Earlier quoted context omitted.
There's a distinction between being a data controller and a data processor. The businesses that use these platforms are the data *controllers* and are responsible for implementing consent, "do not sell my information", "show me my data", or "delete my data" flows as required by law. The platforms generally offer APIs to implement these required data flows in a centralized way, which is another major value prop for th…
The sustainability of that model of responsibility must be in doubt, though. Take a simple case like a website that loads a resource from somewhere else. Given how the technology works, any model where the original site is responsible for everything and the user's data is supposedly protected is obviously misleading, because very often it's the third party services that are run by the bigger, more powerful, data-hoov…
Under the predominant data transfer model, the third-parties cede responsibility by making the data transfer an active behavior by businesses. Ad tech companies can say "We didn't actively collect the data from customers - we passively received it from businesses." That makes a huge difference in term of regulatory compliance.
That said, this has been the most common data transfer model for years. "Data hoovering" is a misconception that allows millions of businesses who actively send customer data to Google/FB to shift privacy criticism onto the platforms.