Back to Blog
GuidesMarch 28, 202613 min readReviewed by the PrivacyLawMap editorial teamLast reviewed July 22, 2026

CCPA Penalties & Fines 2026: Amounts, Recent Cases, and Multi-State Enforcement

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

CCPA Penalties and Fines at a Glance

CCPA penalty amounts (Cal. Civ. Code § 1798.155):

  • $2,500 per unintentional violation of the CCPA/CPRA.
  • $7,500 per intentional violation or any violation involving a consumer under 16.
  • Statutory damages of $100–$750 per consumer per incident (private right of action, data-breach context only, Cal. Civ. Code § 1798.150).
  • Penalties are assessed per violation — typically per affected consumer — and no cure period has been available since January 1, 2023 (CPRA eliminated the 30-day cure that existed under original CCPA).

Who enforces: the California Privacy Protection Agency (CPPA) has primary administrative authority; the California Attorney General retains parallel civil enforcement authority under § 1798.155.

Recent headline fines (2025–2026):

  • Tractor Supply — $1.35 million (CPPA, Sept 30, 2025) — largest CPPA administrative fine to date.
  • Disney — $2.75 million settlement (CA AG, February 2026).
  • PlayOn Sports — $1.1 million (CPPA, March 2026) — student data and dark patterns.
  • Ford Motor Company — $375,703 (CPPA, March 2026) — opt-out friction.

See our live CCPA & CPRA Penalties Tracker for every fine since 2019 with primary-source citations, or our California CCPA/CPRA state page for the full compliance profile. The rest of this guide walks through how penalties compare across all 20 state privacy laws, what recent enforcement actually looks like, and how to minimize risk.

What Are the Penalties for Violating State Privacy Laws?

US state privacy laws carry real financial consequences. In Q1 2026 alone, California regulators issued over $4 million in fines across three enforcement actions (Disney $2.75M, PlayOn Sports $1.1M, Ford $375,703). And California is no longer the only state with teeth — Texas ($1.375B Google settlement in May 2025, $1.4B Meta settlement), Connecticut ($85K TicketNetwork settlement, July 2025), and Massachusetts ($515K Transformative Healthcare, January 2026) have all produced named-company settlements. Oregon and Colorado have moved to active enforcement postures as their cure periods sunset.

This guide breaks down the penalty structures across all 20 state privacy laws, shows you what recent enforcement looks like in practice, and explains how to minimize your risk.

Penalty Amounts by State

Every state privacy law establishes per-violation penalties enforced by the state Attorney General (or, in California’s case, also the CPPA). Here’s how they compare:

StateMax Penalty Per ViolationCure PeriodEnforcer
California (CCPA/CPRA)$2,500 standard / $7,500 intentional or involving minorsNone (eliminated)AG + CPPA
Virginia (VCDPA)$7,50060 daysAG
Colorado (CPA)$20,000 (under CCPA provisions)60 days (sunsets Jan 2025)AG
Connecticut (CTDPA)$5,000 (CUTPA penalties)60 days (sunsets Dec 2024)AG
Utah (UCPA)$7,50030 daysAG
Texas (TDPSA)$7,50030 daysAG
Oregon (OCPA)$7,500None (expired Jan 2026)AG
Montana (MCDPA)$7,500None (expired Oct 2025)AG
Delaware (DPDPA)$10,000Discretionary since Jan 1, 2026 (60 days if offered)AG
Iowa (ICDPA)$7,50090 daysAG
Nebraska (NDPA)$7,50030 daysAG
New Hampshire (NHPA)$10,000Discretionary since Jan 1, 2026 (60 days if offered)AG
New Jersey (NJDPA)$10,000 first / $20,000 subsequentNo mandatory cure since July 2026AG
Tennessee (TIPA)$7,500 (up to $22,500 for willful violations)60 days (permanent)AG
Minnesota (MCDPA)$7,500None (mandatory warning-letter period expired Jan 31, 2026)AG
Maryland (MODPA)$10,000 first / $25,000 subsequent60 daysAG
Indiana (ICDPA)$7,50030 daysAG
Kentucky (KCDPA)$7,50030 daysAG
Rhode Island (RIDTPPA)$10,000NoneAG
Oklahoma (OKCDPA)$7,50030 daysAG

Texas correction source: the Texas Attorney General TDPSA overview states the civil penalty is up to $7,500 per violation after the 30-day cure period (retrieved May 18, 2026).

New Hampshire cure-period source: RSA 507-H:11(II)–(III) made notice and a 60-day cure mandatory only through December 31, 2025. Beginning January 1, 2026, the Attorney General may offer that opportunity after considering statutory factors (retrieved July 22, 2026).

Other 2026 cure-period sources: Delaware Code title 6, § 12D-111 and the New Jersey Division of Consumer Affairs FAQ (retrieved July 22, 2026).

Key takeaway: Penalties are assessed per violation, which typically means per affected consumer per violation. A single compliance failure affecting thousands of consumers can quickly escalate into millions of dollars.

Real Enforcement Cases: What Fines Actually Look Like

Understanding the penalty ranges on paper is one thing — seeing how regulators actually apply them tells the real story. Visit our Enforcement Actions Tracker for the complete database. Here are the most notable cases from early 2026:

Disney — $2.75 Million (February 2026)

The Walt Disney Company settled a CCPA class action for $2.75 million related to data collection and sharing practices across its digital properties. The case alleged Disney failed to provide adequate notice of data collection and did not honor opt-out requests consistently across its streaming and theme park platforms.

PlayOn Sports — $1.1 Million (March 2026)

The CPPA fined PlayOn Sports $1.1 million for CCPA violations involving student data. PlayOn’s GoFan digital ticketing platform, used by roughly 1,400 California schools, required students to agree to tracking before they could access their purchased tickets. The CPPA found this constituted an illegal dark pattern that coerced consent and used student data for targeted advertising.

Ford Motor Company — $375,703 (March 2026)

Ford was fined for adding unnecessary friction to the opt-out process by requiring email verification before consumers could exercise their right to opt out. The CPPA ruled that requiring email confirmation created an unlawful barrier to opt-out rights under CCPA regulations.

Comstar — Multi-State Settlement (Q1 2026)

In a landmark multi-state action, Comstar settled privacy violations with attorneys general from multiple states simultaneously, setting a precedent for coordinated enforcement. This signals that businesses can expect enforcement pressure from multiple states at once for the same conduct.

Which States Are Most Aggressive?

Not all states enforce with equal intensity. Here’s the current enforcement landscape:

  • California — By far the most active, with the dedicated CPPA and the AG’s office both pursuing cases. California has issued millions in fines and doesn’t offer a cure period.
  • Texas — Attorney General Ken Paxton has been aggressive on privacy enforcement. TDPSA penalties reach $7,500 per violation after the 30-day cure period, while separate Texas privacy statutes have driven major cases including a $1.4 billion settlement with Meta over biometric data.
  • Connecticut — Actively conducting GPC enforcement sweeps alongside California and Colorado.
  • Oregon — Eliminated its cure period in January 2026, signaling a shift toward active enforcement.
  • Colorado — Participating in multi-state GPC compliance checks. Colorado’s 60-day cure period sunset January 1, 2025; per-violation penalties run to $20,000 (or $50,000 when paired with a deceptive trade practice), and the AG publishes the official approved-UOOM list.

Cure Periods: Your Window to Fix Issues

Many states offer a “cure period” — a window of time after notification of a violation during which you can fix the issue and avoid penalties. However, these windows are shrinking:

  • California eliminated its cure period entirely.
  • Oregon’s cure period expired January 1, 2026.
  • Colorado’s cure period sunset in January 2025.
  • Connecticut’s cure period was removed via SB 1295 amendments.
  • Delaware’s cure period sunset in December 2025.
  • New Hampshire’s mandatory cure period ended December 31, 2025.
  • New Jersey’s mandatory cure period ended in July 2026.
  • Rhode Island never had one.

The trend is unmistakable: cure periods are being eliminated across the board. Waiting for a violation notice before addressing compliance gaps is an increasingly dangerous strategy.

How to Minimize Your Penalty Risk

  1. Know which laws apply to you — Use our Privacy Law Calculator to check your exposure across all 20 states.
  2. Implement GPC compliance — GPC non-compliance is the most common enforcement trigger in 2026. Use our GPC Compliance Checker to verify your status.
  3. Eliminate dark patterns — Don’t make it harder to opt out than to opt in. The CPPA specifically targets interfaces that discourage consumers from exercising their rights.
  4. Handle consumer requests promptly — Respond within 45 days, verify identity without friction, and document everything.
  5. Conduct data protection assessments — Required in many states for high-risk processing activities. Having documented assessments demonstrates good faith.
  6. Review vendor agreements — Ensure your data processing agreements with third parties include proper privacy protections and flow-down requirements.
  7. Train your team — The employees who interact with consumer data or handle requests must understand their obligations.
  8. Monitor deadlines — New requirements and cure period expirations happen regularly. Track them with our Compliance Deadlines Calendar.

Private Right of Action: Can Consumers Sue You Directly?

Most state privacy laws do not grant a private right of action — only the Attorney General (or CPPA in California) can bring enforcement actions. However, California is the major exception: the CCPA allows private lawsuits for data breaches involving non-encrypted or non-redacted personal information, with statutory damages of $100 to $750 per consumer per incident. This means a breach affecting 100,000 California consumers could expose you to $10–$75 million in statutory damages alone, before actual damages.

The Bottom Line

State privacy law penalties are real, growing, and increasingly coordinated across state lines. The era of warnings and gentle nudges is ending as cure periods expire and enforcement budgets expand. The businesses that fare best are those that treat compliance as a continuous process rather than a one-time project. Start by understanding your obligations with our Privacy Law Calculator, then work through the relevant state compliance checklists to close any gaps before regulators come calling.

Frequently Asked Questions

What are the penalties for violating the CCPA?

Under Cal. Civ. Code § 1798.155, the CCPA/CPRA imposes $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving a consumer under 16. Penalties are assessed per violation, which typically means per affected consumer. A single configuration failure affecting 100,000 Californians exposes a business to $250 million in statutory maximums before any negotiated reduction. The CPPA and the California Attorney General share enforcement authority. No cure period has been available since January 1, 2023. Source: California Civil Code § 1798.155 (retrieved April 24, 2026).

What are the largest CCPA fines so far?

As of June 2026, the largest publicly announced CCPA/CPRA enforcement outcomes are: General Motors — $12.75 million (California AG, four District Attorneys, and CalPrivacy, May 2026, connected-vehicle data sales and data minimization per the California AG announcement, retrieved June 1, 2026); Disney — $2.75 million (California AG settlement, February 2026); Healthline — $1.55 million (California AG settlement, July 2025); Jam City — $1.4 million (California AG settlement, November 2025); Tractor Supply — $1.35 million (CPPA administrative fine, September 30, 2025, for ineffective opt-out mechanisms and failure to honor opt-out preference signals per the CPPA announcement, retrieved April 24, 2026); Sephora — $1.2 million (California AG, August 2022); and PlayOn Sports — $1.1 million (CPPA, March 2026). Non-CCPA-specific privacy settlements involving California data have been larger still — Meta’s $725M class-action settlement (2023) and the Texas / multi-state biometric settlements run into the billions, but those are not CCPA penalties proper.

When did CPRA enforcement actually begin?

The CPRA’s operational date was January 1, 2023, and the CPPA was statutorily authorized to begin administrative enforcement on July 1, 2023. A June 2023 Sacramento Superior Court ruling (California Chamber of Commerce v. CPPA) briefly delayed enforcement of newly finalized CPPA regulations until March 29, 2024, one year after each regulation’s final adoption. The California Court of Appeal reversed that decision in February 2024, and the CPPA has since accelerated administrative enforcement — the Tractor Supply decision (September 2025) was its first major administrative penalty, followed by Ford and PlayOn Sports in March 2026. The AG’s parallel civil-enforcement authority has been active since July 1, 2020 (original CCPA enforcement start).

What are the CPRA fines compared to the CCPA’s original penalties?

CPRA did not change the per-violation penalty amounts — they remain $2,500 / $7,500 as set by original CCPA. What CPRA changed is procedural: it eliminated the 30-day cure period (effective January 1, 2023), created the CPPA as a dedicated enforcement agency with its own administrative adjudication process, and expanded the definition of what counts as an intentional violation (for example, any violation involving the sensitive data of a consumer under 16 is automatically treated as intentional for penalty purposes). In practice this means CPRA-era penalties land harder even though the statutory maximums are identical to the 2018 law.

What are the penalties for non-compliance with the CCPA if I’m a small business?

The CCPA only applies to for-profit businesses that meet at least one of three thresholds: (a) $25M+ annual gross revenue, (b) buy, sell, or share personal information of 100,000+ California consumers or households, or (c) derive 50%+ of annual revenue from selling or sharing California consumers’ personal information. If you meet none of these, CCPA penalties do not apply to your business — though 19 other state privacy laws have lower thresholds (Delaware at 35,000 consumers, for example). Use our Privacy Law Calculator to check exposure across all 20 state laws.

Can consumers sue directly for CCPA violations?

Only in a narrow case: Cal. Civ. Code § 1798.150 provides a private right of action exclusively for data breaches involving non-encrypted and non-redacted personal information where the breach resulted from a failure to implement reasonable security procedures. Statutory damages are $100–$750 per consumer per incident, or actual damages, whichever is greater. Non-breach CCPA violations (failure to honor opt-out, inadequate privacy notice, dark patterns) are not actionable by private plaintiffs — only the CPPA and the Attorney General can bring those cases.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 28, 2026. Last verified: July 22, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly