CCPA Enforcement Actions Tracker: Every Fine to Date
Every public CCPA/CPRA settlement from the California Privacy Protection Agency and the California Attorney General, with verified penalty amounts, violations, and links to the primary source. Updated as new actions land.
Showing 14 CCPA enforcement actions totaling $24,974,871 in penalties, plus $88,800 in Delete Act data-broker registration fines
Sorted newest first
SalesIntel Research, Inc.
·CPPA
$36,400
Delete Act Registration
CalPrivacy's third data-broker decision in under a month, and the first since DROP deletion processing switched on for brokers. The Virginia-based B2B sales-intelligence company sells access to a database of more than 200 million professional contacts and 54 million mobile phone numbers, and infers attributes about those people to support targeted advertising, but never registered with California's Data Broker Registry by the 2025 deadline. Alongside the fine it must publish privacy-rights metrics on its website and process deletion requests through DROP.
CalPrivacy's second data-broker decision in under a week: Boston-based Cybba operated as a data broker in 2024 but never registered with California's Data Broker Registry by the January 31, 2025 deadline the Delete Act imposes. Alongside the penalty, Cybba must publish privacy-rights metrics on its website and process consumer deletion requests through DROP, the state's one-stop deletion platform.
CalPrivacy — the California Privacy Protection Agency — brought its first enforcement action against a data broker under both the CCPA and the Delete Act. Iowa-based LocateSmarter registered late and required Californians to provide the last four digits of their Social Security number before an opt-out of sale would be processed, which unlawfully verified a request that must be honored without identity verification and collected more sensitive data than the task reasonably required. The Board imposed the fine even though only a handful of consumers had submitted opt-out requests.
Data MinimizationPurpose LimitationDeceptive Privacy Policy
California's Attorney General, together with four district attorneys and with support from the CPPA, secured the largest CCPA penalty to date over GM's OnStar connected-vehicle service. GM sold names, geolocation, and driving-behavior data for hundreds of thousands of Californians to data brokers LexisNexis and Verisk despite a privacy policy stating it did not sell driving or location data, and the case was the first CCPA enforcement action built on the data-minimization and purpose-limitation principles.
The CPPA fined Ford for requiring consumers to verify their email address before an opt-out of sale/sharing request would be processed, which the agency found imposed an unlawful identity-verification requirement on a right that must be frictionless. Ford also continued selling or sharing personal information for some consumers after they had already opted out, and must now audit its site-wide tracking technology for Global Privacy Control compliance.
Opt Out FailureGPCMinors DataMissing Privacy Policy Rights
CalPrivacy's first decision addressing privacy violations involving students and California schools. PlayOn's GoFan digital ticketing platform — used by roughly 1,400 California schools — made ticketholders click through to accept tracking technologies before they could view their tickets, then sold and shared that personal information with advertising, social media, and analytics partners. The company offered no opt-out mechanism of its own, pointing consumers instead at the Network Advertising Initiative and Digital Advertising Alliance tools, did not recognize opt-out preference signals such as Global Privacy Control, and sold or shared the data of 13- to 15-year-olds without the affirmative opt-in consent the CCPA requires.
California's largest CCPA penalty at the time it was announced: Disney's opt-out toggle only applied to the specific streaming service being viewed rather than the whole account, its webform stopped first-party ad sharing but not embedded third-party ad-tech partners, and Global Privacy Control signals were honored only for the specific device rather than the logged-in account.
The mobile game developer monetizes by disclosing personal information for advertising, but offered consumers no way to opt out of the sale or sharing of that information across its 21 mobile apps — the very channel through which it collected nearly all of it. The Attorney General also found Jam City sold or shared the personal information of consumers aged 13 to 15 without the affirmative opt-in consent the CCPA requires for anyone under 16.
California's first CCPA enforcement action against a streaming service. Sling TV's opt-out flow tangled the CCPA right together with cookie choices in a confusing multi-step process and made already-logged-in customers re-enter information the company already held, and it offered no opt-out at all inside the living-room apps through which most subscribers actually watched. The settlement also faulted the company's protections for children.
Missing Privacy Policy RightsOpt Out FailureGPCVendor Contracts
The CPPA fined the nation's largest rural lifestyle retailer for a privacy policy that failed to notify consumers (and California job applicants) of their CCPA rights, for lacking an effective mechanism to opt out of the sale/sharing of personal information including via Global Privacy Control, and for sharing personal information with other companies without CCPA-required contract protections.
Opt Out FailurePurpose LimitationVendor ContractsHealth Data Sharing
California's Attorney General secured what was then the largest CCPA settlement to date after Healthline.com's consent banner appeared to disable tracking cookies but did not, continued sending identifying data to ad partners after consumers opted out, and shared article titles suggestive of a medical diagnosis with advertisers without required contract protections.
A misconfigured cookie-preferences portal left Todd Snyder unable to process opt-out of sale/sharing requests for 40 days, and the retailer's privacy portal separately required a government-issued ID before honoring any opt-out request — far more identity verification than the CCPA allows for the opt-out right.
Dark PatternsExcessive VerificationVendor Contracts
The CPPA's first-ever settlement found Honda's cookie management tool required two steps to opt out of advertising cookies (toggle off, then confirm) but only one step to opt in — an asymmetrical dark pattern — plus excessive identity verification for opt-out and limit requests and ad-tech data sharing without CCPA-compliant service-provider contracts.
The Attorney General and the Los Angeles City Attorney settled claims over "SpongeBob: Krusty Cook-Off," a game directed at children. Misconfigured third-party advertising SDKs collected and sold children's personal information, Tilting Point never obtained parental consent for players under 13 or opt-in consent for players aged 13 to 16, and the app's age screen was not neutral — it nudged children toward reporting an age that skipped the child-mode protections entirely.
DoorDash transferred names, addresses, and transaction histories of California customers to marketing-cooperative partners in exchange for new customer leads — a sale of personal information under the CCPA — without disclosing the practice or giving consumers a way to opt out.
California's first public CCPA settlement: Sephora allowed third-party advertising and analytics trackers on its site and app without disclosing that this constituted a sale of personal information, did not honor Global Privacy Control opt-out signals, and failed to cure the violations within the CCPA's 30-day cure period.