This is the same problem with the cookie law in Europe.
They allowed one single, generic, disclaimer which every site pops up.
If they'd demanded:
- a separate disclaimer for each domain (or at least company) setting a cookie
- a description of the purpose of the cookies (e.g. advertising, remembering log-ins)
Then the law might have actually achieved something.