US State Law California, USA

CPPA Enforcement Priorities: What California Targets Next

The California Privacy Protection Agency's enforcement record and stated priorities: dark patterns, data brokers, connected vehicles, ADMT, and audit sweeps.

Regulation

CCPA/CPRA; CPPA Regulations including the 2025 ADMT, risk assessment, and cybersecurity audit rules

Max Penalty

$2,500 per violation; $7,500 per intentional violation or violation involving minors, via administrative order

Enforcing Authority

California Privacy Protection Agency (CPPA) Enforcement Division

Official Source

cppa.ca.gov

Executive Summary

  • The CPPA is the first standalone US privacy regulator, holding rulemaking, audit, and administrative enforcement powers over the CCPA since 2023.
  • Its public record so far: the Honda order ($632,500, 2025) on dark-pattern opt-outs and excessive verification; Todd Snyder ($345,495, 2025) on a broken opt-out portal and ID demands; and a rolling data-broker registration sweep under the Delete Act with per-day penalties.
  • Announced investigative priorities include connected vehicles, data brokers, and children's privacy; the agency has also issued an enforcement advisory against dark patterns and on data minimization in DSAR verification.
  • The 2025 regulations create the next wave: risk assessments for high-risk processing, phased cybersecurity audits, and automated decision-making technology (ADMT) rights with access and opt-out components.
  • The AG enforces in parallel (Sephora, DoorDash, Healthline), so California compliance faces two enforcers with different procedural tracks and no cure period.

California’s privacy agency spent its first two years building rules and its next two proving it will use them. The pattern in its orders is procedural cruelty to consumers: opt-outs that silently fail, verification that demands more data than the request needs, cookie banners with asymmetric effort. The agency has said plainly that it charges what it can see, and what it can see is your public-facing rights machinery.

RegulatorCPPA (+ California AG in parallel)
Orders to dateHonda $632,500; Todd Snyder $345,495; Delete Act sweep fines
Stated prioritiesDark patterns, data brokers, connected vehicles, children, ADMT
Next waveRisk assessments, cyber audits, ADMT rights (2025 regs, phased)

Reading the priorities operationally

Rights machinery is the audit surface. Every order so far began with a testable consumer experience. Self-audit quarterly: submit a DSAR, click the opt-out, send a GPC signal from a clean profile, and verify tags actually stop firing. The CCPA checklist sequences this.

CMP misconfiguration is a business violation. Todd Snyder establishes that “the vendor broke it” is not a defense. Contract for validation rights with your CMP, log signal propagation, and alert on opt-out volumes dropping to zero (the telltale of a broken pipe).

Data brokers have a dedicated regime. Registration (with per-day late fines), disclosure duties, and from 2026 the Delete Act’s DROP deletion mechanism, which the CPPA has signaled it will enforce aggressively. If you sell data about consumers with whom you lack a direct relationship, check the registration guide now.

ADMT turns AI governance into privacy compliance. Pre-use notices, opt-outs for significant decisions, and risk assessments that name model purposes and safeguards. Companies deploying hiring screens, credit models, or behavioral profiling should stand up the assessment templates before the phase-in dates arrive; the risk assessment guide maps the requirements.

Watch the sweeps. Connected vehicles, streaming apps, and children’s services have received inquiry letters; sweeps become orders when responses reveal the gaps above. If you operate in a swept sector, treat the public inquiries as your exam syllabus.

The CPPA finds most of its cases on the open web. See your site the way its investigators do: run a free scan and fix what it surfaces before they ask.

Frequently Asked Questions

What has the CPPA actually enforced so far?

Public orders include Honda ($632,500): requiring excess personal data to verify opt-out requests, asymmetric cookie choices (one click to accept, multiple to decline), and unpapered ad-tech contracts; Todd Snyder ($345,495): a consent-management platform misconfiguration that ignored opt-outs for 40 days and improper ID requirements; and Delete Act registration actions against data brokers (fines assessed per day of late registration). The agency has also run inquiry sweeps on connected vehicles and streaming.

What is the dark-patterns standard?

Symmetry in choice: declining must take no more steps than accepting; language must be neutral; and pre-selected options against the consumer's interest are prohibited. The CPPA's 2024 enforcement advisory told businesses that broken or circular opt-out flows, and cookie banners that manage cookies but not other selling/sharing, are chargeable violations. Test flows from a consumer's browser, not from your CMP's dashboard.

Do we need to worry about the CPPA if a CMP handles our cookies?

Yes, Todd Snyder is the cautionary tale: its CMP was misconfigured so opt-out signals never reached the backend, and the CPPA held the retailer, not the vendor, responsible, stating businesses cannot outsource accountability to compliance tooling. Validate end-to-end: signal in, tags suppressed, downstream partners notified.

What do the 2025 ADMT and risk-assessment rules add?

Finalized in 2025 with phased compliance: risk assessments for high-risk processing (selling/sharing, sensitive data, ADMT for significant decisions, profiling in sensitive contexts), retained and submittable to the agency; cybersecurity audits phasing in by revenue tier (largest businesses first, from 2028 filings); and ADMT rights, pre-use notice, opt-out, and access to decision logic, for significant decisions like hiring, lending, and housing.

How do CPPA and AG enforcement differ?

The CPPA proceeds administratively: investigations, stipulated orders, and fines through its Enforcement Division, with appeal to court; the AG files civil actions. Both can pursue the same conduct (they coordinate), neither must offer a cure period since 2023, and remedies stack: fines, injunctive terms, mandated audits, and multi-year compliance reporting. Practically, expect document demands referencing your own privacy-policy claims, keep them accurate.

Regulatory Crosswalk

CCPADelete ActCPPA ADMT rules

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.