What CCPA enforcement actions has California brought?
California's Attorney General has settled eight CCPA enforcement actions, from a $1.2 million penalty against Sephora in 2022 to a $12,750,000 stipulated judgment against General Motors in May 2026. Most turned on the same failure: the business did not actually honor opt-out requests it appeared to offer.
Applies to: Any business that meets the CCPA definition of a business in Cal. Civ. Code section 1798.140(d) and sells or shares California consumers' personal information, including through third-party advertising and analytics tags on a website or app.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThere is no mystery about what California enforces. The Attorney General publishes every privacy settlement it reaches, with the complaint and the judgment attached, and the CCPA entries on that list have a pattern you can plan around.
The CCPA settlements, newest first
General Motors, $12,750,000, May 8, 2026. A stipulated judgment over the sale of driving and location data collected through OnStar, in violation of the CCPA and the Unfair Competition Law. The Attorney General brought it with four District Attorneys and CalPrivacy, and found GM had misled consumers about how driving data was used and never disclosed the sales to data brokers. The precise location data involved also implicated the CCPA's purpose limitation and data minimization provisions. GM is barred for five years from selling driving data to consumer reporting agencies.
Disney, $2,750,000, February 11, 2026. Disney linked consumer devices and data in order to target advertising, but failed to link those same devices when a consumer exercised the right to opt out. So the opt-out did not carry across every device on a Disney+, Hulu, or ESPN+ account. The judgment requires an opt-out that works across all Disney businesses tied to the account.
Jam City, $1,400,000, November 21, 2025. None of the mobile game developer's 21 apps offered a CCPA-compliant opt-out, and some games shared or sold data of consumers between 13 and 16 without the affirmative consent the CCPA requires.
Sling TV and Dish Media Sales, $530,000, October 30, 2025. The opt-out was combined with cookie choices in a confusing way, took multiple steps even for logged-in consumers, and did not exist inside the apps most customers actually used.
Healthline Media, $1,550,000, July 1, 2025. Tracking technology on a health information site shared data with third parties without CCPA-mandated protections, including data suggesting a reader might have a serious condition. The settlement includes a novel term banning Healthline from sharing article titles that reveal a likely diagnosis.
Tilting Point Media, $500,000, June 19, 2024. A joint investigation with the Los Angeles City Attorney found children's data collected and shared without parental consent through a game directed at under-13s, in violation of the CCPA and COPPA, partly through misconfigured third-party SDKs.
DoorDash, $375,000, February 21, 2024. DoorDash sold California customers' personal information without notice or an opportunity to opt out, violating the CCPA and CalOPPA.
Sephora, $1,200,000, August 24, 2022. The first CCPA settlement. Sephora did not disclose that it was selling personal information and did not process opt-out requests sent through the Global Privacy Control.
The pattern worth acting on
Read those eight together and one theme dominates. Six of them are opt-out failures. Not a missing privacy policy, not a botched deletion request, but a business that published an opt-out and then did not make it work: not across devices, not inside the app, not when the signal arrived from a browser, not without a maze of clicks.
The second theme is third-party tags. Healthline, Tilting Point and General Motors all involved data leaving through code the business had installed and stopped thinking about. An SDK misconfiguration and an advertising pixel on a health article are the same problem wearing different clothes.
The third is children. Jam City, Sling TV and Tilting Point all carried a children's component, and the CCPA treats consumers under 16 differently, which is easy to miss if your product was not built for them but is used by them anyway.
What this means for a smaller business
None of these companies is a small business, and it is tempting to read the list as a large-company problem. That reading is wrong for a practical reason: the conduct being punished is cheap to fix and expensive to ignore. Testing whether your own opt-out works costs an afternoon. The administrative fine and civil penalty amounts apply per violation, and a violation is generally counted per consumer, which is what turns a small mistake into a large number.
If you are not certain whether the CCPA reaches you at all, that is the question to settle first, because these obligations only attach to businesses inside the statutory definition. And if you do sell or share data, the do not sell or share mechanics and Global Privacy Control handling are the two places this list says regulators look first.
Compliance checklist
- Test your own opt-out end to end, on every surface you sell or share data through, including mobile apps and connected-TV apps, not just the website footer.
- Confirm an opt-out applies across every device and property linked to the same account, which is the specific failure the Disney judgment addressed.
- Check that your opt-out is not tangled up with a cookie banner, and that a logged-in consumer can complete it without working through multiple steps.
- Get affirmative opt-in consent before selling or sharing data of consumers you know are at least 13 and under 16, and never sell data of consumers under 13 without parental consent.
- Audit which third-party tags fire on pages that reveal sensitive context, such as health or location, since both the Healthline and General Motors matters turned on exactly that.
- Keep evidence: dated screenshots and test logs of a working opt-out are the cheapest defense you can build.
Sources
- Privacy Enforcement Actions, California Attorney General (official index of settlements, updated July 23, 2026)
- Attorney General Bonta announces $2.75 million settlement with Disney, California Department of Justice
- Cal. Civ. Code sections 1798.155 and 1798.199.90 (administrative fines and civil penalties), CCPA statute text, California Privacy Protection Agency
Last verified: 2026-08-27
Informational, not legal advice.