California's AG says Sephora will pay $1.2M after failing to tell customers that it was selling their data, marking the start of CCPA privacy law enforcement
SAN FRANCISCO — California has its first significant settlement under the state's sweeping online privacy law, and it's not with a tech company.
Context & Ripple Effects
California has been building to this moment since it began enforcing the CCPA on schedule in July 2020 over industry objections (enforcement went live despite pandemic-era delay calls), then voters strengthened the law that November by passing Proposition 24, which expanded its scope and created a dedicated Privacy Protection Agency (Prop 24's passage). The state had already flexed the adjacent right-to-know statute against Amazon over concealed COVID-19 case numbers.
The Sephora settlement is the first significant CCPA action, and the notable detail is the target: a retailer, not a tech company — signaling that any business monetizing customer data through ad networks falls under the law, not just Silicon Valley platforms.
First-order effects
- Sephora pays $1.2M and must disclose its data sales and honor consumer opt-outs going forward, converting an ambiguous legal question about ad-network data sharing into a settled compliance obligation.
Second-order effects
- Every brand running similar ad-tracking arrangements — retail and beyond — now faces a working enforcement template with a known price tag, pushing them toward disclosure and opt-out tooling rather than litigation risk.
Third-order effects
- The pattern holds and escalates: later CCPA settlements against Meta ($50M) and Disney ($2.75M) show California turning privacy fines into a recurring enforcement regime rather than a one-off warning shot.
The trend: State-level privacy regulation is maturing from statute to sustained enforcement, with California's settlement cadence effectively setting the compliance baseline for companies nationwide.