DoorDash: $375K California privacy settlement

California's $375,000 DoorDash settlement targeted the sale of customer information through marketing data cooperatives — and DoorDash's failure to provide the right opt-out path or service-provider contracts.

  • CCPA
  • California
  • Last updated

Enforcement snapshot

Amount
$375K
Regulator
California Attorney General
Sector
Food delivery
Published
February 2024

Technical failure modes

What failed

01. Marketing co-op data sharing as 'sale'

Sharing customer information with marketing cooperatives in exchange for advertising leads constituted a sale under CCPA.

02. No opt-out for cooperative sharing

Customers had no clear way to opt out of marketing-cooperative data exchanges.

03. Missing service-provider terms

Contracts with cooperative members lacked the use-restriction language CCPA requires to convert a sale into a service-provider relationship.

04. Disclosure inadequate

Privacy notices did not name the cooperative practice or its purpose with the specificity CCPA expects.

Next step

Do not wait for a demand letter to find the gap

DoorDash is the marketing-cooperative case. Sharing customer data with cooperatives in exchange for advertising value counts as a 'sale' under CCPA. Without the right contracts and opt-out plumbing, even routine martech moves expose brands to enforcement.

Get Started Free

Get started in less than 5 min