Enforcement Watch

Enforcement Watch

Privacy and Consent Enforcement Watch: GDPR, CCPA and CIPA Cases Explained

Last updated

Summary

Enforcement Watch is a running record of the privacy and consent enforcement actions that turn on how a website tracks people. We cover the cases where a tag, pixel, or cookie is the reason for the fine or the lawsuit, explain what actually went wrong, and note which ones a live scan could have caught first.

Regulators and courts are fining companies for how their websites track people. We keep a running record of the cases that turn on tag behavior, and explain what actually went wrong: which tag fired, in what consent state, and what it cost.

Most of these were preventable. A tag firing before consent, or a pixel still sending data after someone opted out, is the kind of thing a live scan catches before a regulator does.

See the full case index

How to read a privacy enforcement action

Two things get reported wrong, so they’re worth stating plainly.

01

Who brought it

A regulator and a private lawsuit are different events. In California alone there are two separate regulators: the California Privacy Protection Agency (CalPrivacy) and the Attorney General. And most CIPA cases are private class actions brought by plaintiffs, with no government enforcer involved at all. We label every case by who actually brought it.

Regulator

Regulator: FTCRegulator: CalPrivacy (CPPA)Regulator: California Attorney GeneralRegulator: CNIL (France)Regulator: AEPD (Spain)Regulator: OAIC (Australia)

Private litigation

Private litigation (CIPA)Private litigation (PA WESCA)Private litigation
02

What the mechanism was

Most of these cases come down to one of a few technical failures: a tracking tag that fires before the visitor consents, a pixel that keeps sending data after someone opts out, a consent banner that doesn’t actually stop anything, or an opt-out signal the site ignores. PII (personally identifiable information) leaking to an ad platform through one of these is a real, describable problem, and a testable one.

Featured: recent findings where tag monitoring would have helped

These are the actions where a coverage scan across consent states would likely have surfaced the problem before it became a fine or a filing. Each links to its full breakdown.

The health-pixel wave

A cluster of US hospitals, clinics, and telehealth companies has faced lawsuits and agreed to settlements over tracking pixels that sent patient data to advertising platforms. We track that wave on its own pillar page, and each health case also appears in the full index below.

Read the health-pixel wave breakdown

Full case index

Every case we track sits in the full index, most recent first, each row typed by who brought it (a regulator action and a private lawsuit are different events).

See the full case index

Who’s enforcing

Primary sources we watch: the FTC, CalPrivacy (CPPA), the California Attorney General, France’s CNIL, Italy’s Garante, the UK’s ICO, and Australia’s OAIC.

Aggregate trackers: enforcementtracker.com and cookiefines.eu.

30-day free trial

Most of these cases started with a tag doing something nobody saw

DataTrue loads your real pages in each consent state, reads what your tags send, and alerts you when a result changes. A problem shows up in a test before it shows up in a case.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue

Questions

Is a cookie banner enough to avoid these fines?

No. Several of the cases here had a banner. The fines came because the tags fired anyway, before consent or after a refusal. What matters is whether the banner actually gates what runs, and that is something you have to test rather than assume.

What’s the difference between CCPA and CIPA?

CCPA is California’s privacy statute, enforced by regulators. CIPA is a much older wiretapping law now used by private plaintiffs to sue over website tracking. A company can face both.

Does this only apply to California or the EU?

No. The EU (GDPR), the UK (PECR and UK GDPR), Australia (the Privacy Act), Canada (Quebec’s Law 25), and a growing list of US states all now enforce against tracking without proper consent.