Sephora

Sephora’s $1.2M CCPA settlement: trackers as a data sale, and GPC opt-outs ignored (2022)

Regulator: California Attorney GeneralLast updated

At a glance

Brought by
Regulator: California Attorney GeneralRegulator
Company
Sephora
Sector
Cosmetics retail
Law
CCPA (California)
Amount
$1.2M settlement
Date
Settled Aug 24, 2022
Status
Settled

Summary

In August 2022, Sephora agreed to pay $1.2 million in penalties to settle California Attorney General allegations that third-party tracking on its website and app amounted to a sale of shopper data, which it did not disclose and did not stop when shoppers opted out through Global Privacy Control.

What happened

According to the Attorney General, the third-party tracking software monitored shoppers down to what went into a cart and what device they used. Under the California Consumer Privacy Act (CCPA), letting that data flow to third parties in exchange for services counts as a sale.

The mechanism

Global Privacy Control (GPC) is a browser setting that tells a site “do not sell my data.” Sephora’s trackers kept running regardless of it.

A browser with GPC turned on sends Sec-GPC: 1. If the site listens, ad tags stop. If it doesn't, ad tags keep firing.

Why it was preventable

Whether a site honors GPC is directly testable. A scan that sets the GPC signal and then checks which trackers still fire would have shown the opt-out was being ignored.

In the Attorney General’s words

Attorney General Rob Bonta said: “Technologies like the Global Privacy Control are a game changer for consumers looking to exercise their data privacy rights.”

Timeline

  1. Aug 24, 2022Sephora settled.

Source

Questions

Who brought the Sephora CCPA case?

The California Attorney General, in August 2022. The Attorney General and CalPrivacy (the CPPA) are two separate California enforcers.

Why did selling data count against Sephora?

Under the CCPA, letting data flow to third parties in exchange for services counts as a “sale.” Sephora did not disclose that sale and did not honor opt-out requests, including Global Privacy Control signals.

What is the Global Privacy Control?

GPC is a browser setting that tells a website “do not sell my data.” A site is expected to honor it, and whether it does is directly testable.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue