Sephora: $1.2M California privacy settlement

The first CCPA enforcement action: Sephora paid $1.2M after the California AG found that selling consumer data through ad-tech partnerships without honoring opt-out signals violated the CCPA.

  • CCPA
  • California
  • Last updated

Enforcement snapshot

Amount
$1.2M
Regulator
California Attorney General
Sector
Retail and beauty
Published
August 2022

Technical failure modes

What failed

01. Sharing data with ad-tech as 'sale'

Pixel-based data exchange with advertising partners qualified as a sale of personal information under CCPA — not a service provider exception.

02. Opt-out request not honored

Consumers who opted out continued to have their data shared via third-party tags and analytics integrations.

03. Global Privacy Control ignored

GPC browser signals were not treated as a valid opt-out request, despite CCPA's explicit recognition of automated mechanisms.

04. Disclosure gaps

Privacy disclosures did not clearly tell consumers their data was being sold or how to opt out.

Next step

Do not wait for a demand letter to find the gap

Sephora set the template for everything that followed. Pixel firings and third-party tag sharing count as 'sale' under CCPA. Global Privacy Control signals must be honored. The settlement made it clear that consent UI alone is not enough — backend behavior has to match.

Get Started Free

Get started in less than 5 min