Tractor Supply’s $1.35M CPPA fine: an opt-out webform that didn’t stop the trackers (2025)
At a glance
- Brought by
- Regulator: CalPrivacy (CPPA)Regulator
- Company
- Tractor Supply
- Sector
- Retail
- Law
- CCPA (California)
- Amount
- $1.35M
- Date
- Settled Sep 30, 2025
- Status
- Settled
Summary
In September 2025, CalPrivacy fined Tractor Supply $1.35 million after its opt-out webform did not stop the third-party tracking technologies it used for advertising, and its site did not honor opt-out preference signals such as GPC until July 2024. The settlement requires Tractor Supply to scan its digital properties for tracking technologies.
What happened
According to the order, Tractor Supply’s vendor contracts also lacked required privacy terms.
The mechanism
A shopper who tried to opt out was still being tracked, because using the webform did not reach the tracking technologies behind it.

Why it was preventable
“Does the opt-out actually stop the trackers” is a yes-or-no test. The settlement even requires Tractor Supply to scan its digital properties for tracking technologies, which is the check that would have caught this in the first place.
In the regulator’s words
Michael Macko, Head of the CPPA’s Enforcement Division, said: “We will continue to look broadly across industries to identify violations of California’s privacy law.”
Timeline
- Sep 30, 2025settled, with a four-year compliance-certification obligation.
Source
Questions
Who fined Tractor Supply?
CalPrivacy, the California Privacy Protection Agency (CPPA), in September 2025. It is a separate enforcer from the California Attorney General.
The site had an opt-out webform. Why the fine?
The webform was there, but the tracking technologies kept running after a consumer used it, and until July 2024 the site did not honor opt-out preference signals such as GPC. The opt-out did not actually stop anything.
What does the settlement now require?
Among other terms, Tractor Supply has to scan its digital properties for tracking technologies, on a four-year compliance-certification obligation. That scan is the check that would have caught the problem first.
Related cases
Sephora’s $1.2M CCPA settlement
Sale not disclosed; GPC opt-out ignored
Disney’s $2.75M CCPA settlement
Opt-out not carried across devices and services
Ford’s $375,703 CPPA fine
Email-verification friction added to opt-out
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
