CCPA · CPPA ENFORCEMENT · GLOBAL PRIVACY CONTROL
California isn’t warning businesses anymore. It’s fining them.
The CCPA gave California consumers the right to opt out of the sale and sharing of their data, meanwhile CalPrivacy and Attorney General have spent the last two years proving they will enforce it. Settlements have run from six figures to over $12 million. We wire the opt-outs, GPC handling and vendor contracts a regulator actually checks for. Get a demo of our CCPA privacy software solutions.
Six enforcement actions. Under 24 months. Over $20M combined.
The California AG and the CPPA have both moved from warnings to fines. Here is what regulators have actually collected recently for CCPA violations.
Unlawfully collected and sold sensitive driving behavior and precise location data to data brokers and credit bureaus without explicit consent.
Opt-out requests failed to propagate across multi-device accounts, and certain mobile apps had no in-app opt-out mechanism.
Shared article-level health diagnosis data with third-party ad trackers; tracking pixels kept firing after users opted out.
Webform opt-outs didn’t stop ad-tracking sales, Global Privacy Control signals were ignored, and vendor contracts lacked required CCPA terms.
Sold user data via advertising trackers and required consumers to accept tracking as a condition of using the ticketing platform.
Imposed excessive friction, redundant steps and unnecessary identity verification on consumers exercising their privacy rights.
The pattern behind every recent fine.
Ad and analytics trackers that keep firing after a “Do Not Sell/Share” click are treated as an ongoing unlawful sale.
CPPA and AG auditors actively test sites for the Global Privacy Control signal. Ignoring it is a leading trigger for enforcement.
Geolocation and behavioral data from vehicles and IoT devices carries multi-million dollar liability, as the GM settlement shows.
A banner is not enough. Every downstream vendor and contractor handling consumer data needs a CCPA-compliant data processing agreement.
Compliance a regulator can actually verify.
Recent settlements were not about missing banners. They were about opt-outs that did not work, trackers that kept firing, and vendor contracts that did not exist. We build for the audit, not just the click.
GPC auto-honor
The Global Privacy Control signal is detected and treated as a valid opt-out, no click required.
Do Not Sell / Share
A compliant opt-out flow that suppresses sale and sharing across ad and analytics destinations, verified after the click.
Tracker & pixel audits
We confirm every ad and analytics pixel actually stops firing on opt-out, the exact gap that triggered the Healthline and Tractor Supply settlements.
Vendor contract hygiene
We track which vendors touch consumer data and flag any without a signed, CCPA-compliant data processing agreement.
Rights fulfilment
Access, deletion and correction handled with the 45-day clock and confirmation receipt.
Trust Center
A customer-facing page showing your privacy practices and opt-out choices in one place.
One engine, audited the way regulators audit.
The same opt-out logic, GPC handling and vendor tracking you build for CCPA carries straight over to CPRA’s sensitive-PI rules and the dozen-plus states that followed. Build it once with us.
- Day 1 — Site Inventory; Scoping out and design of assets
- Week 1 — Do-Not-Sell/Share flow wired; cookie consent banner integrated
- Week 2 — DSR portal automation with 45-day clock deployed
- Week 2 — Vendor DPA tracking and notice at collection live
- Ongoing — New CPPA/AG enforcement patterns tracked and applied
What changes when the CCPA program is on.
- “Do Not Sell” is a dead-end footer link
- Trackers keep firing after a consumer opts out
- GPC signals silently ignored
- No record of which vendors have signed a DPA
- Nothing to show a regulator who comes asking
- GPC honored automatically as an opt-out
- Trackers audited and cut off the moment someone opts out
- Vendor DPAs tracked and enforced
- 45-day rights workflow with receipts
- Audit trail ready if the CPPA calls
CCPA enforcement, answered plainly.
What’s the difference between CCPA and CPRA?+
Is California actually enforcing this?+
Are we even in scope?+
Is there a private right of action?+
Don’t be the next enforcement headline.
Honor GPC, audit your trackers, and keep vendor contracts current, all from one central dashboard. Start free.