California's AG says Sephora agreed to pay $1.2M for failing to tell customers that it was selling their data, marking the start of CCPA privacy law enforcement
failure to disclose it was selling consumer data and failure to adhere to GPC opt-out signals. https://oag.ca.gov/... Wafa Ben-Hassine / @ousfourita : This is the first #CCPA enforcement action. $1.2M settlement with Sephora. Regulation. It works. https://twitter.com/... Jason Kint / @jason_kint : A massive deal. California is the strongest privacy law in the US as it relates to digital media and the AG is also doubling down on the global privacy control which must be honored under the law as it's being further clarified in an updated rulemaking. https://twitter.com/... Rob Bonta / @agrobbonta : The #CCPA has been in effect for two years. There are no more excuses. Follow the law, honor consumers' rights, and process opt-out requests made via user-enabled global privacy controls. https://oag.ca.gov/... Ryan Barwick / @ryanbarwick : Privacy news: Sephora to pay $1.2 million** for selling customer data and failing to honor opt-out requests, under CCPA **LVMH made $43 billion last quarter https://www.nbcnews.com/...
Context & Ripple Effects
California began enforcing the CCPA in 2020 despite industry calls for a delay, then voters approved an expansion of the law and a dedicated enforcement agency. Sephora’s settlement turns that enforcement posture into a concrete test of disclosure and opt-out requirements.
The case centers on whether a retailer’s data practices and response to GPC signals match the CCPA’s consent rules, making California’s decision to begin enforcement consequential for companies using similar data-sharing arrangements.
First-order effects
- Sephora will pay $1.2 million to California and must address the alleged failures to disclose data sales and honor GPC opt-out signals.
- California Attorney General Rob Bonta establishes the state’s first reported CCPA enforcement action, putting GPC compliance alongside disclosure obligations in the enforcement record.
Second-order effects
- Retailers and ad-supported consumer businesses using data-sharing arrangements face pressure to audit whether their disclosures and opt-out flows recognize GPC signals.
- Privacy teams gain a clearer operational target: consent interfaces and backend data-sharing controls must produce the same outcome when a consumer uses a browser-level opt-out.
Third-order effects
- California’s privacy regime is moving from statutory requirements to case-backed compliance expectations, with consent architecture becoming an enforcement surface rather than a policy-only function.
- Later California settlements involving Meta and Disney indicate that the Sephora action was an early point in a broader state pattern of pursuing alleged failures around consumer data controls.
The trend: US privacy enforcement is increasingly testing whether companies’ data-sharing systems honor consumer choice signals in practice, not merely in published disclosures.