US State Law United States

State Privacy Enforcement Tracker: Cases and Lessons

Attorney general and CPPA enforcement under state privacy laws: California's orders, Texas's lawsuits, Oregon's reports, the multistate consortium, and what gets checked first.

Regulation

Enforcement under comprehensive state privacy laws (2022-2026)

Max Penalty

Settlements to date: Sephora $1.2M, Honda $632,500, Healthline $1.55M, Todd Snyder $345,495; Texas suits seek far more

Enforcing Authority

State attorneys general; California Privacy Protection Agency

Official Source

cppa.ca.gov

Executive Summary

  • State privacy enforcement has three engines: California (AG + CPPA, the deepest case law), Texas (a dedicated AG unit filing headline lawsuits), and the coordinated rest (a bipartisan consortium of AG offices sharing sweeps and referrals since 2025).
  • California's docket defines the violation taxonomy: Sephora ($1.2M, 2022, GPC and sale disclosures), CPPA v. Honda ($632,500, 2025, asymmetric opt-out flows and agent friction), Todd Snyder ($345,495, 2025, broken opt-out portal), Healthline (AG, $1.55M, 2025, ad-tech data of article readers), plus DoorDash and data-broker registration orders.
  • Texas escalates rather than settles: the GM telematics suit (2024), the Allstate/Arity location-SDK suit (2025), a $1.4B biometric settlement with Meta under CUBI, and hundred-company sweep letters on registration and notices.
  • Oregon runs transparency enforcement: published complaint reports showing what consumers actually report (missing rights mechanisms, confusing notices, ignored requests).
  • The pattern across all of it: enforcement starts at the externally visible surface, opt-out links, GPC response, notice accuracy, tracker behavior, then follows the evidence inward.

State privacy enforcement stopped being hypothetical in 2022 and stopped being California-only in 2024. The current machine has specialized regulators (CPPA), aggressive litigators (Texas), transparent complaint-processors (Oregon), and a consortium wiring them together. Its output is remarkably consistent: every major action to date began with something visible from outside, a GPC signal ignored, an opt-out that errored, a notice contradicting the tags on the page, which makes the enforcement record a literal test plan for your own site.

The docket, distilled

ActionAmountCore violation
Sephora (CA AG, 2022)$1.2MGPC ignored; unregistered sales via ad-tech
DoorDash (CA AG, 2024)$375,000Marketing-coop data sale
CPPA v. Honda (2025)$632,500Asymmetric opt-outs, agent friction
Todd Snyder (CPPA, 2025)$345,495Broken CMP; forced verification for opt-outs
Healthline (CA AG, 2025)$1.55MArticle-reader ad-tech sales; missing contracts
Texas v. GM (2024)pendingCovert telematics sale
Texas v. Allstate/Arity (2025)pendingLocation SDK harvesting
Texas/Meta CUBI (2024)$1.4BBiometric capture without consent

Turning the record into a program

Test what they test. GPC response, opt-out link function, notice-versus-tag consistency, agent request handling, the CPPA’s priorities and Texas’s docket define the checklist, and every item is verifiable on your own site today.

Assume coordination. A finding in Oregon’s complaint pipeline or a Connecticut sweep can arrive as a California CID; the cure-period map determines whether a window comes with it, and increasingly it does not.

Fix the top three first. Opt-out mechanics (GPC pipeline), notice accuracy, and ad-tech contracts cover the majority of the docket; rights handling and assessments cover most of the rest.

Run the same external test the regulators run, before they do: free scan.

Frequently Asked Questions

What do the California cases collectively require?

Read as one order: honor GPC without forcing additional steps (Sephora, Honda); make opting out as easy as opting in, symmetric clicks, no forced verification for opt-outs (Honda, Todd Snyder); actually test the consent-management platform, a misconfigured banner is a violation, not a defense (Todd Snyder); treat ad-tech data flows about content readers as sales requiring opt-outs (Healthline, with its 'unique risk of embarrassment' theory for health-adjacent articles); process authorized-agent requests without friction (Honda); and paper ad-tech vendors with contract terms (Healthline).

What is Texas doing differently?

Litigating for structural stakes rather than settling for process fixes: the GM suit attacks covert telematics collection and sale to insurers; Allstate/Arity attacks SDK-based location harvesting across third-party apps; the Meta CUBI settlement ($1.4B) monetized a dormant 2009 biometric statute. Add sweep letters (data-broker registration, TDPSA notices) and a dedicated privacy unit, and Texas functions as the plaintiff's-side complement to California's administrative model. Nine-figure exposure is now a real state-privacy number.

What does the multistate consortium change?

Since early 2025, a bipartisan group including California, Colorado, Connecticut, Oregon, New Jersey, and others coordinates investigations and shares intelligence. Practically: a violation found by one member's sweep reaches the others; parallel cure notices arrive together; and smaller states without dedicated units borrow the big states' targeting. Single-state compliance postures ('we're fine unless California looks') stopped making sense when the looking became collective.

Which violations actually get enforced, by frequency?

From the public record: (1) broken or asymmetric opt-out mechanisms, including unprocessed GPC signals, the plurality of every sweep; (2) notice failures, missing disclosures, notices contradicting practice, missing required links; (3) ad-tech sales without opt-out or contracts; (4) ignored or late consumer requests; (5) registration failures (data-broker registries, with the CPPA fining per-day); (6) dark patterns in consent and cancellation flows; (7) sensitive-data processing without consent, rising as the newer laws mature. Items 1-3 are externally testable, which is why they lead.

How should a company prepare for a sweep letter or CID?

Before: quarterly self-audits of the visible surface (opt-out links resolve, GPC toggles the flag, notices match the tag manager's reality), evidence files for rights handling, and current assessments. On receipt: preserve everything, assign one owner, verify the claims technically before responding (regulators attach their own test results), respond within the window with facts and fixes, not adjectives. The Honda and Todd Snyder orders both cite discrepancies between claimed and observed behavior, the response is tested against your actual website.

Regulatory Crosswalk

CCPA/CPRATexas TDPSAFTC Section 5

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.