Penalty Amount
$632,500
The California Privacy Protection Agency settled with American Honda Motor Co. for CCPA violations, including making it difficult for consumers to opt-out of data sharing, using dark patterns in its privacy tool, hindering authorized agent requests, and sharing data with ad tech companies without proper contracts. Honda must pay a $632,500 fine, implement new processes for privacy requests, certify compliance, train employees, and ensure appropriate data sharing contracts.
Honda must pay a $632,500 fine, cease violative practices, implement a simpler process for privacy rights requests, certify compliance, train employees, consult a UX designer to evaluate methods, and change contracting processes to protect personal information.
In-house legal teams should review vendor agreements, particularly those involving data sharing with ad tech companies, to ensure they contain robust data protection clauses, clear opt-out mechanisms, and provisions for authorized agent requests. Customer agreements must be assessed for CCPA compliance, avoiding dark patterns in privacy tools and ensuring symmetrical presentation of opt-out and limit choices. Data processing addendums may require updates to include specific terms for personal information sharing. Changes could involve adding mandatory contract terms for third-party data transfers, implementing simplified privacy request processes, incorporating user experience evaluations, and embedding compliance certifications and employee training obligations.
Entity
American Honda Motor Co.
Also known as: Honda
Industry
AutomotiveThe California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.
The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.
$376K
The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.
$1.1M
The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.
$45K
Datamasters, a data broker, failed to register with the California Data Broker Registry as required by the Delete Act. The company sold sensitive personal information including health conditions, age, race, and political views. As a result, it must pay a $45,000 fine and cease all sales of Californians' personal information.