The 10 Biggest CCPA Fines in 2026
The largest CCPA fine to date is the $12.75 million General Motors settlement, announced in May 2026. As of July 2026, the ten biggest California Consumer Privacy Act penalties range from $375,000 to $12.75 million. They were issued by three sets of enforcers: the California Attorney General, the California Privacy Protection Agency (CalPrivacy), and local district and city attorneys.
Since California began enforcing the CCPA in 2022, the penalties have climbed into the millions, but business owners should not just be sweating the headline figures. Just as important is what each of these cases teaches about how to avoid the violations that bring the regulators circling.
Most of these cases start in the same place: a tracker, pixel, or tag running on a live web page that kept collecting and sharing data after a consumer said stop.
Here are the ten largest CCPA penalties in the law’s history as they stand in mid-July 2026, ranked by amount, along with what each one reveals about the risks hiding on your own site.
The 10 biggest CCPA fines at a glance
| Rank | Company | Penalty | Date | Enforcer | Core failure |
|---|---|---|---|---|---|
| 1 | General Motors | $12.75M | May 2026 | AG + CalPrivacy + county DAs | Sold driver and location data to data brokers without consent |
| 2 | Walt Disney Company / ABC | $2.75M | Feb 2026 | California AG | Opt-outs not propagated across devices; no in-app opt-out |
| 3 | Healthline Media | $1.55M | Jul 2025 | California AG | Shared health data; trackers kept firing after opt-out |
| 4 | Tractor Supply Company | $1.35M | 2025 | CalPrivacy | No working opt-out; missing required vendor contract terms |
| 5 | Sephora | $1.2M | Aug 2022 | California AG | Undisclosed tracker “sale”; ignored Global Privacy Control |
| 6 | PlayOn Sports (GoFan) | $1.1M | Mar 2026 | CalPrivacy | Ad trackers sold data; tracking required to use the service |
| 7 | American Honda Motor Co. | $632,500 | Mar 2025 | CalPrivacy | Excessive friction on consumer privacy requests |
| 8 | Tilting Point Media | $500,000 | Jun 2024 | AG + LA City Attorney | Children’s data shared via embedded ad SDKs |
| 9 | Ford | $375,703 | Mar 2026 | CalPrivacy | Opt-out compliance failures |
| 10 | DoorDash | $375,000 | Feb 2024 | California AG | Sold data through a marketing co-op without notice or opt-out |
1. General Motors: $12.75 Million (May 2026)
The largest CCPA penalty to date by a country mile. The Attorney General (AG), several county district attorneys, and the California Privacy Protection Agency (CalPrivacy) jointly settled allegations that GM sold the driving and location data of hundreds of thousands of California motorists to data brokers without consent. It was the state’s first data-minimization case and the first joined by local DAs. GM’s mistake also applies to website owners: regulators are now scrutinizing what data you collect, why you collect it, and where it flows, which is why you must monitor third-party channels.
2. The Walt Disney Company / ABC: $2.75 Million (February 2026)
The current number two held the top spot for only three months. The AG found Disney failed to propagate opt-out requests across all the devices and services tied to a consumer’s account, including Disney+, Hulu, and ESPN+, and that its connected-TV apps offered no in-app way to opt out at all. Consumers were bounced to a webform that could not stop the tracking baked into the TV apps. The lesson here is that if you can resolve a consumer’s identity across devices to target ads, you must honor their opt-out across those same devices too.
3. Healthline Media: $1.55 Million (July 2025)
Another biggest-penalty record-holder when it was imposed, the first CCPA action against a publisher, and the first involving health data. Healthline shared sensitive health-related information with advertisers and ran tracking that kept firing even after users opted out. It reportedly affected more than 65,000 consumers and is the purest “your tags betrayed you” case on the list: the company’s revenue depended on advertising scripts, and those same scripts became the violation. Regulators explicitly compared this case to Sephora, hammering the point that businesses displaying online ads must verify that their opt-outs actually work.
4. Tractor Supply Company: $1.35 Million (2025)
CalPrivacy’s largest penalty to date, and it started from a single consumer complaint. The retailer allegedly failed to give consumers a working way to opt out of the sale or sharing of their personal information, failed to disclose privacy rights (including to job applicants), and shared data with vendors without the contract terms the CCPA requires. Vendor and tag sprawl was central to this failure, and that part of it would have been caught early with an actively monitored inventory. In fact, the regulator itself mandated that the company adopt regular monitoring as part of its stipulated settlement.
5. Sephora: $1.2 Million (August 2022)
The one that started it all, and still the template. In the first-ever CCPA settlement, Sephora was penalized for failing to disclose that its use of third-party trackers amounted to “selling” personal information, and for ignoring opt-out signals sent through the Global Privacy Control (GPC). Every case above and below it echoes the same two failures: undisclosed tracker-based data sharing and opt-out signals that were not honored.
6. PlayOn Sports (GoFan): $1.1 Million (March 2026)
The first CCPA action specifically involving students and schools. The youth-sports ticketing platform ran advertising trackers (including a Meta Pixel) that “sold” and “shared” data without an effective opt-out, and consumers had to accept tracking just to use the service. A big surprise with this one is that PlayOn had already fixed the issues months earlier, on its own initiative, and was fined the full amount anyway. This reads as proof that the regulator will punish historic violations regardless of after-the-fact cleanups, which is an even greater incentive to ensure they never happen.
7. American Honda Motor Co.: $632,500 (March 2025)
One of the highest fines in the law’s history when CalPrivacy issued its decision. Honda was ordered to change how it handled consumer privacy requests, including removing friction like excessive verification that made it harder for consumers to exercise their rights. Having a properly functioning rights mechanism is no less important than tracking issues because the risk is just as real: if you cannot cleanly process an opt-out or deletion, you are exposed.
8. Tilting Point Media: $500,000 (June 2024)
Brought by the AG together with the Los Angeles City Attorney, this resolved allegations that the studio collected and shared children’s data without parental consent in its mobile game SpongeBob: Krusty Cook-Off, violating both the CCPA and the federal COPPA rule. The culprit was embedded advertising SDKs that shared data when they should not have. These are the mobile-app cousins of the web trackers common to other cases in this list.
9. Ford: $375,703 (March 2026)
Announced by CalPrivacy the same week as PlayOn, as part of the early-2026 wave centered on opt-out compliance. It landed amid intensifying scrutiny of automakers and connected-vehicle data, and foreshadowed the far larger GM settlement two months later.
10. DoorDash: $375,000 (February 2024)
The online food delivery company sold California customers’ personal information through a marketing co-op without notice or a chance to opt out, violating both the CCPA and CalOPPA. The AG argued the violation could not even be “cured,” because the data had already been sold and resold to the point where it was effectively out of reach. Once data leaves through an unmonitored channel, you cannot pull it back, which is precisely why visibility before it leaves matters so much.
Honorable mention: Todd Snyder, Inc. ($345,178, May 2025)
Just missed the list but worth your attention: Todd Snyder, Inc. paid $345,178 in May 2025 after a misconfigured consent tool left its opt-out broken for roughly 40 days, ignored GPC signals, and demanded excessive identity verification. For anyone running a consent banner on top of a live tag ecosystem, it is the most instructive case of all: the privacy policy said the right things, but the technology underneath did not do them.
What do the biggest CCPA fines have in common?
You cannot honor an opt-out you cannot see. Sephora, Healthline, Tractor Supply, PlayOn, and Todd Snyder all broke the rules because a tracker, pixel, or tag kept selling or sharing data after a consumer opted out, often without anyone at the company realizing it was still firing. Under the CCPA, loading third-party trackers can count as a “sale” or “sharing” of personal information, which means the exact scripts marketing teams add to boost conversions also create legal exposure.
The two biggest fines, GM and Disney, extended the same logic to connected cars and smart TVs: proof that the principle reaches every surface, even if the browser is where most businesses face exposure.
Regulators kept finding an opt-out that “did not fully work,” and that is a client-side visibility problem. Consent banners and privacy policies operate on the assumption that the tags underneath obey them, but in case after case, they did not. A pixel changed behavior after a deployment, a tag manager loaded a fourth-party script no one reviewed, an opt-out applied on one device but not another. None of that shows up in a policy audit. It only shows up when you watch what actually executes in the browser: every script, pixel, and tracker on the live page, what data each one touches, and where it sends it. This is exactly what Reflectiz does.
What comes next for CCPA enforcement?
California is not slowing down. On August 1, 2026, the Delete Request and Opt-out Platform (DROP) will require more than 500 registered data brokers to begin retrieving and processing centralized deletion requests, checking the platform every 45 days or facing $200-per-request, per-day penalties. DROP is aimed at data brokers specifically, but it is the clearest signal yet of where this is heading: well-funded, centralized, consumer-facing enforcement of how personal data flows out of businesses. And because tracker-based “sharing” can put an ordinary website closer to that data-broker line than its owners assume, the smart move is not to wait for a complaint. It is to know exactly what is running on your site, and to be able to prove your opt-outs actually work, before a regulator asks.
See what is actually executing on your pages. Reflectiz monitors every script, pixel, and tracker on your live website from the outside, with no code added to your site and no access to your customers’ data. Book a demo to see your own website privacy compliance exposure.
Frequently Asked Questions
Can you avoid a CCPA fine by fixing the violation before enforcement?
Not reliably. PlayOn Sports fixed its opt-out problems months before CalPrivacy acted, on its own initiative, and still paid the full $1.1 million penalty in March 2026. In the DoorDash case, the Attorney General argued the violation could not be cured at all because the data had already been sold and resold. The mandatory 30-day cure period from the original CCPA was eliminated by the CPRA amendments as of January 1, 2023, so voluntary remediation is now a mitigating factor rather than a defense.
Does loading third-party trackers count as selling data under the CCPA?
Yes. Under the CCPA, letting third-party advertising and analytics trackers collect personal information from your website can qualify as a sale or sharing of that information, even when no money changes hands. This interpretation was established in the 2022 Sephora settlement and reaffirmed in the Healthline Media and PlayOn Sports actions. It means the marketing scripts on your pages create legal exposure, not just performance data.
Does the CCPA require honoring Global Privacy Control signals?
Yes. California regulations require businesses to treat opt-out preference signals such as the Global Privacy Control (GPC) as valid requests to opt out of the sale or sharing of personal information. Ignoring GPC was a central finding in the 2022 Sephora settlement and again in the Todd Snyder case, where the company paid $345,178 in May 2025 after a misconfigured consent tool ignored GPC signals for roughly 40 days.
How do you prove your CCPA opt-out actually works?
You have to observe what actually executes in the browser on your live pages, not just what your privacy policy and consent banner claim. That means a continuous inventory of every script, pixel, and tracker, what data each one accesses, and where it sends that data, verified before and after an opt-out is applied. Reflectiz monitors this from the outside, with no code added to your site and no access to customer data, and alerts you when a tag’s behavior changes.
How much are CCPA fines?
CCPA civil penalties run up to $2,663 per unintentional violation and $7,988 per intentional violation or any violation involving a consumer under 16. Those are the statutory $2,500 and $7,500 caps as adjusted for inflation by CalPrivacy effective January 1, 2025, and they hold through 2026. Penalties are assessed per violation, which usually means per affected consumer, so totals scale quickly. Published settlements have ranged from roughly $345,000 to $12.75 million.
What is California’s DROP platform and when does it start?
DROP is the Delete Request and Opt-out Platform, a centralized system run by the California Privacy Protection Agency that lets a consumer submit one deletion request to every registered data broker at once. Starting August 1, 2026, more than 500 registered data brokers must check DROP at least every 45 days and process the requests they find, or face penalties of $200 per request per day. DROP applies to registered data brokers rather than ordinary websites, but it signals where centralized enforcement is heading.
What is the biggest CCPA fine to date?
The largest CCPA fine to date is $12.75 million, paid by General Motors under a May 2026 settlement with the California Attorney General, the California Privacy Protection Agency (CalPrivacy), and several county district attorneys. Regulators alleged GM sold the driving and location data of hundreds of thousands of California motorists to data brokers without consent. It was California’s first CCPA data-minimization enforcement action and the first joined by local district attorneys.
What was the first CCPA fine?
Sephora received the first CCPA enforcement penalty: $1.2 million in August 2022. The California Attorney General found that Sephora failed to disclose that its use of third-party trackers amounted to selling personal information, and that it ignored opt-out signals sent through the Global Privacy Control. The case set the template that later actions against Healthline Media, Tractor Supply, PlayOn Sports, and Todd Snyder all followed.
Who enforces the CCPA?
Two bodies enforce the CCPA: the California Attorney General, with civil enforcement authority under Civil Code section 1798.155, and the California Privacy Protection Agency (CalPrivacy), which holds administrative enforcement authority under the CPRA amendments. Local prosecutors can join actions too, as the Los Angeles City Attorney did in the Tilting Point Media case and several county district attorneys did in the General Motors settlement. CalPrivacy’s largest penalty to date is the $1.35 million Tractor Supply action.
Why do so many CCPA fines involve tracking pixels and tags?
Because opt-outs usually fail at the technical layer, not the policy layer. Consent banners and privacy policies assume the tags underneath obey them, but a pixel can change behavior after a deployment, a tag manager can load a fourth-party script no one reviewed, or an opt-out can apply on one device and not another. Regulators in the Sephora, Healthline, Tractor Supply, PlayOn Sports, and Todd Snyder cases all found opt-outs that did not fully work in the browser.
Subscribe to our newsletter
Stay updated with the latest news, articles, and insights from Reflectiz.
Related Articles
AI Has Changed The Web.
Are You Ready for What’s Next?
Third-party code shifts by the hour. Supply-chain compromises strike without warning. AI-driven web attacks now evolve faster than traditional security can ever keep up.
Reflectiz delivers the continuous, real-time visibility needed to expose the risks traditional tools miss entirely.
Zero code changes. Zero access to your data. Ultimate peace of mind.