Back to the hub

DoorDash CCPA settlement: what was the $375,000 for?

California's Attorney General announced the DoorDash settlement on February 21, 2024: a $375,000 civil penalty. DoorDash traded customer names, addresses and transaction histories to a marketing cooperative in January 2020. The office treated that trade as a sale under the CCPA, made without notice or an opt-out.

Applies to: Any CCPA-covered business that contributes customer data to a marketing cooperative, data co-op, audience exchange or similar arrangement in return for reach rather than cash.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

No money changed hands for the data. That is the point of this case. DoorDash put customer information into a marketing cooperative so it could advertise to other members' customers, and the other members got the same access to DoorDash's customers. California called that a sale.

What actually happened

DoorDash participated in marketing cooperatives, which are arrangements where businesses contribute the personal information of their customers in exchange for the opportunity to advertise their products to each other's customers.

In January 2020, the first month the CCPA was in effect, DoorDash traded personal information of California consumers to a marketing cooperative in a single transfer. The information included names, addresses and transaction histories. The purpose was to let DoorDash market its services to the customers of the other participating businesses.

One transfer, in the first month of the law, was enough to produce an enforcement action.

The Attorney General also found that the data did not stay inside the cooperative. Consumer personal information was subsequently disclosed to businesses that were not participants of the marketing cooperative, including to a data broker that resold the customer data many times over.

The two laws in play

This settlement is often described as a CCPA case, and it is, but the complaint carried a second count that is easy to miss.

Under the CCPA, the office alleged that the trade was a sale of personal information, that DoorDash violated the CCPA's requirements for businesses that sell personal data, and that it failed to cure those violations. Under CalOPPA, the allegation was narrower and more mechanical: DoorDash's posted privacy policy failed to state that it disclosed personally identifiable information, like a consumer's home address, to the marketing cooperatives.

The Attorney General drew the lesson explicitly, noting that businesses can be exposed to liability under multiple California privacy laws for the same conduct. One transfer, two statutes.

Some secondary write-ups of this case say DoorDash was charged under COPPA, the federal children's privacy law. That is wrong, and the error appears even in a later Attorney General press release summarizing the matter. The DoorDash release itself, which is the primary source, says CalOPPA.

Why "we don't sell data" is not a defense

DoorDash is the second case, after Sephora, where a business almost certainly did not think of itself as selling anything. Sephora let third-party trackers onto its site. DoorDash joined a co-op. Neither invoiced anyone for consumer data.

The CCPA's definition of a sale reaches transfers made for other valuable consideration, and reach into another company's customer list is valuable consideration. If your business gets something back for the data, the label on the arrangement does not decide the question.

The cure warning attached to this one

The release carried a line worth quoting because it marks a change in posture. Announcing the settlement, the Attorney General said that violations cannot be cured, and that the office will hold businesses accountable if they sell data without protecting consumers' rights.

That reflects the state of the law from January 1, 2023, when the CCPA's 30-day notice-and-cure right for Attorney General actions expired. DoorDash's own conduct predated that expiry, which is why failure to cure is pleaded in its complaint. A business in the same position today does not get the window at all. That is a genuine difference from states that kept a cure right, such as the permanent one in the Texas cure period.

What to do about it

If you belong to any audience-sharing arrangement, the work is to write down what you give, what you get, and whether a consumer could have known. The do not sell or share obligations follow from that classification, not from whether you think of the arrangement as a sale.

Compliance checklist

  • List every arrangement where you contribute customer data in exchange for reach, audience or access rather than money, because those are the arrangements this case reclassified as sales.
  • Assume a data co-op transfer is a sale under the CCPA until you can show otherwise, and disclose it before it happens rather than after.
  • Give consumers a working opt-out before the first transfer, not at the point someone complains, since a single transfer was enough here.
  • Check that your posted privacy policy names the categories of personally identifiable information you disclose, which is the separate CalOPPA duty DoorDash was charged under.
  • Trace where data goes after the co-op receives it, because the office found DoorDash data reached businesses outside the cooperative, including a data broker that resold it.

Sources

Last verified: 2026-09-10

Informational, not legal advice.