continuous priority that drives trust & business value.
Automate data rights and consent processes to reduce risk and human error
Use automation and intelligence to ensure accuracy, speed and consistency
Embed privacy into technology and operational workflows from the start
Design privacy into systems and processes, so it's built-in, not bolted-on
Provide visibility into how consent, opt-outs and data sharing function in practice
Monitor & report with real-time insights to demonstrate compliance and build trust
Build scalable privacy frameworks that evolve with cloud and AI adoption
Stay ahead of change with flexible frameworks that scale with innovation and regulation
A modern privacy operating model drives trust, reduces risk, and empowers responsible growth in a data-driven world.
The global signal of privacy and AI is converging
In the U.S., proposed federal legislation such as the SECURE Data Act reflects ongoing efforts to simplify privacy regulation. However, it also introduces new requirements and trade offs rather than fully replacing state laws, signaling that regulatory complexity will persist.
Also, recent amendments to the AI Act in the EU clarify how AI obligations overlap with existing product safety and data governance rules, reinforcing that AI and privacy can no longer be treated as separate compliance exercises.
These changes mean that intelligence and privacy rules must work together and be able to adapt as things happen. Companies that make privacy a normal part of how they operate, rather than just doing the minimum to follow each law, will be better able to adapt AI and rules change. Intelligence and privacy rules are connected and companies need to think about these together to be prepared for the future.
Making privacy work at scale with EXL
As privacy and AI regulations continue to evolve across regions, organizations can no longer rely on static, law by law compliance approaches. What’s needed is a privacy program built to adapt, one that works in practice, not just on paper.
Many industries share a common challenge, fragmented tools, manual processes and controls that don’t scale effectively across ecosystems. Drawing on 15+ years of privacy and GRC advisory experience and over a million hours of GRC delivery, EXL has been helping organizations embed privacy into their operating models rather than treating it as a standalone function.

This approach reflects EXL’s ability to integrate consent, data rights and governance across cloud, data and AI workflows while enabling broader personalization strategies for lasting customer trust.
Building on this, EXL is working with organizations to assess their current privacy maturity, uncover gaps across consent and data workflows and define a clear path to operationalize privacy at scale. It’s a focused assessment that moves beyond surface-level compliance to enable trust and real business value.