Todd Snyder

Todd Snyder’s $345,178 CPPA fine: a privacy portal that quietly stopped processing opt-outs (2025)

Regulator: CalPrivacy (CPPA)Last updated

At a glance

Brought by
Regulator: CalPrivacy (CPPA)Regulator
Company
Todd Snyder
Sector
Apparel retail
Law
CCPA (California)
Amount
$345,178
Date
Settled May 6, 2025
Status
Settled

Summary

In May 2025, CalPrivacy fined the apparel retailer Todd Snyder $345,178 after its privacy portal failed to process opt-out requests for 40 days and it required people to verify their identity before opting out.

What happened

Besides requiring identity verification, Todd Snyder asked for more information than necessary before it would honor an opt-out of sale or sharing.

The mechanism

The failure was silent: the portal looked like it was collecting choices the whole time.

An opt-out runs from request to tags stopping to confirmation. It fails if the form isn't wired, adds friction or is ignored.

Why it was preventable

A consent tool that has stopped honoring opt-outs is invisible from the front end unless you test it. Submitting an opt-out and confirming the trackers actually stop is exactly the check that catches a silent failure like this.

In the regulator’s words

Michael Macko, Head of the CPPA’s Enforcement Division, said: “Using a consent management platform doesn’t get you off the hook for compliance.”

Timeline

  1. May 6, 2025settled.

Source

privacy.ca.gov.

privacy.ca.gov

Questions

Who fined Todd Snyder?

CalPrivacy, the California Privacy Protection Agency (CPPA), in May 2025. It is a separate enforcer from the California Attorney General.

What went wrong with the privacy portal?

It failed to process opt-out requests for 40 days. It looked like it was collecting choices, but the opt-outs went nowhere.

Does using a consent platform make a company compliant?

Not on its own. As the CPPA put it, using a consent management platform doesn’t get you off the hook. Whether the opt-outs actually stop the trackers has to be tested.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue