CCPA Fines & CPRA Penalties Tracker
Search CCPA fines, CPRA penalties, and public US state privacy enforcement actions — California Attorney General settlements, California Privacy Protection Agency (CPPA) orders, Connecticut CTDPA, Texas TDPSA, and FTC COPPA actions. Each row links to the primary-source press release or order.
33 enforcement actions tracked · $3.4B in total penalties
Last updated: 2026-08-13 · Full-dataset review: 2026-06-01 · Latest record check: 2026-08-13 · Statutory fines: $2,500 per unintentional violation, $7,500 per intentional violation or violation involving a minor (Cal. Civ. Code § 1798.155; 2026 CPPA inflation-adjusted ≈ $2,663 / $7,988)
Reviewed by PrivacyLawMap editorial team · Last verified: 2026-08-13
Want to know what staying on the right side of these fines actually costs? Estimate your CCPA compliance cost by company size, applicable states, and DIY-vs-outsourced approach.
For the consumer-right side of these enforcement duties, review the right to be forgotten and US data deletion rights.
How much are CCPA fines and penalties?
As of July 26, 2026, CCPA/CPRA fines are $2,500 per unintentional violation and $7,500 per intentional violation (or any violation involving a consumer under 16), set by California Civil Code § 1798.155 and adjusted for inflation every two years by the California Privacy Protection Agency — approximately $2,663 and $7,988 for 2026. Separately, consumers can sue directly after a qualifying data breach and recover $100 to $750 per consumer per incident in statutory damages under § 1798.150, regardless of proven harm. Because penalties accrue per violation — usually counted per affected consumer or per non-compliant web property — a single practice touching thousands of users can compound into a multi-million-dollar settlement (e.g., General Motors $12.75M in May 2026).
| Violation type | Who recovers it | Amount | Statute |
|---|---|---|---|
| Unintentional violation | CA Attorney General / CPPA | $2,500 per violation (≈ $2,663 in 2026) | § 1798.155 |
| Intentional violation, or any violation involving a minor | CA Attorney General / CPPA | $7,500 per violation (≈ $7,988 in 2026) | § 1798.155 |
| Data breach (private right of action) | Affected consumers, directly | $100–$750 per consumer per incident, or actual damages if greater | § 1798.150 |
Sources: Cal. Civ. Code § 1798.155 (agency penalties) and § 1798.150 (private right of action), California Legislative Information — verified 2026-07-26. 2026 inflation-adjusted amounts per CPPA § 1798.155(b)(3).
$3.4B
Total Penalties
$125.0M
Average Penalty
CA
Most Active Jurisdiction (15 actions)
Children's Privacy Violation
Most Common Violation (3x)
Enforcement by year
| Year | Actions | Total penalties |
|---|---|---|
| 2026 | 8 | $17.6M |
| 2025 | 8 | $1.4B |
| 2024 | 6 | $1.4B |
| 2023 | 5 | $31.3M |
| 2022 | 3 | $276.2M |
| 2021 | 2 | $87.0M |
| 2019 | 1 | $170.0M |
Yearly totals include California CCPA/CPRA actions, other state enforcement (CT CTDPA, TX TDPSA, MA data-breach statute), and federal FTC COPPA/FTC Act matters. Non-monetary consent decrees appear as $0.
Showing 33 of 33 enforcement actions
| Company | Jurisdiction | Date | Violation Type | Penalty Amount | Source |
|---|---|---|---|---|---|
General Motors CCPA / UCL | CA | May 8, 2026 | Driving Data Sale / Data Minimization | $12,750,000 | Link |
Match Group / OkCupid FTC Act Section 5 | US | Mar 30, 2026 | Deceptive Data Sharing with Third-Party AI Firm | Non-monetary | Link |
Ford Motor Company CCPA | CA | Mar 5, 2026 | Adding Unnecessary Friction to Opt-Out Process | $375,703 | Link |
PlayOn Sports (GoFan) CCPA | CA | Mar 3, 2026 | Student Privacy / Failure to Provide Opt-Out | $1,100,000 | Link |
The Walt Disney Company CCPA | CA | Feb 11, 2026 | Failure to Honor Opt-Out Across Services | $2,750,000 | Link |
Comstar (Ambulance Billing) State Data Breach / HIPAA | MA | Jan 28, 2026 | Failure to Implement Adequate Data Security | $515,000 | Link |
Rickenbacher Data LLC (Datamasters) California Delete Act (SB 362) | CA | Jan 8, 2026 | Failure to Register as Data Broker | $45,000 | Link |
S&P Global, Inc. California Delete Act (SB 362) | CA | Jan 8, 2026 | Failure to Register as Data Broker | $62,600 | Link |
Jam City, Inc. CCPA | CA | Nov 21, 2025 | Children's Privacy / Failure to Honor Opt-Out | $1,400,000 | Link |
Sling TV L.L.C. and Dish Media Sales L.L.C. CCPA | CA | Oct 30, 2025 | Opt-Out Friction / Children's Privacy | $530,000 | Link |
Tractor Supply Company CCPA/CPRA | CA | Sep 30, 2025 | Failure to Honor Opt-Out / Privacy Notice Violations | $1,350,000 | Link |
TicketNetwork, Inc. CTDPA | CT | Jul 15, 2025 | Privacy Notice Deficiencies / Inoperable Opt-Out | $85,000 | Link |
Healthline Media LLC CCPA | CA | Jul 1, 2025 | Failure to Honor Opt-Out Requests | $1,550,000 | Link |
Google Texas DTPA | TX | May 9, 2025 | Unauthorized Data Collection | $1,375,000,000 | Link |
American Honda Motor Co. CCPA | CA | Mar 12, 2025 | Opt-Out Friction / Excessive Verification | $632,500 | Link |
Allstate / Arity TDPSA | TX | Jan 13, 2025 | Unauthorized Collection and Sale of Sensitive Geolocation Data | Non-monetary | Link |
Meta (Facebook) Texas CUBI / DTPA | TX | Jul 30, 2024 | Unauthorized Biometric Data Collection | $1,400,000,000 | Link |
NGL Labs (NGL App) COPPA Rule / FTC Act / ROSCA | US | Jul 9, 2024 | Children's Privacy / Dark Patterns | $5,000,000 | Link |
Tilting Point Media CCPA / COPPA | CA | Jun 19, 2024 | Children's Privacy Violation | $500,000 | Link |
Cerebral Inc. FTC Act / ROSCA / OARFPA | US | Apr 15, 2024 | Unauthorized Sharing of Health Data | $7,000,000 | Link |
InMarket Media FTC Act | US | Jan 18, 2024 | Geolocation Data Collection Without Consent | Non-monetary | Link |
X-Mode Social (Outlogic) FTC Act | US | Jan 9, 2024 | Sale of Sensitive Location Data | Non-monetary | Link |
Rite Aid FTC Act | US | Dec 19, 2023 | Facial Recognition Misuse | Non-monetary | Link |
Amazon (Alexa) COPPA | US | May 31, 2023 | Children's Privacy / Voice Data Retention | $25,000,000 | Link |
Amazon (Ring) FTC Act | US | May 31, 2023 | Unauthorized Access to Customer Videos | $5,800,000 | Link |
Easy Healthcare (Premom) FTC Act / Health Breach Notification Rule | US | May 17, 2023 | Unauthorized Sharing of Health Data | $100,000 | Link |
DoorDash CCPA | CA | Jan 10, 2023 | Unauthorized Sale of Personal Information | $375,000 | Link |
Epic Games (Fortnite) COPPA / FTC Act | US | Dec 19, 2022 | Children's Privacy Violation | $275,000,000 | Link |
Kochava Inc. FTC Act | US | Aug 29, 2022 | Sale of Sensitive Geolocation Data | Non-monetary | Link |
Sephora CCPA | CA | Aug 24, 2022 | Failure to Honor Opt-Out | $1,200,000 | Link |
OpenX Technologies COPPA / FTC Act | US | Dec 15, 2021 | Children's Privacy / Geolocation | $2,000,000 | Link |
Zoom Video Communications CCPA / FTC Act | CA | Aug 1, 2021 | Deceptive Security Practices | $85,000,000 | Link |
Google (YouTube) COPPA | US | Sep 4, 2019 | Children's Privacy Violation | $170,000,000 | Link |
General Motors
CCPA / UCL
Driving Data Sale / Data Minimization
California Attorney General Rob Bonta, four California District Attorneys, and CalPrivacy announced a $12.75 million General Motors settlement over allegations that GM sold Californians' OnStar location and driving behavior data to LexisNexis and Verisk in violation of the CCPA and Unfair Competition Law. The settlement bans sales of driving data to consumer reporting agencies for five years and requires a privacy program for OnStar data collection.
View SourceMatch Group / OkCupid
FTC Act Section 5
Deceptive Data Sharing with Third-Party AI Firm
The FTC took action against Match Group Americas and Humor Rainbow, Inc. (operator of OkCupid) for sharing photos, demographic information, and location data of millions of OkCupid users with AI firm Clarifai — a company with which OkCupid had no business relationship — in violation of OkCupid's own privacy policy. The proposed 20-year consent order bars Match and OkCupid from misrepresenting their information practices and the function of privacy controls; no monetary civil penalty was imposed.
View SourceFord Motor Company
CCPA
Adding Unnecessary Friction to Opt-Out Process
The California Privacy Protection Agency (CPPA) fined Ford Motor Company $375,703 for adding unnecessary friction to the consumer opt-out process. Ford required consumers to verify their email address before their opt-out requests would be processed — those who did not click the confirmation link had their requests ignored. This was CalPrivacy's second enforcement action stemming from its connected vehicles investigative sweep. Ford must process all previously unfulfilled opt-out requests, provide compliant opt-out submission methods, audit tracking technologies on its website, and ensure proper handling of opt-out preference signals.
View SourcePlayOn Sports (GoFan)
CCPA
Student Privacy / Failure to Provide Opt-Out
The California Privacy Protection Agency (CPPA) issued a $1.10 million fine against PlayOn Sports, whose GoFan platform sells digital tickets for approximately 1,400 California schools. PlayOn used tracking technologies to deliver targeted ads to ticketholders without providing a sufficient opt-out mechanism, instead directing users to third-party ad industry tools rather than operating its own opt-out. This is the first CPPA enforcement action addressing student privacy violations.
View SourceThe Walt Disney Company
CCPA
Failure to Honor Opt-Out Across Services
California Attorney General Rob Bonta secured the largest CCPA settlement in state history — $2.75 million against Disney for failing to fully effectuate consumer opt-out requests across all streaming services and devices linked to their Disney accounts. When consumers opted out on one Disney streaming app, the opt-out did not carry across to other Disney platforms like Hulu or ESPN+.
View SourceComstar (Ambulance Billing)
State Data Breach / HIPAA
Failure to Implement Adequate Data Security
Massachusetts AG and Connecticut AG jointly settled with Comstar, an ambulance billing vendor, for $515,000 ($415,000 to MA, $100,000 to CT) following a 2022 ransomware attack that exposed the personal and medical information of 585,621 individuals. The company failed to conduct adequate risk assessments and maintain reasonable data security practices. Settlement requires Comstar to implement a comprehensive information security program, appoint a CISO, and maintain compliance documentation.
View SourceRickenbacher Data LLC (Datamasters)
California Delete Act (SB 362)
Failure to Register as Data Broker
The CPPA's Data Broker Enforcement Strike Force fined Rickenbacher Data LLC (d/b/a Datamasters) $45,000 for failing to register as a data broker under the California Delete Act (SB 362). Datamasters bought and resold names, addresses, phone numbers, and email addresses of millions of people with health conditions including Alzheimer's disease and drug addiction for targeted advertising. The company was also ordered to stop selling all Californians' personal information.
View SourceS&P Global, Inc.
California Delete Act (SB 362)
Failure to Register as Data Broker
The CPPA fined S&P Global, Inc. $62,600 for failing to register as a data broker under the California Delete Act (SB 362). The New York-based provider of data and technology failed to register due to an administrative error. After discovering the error, the company promptly registered and agreed to implement procedures to ensure ongoing compliance with California's data broker registration requirements.
View SourceJam City, Inc.
CCPA
Children's Privacy / Failure to Honor Opt-Out
California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, a mobile gaming company, for CCPA violations including lacking opt-out mechanisms in 20 of 21 apps and selling personal information of minors aged 13-16 without obtaining required affirmative authorization.
View SourceSling TV L.L.C. and Dish Media Sales L.L.C.
CCPA
Opt-Out Friction / Children's Privacy
California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV and Dish Media Sales for confusing CCPA opt-out flows, requiring unnecessary webform steps from logged-in users, lacking in-app opt-out methods on living-room devices, and failing to provide sufficient children's privacy protections.
View SourceTractor Supply Company
CCPA/CPRA
Failure to Honor Opt-Out / Privacy Notice Violations
The California Privacy Protection Agency (CPPA) issued its largest monetary penalty to date — $1.35 million against Tractor Supply Company for failing to properly notify consumers and job applicants of their privacy rights, failing to maintain adequate service provider agreements, and failing to provide effective opt-out mechanisms.
View SourceTicketNetwork, Inc.
CTDPA
Privacy Notice Deficiencies / Inoperable Opt-Out
Connecticut Attorney General William Tong announced the state's first enforcement action under the Connecticut Data Privacy Act (CTDPA) — an $85,000 settlement with TicketNetwork, Inc., a Connecticut-based online ticket marketplace. The AG found that TicketNetwork's privacy notice was "largely unreadable," lacked required consumer data rights disclosures, and had misconfigured or inoperable opt-out mechanisms. The company had been given multiple notices to cure since November 2023 but failed to fully remediate.
View SourceHealthline Media LLC
CCPA
Failure to Honor Opt-Out Requests
California Attorney General Rob Bonta announced a $1.55 million settlement with Healthline Media LLC for violating the CCPA by failing to honor opt-out requests and improperly sharing consumer data with third parties.
View SourceTexas DTPA
Unauthorized Data Collection
Texas Attorney General Ken Paxton secured a $1.375 billion settlement with Google related to data privacy rights of Texans. The settlement addressed unauthorized collection and use of personal data, marking the second billion-dollar privacy settlement for Texas.
View SourceAmerican Honda Motor Co.
CCPA
Opt-Out Friction / Excessive Verification
The California Privacy Protection Agency (CPPA) fined Honda $632,500 for requiring excessive verification or personal information for privacy rights requests, using asymmetrical privacy choices, making authorized-agent requests difficult, and sharing personal information with ad tech companies without required contract terms.
View SourceAllstate / Arity
TDPSA
Unauthorized Collection and Sale of Sensitive Geolocation Data
Texas Attorney General Ken Paxton filed the first-ever enforcement action under a state comprehensive data privacy law, suing Allstate and its subsidiary Arity for collecting and selling the driving behavior data of over 45 million Americans. Arity paid app developers (GasBuddy, Fuel Rewards, Routely) to embed tracking SDKs that collected precise geolocation data without consumer notice or consent. The data was used to build a "driving behavior database" sold to insurance companies to justify premium increases. The AG is seeking over $1 million in penalties ($7,500 per TDPSA violation, $10,000 per Data Broker Law violation). Case is ongoing.
View SourceMeta (Facebook)
Texas CUBI / DTPA
Unauthorized Biometric Data Collection
Texas Attorney General Ken Paxton secured a record $1.4 billion settlement with Meta for running facial recognition on photos uploaded to Facebook without user consent, violating the Texas Capture or Use of Biometric Identifier Act (CUBI). This is the largest privacy settlement ever obtained by a single state.
View SourceNGL Labs (NGL App)
COPPA Rule / FTC Act / ROSCA
Children's Privacy / Dark Patterns
NGL Labs and two co-founders agreed to pay $5 million and were banned from offering their anonymous messaging app to anyone under 18, for marketing the service to children and teens, sending fake messages that appeared to come from real people to sell a paid subscription, and violating the COPPA Rule. Brought jointly by the FTC and the Los Angeles County District Attorney's Office as co-plaintiff — the charged statutes are federal, not California privacy law.
View SourceTilting Point Media
CCPA / COPPA
Children's Privacy Violation
Mobile game developer Tilting Point Media settled for $500,000 for collecting personal information from children under 13 playing its games without parental consent.
View SourceCerebral Inc.
FTC Act / ROSCA / OARFPA
Unauthorized Sharing of Health Data
Telehealth firm Cerebral agreed to pay more than $7 million — nearly $5.1 million in partial consumer refunds plus a civil penalty — for disclosing the sensitive health data of nearly 3.2 million consumers to third parties such as LinkedIn, Snapchat, and TikTok for advertising, and for failing to honor its "cancel anytime" promise. The complaint charged the FTC Act, the Restore Online Shoppers' Confidence Act (ROSCA), and the Opioid Addiction Recovery Fraud Prevention Act (OARFPA) — not the Health Breach Notification Rule.
View SourceInMarket Media
FTC Act
Geolocation Data Collection Without Consent
The FTC settled with InMarket Media, prohibiting the data aggregator from selling or licensing precise location data. InMarket tracked consumers' locations through its own apps and third-party apps carrying its SDK to serve targeted advertising without fully informing them or obtaining consent. The order was finalized in May 2024.
View SourceX-Mode Social (Outlogic)
FTC Act
Sale of Sensitive Location Data
The FTC banned data broker X-Mode Social (now Outlogic) from sharing or selling sensitive location data, marking the first FTC action to prohibit a data broker from selling sensitive location data.
View SourceRite Aid
FTC Act
Facial Recognition Misuse
The FTC barred Rite Aid from using facial recognition technology for surveillance purposes for five years after its AI-based system, deployed from 2012 to 2020 without reasonable safeguards, falsely tagged consumers as shoplifters — particularly women and people of color. The order carried no civil penalty but requires biometric-use notice and deletion of collected biometric information.
View SourceAmazon (Alexa)
COPPA
Children's Privacy / Voice Data Retention
Amazon agreed to pay a $25 million civil penalty to settle federal COPPA allegations that Alexa retained children's voice recordings and geolocation data for years, failed to honor some parental deletion requests, and used unlawfully retained data to improve its algorithms.
View SourceAmazon (Ring)
FTC Act
Unauthorized Access to Customer Videos
Ring agreed to pay $5.8 million for consumer refunds under a proposed federal order resolving FTC allegations that employees and contractors had broad access to customers' private videos and that weak security controls enabled account and camera takeovers.
View SourceEasy Healthcare (Premom)
FTC Act / Health Breach Notification Rule
Unauthorized Sharing of Health Data
Illinois-based Easy Healthcare, maker of the Premom fertility app, agreed to a $100,000 civil penalty in a proposed order filed by the Department of Justice on behalf of the FTC, for sharing users' sensitive health data with third-party analytics and marketing companies including AppsFlyer and Google without consent and failing to notify consumers of those disclosures. This was the FTC's second enforcement action under the Health Breach Notification Rule, after GoodRx.
View SourceDoorDash
CCPA
Unauthorized Sale of Personal Information
DoorDash was fined for selling consumers' personal information to a marketing cooperative without providing notice or an opportunity to opt out of the sale.
View SourceEpic Games (Fortnite)
COPPA / FTC Act
Children's Privacy Violation
Epic Games paid a $275 million civil penalty for COPPA violations involving Fortnite, including collecting children's personal information without parental consent and retaining data after deletion requests. A separate $245 million consumer-refund order addressed dark patterns and unwanted charges and is not included in this record's penalty amount.
View SourceKochava Inc.
FTC Act
Sale of Sensitive Geolocation Data
The FTC sued Idaho-based data broker Kochava in federal court for selling geolocation data that could be used to track people to sensitive locations such as reproductive health clinics, places of worship, and domestic violence shelters. The complaint sought an injunction rather than a civil penalty; the matter was still in litigation as of the cited release.
View SourceSephora
CCPA
Failure to Honor Opt-Out
Sephora settled with the California AG for $1.2 million for failing to disclose it was selling consumers' personal information, failing to process opt-out requests via Global Privacy Control (GPC), and failing to cure violations within 30 days.
View SourceOpenX Technologies
COPPA / FTC Act
Children's Privacy / Geolocation
OpenX paid $2 million to settle federal allegations that its advertising exchange collected personal information from children under 13 without parental consent and continued collecting geolocation data from some Android users who had opted out of location tracking.
View SourceZoom Video Communications
CCPA / FTC Act
Deceptive Security Practices
Zoom settled a class action for $85 million related to privacy and security issues including sharing user data with Facebook, Google, and LinkedIn, and falsely claiming end-to-end encryption.
View SourceGoogle (YouTube)
COPPA
Children's Privacy Violation
Google and YouTube paid $170 million to settle COPPA allegations that YouTube collected persistent identifiers from viewers of child-directed channels without first notifying parents or obtaining consent. The joint FTC and New York Attorney General resolution allocated $136 million to the FTC and $34 million to New York.
View Source