Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Policy discloses that UnitedHealthcare does not honor web browser Do Not Track signals, citing the absence of a common definition and industry-accepted standards for such signals.
This analysis describes what UnitedHealthcare's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state privacy laws, including California's, require disclosure of Do Not Track response practices, which this provision satisfies as a disclosure obligation. The Global Privacy Control signal, which some states require platforms to honor as an opt-out of sale or sharing mechanism, is not addressed in this provision.
Interpretive note: The applicability of Global Privacy Control signal response requirements to UnitedHealthcare's Online Services under CPRA depends on whether the company meets CPRA coverage thresholds, which is not established by the document.
This clause discloses that UnitedHealthcare does not respond to browser Do Not Track signals, meaning browser-level privacy settings using this mechanism will not affect data collection on the Online Services. Users seeking to limit behavioral tracking may use the opt-out mechanisms described in the Policy, including adjusting browser cookie settings or using the advertising network opt-out links provided.
Cross-platform context
See how other platforms handle Do Not Track Non-Response Disclosure and similar clauses.
Compare across platforms →Monitoring
UnitedHealthcare has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Please note that we do not currently respond to web browser "Do Not Track" signals that provide a method to opt out of the collection of Information about online activities over time and across third-party websites or online services because, among other reasons, there is no common definition of such signals and no industry-accepted standards for how such signals should be interpreted.Excerpt from UnitedHealthcare's Privacy Policy
1. REGULATORY LANDSCAPE: California's Online Privacy Protection Act requires disclosure of Do Not Track response practices, which this provision satisfies. The California Consumer Privacy Act and California Privacy Rights Act establish requirements regarding the Global Privacy Control signal as a valid opt-out of sale or sharing mechanism; the Policy's silence on GPC response may require evaluation under current CCPA enforcement guidance from the California Privacy Protection Agency. 2. GOVERNANCE EXPOSURE: Medium. The non-response to Do Not Track signals is a standard disclosure in current industry practice. However, the absence of any reference to Global Privacy Control signal response, which the California Privacy Protection Agency has treated as a required opt-out mechanism for covered businesses under CPRA, creates a potential compliance gap for California users that is distinct from the Do Not Track disclosure addressed here. 3. JURISDICTION FLAGS: California's CPRA framework and CPPA enforcement guidance on GPC signals creates specific exposure for California-resident users. Colorado, Connecticut, and other state comprehensive privacy statutes may similarly require recognition of universal opt-out signals that are not addressed by the Do Not Track disclosure in this provision. 4. CONTRACT AND VENDOR IMPLICATIONS: Third-party analytics and advertising vendors operating on the platform should be assessed for their own GPC and Do Not Track signal handling practices, as the company's stated non-response to Do Not Track does not necessarily extend to or bind those vendors' independent data collection activities. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the company's Online Services are required to honor Global Privacy Control signals under CPRA for California residents, and if so, whether the current technical implementation and Policy disclosures address that requirement. The Do Not Track disclosure in this provision should be reviewed for adequacy under current multi-state privacy law requirements.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state privacy laws, including California's, require disclosure of Do Not Track response practices, which this provision satisfies as a disclosure obligation. The Global Privacy Control signal, which some states require platforms to honor …
This clause discloses that UnitedHealthcare does not respond to browser Do Not Track signals, meaning browser-level privacy settings using this mechanism will not affect data collection on the Online Services. Users seeking to limit behavioral tracking may use the opt-out mechanisms described in the Policy, including adjusting browser cookie settings or using the advertising network opt-out links provided.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by UnitedHealthcare.