Digital compliance in the news
Regulators, attorneys general and the courts are acting on how websites and apps treat the choices people make about their data, and the rules keep moving. These are the public actions and changes we follow, each summarised in our words and linked to its source.
- 24enforcement actions on this page, since 2022
- 2new laws, audits and other regulator updates
- $1.865 billionagreed or ordered to be paid, across 21 of 21 US actions
Actions and updates, newest first
California widens the right to delete to data a business got from third parties
Regulatory updateGovernor Newsom signed the Expanding Privacy Rights Act (SB 923), sponsored by CalPrivacy. Until now, a deletion request in California did not reach personal information a business had obtained from third parties rather than from the consumer; the new law closes that gap and lets businesses keep a suppression list so deleted records stay deleted. Online-only businesses must also offer an online way to submit privacy requests, such as a webform, not just an email address. The law takes effect on 1 January 2027.
Why it matters for your siteA deletion request has to reach every copy of a person’s data, including data bought or enriched from elsewhere, and an online store needs a request form, not just an inbox.
Data rights requestsSource: California Privacy Protection Agency
TikTok settles US claims over how it collected children’s data
$400 millionThe Justice Department alleged that TikTok did not follow the Children’s Online Privacy Protection Act and its rules on collecting personal information from children. TikTok agreed to pay $400 million: $300 million straight away and $100 million when an earlier consent decree is vacated. The department also pointed to changes TikTok had already made, including stronger age controls and more parental oversight.
Why it matters for your siteHow an app screens ages and gets parental consent is examined as closely as what its privacy policy says.
Children’s dataSource: U.S. Department of Justice
TaxAct settles over tracking code that sent tax details to ad platforms
$275,000The Attorney General said that from January 2018 to December 2022, tracking technologies on TaxAct’s site sent Meta and Google financial details such as rounded adjusted gross income and refund amounts, and customers were not told. TaxAct agreed to pay $275,000. It must also set up a committee to approve third-party trackers, write tracking policies, run a tag-monitoring system that scans the site regularly, and obtain two independent audits.
Why it matters for your siteEvery tag on a page that handles sensitive data needs an owner, an approval step and continuous scanning.
Tracking pixelsSource: Connecticut Attorney General
CalPrivacy opens its first sector audit, starting with gig economy platforms
Regulatory updateCalPrivacy’s new Audits Division began its first formal privacy audit, looking at app-based ride, delivery and task platforms operating in California. It will test whether consumers and gig workers can find out what data is collected about them, how it is used and who it is shared with, and whether access requests are answered fully within the 45-day window. The agency says this is the first in a series of sector audits and that it will publish what it finds.
Why it matters for your siteWhole sectors are now audited at once, so how a site handles rights requests is tested in practice, not just read on paper.
Data rights requestsSource: California Privacy Protection Agency
Ford ordered to simplify an opt-out that asked people to verify their email
$375,703CalPrivacy said Ford made people verify their email address before it would act on a request to opt out of the sale or sharing of their data, which added needless friction. Ford was ordered to pay $375,703. It must also simplify its opt-out process, audit the tracking technologies on its website, honour opt-out preference signals including Global Privacy Control, and process the opt-out requests it had earlier rejected.
Why it matters for your siteEach extra step in an opt-out flow is friction, and this order counted it.
Opt-out signalsSource: California Privacy Protection Agency
Youth sports streamer PlayOn ordered to give its own opt-out and honour browser signals
$1.1 millionCalPrivacy said PlayOn used tracking technologies for targeted ads and made users accept tracking before they could buy tickets or use its sites. It also said PlayOn sent people to industry opt-out pages instead of offering its own opt-out, ignored opt-out preference signals, and gave inadequate notices. PlayOn was ordered to pay $1.10 million, carry out risk assessments, provide working opt-out methods and clear disclosures, and get affirmative consent before selling or sharing data of users aged 13 to 16.
Why it matters for your siteSending visitors to a third-party ad-industry opt-out page does not replace your own opt-out.
Opt-out signalsSource: California Privacy Protection Agency
Disney settles claims that its opt-outs stopped at one device
$2.75 millionThe Attorney General alleged that Disney’s opt-out choices worked only partly. Toggles applied to one service or device rather than the whole account, the web-form opt-out still let embedded third-party ad tech receive data, and Global Privacy Control signals applied to one device even when users were logged in. Disney agreed to pay $2.75 million and to put in place opt-out methods that fully stop sale and sharing across its businesses and products.
Why it matters for your siteAn opt-out has to follow the person across every device and service tied to their account.
Opt-out signalsSource: California Attorney General
Disney ordered to pay over children’s videos not labelled ‘Made for Kids’
$10 millionThe FTC alleged that Disney did not label YouTube videos aimed at children as ‘Made for Kids’, so personal data was collected from viewers under 13 without notice to or consent from parents. A court approved an order requiring Disney to pay $10 million, follow the children’s privacy rule, and run a programme to review which videos should carry the label.
Why it matters for your siteHow content is labelled on a platform you do not own can decide whether children’s data is collected.
Children’s dataSource: Federal Trade Commission
Kaiser Permanente settles class claims over trackers on its sites and apps
$46 millionThe plaintiffs claimed that tracking code on Kaiser’s websites and apps disclosed members’ health-related information to third parties such as Google, Microsoft, Adobe and X without their knowledge. Kaiser agreed to a class settlement of $46 million, which can rise to $47.5 million, covering about 13.4 million people. It denied the claims and admitted no wrongdoing.
Why it matters for your siteAnalytics and ad tags inside patient portals and apps can turn into an eight-figure class settlement even when no misuse is shown.
Health dataSource: HIPAA Journal
Game maker Jam City settles over missing in-app opt-outs
$1.4 millionThe Attorney General alleged that Jam City offered no way to opt out of the sale or sharing of personal information across 21 mobile game apps, and that it sold or shared data of users aged 13 to 15 without the opt-in consent California sets for that age. Jam City agreed to pay $1.4 million, add in-app opt-out methods, and get opt-in consent before selling or sharing data of users under 16.
Why it matters for your siteApps need their own opt-out controls; a policy page on a website does not cover them.
Children’s dataSource: California Attorney General
French regulator sanctions Vanity Fair’s publisher over cookies placed before any choice
€750,000The CNIL found that cookies requiring consent were placed on vanityfair.fr as soon as visitors arrived, before they touched the banner, and that some cookies were labelled ‘strictly necessary’ without saying what they did. It also found that after people clicked ‘refuse all’ or withdrew consent, cookies kept being read and new ones were placed. The CNIL imposed a €750,000 monetary sanction and took account of an earlier order against the publisher.
Why it matters for your siteCalling an ad cookie ‘strictly necessary’ is tested against what the cookie actually does.
Consent bannersSource: CNIL (France)
Sling TV settles claims that cookie settings stood in for a real opt-out
$530,000The Attorney General alleged that Sling TV did not offer an easy way to opt out of the sale of personal data for targeted ads and did not do enough to protect children’s privacy. Sling agreed to pay $530,000 and to stop sending people to cookie preferences instead of a proper opt-out tool. It also agreed to drop web forms for logged-in users, add opt-out inside its TV-device apps, and offer kids’ profiles with targeted ads off by default.
Why it matters for your siteA cookie-preferences panel is not the same thing as a ‘Do Not Sell or Share’ opt-out.
Selling and sharing dataSource: California Attorney General
Tractor Supply ordered to pay and to keep an inventory of its trackers
$1.35 millionCalPrivacy alleged that Tractor Supply’s privacy notices fell short, that job applicants were not told their privacy rights, that it had no working opt-out including for Global Privacy Control, and that it shared data with third parties without the required contracts. Tractor Supply was ordered to pay $1.35 million and change its practices. That includes scanning its digital properties to list the tracking technologies on them and having an officer sign off on its practices every year for four years.
Why it matters for your siteKnowing every tracker running on your sites is now part of the work: this order requires a current list.
Opt-out signalsSource: California Privacy Protection Agency
French regulator sanctions Google over Gmail ads and harder-to-refuse cookies
€325 millionThe CNIL found that Google showed ads between emails in Gmail’s Promotions and Social tabs without consent. It also found that during account creation it was harder to refuse personalised-advertising cookies than to accept them. The CNIL imposed €325 million (€200M on Google LLC and €125M on Google Ireland) and gave Google six months to fix both practices or face €100,000 per day for each company.
Why it matters for your siteRefusing tracking has to take no more effort than accepting it.
Consent bannersSource: CNIL (France)
French regulator sanctions SHEIN over cookies that kept loading after ‘Refuse all’
€150 millionThe CNIL found that advertising cookies were placed on shein.com as soon as visitors arrived, before any choice on the banner. It also found that the banners did not explain advertising purposes or name the third parties placing cookies, and that new cookies were still placed after users clicked ‘Refuse all’. The CNIL imposed a €150 million monetary sanction; no order to change was needed because SHEIN had changed the site during the proceedings.
Why it matters for your siteA ‘Refuse all’ button has to stop tracking, not just close the banner.
Consent bannersSource: CNIL (France)
TicketNetwork settles over an unreadable notice and opt-out links that did not work
$85,000The Attorney General said TicketNetwork’s privacy notice was largely unreadable, left out key consumer rights and linked to opt-out mechanisms that did not work. It also said the company did not correct these problems after a cure notice in November 2023. TicketNetwork agreed to pay $85,000 and to track and report metrics on consumer rights requests to the Attorney General.
Why it matters for your siteA privacy notice has to be readable and its links have to work, and ignoring a cure notice raises the cost.
Privacy noticesSource: Connecticut Attorney General
Healthline settles claims that its opt-outs and consent banners did not work
$1.55 millionThe Attorney General alleged that Healthline.com’s opt-outs for targeted advertising did not work and that its consent banners misled visitors. It also alleged that article titles suggesting a reader’s medical diagnosis were shared with ad partners, and that its advertising contracts lacked the required privacy terms. Healthline agreed to pay $1.55 million, fix its opt-out mechanisms, stop sharing data that links a reader to diagnosis-suggestive article titles, and keep a programme with contract audits.
Why it matters for your siteA consent banner is judged by what the trackers do after a click, not by how the banner looks.
Consent bannersSource: California Attorney General
Google settles Texas claims over location, incognito and biometric data
$1.375 billionThe Texas Attorney General alleged that Google tracked people’s location, their activity in incognito search mode, and biometric identifiers such as voiceprints and facial geometry without proper consent. Google agreed to a $1.375 billion settlement with Texas. The office described it as the largest amount any single state has recovered from Google over data privacy.
Why it matters for your sitePrivacy promises in product settings such as private-browsing modes are held to what the product does.
Location dataSource: Texas Attorney General
Retailer Todd Snyder ordered to pay after a misconfigured consent tool left opt-outs waiting 40 days
$345,178The agency alleged that Todd Snyder’s privacy portal was set up wrongly, so opt-out requests went unprocessed for 40 days. It also alleged that the company asked for more information than needed and made people verify their identity before opting out. Todd Snyder was ordered to pay $345,178, reconfigure its opt-out tools and train staff. The agency stressed that using a third-party consent platform does not shift the company’s own responsibility.
Why it matters for your siteBuying a consent management platform does not move responsibility for how it is set up.
Opt-out signalsSource: California Privacy Protection Agency
Honda ordered to make declining as easy as accepting
$632,500The agency alleged that Honda asked for too much personal information before letting people use their privacy rights, and that its online privacy-choice tool made accepting easier than declining. It also alleged that Honda put obstacles in front of authorized agents and shared data with ad tech firms without the required contracts. Honda agreed to pay $632,500, simplify its request process, bring in a UX designer, train staff and revise its contracts.
Why it matters for your site‘Accept’ and ‘decline’ must be equally easy to find and use.
Consent bannersSource: California Privacy Protection Agency
Game publisher Tilting Point settles over children’s data shared through SDKs
$500,000The two offices alleged that the mobile game ‘SpongeBob: Krusty Cook-Off’ collected and shared children’s personal data without parental consent. Tilting Point agreed to pay $500,000. It must also get parental consent for users under 13, use neutral age screens, configure third-party SDKs correctly, set up ongoing SDK review across its games, and send annual reports.
Why it matters for your siteEvery third-party SDK and tag acts on your behalf, so each one has to be configured and reviewed.
Children’s dataSource: California Attorney General
DoorDash settles over customer data given to a marketing cooperative
$375,000The Attorney General alleged that DoorDash gave customers’ names, addresses and order histories to a marketing cooperative without notice or a chance to opt out, and that its privacy policy did not disclose this. DoorDash agreed to pay $375,000, review its contracts with marketing and analytics vendors, and report yearly to the Attorney General on any sale or sharing of personal data.
Why it matters for your siteSwapping data with marketing partners can count as a sale and needs notice and an opt-out.
Selling and sharing dataSource: California Attorney General
Advocate Aurora Health settles class claims over the Meta Pixel on its patient portal
$12.225 millionThe plaintiffs claimed that the Meta Pixel, Google Analytics and other third-party tools on Advocate Aurora’s website, MyChart patient portal and scheduling app disclosed patient data. The class covered about 2.5 million people from October 2017 to October 2022. Advocate Aurora agreed to a $12.225 million class settlement, with payments capped at $50 per person, and had removed the tracking tools.
Why it matters for your siteA standard ad pixel on a patient portal can expose a health system to a class settlement worth millions.
Tracking pixelsSource: HIPAA Journal
BetterHelp ordered to refund customers after sharing therapy data with ad platforms
$7.8 millionThe FTC alleged that BetterHelp shared sensitive mental-health information, including email addresses and whether someone was in therapy, with Facebook, Snapchat, Criteo and Pinterest for advertising after promising to keep it private. BetterHelp agreed to an order with $7.8 million for consumer refunds. The order bans sharing health data for ads and requires express consent before other sharing, deletion of data held by third parties, and limits on how long data is kept.
Why it matters for your siteHashed emails and ‘lookalike audience’ uploads are still sharing data with ad platforms.
Health dataSource: Federal Trade Commission
GoodRx settles FTC claims over health data shared with advertisers
$1.5 millionThe FTC alleged that GoodRx shared prescription and health-condition information with Facebook, Google, Criteo and others for advertising despite promising not to, and did not notify users about those disclosures. GoodRx agreed to pay $1.5 million and to a permanent ban on sharing health information for advertising. It must also get consent for other sharing, have third parties delete the data, and notify affected users.
Why it matters for your siteTracking events on a health site can reveal medical information through the event names alone.
Health dataSource: Federal Trade Commission
Sephora settles the first California action over Global Privacy Control
$1.2 millionThe Attorney General alleged that third-party trackers on Sephora’s site collected browsing and product-interest data that counted as a sale, that Sephora did not disclose this, and that it ignored Global Privacy Control opt-out signals. Sephora agreed to pay $1.2 million, update its privacy policy to say it sells data, support Global Privacy Control, align its service-provider contracts and report to the Attorney General.
Why it matters for your siteHonouring a browser opt-out signal is checked, not assumed.
Opt-out signalsSource: California Attorney General
Each summary is ours, drawn from the public announcement it links to. Allegations are the regulator’s own, and a settlement usually comes without any admission. This page reports what was announced. It is not legal advice, and it says nothing about any site we audit.
Find these problems before anyone else does
The digital compliance problems behind actions like these are the ones we look for. We find them on your site and show you exactly where each one sits.