Penalty Amount
$345,178
The California Privacy Protection Agency (CPPA) settled with Todd Snyder, Inc. for violating the California Consumer Privacy Act (CCPA) by failing to process opt-out requests, requiring excessive information for privacy requests, and improperly verifying identities for opt-outs. The company must pay a $345,178 fine and overhaul its privacy practices, including configuring opt-out mechanisms and providing employee training.
Todd Snyder must pay a $345,178 fine, properly configure its systems to handle opt-out requests, and implement CCPA compliance training for employees.
In-house legal teams should review all agreements involving personal data handling, such as vendor contracts, customer terms of service, and employee privacy policies. Focus on clauses governing data sharing, consumer opt-out rights, privacy request procedures, and identity verification standards. Ensure that contracts require compliance with CCPA, including proper configuration of opt-out mechanisms, prohibition on excessive information collection for privacy requests, and appropriate verification methods that do not override opt-out rights. Additionally, include provisions for regular employee training on privacy compliance and audit rights to monitor adherence.
Entity
Todd Snyder, Inc.
Also known as: Todd Snyder
Industry
RetailOfficial Press Release
https://privacy.ca.gov/2025/05/cppa-orders-clothing-retailer-todd-snyder-to-pay-six-figure-fine-overhaul-privacy-practices/
20250501 snyder order
https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/20250501_snyder_order.pdf
California Privacy Protection Agency Enforcement Page
https://cppa.ca.gov/enforcement/
CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.
$36K
The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.
The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.
$52K
The California Privacy Protection Agency Board issued an Order of Decision and Stipulated Final Order requiring Boston-based data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the Agency's Data Broker Registry by the 2025 deadline, as required by the Delete Act. The order also requires Cybba to post metrics about privacy rights on its website, access the Agency's Delete Request and Opt-Out Platform (DROP), and process future deletion requests through that system. This is CalPrivacy's second data broker enforcement action announced in less than a week, following its action against LocateSmarter.
$116K
The California Privacy Protection Agency Board issued a decision and stipulated order requiring Iowa data broker LocateSmarter LLC to pay $116,490 and change its practices. The company failed to timely register as a data broker and unlawfully required Californians to provide the last four digits of their Social Security numbers before exercising opt-out rights, violating the CCPA's data minimization requirements. This is the first action against a data broker under both the CCPA and the Delete Act.
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.