Privacy and Consent Enforcement Watch: GDPR, CCPA and CIPA Cases Explained

Summary
Enforcement Watch is a running record of the privacy and consent enforcement actions that turn on how a website tracks people. We cover the cases where a tag, pixel, or cookie is the reason for the fine or the lawsuit, explain what actually went wrong, and note which ones a live scan could have caught first.
Regulators and courts are fining companies for how their websites track people. We keep a running record of the cases that turn on tag behavior, and explain what actually went wrong: which tag fired, in what consent state, and what it cost.
Most of these were preventable. A tag firing before consent, or a pixel still sending data after someone opted out, is the kind of thing a live scan catches before a regulator does.
See the full case indexHow to read a privacy enforcement action
Two things get reported wrong, so they’re worth stating plainly.
Who brought it
A regulator and a private lawsuit are different events. In California alone there are two separate regulators: the California Privacy Protection Agency (CalPrivacy) and the Attorney General. And most CIPA cases are private class actions brought by plaintiffs, with no government enforcer involved at all. We label every case by who actually brought it.
Regulator
Private litigation
What the mechanism was
Most of these cases come down to one of a few technical failures: a tracking tag that fires before the visitor consents, a pixel that keeps sending data after someone opts out, a consent banner that doesn’t actually stop anything, or an opt-out signal the site ignores. PII (personally identifiable information) leaking to an ad platform through one of these is a real, describable problem, and a testable one.
Featured: recent findings where tag monitoring would have helped
These are the actions where a coverage scan across consent states would likely have surfaced the problem before it became a fine or a filing. Each links to its full breakdown.
FTC v. Hims & Hers (2026)
a pending lawsuit alleging health information about erectile dysfunction and mental health treatment was shared with ad platforms such as Meta and Snap without clear disclosure.
CNIL fine against Condé Nast, 750,000 euros (2025)
cookies set on arrival, and a “reject” button that didn’t stop the tracking.
CalPrivacy fine against Tractor Supply, 1.35 million dollars (2025)
an opt-out webform that didn’t stop the third-party trackers used for advertising, and a site that didn’t honor opt-out preference signals such as GPC until July 2024.
The health-pixel wave
A cluster of US hospitals, clinics, and telehealth companies has faced lawsuits and agreed to settlements over tracking pixels that sent patient data to advertising platforms. We track that wave on its own pillar page, and each health case also appears in the full index below.
Full case index
Every case we track sits in the full index, most recent first, each row typed by who brought it (a regulator action and a private lawsuit are different events).
Who’s enforcing
Primary sources we watch: the FTC, CalPrivacy (CPPA), the California Attorney General, France’s CNIL, Italy’s Garante, the UK’s ICO, and Australia’s OAIC.
Aggregate trackers: enforcementtracker.com and cookiefines.eu.
Most of these cases started with a tag doing something nobody saw
DataTrue loads your real pages in each consent state, reads what your tags send, and alerts you when a result changes. A problem shows up in a test before it shows up in a case.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.

Questions
Is a cookie banner enough to avoid these fines?
No. Several of the cases here had a banner. The fines came because the tags fired anyway, before consent or after a refusal. What matters is whether the banner actually gates what runs, and that is something you have to test rather than assume.
What’s the difference between CCPA and CIPA?
CCPA is California’s privacy statute, enforced by regulators. CIPA is a much older wiretapping law now used by private plaintiffs to sue over website tracking. A company can face both.
Does this only apply to California or the EU?
No. The EU (GDPR), the UK (PECR and UK GDPR), Australia (the Privacy Act), Canada (Quebec’s Law 25), and a growing list of US states all now enforce against tracking without proper consent.