Todd Snyder’s $345,178 CPPA fine: a privacy portal that quietly stopped processing opt-outs (2025)
At a glance
- Brought by
- Regulator: CalPrivacy (CPPA)Regulator
- Company
- Todd Snyder
- Sector
- Apparel retail
- Law
- CCPA (California)
- Amount
- $345,178
- Date
- Settled May 6, 2025
- Status
- Settled
Summary
In May 2025, CalPrivacy fined the apparel retailer Todd Snyder $345,178 after its privacy portal failed to process opt-out requests for 40 days and it required people to verify their identity before opting out.
What happened
Besides requiring identity verification, Todd Snyder asked for more information than necessary before it would honor an opt-out of sale or sharing.
The mechanism
The failure was silent: the portal looked like it was collecting choices the whole time.

Why it was preventable
A consent tool that has stopped honoring opt-outs is invisible from the front end unless you test it. Submitting an opt-out and confirming the trackers actually stop is exactly the check that catches a silent failure like this.
In the regulator’s words
Michael Macko, Head of the CPPA’s Enforcement Division, said: “Using a consent management platform doesn’t get you off the hook for compliance.”
Timeline
- May 6, 2025settled.
Source
Questions
Who fined Todd Snyder?
CalPrivacy, the California Privacy Protection Agency (CPPA), in May 2025. It is a separate enforcer from the California Attorney General.
What went wrong with the privacy portal?
It failed to process opt-out requests for 40 days. It looked like it was collecting choices, but the opt-outs went nowhere.
Does using a consent platform make a company compliant?
Not on its own. As the CPPA put it, using a consent management platform doesn’t get you off the hook. Whether the opt-outs actually stop the trackers has to be tested.
Related cases
American Honda’s $632,500 CPPA fine
Asymmetric opt-out; excessive verification
Tractor Supply’s $1.35M CPPA fine
Opt-out webform did not stop trackers; GPC not honored until Jul 2024
Ford’s $375,703 CPPA fine
Email-verification friction added to opt-out
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
