State privacy enforcement stopped being hypothetical in 2022 and stopped being California-only in 2024. The current machine has specialized regulators (CPPA), aggressive litigators (Texas), transparent complaint-processors (Oregon), and a consortium wiring them together. Its output is remarkably consistent: every major action to date began with something visible from outside, a GPC signal ignored, an opt-out that errored, a notice contradicting the tags on the page, which makes the enforcement record a literal test plan for your own site.
The docket, distilled
| Action | Amount | Core violation |
|---|---|---|
| Sephora (CA AG, 2022) | $1.2M | GPC ignored; unregistered sales via ad-tech |
| DoorDash (CA AG, 2024) | $375,000 | Marketing-coop data sale |
| CPPA v. Honda (2025) | $632,500 | Asymmetric opt-outs, agent friction |
| Todd Snyder (CPPA, 2025) | $345,495 | Broken CMP; forced verification for opt-outs |
| Healthline (CA AG, 2025) | $1.55M | Article-reader ad-tech sales; missing contracts |
| Texas v. GM (2024) | pending | Covert telematics sale |
| Texas v. Allstate/Arity (2025) | pending | Location SDK harvesting |
| Texas/Meta CUBI (2024) | $1.4B | Biometric capture without consent |
Turning the record into a program
Test what they test. GPC response, opt-out link function, notice-versus-tag consistency, agent request handling, the CPPA’s priorities and Texas’s docket define the checklist, and every item is verifiable on your own site today.
Assume coordination. A finding in Oregon’s complaint pipeline or a Connecticut sweep can arrive as a California CID; the cure-period map determines whether a window comes with it, and increasingly it does not.
Fix the top three first. Opt-out mechanics (GPC pipeline), notice accuracy, and ad-tech contracts cover the majority of the docket; rights handling and assessments cover most of the rest.
Run the same external test the regulators run, before they do: free scan.