CCPA / CPRA

The CCPA Enforcement Record: Every Public Action, Its Penalty and What It Alleged

Key Takeaways

  • Twelve publicly documented CCPA actions carry $23,462,568 in penalties — eight Attorney General settlements totalling $21,055,000 and four CPPA administrative orders totalling $2,407,568
  • The largest is the $12.75 million General Motors settlement announced May 8, 2026, which the Attorney General describes as its first action enforcing the CCPA's data minimization requirement
  • Opt-out mechanics are the recurring theory: failure to honor the Global Privacy Control, opt-outs buried behind verification, and opt-outs absent from apps appear in most of the actions
  • Three of the twelve are documented here from the enforcer's own press release because the filed judgment is a scanned image with no retrievable text
  • Registration actions under the Delete Act are a separate statute and are not counted in these figures

Two Enforcers, One Statute

The CCPA is enforced along two tracks that produce different kinds of documents. The Attorney General sues in superior court and resolves cases by stipulated judgment, recovering civil penalties under Civil Code section 1798.199.90 — "not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation and each violation involving the personal information of minor consumers." The California Privacy Protection Agency, which now also operates under the name CalPrivacy, proceeds administratively: under section 1798.199.55 it holds a hearing under the Administrative Procedure Act and issues an order that may require the violator to cease and desist and to pay an administrative fine, at the same per-violation figures set by section 1798.155.

That procedural split matters for anyone reading the record, because the two enforcers publish different things. Superior court judgments are filed documents; CPPA resolutions are Board orders adopting a stipulated final order, published on the agency's own site with a case number.

The Attorney General Settlements

AnnouncedRespondentPenaltyCore allegation
Aug 24, 2022Sephora USA, Inc.$1,200,000Failure to disclose the sale of personal information and to process opt-outs sent via global privacy controls
Feb 21, 2024DoorDash, Inc.$375,000Disclosure of customer data to a marketing cooperative treated as a sale, without notice or opt-out; also CalOPPA
Jun 19, 2024Tilting Point Media LLC$500,000Collection and sale of children's data through a mobile game without parental consent; also COPPA
Jul 1, 2025Healthline Media LLC$1,550,000Tracking technology on a health information site; no working opt-out; sharing without required contract terms
Oct 30, 2025Sling TV$530,000Opt-out combined confusingly with cookie choices and absent from living-room apps; no children's profile controls
Nov 21, 2025Jam City, Inc.$1,400,000No compliant opt-out in any of 21 mobile apps; data of 13-to-15-year-olds shared without opt-in consent
Feb 11, 2026The Walt Disney Company$2,750,000Opt-out not effectuated across all devices linked to an account, though the same links were used for ad targeting
May 8, 2026General Motors$12,750,000Sale of OnStar location and driving data to two data brokers; purpose limitation and data minimization

The eight settlements total $21,055,000. Five are documented here from the filed judgment itself. The Sephora judgment records payment of "$1.2 million" deposited into the Consumer Privacy Fund under Civil Code section 1798.155(c). The Healthline judgment, filed in San Francisco Superior Court as case number CGC-25-626794, records "$1,550,000 dollars." The Sling TV judgment is Los Angeles Superior Court case number 25STCV31561. The Disney judgment records payment of "$2,750,000 pursuant Civil Code Section 1798.199.90" within thirty days of the effective date. The Tilting Point judgment splits its $500,000 between the Attorney General and the Los Angeles City Attorney's Office, which investigated jointly.

The General Motors settlement is the outlier in size and in theory. The Attorney General's release states that from 2020 to 2024 GM sold names, contact information, geolocation data and driving behavior data of hundreds of thousands of Californians to Verisk Analytics and LexisNexis Risk Solutions, that GM "reportedly made approximately $20 million nationwide from these data sales," and that retaining the data after it was needed to operate OnStar violated "the CCPA's purpose limitation and data minimization requirements, added in 2023." The release calls it the department's "first action enforcing the data minimization principle," and notes that the settlement is subject to court approval. Four district attorneys joined, and CalPrivacy supported the action.

The CPPA Orders

Order dateRespondentFineCase number
Mar 7, 2025American Honda Motor Co., Inc.$632,500ENF23-V-HO-2
May 1, 2025Todd Snyder, Inc.$345,178ENF23-M-TO-26
Sep 30, 2025Tractor Supply Company$1,350,000ENF24-M-TR-04
Aug 11, 2026LocateSmarter LLC$79,890 (CCPA portion)ENF26-05-D-LO

The Honda order is the one that shows the arithmetic. It allocates $382,500 of the $632,500 fine to "119 Consumers who were required to provide more information than necessary" to opt out or to limit, "20 Consumers who had their Requests to Opt-out of Sale/Sharing and Requests to Limit denied because Honda required the Consumer to Verify themselves," and "14 Consumers who were required to confirm with Honda directly that they had given their Authorized Agents permission." That is 153 consumers at the $2,500 statutory maximum. The remainder of the fine is not broken out the same way.

The Tractor Supply order, at $1,350,000, is the largest CPPA fine on the record. Its injunctive terms are unusually operational: quarterly scans of digital properties to maintain "a full and current inventory of tracking technologies," a good-faith determination for each one of whether it is used for selling or sharing and is covered by a compliant contract, configuration to honor opt-out preference signals including Global Privacy Control under section 7025, and symmetry of choice under section 7004(a)(2) — the reject button on the cookie banner has to be "a similar size and design" as the accept button. The agency's release adds that the decision is its first to address job applicants' privacy rights.

The LocateSmarter order is the first the agency has brought under the CCPA and the Delete Act together. Its CCPA component is a $79,890 fine under section 1798.199.55 for requiring consumers to supply a full name, the last four digits of a Social Security number and a mailing address in order to opt out of sale or sharing — conduct the order characterizes as a data minimization violation, since "a Social Security number is more than the minimum personal information" needed. Its separate Delete Act component, $30,600 under section 1798.99.82(c), is 153 days of non-registration at the statutory $200 a day, and is not counted in the CCPA total above.

What the Orders Consistently Allege

Across twelve actions the same handful of theories recur, and they are mechanical rather than conceptual.

  • Opt-out mechanics. Sephora, Sling TV, Jam City, Disney, Honda, Todd Snyder and Tractor Supply all turn on an opt-out that existed on paper and failed in operation — not honored via Global Privacy Control, buried behind verification, missing from the app, or not applied across linked devices.
  • Excessive information demanded to exercise a right. Honda, Todd Snyder and LocateSmarter each involve requiring more from a consumer than the request needed. The Todd Snyder allegations include requiring identity verification before an opt-out, which the CPPA notes echoes an enforcement advisory it had issued the previous year.
  • Contracts with recipients. Honda, Healthline and Tractor Supply each involve disclosing personal information to other companies without contracts carrying the terms the statute requires.
  • Minors. Tilting Point, Sling TV and Jam City involve children's or teenagers' data, where the statute requires opt-in consent for consumers under 16 and the per-violation penalty rises to $7,500.
  • Configuration failures by a vendor tool. The Todd Snyder order concerns a privacy portal misconfigured such that opt-out requests went unprocessed for 40 days.

Cure Periods Before and After

The first and second Attorney General settlements bracket a change in the statute. The Sephora release alleges that the company "did not cure these violations within the 30-day period currently allowed by the CCPA," and states plainly that the notice-and-cure provision "will expire on January 1, 2023." Eighteen months later, announcing the DoorDash settlement, the Attorney General put it in three words: "Violations cannot be cured." Every action after Sephora rests on that footing.

The Penalty Figures in Context

The twelve actions together carry $23,462,568. Set against a per-violation maximum of $2,500, that is a small number of consumers relative to the size of the businesses involved — the Honda order reaches $382,500 from 153 identified consumers. Penalty size in this record tracks the count of provable affected consumers and the enforcer's characterization of intent, not the revenue of the respondent. The distribution is also lopsided: the single General Motors settlement is more than half the total, and the eight Attorney General settlements are roughly nine times the four CPPA fines combined.

The pace is the other thing the table shows. Two actions closed in the first four years of the statute; ten have closed since the start of 2024, seven of them since the start of 2025.

What This Record Does Not Include

Three limits are worth stating rather than leaving to inference.

First, three of the twelve filed judgments — DoorDash, Jam City and General Motors — are published as scanned images from which no text could be retrieved. Those three are reported here from the Attorney General's own press releases and from the department's Privacy Enforcement Actions index, both of which state the amount and the allegations. The same is true of the attachment to the Todd Snyder order: the Board's Order of Decision adopting the stipulated final order is readable and carries the case number and date, and the fine amount and allegations come from the agency's release.

Second, the Attorney General maintains a separate page of CCPA "enforcement case examples." It carries no penalties and no judgments. As that page states, "the OAG does not generally release information to the public about its investigations," and the entries are "illustrative examples of situations in which it sent a notice of alleged noncompliance and steps taken by each company in response." Those notices are not counted here, and there is no public basis for counting them.

Third, the CPPA's larger volume of data broker actions — including the Cybba order issued two days after LocateSmarter — enforce the Delete Act's registration requirement at Civil Code section 1798.99.82, not the CCPA. Only the CCPA component of the LocateSmarter order appears in these totals.

Background

For the underlying law rather than this development: California privacy law, Retail & E-Commerce privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

What is the largest CCPA penalty to date?
The $12.75 million General Motors settlement announced May 8, 2026, which the Attorney General describes as the largest CCPA penalty in California history and as its first action enforcing the statute's data minimization requirement. The release states the settlement is subject to court approval. The largest CPPA administrative fine is $1,350,000 against Tractor Supply Company, issued September 30, 2025.
How much can a business be fined per CCPA violation?
Civil Code section 1798.199.90 sets the Attorney General's civil penalty at not more than $2,500 for each violation and $7,500 for each intentional violation and each violation involving a minor consumer's personal information, adjusted under section 1798.199.95(d). Sections 1798.155 and 1798.199.55 set the same figures for administrative fines imposed by the CPPA.
Can a business still cure a CCPA violation before enforcement?
The Attorney General's Sephora release states that the CCPA's notice-and-cure provision expired on January 1, 2023, and its DoorDash release states that violations cannot be cured. Every publicly resolved action after Sephora proceeded without a cure period.
Do the CPPA's data broker fines count as CCPA enforcement?
Not as such. Most of them enforce the Delete Act's registration requirement at Civil Code section 1798.99.82, which carries its own $200-per-day fine and is a separate statute. The August 2026 LocateSmarter order is the first the agency has brought under both, and it separates the two components: $79,890 under the CCPA and $30,600 under the Delete Act.
Which CCPA obligation shows up most often in enforcement?
The opt-out from sale or sharing, and specifically whether it works. Seven of the twelve actions charted here allege an opt-out that failed in operation — not honored via the Global Privacy Control, gated behind identity verification, missing from an app, or not applied across the devices linked to one account.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. California Attorney General — Privacy Enforcement Actions (index of stipulated judgments, with amounts and dates) agency guidance
  2. People v. Sephora USA, Inc. — Final Judgment and Permanent Injunction (August 24, 2022) docket
  3. California Attorney General — press release announcing the DoorDash settlement (February 21, 2024) agency release
  4. People v. Tilting Point Media LLC — stipulated final judgment (June 19, 2024) docket
  5. People v. Healthline Media LLC — final judgment, San Francisco Superior Court No. CGC-25-626794 (July 1, 2025) docket
  6. People v. Sling TV — Final Judgment and Permanent Injunction, Los Angeles Superior Court No. 25STCV31561 (October 30, 2025) docket
  7. California Attorney General — press release announcing the $1.4 million Jam City settlement (November 21, 2025) agency release
  8. People v. The Walt Disney Company — Final Judgment and Permanent Injunction (February 11, 2026) docket
  9. California Attorney General — press release announcing the $12.75 million General Motors settlement (May 8, 2026) agency release
  10. CPPA — In the Matter of American Honda Motor Co., Inc., Case No. ENF23-V-HO-2, stipulated final order (March 12, 2025) agency release
  11. CPPA — In the Matter of Todd Snyder, Inc., Case No. ENF23-M-TO-26, order of decision (May 6, 2025) agency release
  12. CPPA — In the Matter of Tractor Supply Company, Case No. ENF24-M-TR-04, stipulated final order (September 30, 2025) agency release
  13. CalPrivacy — In the Matter of LocateSmarter LLC, Case No. ENF26-05-D-LO, order of decision and stipulated order (August 11, 2026) agency release
  14. California Attorney General — CCPA enforcement case examples (notices of alleged noncompliance) agency guidance
  15. California Civil Code § 1798.199.90 — Attorney General civil penalties statute
  16. California Civil Code § 1798.199.55 — CPPA administrative enforcement orders and fines statute
  17. California Civil Code § 1798.155 — administrative fine amounts and disposition of proceeds statute

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.