California Tightens Privacy Opt-Out Rules
Coverage from PPC Land, Mondaq, and others

California privacy regulators and courts are increasing scrutiny of how businesses collect, share, and track consumer data, particularly when opt-out mechanisms are difficult to use or require unnecessary information.
The California Privacy Protection Agency’s $1.1 million PlayOn Sports settlement highlights heightened concern over student and family data on school-event platforms, while related enforcement against Ford and emerging adtech litigation extend the focus across industries. New CCPA/CPRA audit and risk-assessment requirements are also moving privacy controls toward formal executive and board oversight.
The story has broadened beyond agency enforcement into private adtech litigation and formal privacy-governance obligations. New audit and risk-assessment requirements, with concrete deadlines, indicate that regulatory expectations are moving into implementation and executive oversight.
The story has sharpened from general CCPA opt-out enforcement into a more specific push against fragmented, burdensome, and technically incomplete opt-out handling. The new version also elevates Ford and reframes the remedies as increasingly operational, including monitoring and testing of tracking implementations.
The story has moved from a broad pattern of California opt-out enforcement to specific, named actions against PlayOn Sports and Disney, clarifying the concrete compliance failures regulators are pursuing. The emphasis is now more explicit on native opt-out design, preference-signal handling, and frictionless exercise of rights across tracking systems and services.
- PlayOn Sports was fined $1.1 million over GoFan.
- Disney agreed to a $2.75 million settlement.
- Regulators reject opt-outs routed to industry tools instead of native controls.
- Identity verification and interface design are now under scrutiny.
- Student-facing platforms are singled out as especially vulnerable.
The story has broadened from general CCPA opt-out enforcement into a denser enforcement pattern that now explicitly includes connected vehicles and cross-service compliance failures. The new version also adds California’s attorney general and Disney as major actors, signaling that regulators are targeting broader account-level and device-level privacy controls, not just website tracker disclosures.
- Connected vehicle privacy is now part of the enforcement pattern.
- Opt-out choices must work across devices, services, and vendor systems.
- California Attorney General Rob Bonta and Disney are newly included.
- Email verification and Global Privacy Control face scrutiny in vehicle-related contexts.
- The enforcement pattern now spans consumer platforms, streaming, youth services, and vehicles.
The story is now more concretely anchored by the $1.1 million PlayOn Sports settlement, which clarifies that third-party opt-out tools do not satisfy CCPA duties when companies continue their own tracking and sharing. The enforcement focus is also more explicitly tied to audience-appropriate notices and direct, company-controlled opt-out mechanisms.
The story is now framed more narrowly around whether opt-out requests actually halt sale, sharing, and tracking across interconnected services. This sharpens the operational focus but does not materially change the underlying enforcement trend.
The story now centers more explicitly on CPPA/CPRA enforcement as a maturing regulatory regime, with added emphasis on ongoing compliance obligations and a separate policy debate over whether California should tighten or weaken privacy rights. The enforcement pattern is broader and more operationally demanding than before.
The update broadens the enforcement story by adding a more explicit role for the California Attorney General and by framing school-adjacent and youth-facing apps as a more sensitive enforcement target. It also strengthens the view that compliance now hinges on propagating preference signals across entire account ecosystems, not just honoring them at a single touchpoint.
The cluster is centered on California privacy enforcement against companies whose opt-out, tracking, and data-sharing practices do not meet CCPA/CPRA requirements. The strongest current signal is a sequence of enforcement actions and settlements that require direct, symmetric, and cross-platform opt-out handling, better notice, tracking audits, and in some cases board-level oversight. Student-related platforms and connected vehicle services are recurring contexts, but the common pattern is broader: regulators are moving from abstract privacy rights to specific operational controls over consent, tracking technologies, and propagation of opt-out signals across systems.
