Back to the hub

Sephora CCPA settlement: what did California require?

California's Attorney General announced the Sephora settlement on August 24, 2022: $1.2 million in penalties plus injunctive terms. The allegations were that Sephora sold personal information without disclosing it, ignored opt-out requests sent through the Global Privacy Control, and did not cure within the 30 days the CCPA then allowed.

Applies to: Any business covered by the CCPA that allows third-party advertising or analytics code to collect data from its website or app, whether or not money changes hands for that data.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Sephora was the first company California penalized under the CCPA, and the case is still the clearest illustration of how a business can be selling personal information without believing it sells anything. Nobody wired money to Sephora for customer data. The Attorney General said that did not matter.

What the Attorney General alleged

The office ran an enforcement sweep of online retailers and then alleged three things against Sephora. That it failed to disclose to consumers that it was selling their personal information. That it failed to process user requests to opt out of sale sent through user-enabled global privacy controls. And that it did not cure these violations within the 30-day period the CCPA then allowed.

The mechanism behind the first two is the part worth studying. Many online retailers let third-party companies install tracking software on their website and in their app so those third parties can monitor consumers as they shop. In Sephora's case, the Attorney General described third parties able to build profiles by tracking whether a consumer was using a MacBook or a Dell, the brand of eyeliner or the prenatal vitamins in a shopping cart, and even a consumer's precise location. Retailers benefit in kind from these arrangements, which let them target potential customers more effectively.

That benefit in kind is the consideration. As the Attorney General put it, Sephora's arrangement with these companies constituted a sale of consumer information under the CCPA, and it triggered basic obligations: telling consumers they are selling their information, and allowing consumers to opt out. Sephora did neither.

What the settlement required

The settlement required Sephora to pay $1.2 million in penalties and to comply with four injunctive terms. Sephora must clarify its online disclosures and privacy policy to include an affirmative representation that it sells data. It must provide mechanisms for consumers to opt out of the sale of personal information, including via the Global Privacy Control. It must conform its service provider agreements to the CCPA's requirements. And it must provide reports to the Attorney General relating to its sale of personal information, the status of its service provider relationships, and its efforts to honor Global Privacy Control.

Read those four together and they are a compliance program, not a fine. The reporting obligation in particular means the office kept visibility after the case closed.

The cure period that no longer exists

The same announcement carried a warning that has since become the operative fact. Attorney General Bonta noted that businesses' right to avoid liability by curing their CCPA violations after they are caught was expiring. Alongside the Sephora settlement, the office sent notices to a number of businesses alleging failure to process opt-out requests made via user-enabled global privacy controls, giving them 30 days to cure. The release states plainly that the CCPA's notice and cure provision, which required businesses to receive notice and an opportunity to cure before the Attorney General could hold them accountable, expired on January 1, 2023.

So the Sephora template applies today without the safety net Sephora had. A business in the same position now gets the allegation and the penalty exposure, not a 30-day grace window. That is a real difference from the states that kept a cure right, and it is worth comparing against the Texas cure period, which is permanent.

Why this case still matters for smaller businesses

Sephora is a large retailer, and the instinct is to file this under large-company problems. The conduct does not support that reading. The failure was a privacy policy that did not say what the company was doing, and an opt-out signal the site ignored. Both are configuration problems, and both are cheap to find if you look.

The Global Privacy Control handling is the specific thing to test, because it is the thread running through most of what California has enforced since. For the full list of settlements the Attorney General has reached, see CCPA enforcement actions, and for the amounts at stake per violation, see CCPA fines and penalties.

Next step

If third-party tags run on your site and you are not certain whether that makes you a seller of personal information under the CCPA, the free 2-minute Obligation Scan works out whether the CCPA reaches your business and which disclosure and opt-out duties come with it.

Compliance checklist

  • Inventory every third-party tag, pixel, and SDK on your site and app, and ask what each one receives, because that is where the Sephora theory of sale starts.
  • State plainly in your privacy policy whether you sell or share personal information, rather than leaving it implied or unmentioned.
  • Test that a Global Privacy Control signal from a browser actually stops the data flow, rather than only that your site records it.
  • Bring your vendor agreements up to the CCPA service provider standard, or treat those vendors as third parties and disclose the transfer.
  • Do not plan around a cure period: the CCPA's 30-day notice-and-cure right for Attorney General actions expired on January 1, 2023.

Sources

Last verified: 2026-09-08

Informational, not legal advice.