Disney’s $2.75M CCPA settlement: opt-outs that stopped at one device (2026)
At a glance
- Brought by
- Regulator: California Attorney GeneralRegulator
- Company
- Disney (Disney DTC and ABC Enterprises)
- Sector
- Media and streaming
- Law
- CCPA (California)
- Amount
- $2.75M settlement
- Date
- Settled Feb 11, 2026
- Status
- Settled
Summary
In February 2026, Disney agreed to $2.75 million in civil penalties to settle claims by the California Attorney General, which said opt-outs, including GPC, applied only to a single Disney streaming service or device instead of the whole account, so data kept being sold or shared elsewhere.
What happened
The settling companies are Disney DTC, LLC and ABC Enterprises, Inc., Disney subsidiaries, and the services named are Disney+, Hulu and ESPN+. According to the Attorney General, a choice made on one service or device did not carry to the others on the same account, and many connected-TV apps had no in-app opt-out at all.
The mechanism
A person could opt out on their laptop and still be tracked on their living-room TV app under the same login.

Why it was preventable
Whether an opt-out propagates across an account is testable by exercising it on one surface and checking the others. Cross-device behavior is exactly the kind of thing that looks fine in a single-page check and fails when you walk the whole journey.
In the Attorney General’s words
Attorney General Rob Bonta said: “Consumers shouldn’t have to go to infinity and beyond to assert their privacy rights.”
Timeline
- Feb 11, 2026settled. *(The Attorney General called it the largest settlement to date under the CCPA, as of February 2026.)*
Source
Questions
Who brought the Disney case, and how much?
The California Attorney General. Disney agreed to $2.75 million in civil penalties in February 2026, which the Attorney General called the largest settlement to date under the CCPA, as of February 2026.
What was the actual failure?
Opting out on one Disney service or device did not carry across the other services and connected devices on the same account. Many connected-TV apps had no in-app opt-out at all.
How do you test cross-device opt-out?
Exercise the opt-out on one surface, then check the others under the same login. A per-device check looks fine while the account-level behavior fails.
Related cases
Sephora’s $1.2M CCPA settlement
Sale not disclosed; GPC opt-out ignored
Tractor Supply’s $1.35M CPPA fine
Opt-out webform did not stop trackers; GPC not honored until Jul 2024
Healthline’s $1.55M CCPA settlement
Banner did not disable tracking cookies; diagnosis-suggesting titles shared
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
