Sephora’s $1.2M CCPA settlement: trackers as a data sale, and GPC opt-outs ignored (2022)
At a glance
- Brought by
- Regulator: California Attorney GeneralRegulator
- Company
- Sephora
- Sector
- Cosmetics retail
- Law
- CCPA (California)
- Amount
- $1.2M settlement
- Date
- Settled Aug 24, 2022
- Status
- Settled
Summary
In August 2022, Sephora agreed to pay $1.2 million in penalties to settle California Attorney General allegations that third-party tracking on its website and app amounted to a sale of shopper data, which it did not disclose and did not stop when shoppers opted out through Global Privacy Control.
What happened
According to the Attorney General, the third-party tracking software monitored shoppers down to what went into a cart and what device they used. Under the California Consumer Privacy Act (CCPA), letting that data flow to third parties in exchange for services counts as a sale.
The mechanism
Global Privacy Control (GPC) is a browser setting that tells a site “do not sell my data.” Sephora’s trackers kept running regardless of it.

Why it was preventable
Whether a site honors GPC is directly testable. A scan that sets the GPC signal and then checks which trackers still fire would have shown the opt-out was being ignored.
In the Attorney General’s words
Attorney General Rob Bonta said: “Technologies like the Global Privacy Control are a game changer for consumers looking to exercise their data privacy rights.”
Timeline
- Aug 24, 2022Sephora settled.
Source
Questions
Who brought the Sephora CCPA case?
The California Attorney General, in August 2022. The Attorney General and CalPrivacy (the CPPA) are two separate California enforcers.
Why did selling data count against Sephora?
Under the CCPA, letting data flow to third parties in exchange for services counts as a “sale.” Sephora did not disclose that sale and did not honor opt-out requests, including Global Privacy Control signals.
What is the Global Privacy Control?
GPC is a browser setting that tells a website “do not sell my data.” A site is expected to honor it, and whether it does is directly testable.
Related cases
American Honda’s $632,500 CPPA fine
Asymmetric opt-out; excessive verification
Tractor Supply’s $1.35M CPPA fine
Opt-out webform did not stop trackers; GPC not honored until Jul 2024
Disney’s $2.75M CCPA settlement
Opt-out not carried across devices and services
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
