Court Rules
All enforcement actions
SettlementMedium Risk

California AG and LA City Attorney Settle with Tilting Point Media for $500,000 Over Children’s Data Violations

Tilting Point Media LLCJuly 2, 2024California Attorney General

Penalty Amount

$500,000

Summary

California Attorney General Rob Bonta and Los Angeles City Attorney Hydee Feldstein Soto announced a $500,000 settlement with Tilting Point Media LLC over allegations that the company violated COPPA and the CCPA by illegally collecting and sharing children’s personal data without parental consent via its 'SpongeBob: Krusty Cook-Off' mobile game. The settlement requires Tilting Point to pay $500,000 in civil penalties and comply with injunctive terms including implementing neutral age screens, obtaining parental consent for children’s data collection/sharing, and maintaining an SDK governance framework. Tilting Point must also submit annual compliance reports to the California DOJ and LA City Attorney’s Office.

Remedy

Tilting Point must pay $500,000 in civil penalties. Injunctive terms require the company to: comply with CCPA and COPPA for all child-directed games; obtain parental consent for selling/sharing data of children under 13 and opt-in consent for 13-16 year olds; provide just-in-time notices for children's data sales/sharing; use neutral age screens; properly configure third-party SDKs; implement an SDK governance framework; follow advertising laws for minors; and implement a compliance monitoring program with annual reporting to the California DOJ and LA City Attorney’s Office.

Monetary PenaltyInjunctionConsent DecreeCompliance ProgramReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements with third-party SDK providers to include mandatory configuration requirements, SDK governance audits, and compliance with children’s privacy laws like COPPA and CCPA. Privacy policies and user agreements for child-directed games must be updated to mandate neutral age screens, just-in-time notices for data collection/sharing, parental consent mechanisms for users under 13, and opt-in consent for users aged 13-16. Additionally, operational agreements should include clauses requiring data minimization for minors, annual compliance reporting to regulators, and internal monitoring programs to ensure adherence to children’s data protection rules.

Contract Search Terms

parental consent mechanismneutral age screenSDK governance frameworkthird-party SDK configurationchildren's data sharingopt-in consent (13-16)just-in-time privacy noticeCOPPA compliance clause

Laws Cited

CCPACOPPA

Violation Types

Entity Details

Entity

Tilting Point Media LLC

Industry

Gaming

Official Sources

Source Evidence

Entity Name
"Tilting Point Media LLC"
Fine Amount
"$500,000 in civil penalties"
Laws Cited
"California Consumer Privacy Act (CCPA)"
Laws Cited
"Children’s Online Privacy Protection Act (COPPA)"
Violation Types
"collecting and sharing children’s data without parental consent"
Violation Types
"Tilting Point’s age screen did not ask age in a neutral manner"

Related Enforcement Actions

CA

Tilting Point Media LLC

$500K

Tilting Point Media LLC illegally collected and shared children's personal data in its mobile app game 'SpongeBob: Krusty Cook-Off' without parental consent, violating COPPA and CCPA. The settlement imposes a $500,000 civil penalty and injunctive terms to ensure compliance with children's data privacy laws.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.