top of page

CCPA Radar tracks publicly announced enforcement actions, settlements, and penalty decisions under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Its purpose is to provide a clear, practical view of how California regulators interpret and enforce privacy obligations in real cases.

 

The radar brings together key information on enforcement trends, including the regulator, the organization involved, the amount of the penalty, the legal basis of the violation, and the core compliance issues identified in each matter. By presenting these cases in one place, CCPA Radar helps privacy, legal, compliance, and security teams better understand which failures most often lead to regulatory action.

 

More than a list of fines, CCPA Radar is designed as a working compliance resource. It shows how regulators approach topics such as opt-out mechanisms, dark patterns, children’s data, privacy notices, vendor contracts, and the technical implementation of consumer rights. This makes it easier to translate enforcement activity into concrete lessons for internal privacy governance and risk management.

Todd Snyder, Inc.

Penalty:

345,18 USD

Opt-out requests not processed; excessive request burden; unnecessary verification

Core issue:

May 6, 2025

Date:

Main public findings:

CPPA announced that Todd Snyder failed to process consumer opt-out requests for 40 days, required more information than necessary from consumers, and required identity verification before allowing them to opt out of sale/sharing.

Cause of the violation:

Core issue:

Recommendations:

Source:

Todd Snyder misconfigured or insufficiently supervised its privacy request system, causing opt-out requests to fail and imposing burdens that were not necessary to process those requests.

Opt-out requests not processed; excessive request burden; unnecessary verification

Validate privacy-platform configurations after deployment; monitor request logs continuously; remove unnecessary form fields; do not require verification for standard opt-out requests; train staff responsible for privacy operations.

bottom of page