got gpc?

California Privacy Enforcement: What Regulators Have Actually Fined People For

Updated 2026-08-05 · 5 enforcement actions cited · 4 official sources

California now has two active privacy enforcers: the Attorney General, who has brought CCPA actions since 2022, and the California Privacy Protection Agency, whose Enforcement Division began issuing its own decisions in 2025. The public record is small enough to read in full — and remarkably consistent about what gets you fined.

TL;DR

  • Sephora (2022, $1.2M) established that failing to honor GPC is an enforceable CCPA violation.
  • DoorDash (2024, $375K) established that contributing data to a marketing co-op is a 'sale'.
  • Honda (2025, $632.5K) and Todd Snyder (2025, $345K) targeted friction: asymmetric choices, verification demands, and broken opt-out mechanisms.
  • Healthline (2025, $1.55M) — the largest CCPA settlement to date — turned on sharing sensitive health-related browsing data for advertising.
  • Both agencies run automated sweeps. GPC handling is a standing item on those sweeps.

See whether your own site honors GPC. $99, runs in a real California browser.

The Sephora settlement set the baseline

In August 2022 the Attorney General announced a $1.2 million settlement with Sephora, the first public CCPA enforcement action. The complaint alleged that Sephora allowed third parties to install trackers on its site that collected customer data in exchange for advertising and analytics benefits — a sale — while telling consumers it did not sell personal information, offering no Do Not Sell link, and, crucially, failing to process opt-out requests submitted via Global Privacy Control.

The AG's accompanying guidance was blunt: businesses must honor GPC. Every subsequent sweep has used that as a settled premise rather than an open question.

DoorDash: the boundaries of 'sale'

In February 2024 the AG settled with DoorDash for $375,000 over its participation in a marketing cooperative, in which member businesses contributed customer personal information in exchange for the ability to advertise to other members' customers. DoorDash argued this was not a sale; the AG disagreed, holding that the exchange of data for advertising access is valuable consideration.

The practical lesson: 'we don't sell data' is a legal conclusion, not a factual one, and the definition is broader than most marketing teams assume.

Honda and Todd Snyder: friction is the violation

The CPPA's first two public enforcement decisions, both in 2025, were about mechanics rather than data flows. American Honda Motor Co. was fined $632,500 for a cookie-consent interface where accepting all cookies took one click but rejecting them took two, for requiring consumers to submit excessive personal information to exercise opt-out rights, and for having no straightforward process for authorized agents.

Todd Snyder, Inc. was fined $345,178 after its opt-out mechanism silently failed for 40 days — a third-party consent tool that never actually processed requests — and because the company required consumers to verify their identity to submit an opt-out, which the regulations forbid.

Both decisions also required ongoing compliance programs and reporting. The message is that the regulator will treat an implementation bug in your consent tooling as your violation, not your vendor's.

Not sure where your site stands? Find out in a few minutes.

Healthline: sensitive inferences and purpose limitation

In July 2025 the Attorney General announced a $1.55 million settlement with Healthline Media — the largest CCPA settlement to date. The allegations included sharing information that allowed advertisers to infer that a reader had a specific serious medical condition, failing to honor opt-out requests, and failing to enforce contractual privacy terms with advertising partners.

The AG emphasized the purpose-limitation principle: even where sharing is permitted, it must be limited to what is reasonably necessary and compatible with the disclosed purpose. This has direct implications for health, finance, and legal-services publishers whose URL paths and page titles are themselves sensitive.

How sweeps actually find you

Both the AG and the CPPA have announced investigative sweeps — connected televisions, streaming apps, data brokers, mobile apps, and employers among them. The mechanics are consistent: automated crawlers load a large set of California-facing sites with an opt-out preference signal enabled, record what happens, and flag the ones that show no behavioral change.

There is nothing secret about the test. You can run it against your own property before a regulator does, which is the entire premise of this tool.

Key enforcement actions

People v. Sephora USA, Inc.

Cal. Att'y Gen., Aug. 24, 2022 — $1,200,000

Failure to disclose sale of personal information, no Do Not Sell mechanism, failure to honor Global Privacy Control opt-out signals, failure to cure. Included two years of compliance reporting.

Read the official source ↗

People v. DoorDash, Inc.

Cal. Att'y Gen., Feb. 21, 2024 — $375,000

Sale of customer personal information via a marketing cooperative without notice or opt-out. First AG action to squarely address data co-ops as sales.

Read the official source ↗

In re American Honda Motor Co., Inc.

Cal. Privacy Protection Agency, Mar. 12, 2025 — $632,500

Asymmetric cookie choices, excessive verification for opt-out requests, deficient authorized-agent process, and contractual failures with ad-tech vendors.

Read the official source ↗

In re Todd Snyder, Inc.

Cal. Privacy Protection Agency, May 6, 2025 — $345,178

Opt-out mechanism non-functional for 40 days due to a misconfigured consent tool; unlawful identity verification for opt-out requests; over-collection on the privacy request form.

Read the official source ↗

People v. Healthline Media LLC

Cal. Att'y Gen., Jul. 1, 2025 — $1,550,000

Largest CCPA settlement to date. Sharing data enabling inference of serious medical conditions, failure to honor opt-outs, and failure to enforce contractual privacy terms with advertising partners.

Read the official source ↗

FAQ

Who enforces the CCPA — the AG or the CPPA?

Both. The Attorney General has civil enforcement authority and brings court actions; the CPPA has administrative enforcement authority and issues its own decisions and orders. They coordinate but act independently.

Is there a private right of action for GPC violations?

Not directly. The CCPA's private right of action is limited to certain data breaches. However, plaintiffs' firms have used other theories — including California's wiretap statute — to reach tracking conduct, and non-compliance evidence developed for one theory is readily reused for another.

How much time do I get to fix something before a fine?

None guaranteed. The mandatory 30-day cure period was eliminated as of January 1, 2023. Regulators may consider good faith and prompt remediation as mitigating factors.

Do these decisions apply to small businesses?

Only if you meet a CCPA applicability threshold. But the thresholds catch far more mid-sized e-commerce and media businesses than owners typically expect, particularly the 100,000-consumer threshold.

Official sources

Related reading

This guide is general information about California privacy law and the Global Privacy Control signal, not legal advice. Enforcement actions are summarized from official regulator publications; verify before relying on them. Consult qualified counsel for your specific situation.