CCPA enforcement actions: every California settlement and order
California enforces the CCPA on two tracks. The Attorney General has settled eight civil actions, from $1.2 million against Sephora in 2022 to $12.75 million against General Motors in May 2026. CalPrivacy, the California Privacy Protection Agency, separately issues administrative orders, and has published twenty-two board decisions.
Applies to: Any business that meets the CCPA definition of a business in Cal. Civ. Code section 1798.140(d) and sells or shares California consumers' personal information, including through third-party advertising and analytics tags on a website or app.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThere is no mystery about what California enforces. The Attorney General publishes every privacy settlement it reaches, with the complaint and the judgment attached, and the CCPA entries on that list have a pattern you can plan around.
The CCPA settlements, newest first
General Motors, $12,750,000, May 8, 2026. A stipulated judgment over the sale of driving and location data collected through OnStar, in violation of the CCPA and the Unfair Competition Law. The Attorney General brought it with four District Attorneys and CalPrivacy, and found GM had misled consumers about how driving data was used and never disclosed the sales to data brokers. The precise location data involved also implicated the CCPA's purpose limitation and data minimization provisions. GM is barred for five years from selling driving data to consumer reporting agencies. See the General Motors settlement page for the full set of terms.
Disney, $2,750,000, February 11, 2026. Disney linked consumer devices and data in order to target advertising, but failed to link those same devices when a consumer exercised the right to opt out. So the opt-out did not carry across every device on a Disney+, Hulu, or ESPN+ account. The judgment requires an opt-out that works across all Disney businesses tied to the account.
Jam City, $1,400,000, November 21, 2025. None of the mobile game developer's 21 apps offered a CCPA-compliant opt-out, and some games shared or sold data of consumers between 13 and 16 without the affirmative consent the CCPA requires. See the Jam City settlement page.
Sling TV and Dish Media Sales, $530,000, October 30, 2025. The opt-out was combined with cookie choices in a confusing way, took multiple steps even for logged-in consumers, and did not exist inside the apps most customers actually used.
Healthline Media, $1,550,000, July 1, 2025. Tracking technology on a health information site shared data with third parties without CCPA-mandated protections, including data suggesting a reader might have a serious condition. The settlement includes a novel term banning Healthline from sharing article titles that reveal a likely diagnosis.
Tilting Point Media, $500,000, June 19, 2024. A joint investigation with the Los Angeles City Attorney found children's data collected and shared without parental consent through a game directed at under-13s, in violation of the CCPA and federal law, partly through misconfigured third-party SDKs.
DoorDash, $375,000, February 21, 2024. DoorDash sold California customers' personal information without notice or an opportunity to opt out, violating the CCPA and CalOPPA.
Sephora, $1,200,000, August 24, 2022. The first CCPA settlement. Sephora did not disclose that it was selling personal information and did not process opt-out requests sent through the Global Privacy Control. The full terms are covered on the Sephora settlement page.
The pattern worth acting on
Read those eight together and one theme dominates. Six of them are opt-out failures. Not a missing privacy policy, not a botched deletion request, but a business that published an opt-out and then did not make it work: not across devices, not inside the app, not when the signal arrived from a browser, not without a maze of clicks.
The second theme is third-party tags. Healthline, Tilting Point and General Motors all involved data leaving through code the business had installed and stopped thinking about. An SDK misconfiguration and an advertising pixel on a health article are the same problem wearing different clothes.
The third is children. Jam City, Sling TV and Tilting Point all carried a children's component, and the CCPA treats consumers under 16 differently, which is easy to miss if your product was not built for them but is used by them anyway.
What this means for a smaller business
None of these companies is a small business, and it is tempting to read the list as a large-company problem. That reading is wrong for a practical reason: the conduct being punished is cheap to fix and expensive to ignore. Testing whether your own opt-out works costs an afternoon. The administrative fine and civil penalty amounts apply per violation, and a violation is generally counted per consumer, which is what turns a small mistake into a large number.
If you are not certain whether the CCPA reaches you at all, that is the question to settle first, because these obligations only attach to businesses inside the statutory definition. And if you do sell or share data, the do not sell or share mechanics and Global Privacy Control handling are the two places this list says regulators look first.
What CPPA enforcement actions has CalPrivacy brought?
The settlements above are Attorney General civil actions. The California Privacy Protection Agency, which now operates as CalPrivacy, runs a second, separate track: administrative enforcement, decided by its board and published as board decisions. Searching for "CPPA enforcement actions" and finding only the Attorney General list is how businesses end up watching one regulator and missing the other.
The published decisions split into two groups. The CCPA decisions look much like the Attorney General's cases: American Honda Motor Co., $632,500 in March 2025, over excessive verification, dark patterns, obstruction of authorized agents and ad-tech sharing without protective contracts. Todd Snyder, Inc., $345,178 in May 2025, over a misconfigured opt-out portal and identity verification demanded for opt-outs. Tractor Supply Company, $1,350,000 in September 2025, over an inadequate privacy policy, a missing job-applicant notice and an ineffective opt-out including opt-out preference signals. Ford Motor Company, $375,703 in February 2026, over unnecessary friction in the opt-out process. And 2080 Media, Inc., trading as PlayOn Sports, $1.1 million in February 2026, the first decision addressing violations involving students and California schools.
The second group is Delete Act registration enforcement against data brokers, and it is the larger group by count. Fines there have ranged from $10,800 to $116,490, and the conduct is usually as simple as failing to register on time or registering with incorrect information. LocateSmarter, LLC, in August 2026, was the first combined CCPA and Delete Act action, at $116,490, for late registration and for requiring partial Social Security numbers before allowing an opt-out.
Two practical points follow. First, the administrative amounts are set by Cal. Civ. Code section 1798.155(a) and, as CPI-adjusted, stand at $2,663 per violation and $7,988 for an intentional violation or one involving a consumer known to be under 16. Those figures are lower per violation than the headline settlement numbers, and they still produce six-figure orders because violations are counted per consumer. Second, an agency that fines a company for a registration form filed with incorrect information is an agency that will notice a broken opt-out. For the arithmetic behind both tracks, see CCPA fines and penalties.
Compliance checklist
- Test your own opt-out end to end, on every surface you sell or share data through, including mobile apps and connected-TV apps, not just the website footer.
- Confirm an opt-out applies across every device and property linked to the same account, which is the specific failure the Disney judgment addressed.
- Check that your opt-out is not tangled up with a cookie banner, and that a logged-in consumer can complete it without working through multiple steps.
- Get affirmative opt-in consent before selling or sharing data of consumers you know are at least 13 and under 16, and never sell data of consumers under 13 without parental consent.
- Audit which third-party tags fire on pages that reveal sensitive context, such as health or location, since both the Healthline and General Motors matters turned on exactly that.
- Keep evidence: dated screenshots and test logs of a working opt-out are the cheapest defense you can build.
Sources
- Privacy Enforcement Actions, California Attorney General (official index of settlements, updated July 23, 2026)
- Attorney General Bonta announces $2.75 million settlement with Disney, California Department of Justice
- 2025 Increases for CCPA Fines and Penalties, California Privacy Protection Agency (CPI adjustment to Cal. Civ. Code sections 1798.155(a) and 1798.199.90(a))
- CalPrivacy board decisions (published administrative enforcement orders), California Privacy Protection Agency
- Attorney General Bonta Secures $1.4 Million Settlement with Mobile App Gaming Company (Jam City, November 21, 2025), California Department of Justice
Last verified: 2026-09-08
Informational, not legal advice.