Court Rules

Privacy Enforcement Tracker

1,338 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,338

Total Actions

14

Jurisdictions

$50.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CASettlement

Ford Motor Company

The California Privacy Protection Agency (CalPrivacy) settled with Ford Motor Company requiring the company to pay a $375,703 fine and change its practices. Ford violated the CCPA by requiring consumers to complete an email verification step before they could opt-out of the sale and sharing of their personal information collected through digital properties and connected vehicle services. In addition to the fine, Ford must provide easy methods to submit opt-out requests with minimal steps, audit its tracking technologies, and ensure compliance with opt-out preference signals including Global Privacy Control.

MediumOpt-Out Failure

$376K

CASettlement

The Walt Disney Company(Disney)

California Attorney General Rob Bonta announced a $2.75 million settlement with The Walt Disney Company, the largest CCPA settlement in state history, resolving allegations that Disney violated the CCPA by failing to fully honor consumers’ opt-out requests for the sale or sharing of their personal data across all devices and streaming services linked to their accounts. Disney’s opt-out methods, including in-app toggles, webforms, and Global Privacy Control implementation, had gaps that allowed continued data sale or sharing even after consumers opted out. Under the settlement, Disney must pay the civil penalty and implement comprehensive opt-out methods that fully cease all sale or sharing of consumer data upon request.

HighOpt-Out Failure

$2.8M

CASettlement

Jam City, Inc.(Jam City)

California Attorney General Rob Bonta announced a $1.4 million settlement with mobile gaming company Jam City, Inc. for violating the CCPA by failing to provide consumers with compliant methods to opt out of the sale or sharing of their personal information across its 21 mobile apps. The settlement also resolves allegations that Jam City sold or shared personal data of users aged 13 to 16 without the required affirmative opt-in consent. In addition to the civil penalty, Jam City must implement in-app opt-out methods and obtain opt-in consent for minor users' data sales and sharing.

HighOpt-Out FailureChildren's Data

$1.4M

CASettlement

Sling TV LLC(Sling TV)

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

MediumOpt-Out FailureChildren's Data

$530K

CASettlement

Sling TV LLC and Dish Media Sales LLC(Sling TV)

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the CCPA by failing to provide an easy-to-use opt-out mechanism for the sale of personal information and insufficient privacy protections for children. The settlement, subject to court approval, requires Sling TV to implement streamlined opt-out processes across all devices, stop redirecting users to cookie preferences for CCPA opt-outs, and add kid-specific profiles with default opt-out of data sales and targeted advertising. This is the first enforcement action from the DOJ's 2024 investigative sweep of streaming services.

MediumOpt-Out FailureChildren's DataConsent Failure

$530K

CASettlement

Healthline Media LLC(Healthline)

California Attorney General Rob Bonta announced a $1.55 million settlement with health information website publisher Healthline Media LLC, resolving allegations that the company violated the CCPA and Unfair Competition Law. Violations included failing to honor consumer opt-out requests, sharing sensitive health data with third parties without required privacy protections, and using deceptive consent banners that did not disable tracking cookies. The settlement imposes injunctive terms, compliance requirements, and a civil penalty, marking the largest CCPA settlement to date.

HighOpt-Out FailureUnauthorized Data SharingHealth Data

$1.6M

CASettlement

DoorDash

California Attorney General Rob Bonta announced a settlement with DoorDash resolving allegations that the company violated the CCPA and CalOPPA by selling California consumers' personal information to a marketing cooperative without required notice or an opt-out mechanism. DoorDash disclosed consumers' names, addresses, and transaction histories to the cooperative, failing to disclose this practice in its privacy policy as required by CalOPPA. The settlement requires DoorDash to pay a $375,000 civil penalty and comply with injunctive terms including vendor contract reviews and annual reporting to the AG.

MediumOpt-Out FailureNotice Failure

$375K

CASettlement

Google

California Attorney General Rob Bonta announced a $93 million settlement with Google resolving allegations that the company violated state consumer protection laws through deceptive location-privacy practices. Google was accused of falsely telling users that turning off the “Location History” setting would stop location data collection, while continuing to collect and use location data for user profiling and targeted advertising without informed consent. In addition to the monetary penalty, Google must implement several injunctive measures to increase transparency and user control over location tracking.

CriticalConsent FailureOpt-Out FailureGeolocation Data

$93.0M

CASettlement

Sephora, Inc.(Sephora)

California Attorney General Rob Bonta announced a settlement with Sephora, Inc. resolving allegations that the company violated the California Consumer Privacy Act (CCPA) by failing to disclose it was selling consumers' personal information and failing to process opt-out requests via user-enabled Global Privacy Controls. Sephora agreed to pay $1.2 million in penalties and implement injunctive measures including updating privacy disclosures, enabling opt-out via GPC, conforming service provider agreements to CCPA, and reporting to the AG. The settlement is part of ongoing CCPA enforcement efforts, with the AG also issuing cure notices to other businesses failing to honor GPC opt-out signals.

HighOpt-Out FailureNotice Failure

$1.2M

CASettlementMultistate

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

HighNotice FailureConsent FailureOpt-Out Failure

$3.5M

Explore Enforcement Data