Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CPPAGuidance

Data brokers (unspecified - advisory applies to all businesses registered with California's data broker registry)

CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.

LowData Broker Non-ComplianceNotice Failure
CPPAAdministrative Order

SalesIntel Research, Inc.

The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.

LowData Broker Non-Compliance

$36K

CPPARegulatory Report

Data brokers registered on California's DROP platform (654)

The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.

LowData Broker Non-Compliance
CPPAAdministrative Order

Cybba, Inc.

The California Privacy Protection Agency Board issued an Order of Decision and Stipulated Final Order requiring Boston-based data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the Agency's Data Broker Registry by the 2025 deadline, as required by the Delete Act. The order also requires Cybba to post metrics about privacy rights on its website, access the Agency's Delete Request and Opt-Out Platform (DROP), and process future deletion requests through that system. This is CalPrivacy's second data broker enforcement action announced in less than a week, following its action against LocateSmarter.

LowData Broker Non-Compliance

$52K

CPPAAdministrative Order

LocateSmarter LLC

The California Privacy Protection Agency Board issued a decision and stipulated order requiring Iowa data broker LocateSmarter LLC to pay $116,490 and change its practices. The company failed to timely register as a data broker and unlawfully required Californians to provide the last four digits of their Social Security numbers before exercising opt-out rights, violating the CCPA's data minimization requirements. This is the first action against a data broker under both the CCPA and the Delete Act.

MediumData Broker Non-ComplianceOpt-Out FailureNotice Failure

$116K

CPPARegulatory Report

California Privacy Protection Agency

The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.

LowData Broker Non-Compliance
CPPASettlement

General Motors

CalPrivacy and the California Attorney General secured a $12.75 million settlement from General Motors for data sharing practices from connected vehicles. The settlement includes injunctive terms to change business practices.

CriticalUnauthorized Data Sharing

$12.8M

CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.

LowData Broker Non-Compliance
CPPASettlement

Ford Motor Company(Ford)

The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.

MediumOpt-Out Failure

$376K

CPPASettlement

PlayOn Sports

The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.

HighOpt-Out FailureNotice FailureChildren's Data

$1.1M

CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.

Low
CPPAAdministrative Order

Rickenbacher Data LLC, d/b/a Datamasters(Datamasters)

Datamasters, a data broker, failed to register with the California Data Broker Registry as required by the Delete Act. The company sold sensitive personal information including health conditions, age, race, and political views. As a result, it must pay a $45,000 fine and cease all sales of Californians' personal information.

LowData Broker Non-Compliance

$45K

CPPAFine

ROR Partners LLC(ROR Partners)

The California Privacy Protection Agency fined ROR Partners LLC $56,600 for failing to register as a data broker under the Delete Act. The marketing firm sold custom audience lists built from consumer data without registration, highlighting that businesses collecting and selling personal information must comply with data broker requirements.

LowData Broker Non-Compliance

$57K

CPPAEnforcement Action

Data Brokers

The California Privacy Protection Agency (CalPrivacy) announced the creation of a Data Broker Enforcement Strike Force to investigate privacy violations by data brokers. The strike force will focus on compliance with the Delete Act's registration requirement and the CCPA, building on previous enforcement actions. This initiative aims to hold data brokers accountable and protect Californians' personal information.

LowData Broker Non-Compliance
CPPASettlement

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) settled with Tractor Supply Company for $1.35 million over violations of the California Consumer Privacy Act (CCPA). The violations included failing to maintain a proper privacy policy, not notifying job applicants of their rights, lacking an effective opt-out mechanism, and sharing personal information without adequate contracts. Tractor Supply must pay the fine and implement remedial measures such as scanning digital properties and annual compliance certification.

HighNotice FailureOpt-Out FailureUnauthorized Data Sharing

$1.4M

CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) announced the approval of final regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), insurance companies, and updates to existing CCPA regulations. The regulations go into effect January 1, 2026, with phased compliance deadlines for businesses based on revenue and type of requirement.

LowAI/Automated DecisionsSecurity Failure
CPPAEnforcement ActionMultistate

Multiple businesses(Multiple Businesses)

The California Privacy Protection Agency, together with the Attorneys General of California, Colorado, and Connecticut, announced an investigative sweep targeting businesses that fail to honor Global Privacy Control (GPC) signals, which automatically communicate consumers' opt-out requests. The coalition is contacting identified businesses and demanding immediate compliance with state privacy laws. This coordinated effort highlights the states' commitment to enforcing consumers' right to opt-out of the sale of their personal information.

LowOpt-Out Failure
CPPAEnforcement Action

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) filed a petition in Superior Court to enforce a subpoena against Tractor Supply Company for alleged CCPA violations, including failure to honor consumers' right to opt-out of the sale and sharing of personal information. This is the CPPA's first judicial action to enforce an investigative subpoena, and the agency is seeking court assistance to compel the company's compliance.

LowOpt-Out Failure
CPPAFine

Accurate Append, Inc.(Accurate Append)

The California Privacy Protection Agency (CPPA) ordered Accurate Append, Inc. to pay a $55,400 fine for failing to register as a data broker under the Delete Act by the January 31, 2024 deadline. The company registered only after being contacted during an enforcement sweep and agreed to injunctive terms, including paying attorney fees for future non-compliance.

LowData Broker Non-Compliance

$55K

CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) submitted a letter to the House Energy & Commerce Committee opposing a provision in the Committee's budget reconciliation bill that would impose a 10-year moratorium on enforcement of state artificial intelligence and automated decisionmaking technology (ADMT) laws and regulations. The CPPA argues that the moratorium threatens critical consumer protections approved by California voters under the CCPA, including regulations governing consumers' access and opt-out rights related to businesses' use of ADMT.

LowAI/Automated Decisions
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) opened a formal public comment period on modifications to proposed regulations for CCPA updates, cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance companies. The modifications were approved unanimously during the May 1 Board Meeting, and comments are accepted until June 2, 2025.

LowNotice FailureConsent FailureSecurity Failure
CPPAFine

Jerico Pictures, Inc.(National Public Data)

The California Privacy Protection Agency (CPPA) ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under California's Delete Act. The order was issued by default after the company did not contest the allegations. This enforcement action highlights the CPPA's efforts to ensure data broker compliance with registration laws.

LowData Broker Non-Compliance

$46K

CPPAFine

Jerico Pictures, Inc., d/b/a National Public Data(National Public Data)

The California Privacy Protection Agency ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under the Delete Act. The order was issued by default after the company did not contest the allegations, highlighting CPPA's enforcement of data broker registration requirements.

LowData Broker Non-Compliance

$46K

CPPAAdministrative Order

Todd Snyder, Inc.(Todd Snyder)

The California Privacy Protection Agency (CPPA) settled with Todd Snyder, Inc. for violating the California Consumer Privacy Act (CCPA) by failing to process opt-out requests, requiring excessive information for privacy requests, and improperly verifying identities for opt-outs. The company must pay a $345,178 fine and overhaul its privacy practices, including configuring opt-out mechanisms and providing employee training.

MediumOpt-Out Failure

$345K

CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) and the UK Information Commissioner's Office (UK ICO) signed a declaration of cooperation to coordinate international privacy and data protection efforts. The agreement facilitates joint research, sharing of best practices, and mutual collaboration on privacy enforcement across jurisdictions.

Low
CPPACoalitionMultistate

Consortium of Privacy Regulators (California, Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon)

Eight state regulators, including the California Privacy Protection Agency and attorneys general from seven states, formed the bipartisan Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. The group aims to share expertise, resources, and coordinate investigations to protect consumer privacy across jurisdictions.

Low
CPPASettlement

American Honda Motor Co.(Honda)

The California Privacy Protection Agency settled with American Honda Motor Co. for CCPA violations, including making it difficult for consumers to opt-out of data sharing, using dark patterns in its privacy tool, hindering authorized agent requests, and sharing data with ad tech companies without proper contracts. Honda must pay a $632,500 fine, implement new processes for privacy requests, certify compliance, train employees, and ensure appropriate data sharing contracts.

MediumOpt-Out FailureDark PatternsConsent Failure

$633K

CPPASettlement

Background Alert, Inc.(Background Alert)

The California Privacy Protection Agency settled with data broker Background Alert, Inc. for failing to register and pay fees under the Delete Act. The company must shut down its operations through 2028 or face a $50,000 fine. This action is part of a broader enforcement sweep against non-compliant data brokers.

LowData Broker Non-Compliance
CPPAEnforcement Action

Jerico Pictures, Inc.(Jerico Pictures)

The California Privacy Protection Agency (CPPA) filed an administrative action against Jerico Pictures, Inc., doing business as National Public Data, for failing to register and pay the required annual fee under the California Delete Act. The action seeks a $46,000 fine for the company's 230-day late registration, as part of CPPA's enforcement sweep against data brokers.

LowData Broker Non-Compliance

$46K

CPPAAdministrative Order

Jerico Pictures, Inc., d/b/a National Public Data(National Public Data)

The California Privacy Protection Agency (CPPA) filed an administrative action against National Public Data, a Florida-based data broker, for failing to register and pay the required annual fee under California's Delete Act. The agency is seeking a $46,000 fine for the violation, which occurred 230 days late, as part of an enforcement sweep targeting non-compliant data brokers.

LowData Broker Non-Compliance

$46K

Explore Enforcement Data