Humans of Martech
Avsnitt

229: The Privacy lawsuits coming for every marketing team, with Cara Caruso and Dustin Taylor

Dela

What's up everyone, today we have the pleasure of sitting down with Cara Caruso, CEO and co-founder of Sentinel Insights, and Dustin Taylor, counsel at Troutman Pepper Locke.

We'll cover:

  • (00:00) - Cara-audio
  • (00:53) - In This Episode
  • (04:40) - 1 — Why Your Website Is Running More Tracking Tools Than You Know
  • (08:17) - 2 — How a Plaintiff's Firm Turns Your Website Into a Lawsuit
  • (17:55) - 3 — The ECPA Wave and the Privacy Policy That Sues You
  • (20:53) - 4 — What Consent Drift Actually Looks Like
  • (25:16) - 5 — Who Actually Owns Privacy Compliance
  • (30:49) - 6 — The Business Case for Privacy-First Marketing
  • (35:52) - 7 — What Marketing Ops Can Do About Privacy This Week
  • (42:35) - 8 — Why Email Marketing Is the Next Privacy Lawsuit
  • (48:04) - 9 — AI, Consent, and Being Forced to Delete Your Data
  • (51:46) - 10 — Why Small Companies Get Privacy Lawsuits Too
  • (58:42) - 11 — How to Decide What Deserves Your Energy


Summary: A privacy-software CEO and a litigation defense attorney walk into a podcast and proceed to scare every marketer in the room, in the most useful way possible. Cara Caruso has scanned over 10,000 websites and found nearly 90% of them non-compliant, while Dustin Taylor has defended more than 100 companies against the exact lawsuits that follow. Together they trace how a forgotten tag from three years ago becomes a seven-figure settlement, why your own privacy policy is the document most likely to sue you, and how one month of a broken cookie banner turns into 10,000 dollars per visitor. Then they flip the whole thing and make the case for why clean, consented data actually performs better. Stick around for the part where your email open rates might be illegal and the FTC makes companies delete four years of data.

About Cara Caruso and Dustin Taylor

Cara Caruso is the CEO and co-founder of Sentinel Insights, where she leads a platform that monitors websites in real time for consent violations and privacy exposure. Before starting the company she spent more than 25 years in data and martech, building and scaling teams across technology and financial services in both B2B and B2C. She pairs strategic planning with hands-on execution, and she's also a certified yoga instructor who has been known to bring a workshop into the office.

Dustin Taylor is counsel at Troutman Pepper Locke, where he defends companies at the intersection of privacy law and marketing technology. He's defended more than 100 companies in ad-tech privacy cases involving cookies, pixels, session replay, and website chat, secured dismissals at the pleading stage in federal court, and argued in California, New York, Florida, Texas, and New Jersey. He started out with an advertising degree before law school, which makes him fluent in the martech stack in a way most litigators never are. He also publishes monthly privacy litigation reports and tracks ECPA filings with AI.

Why Your Website Is Running More Tracking Tools Than You Know

Most marketing teams believe they have a clean inventory of what runs on their website. There's a tag manager, a cookie banner, a vendor list in a spreadsheet somewhere, and a general sense that someone signed off on all of it. Then someone actually scans the site, and the number comes back two, three, sometimes four times higher than anyone expected.

Cara has watched this play out thousands of times. Sentinel Insights has scanned over 10,000 websites in the past year, and the pattern barely changes from one company to the next. Nearly 90% of those sites are not compliant. Every new customer gets the same uncomfortable conversation on day one.

The gap between what a team thinks is running and what's actually firing comes from two places. The first is history. Somebody three years ago added a tag for a campaign that ended, then left the company, and nobody ever took it down. The team you have today inherited a stack built by people they never met, and most of those decisions were never written down anywhere. Cara calls it the ghost of marketers past, and it's sitting on almost every site she scans.

The second is piggybacking. You buy one tool, drop in one script, and that single tag quietly loads four more. Each of those can load more on top. An agency hard-codes a pixel straight into a landing page because they didn't have access to the tag manager, and now your customer data flows to companies nobody on your team could name. None of it shows up in the tidy spreadsheet. All of it shows up in a scan.

This is the part most marketers underestimate. The real exposure comes from the tools nobody chose on purpose, the dozen scripts running quietly in the background, each one sending customer data somewhere you've never audited. They pile up while everyone assumes the banner has it covered. No marketing team actually knows what's on its website until a scan proves otherwise, and "we reviewed it last year" is closer to a guess than a control.

Why Not Knowing Is Not a Legal Defense

The instinct, once you find those orphaned tags, is to assume they don't count against you. You didn't install them. You didn't even know they were there. Dustin spends a lot of his time correcting that assumption. These privacy laws do have a knowledge component, but courts read knowledge very differently than a normal person would. As long as the person who installed the tag three years ago knew they were installing something, the legal requirement is met. The fact that today's marketing team forgot it existed changes nothing.

There's a second trap hiding inside the same problem. What marketing knew, what IT knew, and what legal knew are rarely the same thing, and that fragmentation is its own risk. Each group assumes another group is watching the stack. The court doesn't care which department dropped the ball. It only cares that someone, at some point, hit install.

Key takeaway: Run a full scan of your live website this month and compare the results against your documented vendor list. Flag every tag you can't immediately explain, especially anything loading third-party scripts you never installed directly. The tools you can't account for are the ones quietly building your legal exposure, and forgetting they exist won't protect you.

How a Plaintiff's Firm Turns Your Website Into a Lawsuit

Here's the mental model most marketing teams carry around: we're compliant until someone complains. You picture a single annoyed customer who takes the time to file something against your little startup, and you quietly decide the odds are low. Who's really going to sue over one text message or one tracking cookie? That assumption is the most expensive thing on your website, because litigation in this space doesn't start with a complaint. It starts with a scan of your site that you never see.

Plaintiffs' law firms run continuous automated audits of company websites, and they're looking for far more than a typo in your privacy policy. Dustin walked through exactly what their scanners check:

What loads automatically the moment someone lands on the page, before any consent is given, Whether there's a banner at all, and what it actually does, What keeps firing after a visitor opts out, Whether anything is miscategorized, like a marketing cookie quietly labeled "essential" so it can't be turned off

Once a firm finds the exposure, they find a plaintiff. The demand letter arrives, and the dollar amounts climb fast. Cara breaks the pressure into three forces bearing down on marketing teams at once:

Trophy-hunting plaintiff attorneys who come after you for small amounts individually, then scale it into a class action, Brand and reputational damage that lingers long after a settlement clears, State enforcement at the atto...

Podden och tillhörande omslagsbild på den här sidan tillhör Phil Gamache. Innehållet i podden är skapat av Phil Gamache och inte av, eller tillsammans med, Poddtoppen.