Law report No. GLW-1882 · filed October 10, 2026

Regulation & EnforcementReported case

California Regulators Announce Largest CCPA Fine to Date

California privacy regulators have imposed the largest financial penalty under the CCPA on record, according to IAPP. The dollar figure, target company, and cited provisions were not disclosed in the headline notification.

By Sophie Lindqvist3 min read590 words

Holding

  1. California privacy regulators announced the largest CCPA fine on record, per IAPP reporting
  2. Statutory damages currently stand at $2,663 per violation and $7,988 per intentional violation or violation involving minors, per § 1798.155
  3. The California Privacy Protection Agency and the Attorney General's office share enforcement authority over the CCPA
  4. Under the statute, each affected consumer record counts as a separate violation for penalty calculation
  5. Earlier CCPA enforcement actions generally settled near the lower end of the statutory range
California authorities announce largest CCPA fine to date - IAPP
PlateCalifornia authorities announce largest CCPA fine to date - IAPP — AI-generated

California privacy regulators have imposed the largest financial penalty under the California Consumer Privacy Act to date, according to reporting from the International Association of Privacy Professionals. The exact dollar amount, sanctioned company, and specific statutory violations were not disclosed in the headline-level notification. The action nonetheless functions as a clear signal that the regulator pairing is prepared to test the statute's upper penalty limits rather than continuing the lower-end settlements that characterized earlier CCPA enforcement.

Who enforces the CCPA?

The California Privacy Protection Agency, created by the 2020 California Privacy Rights Act and operational since 2023, shares enforcement authority over the CCPA with the California Attorney General's office. Civil penalties accrue under Cal. Civ. Code § 1798.155 at $2,663 per violation, rising to $7,988 per intentional violation or per violation involving consumers under 16. Each affected consumer record counts as a separate violation, and the inflation factor refreshes annually.

The agency exercises administrative subpoena power, examination authority, and the ability to enter stipulated orders with respondents. The Attorney General retains concurrent power to bring civil actions and to coordinate cross-statute claims involving data breach notification and unfair competition law.

What do we know about the record penalty?

IAPP characterized the action as the largest CCPA fine on record. Practitioners awaiting the full administrative decision or stipulated order should watch for:

  • The procedural pathway — stipulated settlement under the CPPA, an administrative hearing decision, or an Attorney General-driven civil action
  • Specific CCPA provisions cited, which may include notice and disclosure (§ 1798.100), deletion rights (§ 1798.105), opt-out obligations (§§ 1798.120, 1798.135), and sensitive personal information rules (§ 1798.121)
  • Remediation, audit, or injunctive terms layered onto the monetary penalty
  • Whether minors' data featured in the allegations, since that finding materially raises the per-violation multiplier

Why does a record penalty matter to practitioners?

The dollar figure matters less than the precedent it sets. Because earlier CCPA enforcement actions generally settled near the lower end of the statutory range, a step-change indicates regulators are willing to scale penalties by record volume rather than per-incident counts. Civil penalties are paid to the State and do not flow to consumers, but parallel private rights of action under § 1798.150 remain available for qualifying data breach cases.

Compliance teams handling California-resident data should re-examine four recurring pressure points:

  • Opt-out signal handling, particularly Universal Opt-Out Signals under § 1798.135(b)(1), which require honoring browser- or device-level signals as valid requests to opt out of sale or sharing
  • Vendor and service-provider due diligence, where contractors must be contractually bound to use personal information only for the business's specified purposes
  • Consumer response workflows for access and deletion requests, where verification gaps remain an enforcement trigger
  • Privacy policy disclosures distinguishing "sale" from "sharing" under § 1798.140, particularly where targeted advertising, profiling, or cross-context behavioral tracking is involved

What comes next?

The CPPA and the Attorney General typically publish final stipulated orders, administrative decisions, and press releases through the Attorney General's enforcement portal. Practitioners should compare the operative language of any final order against internal compliance programs, particularly where prior advisories flagged practices that were undercorrected. Until the underlying documents are public, the announcement functions as a calibration signal — financial exposure now tracks per-record treatment, not per-incident treatment alone. Internal counsel should also reassess data inventory and record-retention practices, since per-record penalty math turns over-disclosure as much as under-disclosure into a quantifiable risk.

via GN Enforcement (Source)

Filed under

  • ccpa
  • california-privacy-protection-agency
  • privacy-enforcement
  • data-privacy
  • consumer-privacy
Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

News editor covering industry trends and analytics at Global Law Wire.

201 articles

Also before the court

« Previous articleNext article »