1,509 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,509
Total Actions
16
Jurisdictions
$26.6B+
Total Fines Tracked
Governor Newsom signed the California Opt Me Out Act (AB 566), requiring browsers to offer built-in opt-out preference signals (OOPS) by January 2027. This makes California the first state to mandate that browsers provide easy-to-use tools for consumers to automatically communicate their privacy preferences to websites, closing a major gap in CCPA enforcement.
Minnesota and New Hampshire joined the Consortium of Privacy Regulators, a bipartisan group of state privacy enforcers. The consortium coordinates enforcement of state privacy laws, which share common features like consumer rights to access, delete, and opt out of data sales. The CPPA also highlighted recent enforcement actions against Tractor Supply Company, Todd Snyder, American Honda, and data broker Background Alert.
California Attorney General Rob Bonta filed a lawsuit against the City of El Cajon for unlawfully sharing Automated License Plate Reader (ALPR) data with over 100 out-of-state law enforcement agencies, violating state law that restricts such data to California public agencies. The AG is seeking a court order to halt the sharing and compel compliance with state privacy protections.
The California Legislature passed AB 566, the California Opt Me Out Act, which will require browsers to support opt-out preference signals (OOPS), allowing consumers to easily limit the sale and sharing of their personal information. The bill now heads to the Governor for signature. The CPPA commended the legislature for this action.
On May 1, 2025, the CPPA Board voted to support four California bills that expand privacy protections, including restrictions on location data, neural data protections, data broker disclosure requirements, and teleconference meeting provisions. The Board also took a 'support if amended' position on an AI security bill. This is a legislative support action, not an enforcement action.
The California Privacy Protection Agency (CPPA) opened a public comment period for proposed Delete Request and Opt-out Platform (DROP) regulations, which will allow California residents to delete their personal information held by CPPA-registered data brokers in a single request. The comment period runs from April 25 to June 10, 2025, with a hybrid public hearing on June 10.
The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.
In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.
All data sourced from official government enforcement pages.