Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

California Burned $4.2M in CCPA Penalties in Six Weeks: What Disney, Ford, and PlayOn Mean for Your Fintech

The CPPA's first major enforcement wave of 2026 — Disney's $2.75M opt-out settlement, Ford's $375K friction finding, and PlayOn's $1.1M GPC failure — establishes a clear enforcement playbook. Here's what fintechs and financial services companies need to fix before auditors show up.

By Rebecca Leung · June 17, 2026 ·
Table of Contents

TL;DR:

  • California regulators issued $4.25 million in CCPA penalties across three enforcement actions in six weeks (February–March 2026), targeting opt-out failures at Disney, Ford, and PlayOn Sports.
  • The enforcement pattern is clear: siloed opt-out mechanisms, failure to honor GPC browser signals, and unnecessary friction in the opt-out process are now reliably triggering action.
  • Fintechs and financial services companies are not fully protected by the GLBA — the exemption covers specific financial data types, not the institution — making California-based data collection a live compliance risk.
  • The CPPA’s new Audits Division can examine any CCPA-covered business proactively, without a consumer complaint, and has specifically flagged fintechs and data brokers as high-priority sectors.

California’s privacy enforcement machine ran hot in early 2026. In six weeks, regulators collected $4.25 million in penalties from three household names — Disney, Ford, and PlayOn Sports — and each action was grounded in the same root cause: consumers could not actually exercise the right to opt out of having their data sold or shared.

If your fintech collects behavioral data, location data, device identifiers, or anything beyond the specific financial transaction records protected by GLBA, these enforcement actions are about you. The compliance gap that cost Disney $2.75 million isn’t exotic. It’s an architecture problem that exists at most companies running multi-platform products, and California just handed regulators a detailed enforcement blueprint for finding it.

Here’s what happened, what it means, and what to fix before an auditor shows up.

What the Three Enforcement Actions Actually Found

Disney and ABC: $2.75 Million (February 11, 2026)

California Attorney General Rob Bonta filed and simultaneously settled against Disney DTC, LLC and ABC Enterprises for failures in CCPA opt-out implementation across streaming services, connected TV apps, and mobile platforms. The $2.75 million settlement is the largest CCPA enforcement action in California history.

The core finding: Disney implemented opt-out mechanisms in silos. A consumer who opted out on one platform — say, Disney+ on a web browser — had that opt-out ignored on Disney+ via a connected TV, through a mobile app, or through a third-party streaming integration. Disney could unify consumer identity for advertising purposes but had not built unified identity infrastructure to propagate opt-outs across the same product surface area.

The settlement requires Disney to honor a single opt-out request across all services, devices, and third-party data partners associated with a consumer’s account.

What this establishes: If a business can unify consumer identity for advertising, it must unify that identity for opt-out compliance. The AG’s message was direct — you can’t claim technical limitation as a defense on the same system you use to deliver personalized ads.

Ford Motor Company: $375,000 (March 2026)

The CPPA fined Ford for adding “unnecessary friction” to the opt-out process on its website and connected vehicle platform. The specific violation: Ford required consumers to complete an email verification step before they could opt out of the sale and sharing of their data.

That single additional step — which Ford presumably added to prevent unauthorized opt-outs — made the opt-out flow harder to complete than signing up for an account. The CPPA found this violated CCPA’s requirement that opt-out mechanisms be easy to use and not require unnecessary information beyond what’s needed to process the request.

What this establishes: Identity verification before completing an opt-out is friction that can trigger enforcement. If your opt-out flow asks consumers to re-enter credentials, verify an email, complete a CAPTCHA, or navigate more than a few steps, audit that flow today.

PlayOn Sports: $1.1 Million (March 3, 2026)

PlayOn Sports — a youth and high school sports media platform — received a $1.1 million fine for three distinct violations. First and most significant: PlayOn failed to recognize and honor Global Privacy Control (GPC) signals. Second, PlayOn’s privacy policy had not been updated in over a year and failed to accurately disclose consumers’ CCPA rights. Third, the policy contained misleading statements about whether the company sold personal information.

The children’s data component elevated the violation severity significantly, since intentional violations or those involving minors carry fines of $7,988 per incident rather than $2,663. The CPPA’s late-2025 enforcement sweep specifically targeted GPC compliance; PlayOn was caught in it.

What this establishes: GPC is not optional. Any business that sells or shares personal information must configure its web infrastructure, mobile apps, and tag management systems to detect and honor GPC browser signals as a valid opt-out. Non-recognition is a per-violation CCPA violation — at scale, it compounds fast.

The Pattern and What’s Coming Next

Enforcement ActionFineCore Violation
Disney / ABC$2.75MSiloed opt-out mechanisms across platforms
PlayOn Sports$1.1MNo GPC recognition; stale privacy policy
Ford$375KEmail verification friction in opt-out flow
Total$4.225MSix weeks of enforcement

Three actions. Three different violation types. One unifying principle: consumers were systematically unable to exercise their CCPA rights in a meaningful way.

Enforcement is escalating on multiple tracks. The CPPA’s late-2025 joint sweeps specifically targeting GPC compliance produced the PlayOn case. The AG’s most recent investigative focus has expanded into surveillance pricing — examining how businesses use consumer data to price products differently — which has direct implications for credit decisioning, insurance pricing, and personalized financial offers in fintech.

The math on per-violation fines concentrates enforcement attention on large-scale processors. At $2,663 per unintentional violation, a company with 200,000 California consumers who cannot complete an opt-out faces theoretical exposure that drives aggressive settlement postures. Actual settlements are far lower than theoretical maximums, but the underlying calculus shapes enforcement priority.

Most consequentially: the CPPA’s Audits Division, launched in February 2026 under Chief Privacy Auditor Sabrina Boyson Ross, fundamentally changes the enforcement environment. Before February 2026, enforcement was largely reactive — it started with a consumer complaint or a breach disclosure. The Audits Division can initiate examinations without any triggering event, targeting businesses based on sector risk analysis, processing volume, or regulatory priority. Fintechs, data brokers, and businesses with high annual revenue are explicitly identified as high-priority sectors.

What Fintechs Need to Know

The GLBA Exemption Doesn’t Cover Your Entire Data Footprint

This is the most dangerous misconception in financial services privacy compliance. The CCPA includes a GLBA exemption — but it exempts specific data types, not institutions. The exemption applies to personal information collected, processed, sold, or disclosed subject to the GLBA and its regulations. It does not exempt a fintech from CCPA obligations just because part of its business handles GLBA-regulated information.

If your fintech collects behavioral data (browsing patterns, feature usage, time-in-app), device data (device identifiers, IP addresses, location pings), marketing data (email engagement, ad click behavior), or any personal information that flows through your analytics stack or ad-tech infrastructure — that data is not automatically GLBA-exempt.

Disney is a media company. Ford sells cars. PlayOn is a sports platform. None are financial services entities. But the enforcement logic applies identically to fintech: the data you use for product analytics, marketing attribution, and customer engagement is not insulated by your GLBA compliance program.

Your Opt-Out Architecture Probably Doesn’t Scale

Most fintechs built opt-out mechanisms as an afterthought — a link in the privacy policy footer, a toggle in account settings, a response workflow for DSARs. What the enforcement actions reveal is that fragmented opt-out implementations at scale create systematic violation exposure that auditors are now trained to find.

Specific gaps to audit:

GPC Signal Recognition: Test whether your web and app properties actually detect and respond to GPC signals. Browser extensions can simulate a GPC signal to verify detection. If your tag manager, consent management platform, or first-party data infrastructure doesn’t respond to GPC, fix it before the CPPA’s next enforcement sweep identifies your sector.

Cross-Platform Propagation: Map where consumer data flows across your product surface area. If a consumer opts out on your web app, does that preference propagate to your mobile app, email marketing platform, analytics vendor, ad pixels, and every API integration that shares that consumer’s data? If the answer involves any exceptions, you have a Disney-style siloed architecture problem.

Verification Friction: Review your opt-out flow for steps that could be characterized as unnecessary. Email verification, re-authentication, and multi-page forms are all potential enforcement targets. A consumer should be able to opt out with no more friction than submitting a simple web form.

The New Risk Assessment Requirements Are Already Live

The CPPA’s regulations effective January 1, 2026 created significant obligations beyond opt-out mechanisms. If your business uses automated decision-making technology (ADMT) for significant decisions affecting consumers in credit, employment, housing, or education — which covers any AI-based credit scoring, fraud scoring, or customer risk assessment tool — risk assessment obligations are already in force for new deployments.

The cybersecurity audit requirement is staggered by revenue tier (2028–2030), but the audit framework requires controls to be implemented now. The 2028 certification date is when you document completion, not when you start building. For the full technical requirements picture, the CPPA cybersecurity audit and ADMT compliance post covers what financial services teams need to have in place.

Building Opt-Out Compliance That Survives an Audit

A CCPA opt-out compliance program that holds under CPPA scrutiny has three operational components. Most fintechs have implemented only the first.

Discovery and Data Mapping: Identify every touchpoint where you collect personal information from California consumers, and every downstream system where that information flows. This includes your analytics stack, ad pixels, data enrichment vendors, and every API integration that shares consumer data with third parties. You cannot honor opt-outs for data flows you haven’t mapped. This exercise also surfaces your GPC detection gaps and your cross-platform propagation weaknesses.

Mechanism and Technical Controls: Implement opt-out with explicit GPC recognition, cross-platform propagation, and a documented signal-propagation log. Your consent management platform should treat GPC signals as a first-class opt-out trigger — not an afterthought added under enforcement pressure. Test the implementation quarterly: use a test account from a California device or simulate a GPC signal to verify the entire propagation chain.

Operational Response: Build opt-out requests into your DSAR intake workflow with documented completion SLAs. The DSAR response workflow post covers how to handle California consumer requests efficiently across CCPA, GDPR, and state law requirements. Opt-outs and access requests require different responses, and a DSAR system that handles both with clear audit trails is the operational baseline.

For ongoing monitoring, your privacy compliance program should track opt-out request completion rates, GPC signal detection rates (measured technically, not just operationally), and days-to-completion for consumer requests. If you’re not tracking these, you don’t know whether your mechanism works at scale.

The Regulatory Backdrop

These three enforcement actions are the visible output of a multi-year enforcement strategy, not isolated incidents. The CPPA’s 2025 joint sweeps specifically targeted GPC compliance across consumer-facing industries. The Disney action followed an AG investigation into streaming platforms. The Ford action followed the CPPA’s connected vehicle data focus from 2024.

The CPPA has also signaled that surveillance pricing — using behavioral and location data to price products differently by consumer — is its next enforcement focus area. For fintechs and financial services companies using customer data in pricing models, underwriting algorithms, or rate-setting: this enforcement direction is heading toward your business.

For context on how state privacy laws are reshaping the GLBA safe harbor more broadly and why fintechs should not rely on federal exemptions as a default defense, the state privacy laws and GLBA safe harbor erosion post covers the multi-state compliance landscape that financial services teams are navigating.

So What?

California burned through $4.25 million in CCPA enforcement in six weeks in early 2026. Disney. Ford. PlayOn. Each case has a different technical failure, but the pattern is identical: at scale, across platforms, consumers could not actually opt out.

If your fintech uses any data outside GLBA-covered transaction records for analytics, marketing, product personalization, or fraud modeling — and most do — you are operating in the same regulatory environment these companies just exited via settlement.

The CPPA Audits Division is operational and proactively examining high-data-volume businesses. GPC recognition is a live enforcement target. Cross-platform opt-out architecture is a gap auditors are specifically trained to find.

Audit your opt-out implementation now. Test GPC recognition technically, not just operationally. Map your cross-platform data flows. Document the analysis. The settlement amounts are always less than what it costs to remediate under investigation pressure — and the Disney case established that $2.75 million is where CCPA enforcement lands when the violation is systematic and the company should have known better.


Sources: California AG Disney CCPA Settlement · CPPA Ford Enforcement Action · WilmerHale on PlayOn $1.1M Fine · Jones Day on Disney Settlement Details · CPPA 2026 Regulations Overview

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the GLBA exempt fintechs from CCPA enforcement?
Not fully. California takes a narrow approach: specific financial data covered by GLBA may be exempt, but the institution itself is not. If your fintech collects behavioral data, device data, IP addresses, or any personal information outside your core financial transaction records, that data is likely subject to CCPA. The Disney, Ford, and PlayOn enforcement actions involved non-financial data — streaming preferences, vehicle telematics, student ad tracking — but the CPPA's Audits Division can review any CCPA-covered business, including financial services entities, and will examine your entire data footprint.
What is GPC (Global Privacy Control) and why does it matter for compliance?
GPC is a browser-level opt-out signal — a technical specification that lets consumers set a single preference to opt out of the sale and sharing of their data across all websites they visit. PlayOn Sports was fined $1.1M in March 2026 specifically for failing to recognize and honor GPC signals. Any business that sells or shares personal information of California consumers must recognize GPC signals as a valid opt-out request — including via mobile apps, web platforms, and connected devices. Non-recognition is now an active target of CPPA enforcement sweeps.
Our opt-out link works on our main website. Isn't that enough?
No. Disney's $2.75M settlement specifically requires that a single opt-out request be honored across all services, devices, and third-party partners. The CPPA found that Disney had siloed opt-out mechanisms — what worked on one platform didn't work on connected TVs and streaming apps. If your fintech operates on multiple platforms (web, mobile, embedded partner integrations), a single consumer opt-out must propagate to every system where that consumer's data is shared.
What does the new CPPA Audits Division mean for companies not yet under investigation?
It changes the compliance calculus entirely. The CPPA's Enforcement Division has historically been driven by consumer complaints. The Audits Division, launched in February 2026 under Chief Privacy Auditor Sabrina Boyson Ross, can examine any CCPA-covered business at any time based on sector risk or regulatory priority — no complaint required. Fintechs, data brokers, and businesses with high data processing volumes are specifically mentioned as high-priority sectors. An audit can arrive without any triggering event.
When are the new CCPA cybersecurity audit and risk assessment requirements due?
Risk assessments: required for all ongoing high-risk processing activities by December 31, 2027, with the first certified reports due to CPPA by April 1, 2028. Cybersecurity audits are staggered by revenue: April 1, 2028 for businesses over $100M revenue, April 1, 2029 for $50M–$100M, and April 1, 2030 for under $50M. The ADMT risk assessment requirement — covering automated systems used for credit, employment, and housing decisions — started January 1, 2026 for new deployments.
What's the CCPA penalty per violation in 2026?
Per violation: $2,663 for unintentional violations, $7,988 for intentional violations or those involving minors' data (2026 adjusted figures). Violations are assessed individually — a company with hundreds of thousands of California consumers who were denied opt-out rights faces hundreds of thousands of separate violation counts. That's how a technical compliance gap turns into a seven-figure settlement.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.