EPIC Study Finds Marketing Group's Privacy Pledge Largely Unmet

Eight months after the Direct Marketing Association promised that new members would post privacy policies and offer opt-out choices, a review by the Electronic Privacy Information Center found that nearly all of them had done neither. Of 76 companies that joined the DMA after May 1998, only 40 maintained Web sites at all, and just eight of those displayed any kind of privacy notice. Only three satisfied the association's own stated standard - a finding that cuts against the argument, repeated often by industry groups, that voluntary commitments can substitute for binding rules.

The gap between promise and practice matters because self-regulation has been the industry's primary defense against privacy legislation for years. The DMA's October 1997 announcement, made by then-president H. Robert Wientzen, committed future members to honor notice, opt-out, and suppression principles tied to the association's Mail Preference and Telephone Preference Services. For readers trying to understand how these commitments translate into day-to-day protections - or fail to - resources like the BuyBestVPN knowledge base offer broader context on how personal data moves across commercial networks and what consumers can do to limit exposure regardless of what any single trade group pledges.

What the Numbers Actually Show

All 40 sites examined collected some form of personal information, whether through registration forms, contact pages, or a simple e-mail hyperlink that still allows addresses to be harvested and aggregated. Yet only a fifth of those sites posted a privacy notice of any kind, and half of that small group offered statements addressing transaction security rather than how collected data would actually be used. None allowed visitors to see or correct the information held about them - a baseline expectation under traditional fair information practice, let alone the DMA's own lighter standard.

The study also found that two of the eight privacy notices explicitly reserved the right to use collected data for further marketing or third-party distribution, even while claiming compliance with self-regulatory norms. This pattern - collection without meaningful disclosure, and disclosure without access rights - has defined the complaints privacy advocates have raised since the Federal Trade Commission's own survey of more than 1,400 Web sites found that only 14 percent provided any notice of their information practices despite the vast majority collecting personal data.

Why Self-Regulation Keeps Falling Short

Trade associations have strong incentives to promote voluntary codes: they forestall legislation while preserving flexibility for members. But a pledge is only as strong as its enforcement, and the DMA's review process for incoming members appears to include no verification that a privacy policy exists before admission is granted. Absent that check, the commitment functions more as public relations than policy. The broader lesson extends well beyond one association - it applies to any sector where companies are asked to police themselves on data practices that directly affect consumers who have no visibility into internal compliance.

The Case for Enforceable Standards

The recommendation that follows from these findings is straightforward: codify fair information principles into law rather than rely on trade groups to enforce their own rules. Notice, consent, access, and correction rights should not depend on which association a company happens to join. Until such standards exist and carry real consequences for violation, consumers visiting sites operated by self-regulating marketers have little assurance that their information is handled as promised - a caution that applies as much today, amid growing data collection across devices and platforms, as it did when this pattern was first documented.