Takes effect
New California
California expands CCPA deletion rights
From January 1, 2027, deletion rights reach data about consumers, and direct-to-consumer online-only businesses must also accept requests online.
Last updated
A free, fast reference for US state data-privacy regulations. Built for people who already know the law applies.
Searches only what the engine has published and verified.
50 states + DC · colored by status
Takes effect
New California
From January 1, 2027, deletion rights reach data about consumers, and direct-to-consumer online-only businesses must also accept requests online.
Timeline
Every dated milestone we publish for every state we track (signings, effective dates, enforcement starts, recurring duties) in one browsable view. Drag the quarter scrubber or filter by type to narrow it down, then jump into the state that matters to you.
Drag the handle or use the arrow keys to jump to a quarter — every milestone is already listed below.
Showing all 37
Data brokers must undergo an independent compliance audit, recurring every three years.
The CPPA adopted the accessible-deletion-mechanism (DROP) regulations on September 26, 2025; the Office of Administrative Law approved them on November 6, 2025.
The CPPA was required to establish the accessible deletion mechanism (DROP); consumers can submit a single deletion request to all registered data brokers.
Beginning August 1, 2026, a data broker must access DROP at least once every 45 days and delete the personal information of consumers who requested it.
Data brokers doing business in California must register with the CPPA each year by January 31.
The DROP mechanism must let the consumer, or their authorized agent, verify the status of their deletion request — a distinct duty from checking DROP and deleting data (see "Data brokers must process via DROP" below).
Nothing in this window
No milestones match that quarter or type filter. Re-enable a type, or open earlier history.
Governor Newsom signed SB 362; chaptered as Chapter 709, Statutes of 2023.
The Delete Act and its data-broker registration regime became operative.
The authorized-agent opt-out technology rule in 541.055(e) took effect January 1, 2025 (H.B. 4 SECTION 7(b)).
Applies to organizations described in section 501(c)(3) of the Internal Revenue Code.
Compare
Filter to the states that fit your criteria, then pick two to four to compare side by side: rights, exemptions, penalties, and cure periods, each linked to the statute behind it.
No state matches all of these filters
That combination doesn’t exist in the tracked data; that’s not an error. Drop a filter to widen the field.
What changed
Regulatory actions, settlements, and lawsuits across the privacy laws we track. Every entry is a DataGrail summary that links to the primary source.
Showing 1-6 of 30
Google Ireland Limited
€403,000,000Decided
The fourth-largest GDPR fine ever issued, for tracking exactly the kind of location data most apps collect by default.
Meta Platforms, Inc.
$459,300,000Settled
Eight years after Cambridge Analytica broke, states are still collecting on it. This time it's $459 million, folded into an even larger settlement over Meta's design choices for kids.
TikTok Inc. and ByteDance Ltd.
$400,000,000Pending
A $400M privacy settlement isn't final just because the government announced it: a judge can still send both sides back to the table.
TaxAct, Inc.
$275,000Settled
The information you enter into tax software feels private by default. This is what happens when a company treats it as ad-targeting data instead.
Flagstar Bank, N.A.
$31,500,000Settled
A bank paid hackers a ransom to delete stolen data, then still had to pay $31.5 million to the customers whose data was stolen in the first place.
23andMe Holding Co.
$18,000,000Settled
Genetic data is uniquely permanent and uniquely sensitive, and this is one of the largest privacy settlements ever tied to a single breach of it.
Illuminate Education, Inc.
DecidedNo monetary penalty
There was no fine, but a company that ignores a two-year-old security warning can still be forced into a binding security overhaul.
General Motors LLC / OnStar
$12,750,000Settled
Connected-vehicle data is squarely in scope, and data minimization is now being enforced. Collect only what a stated purpose needs, and get real consent before selling location or behavior data.
Match Group, LLC and OkCupid
DecidedNo monetary penalty
There's no fine, but a privacy policy promise about who sees your data is now something the FTC will hold the company to directly.
PlayOn Sports, Inc. (GoFan)
$1,100,000Settled
A first: California's privacy regulator drew a direct line from a school sports ticketing app to a company's ad-tracking practices, and fined it accordingly.
General Motors LLC; OnStar LLC
DecidedNo monetary penalty
Federal and state regulators are moving in parallel on connected-car data. A confusing enrollment screen is treated as a lack of consent, so make disclosures and opt-in clear and specific.
Rickenbacher Data LLC (d/b/a Datamasters)
$45,000Settled
Selling lists sorted by disease and addiction status, without ever registering as a data broker, is exactly what California's Delete Act exists to catch.
The Walt Disney Company
$10,000,000Settled
Mislabeling children's content is a COPPA problem even when a platform does the collecting. If your videos reach kids, label them correctly and treat parental consent as mandatory.
ROR Partners LLC
$56,600Settled
Unregistered, not just unlawful: California's Delete Act requires data brokers to register before they can legally sell audience data at all.
Tractor Supply Company
$1,350,000Settled
CPPA's largest fine to date, and its first decision addressing privacy protections for job applicants.
Accurate Append, Inc.
$55,400Settled
California's Delete Act now carries real teeth: even a missed registration deadline draws a five-figure fine.
Healthline Media LLC
$1,550,000Settled
Tracking pixels that leak health-related signals draw the largest penalties. When a user opts out, the data flow to third parties has to actually stop, including page titles and identifiers.
Google LLC
$1,375,000,000Settled
Biometric identifiers captured through convenience features like photo face-grouping or voice assistants fall under standalone state biometric statutes, not just general privacy law, and an 'off' setting has to actually stop tracking, including in a browser's private mode.
Jerico Pictures, Inc. (d/b/a National Public Data)
$46,000Settled
The same data broker behind 2024's headline-making breach was also fined for skipping California's registration requirement entirely.
Todd Snyder, Inc.
$345,178Settled
Six weeks of a broken opt-out portal turned into a $345,178 CPPA fine.
TikTok Technology Limited
€530,000,000Decided
A real deadline comes with this one: comply within six months, or TikTok has to stop sending EU user data to China altogether.
Clearview AI, Inc.
$51,750,000Settled
The facial-recognition company that scraped billions of photos without asking didn't pay cash. It gave away nearly a quarter of itself instead.
American Honda Motor Co., Inc.
$632,500Settled
A confusing privacy interface, not a data breach, was enough to draw this six-figure CPPA fine.
Key Marketing Advantage, LLC
$55,800Settled
Nearly a year of unregistered operation before this data broker got caught.
Amazon.com, Inc.
$25,000,000Settled
A delete button has to actually delete once you tell parents it will. If retained data keeps feeding a model after a deletion request, that gap is the violation, not a technicality.
BetterHelp, Inc.
$7,800,000Settled
A privacy promise about sensitive data is independently enforceable. Breaking a stated commitment ("this stays between you and your therapist") is a violation on its own, before you even get to whether the sharing itself was disclosed.
GoodRx Holdings, Inc.
$1,500,000Settled
Sharing health-adjacent data with ad platforms can trigger the Health Breach Notification Rule even outside a traditional data breach, and a compliance seal you don't actually qualify for (like HIPAA) is its own separate violation.
Epic Games, Inc.
$520,000,000Settled
Default settings and confusing purchase flows are enforcement risk, not just UX debt. Defaulting a kids' product to voice chat or in-game messaging can itself be a COPPA violation, and a button layout that causes unintended charges is treated the same as a false claim.
Sephora, Inc.
$1,200,000Settled
Selling data through routine ad-tech and analytics tags still counts as a 'sale' under the CCPA. Honor Global Privacy Control automatically, and audit every vendor tag against your service-provider contracts.
Snap Inc.
$35,000,000Settled
A face filter most people think of as a toy was, legally speaking, biometric data collection, and expensive to get wrong.