Penalty Amount
$345,178
The California Privacy Protection Agency (CPPA) settled with Todd Snyder, Inc. for violating the California Consumer Privacy Act (CCPA) by failing to process opt-out requests, requiring excessive information for privacy requests, and improperly verifying identities for opt-outs. The company must pay a $345,178 fine and overhaul its privacy practices, including configuring opt-out mechanisms and providing employee training.
Todd Snyder must pay a $345,178 fine, properly configure its systems to handle opt-out requests, and implement CCPA compliance training for employees.
In-house legal teams should review all agreements involving personal data handling, such as vendor contracts, customer terms of service, and employee privacy policies. Focus on clauses governing data sharing, consumer opt-out rights, privacy request procedures, and identity verification standards. Ensure that contracts require compliance with CCPA, including proper configuration of opt-out mechanisms, prohibition on excessive information collection for privacy requests, and appropriate verification methods that do not override opt-out rights. Additionally, include provisions for regular employee training on privacy compliance and audit rights to monitor adherence.
Entity
Todd Snyder, Inc.
Also known as: Todd Snyder
Industry
RetailOfficial Press Release
https://privacy.ca.gov/2025/05/cppa-orders-clothing-retailer-todd-snyder-to-pay-six-figure-fine-overhaul-privacy-practices/
20250501 snyder order
https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/20250501_snyder_order.pdf
California Privacy Protection Agency Enforcement Page
https://cppa.ca.gov/enforcement/
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.
The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.
$376K
The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.
$1.1M
The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.
$45K
Datamasters, a data broker, failed to register with the California Data Broker Registry as required by the Delete Act. The company sold sensitive personal information including health conditions, age, race, and political views. As a result, it must pay a $45,000 fine and cease all sales of Californians' personal information.