Join our Newsletter — 33% off our NHI Course

What are the signs that a company is not being transparent enough about customer data?

The clearest warning signs are declining willingness to share data, weaker engagement with personalization, and customer hesitation around consent requests or preference settings. If people do not understand what is being collected or why, trust erodes quickly. Organisations should also watch for complaints, opt-outs, and brand skepticism, since those often indicate that disclosure is not clear, timely, or credible enough.

What a transparency problem looks like in customer behaviour

When transparency is weak, customers usually do not file a formal complaint first. They change behaviour. The clearest signs are lower willingness to share data, less engagement with personalization, more hesitation when consent choices appear, and a growing tendency to decline optional collection. Those shifts often show up before any public criticism does.

A second pattern is inconsistency. Customers may continue using a service but stop completing profile fields, ignore preference centres, or become selective about what they disclose. That is often a sign that the explanation for collection, retention, or sharing has not been clear enough to earn informed consent.

The signal is strongest when trust and action diverge. If people say they value the service but still avoid data-sharing prompts, the issue is usually not the existence of collection itself, it is the quality of disclosure, timing, and credibility around why the data is needed.

Transparency gaps also surface through support and product signals. Repeated questions about what is collected, why it is collected, who sees it, or how long it is kept indicate that the privacy message is not landing. Complaints about “too much asking” or “unclear settings” usually mean the organisation has made the user work too hard to understand the data flow.

Opt-outs are another useful indicator, but they need context. A single opt-out is normal; a pattern of rapid opt-outs after onboarding, consent refreshes, or policy updates suggests the disclosure is not credible enough to support ongoing trust. Brand skepticism, negative reviews, and avoidance of preference tools all point in the same direction: the organisation may be technically compliant but still failing the transparency test in practice.

For a broader governance view, privacy transparency is not just a communications issue. It is closely tied to data minimisation, notice quality, and the credibility of the customer experience. Poor transparency tends to show up when policies are accurate on paper but hard to understand at the moment the customer has to decide.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-02 — Cybersecurity Risk Strategy Transparency failures create trust and privacy risk that belongs in governance and risk strategy.
PR.DS-01 — Data-at-Rest Protection Customer data transparency is tied to how data is collected, retained, and handled across its lifecycle.
GV.PO-01 — Policy Clear privacy disclosure depends on policies that are communicated and consistently applied.
Recommendation — Use governance reviews to assess whether customer disclosure gaps are creating material trust risk. Define handling rules that make customer-data collection and retention understandable and bounded. Publish and maintain customer-facing data policies that reflect actual collection and sharing practices.
NIST SP 800-63 IAL/Authentication Assurance — Digital Identity and Authenticator Assurance Consent and preference changes depend on trustworthy account interactions and user comprehension of access decisions.
AAL/Phishing-Resistant Authentication — Authentication Assurance Level Clear, trustworthy account controls support confidence in privacy-related actions and account settings.
FAL/Federation Assurance — Federation Assurance Level Third-party sharing and delegated access increase the need for understandable disclosure about who receives data.
Recommendation — Ensure customer-facing identity flows make consent and preference actions clear and attributable. Use strong authentication for settings that change customer-data permissions or sharing. Make federated and third-party data-sharing paths visible in customer disclosure and consent flows.
NIST AI RMF GOVERN 1.1 — Map AI system context and risks If customer data is used in AI-driven personalization, transparency must cover the data use context and related risk.
MEASURE 1.1 — Map and Measure AI Risks Customer hesitation can signal that data-use risk or explainability gaps are not being measured well.
MANAGE 2.1 — Allocate Risk Resources Transparency issues become material when organisations fail to invest in clearer notices and consent design.
Recommendation — Document how customer data is used in personalization and what customers should understand about that use. Measure customer-facing friction and trust signals to identify where disclosure is failing. Allocate remediation effort to the customer journeys where disclosure is most likely to fail.

Practitioner Guidance

What to verify: Review the exact moments where disclosure happens, especially signup, consent refresh, profile completion, and preference changes. If customers are declining there, check whether the wording explains purpose, retention, and sharing in plain language rather than legal language.

What to measure: Track consent conversion, opt-out rates after policy changes, abandonment at preference centres, and the volume of privacy-related support contacts. A rise in those signals is often more actionable than survey feedback because it shows where friction is actually occurring.

Common mistake: Treating a posted privacy notice as proof of transparency. Real transparency is demonstrated by whether customers can make an informed choice without guessing what the organisation plans to do with their data.

Practitioner takeaway: The most reliable warning sign is not that customers stop using the product, it is that they keep using it while becoming less willing to disclose anything new.