ConsentPixel – Privacy · Verified

Industry News

The CPPA Is Now Knocking: What the GM $12.75M CCPA Settlement Means for Your Site

The CPPA Is Now Knocking: What the GM $12.75M CCPA Settlement Means for Your Site

California just handed down its largest CCPA penalty ever — nearly five times the previous record. The same agency that imposed it also just launched a dedicated Audits Division capable of showing up unannounced at any business that serves California residents. Here's what happened, why it matters, and what you need to do before they find you first.

By the ConsentPixel — Privacy · Verified team June 2026 14 min read
$12.75M
Largest CCPA penalty ever — nearly 5x the previous record
8th
CCPA enforcement action ever — the pace is accelerating fast
Unannounced
CPPA's new Audits Division can audit any business without notice

Privacy enforcement in California entered a new phase on May 8, 2026. California Attorney General Rob Bonta — together with the California Privacy Protection Agency and district attorneys from Los Angeles, San Francisco, Napa, and Sonoma counties — announced a $12.75 million settlement with General Motors over its OnStar connected-vehicle data practices. The penalty is the largest in CCPA history, nearly five times the previous record, and it's the first time California has enforced the law's data minimization and purpose limitation requirements.

Those two facts together — record penalty, first-ever enforcement of new principles — signal something important: the CCPA is no longer just about cookie banners and opt-out buttons. Regulators are now coming after how you use data after you collect it, not just how you disclosed it. And with the CPPA's newly operational Audits Division capable of showing up at any CCPA-covered business without notice, the question for every US-facing website has changed from "have we been targeted?" to "are we ready if they come?"

The GM case: what actually happened

The General Motors / OnStar case isn't a story about a rogue data practice nobody knew about. It's a story about a company that collected data for one reason, then quietly used it for another — and got caught when investigators compared what the privacy policy said to what the data actually did.

From 2020 to 2024, GM sold the names, contact information, precise geolocation data, and driving behavior metrics of hundreds of thousands of California OnStar subscribers to two large data brokers: LexisNexis Risk Solutions and Verisk Analytics. Those brokers packaged the driving data — hard braking, rapid acceleration, speed, late-night driving, seatbelt use — into driver-rating products that insurers used to set rates. GM reportedly collected approximately $20 million nationwide from these sales.

The problem was twofold. First, GM's privacy policy told OnStar subscribers their data would only be used to provide OnStar services — things like emergency assistance, navigation, and driving feedback. It explicitly stated GM did not sell driving or location data. Second, when the CPPA first began investigating and asked GM about its data practices, investigators allege GM omitted any mention of selling consumer data to brokers. The actual data flows directly contradicted both the policy representations and the initial regulator response.

The critical detail

GM didn't just fail to disclose. Its privacy policy affirmatively stated it did not sell driving or location data — while it was actively selling that data. A federal court in a different 2026 case described this pattern as a "representational failure," which pulls in unfair competition and false advertising claims alongside the core privacy counts. That's why the AG pursued California's Unfair Competition Law and False Advertising Law alongside CCPA.

Under the settlement — subject to court approval — GM agreed to pay $12.75 million in civil penalties, stop selling driving data to consumer reporting agencies for five years, delete all previously retained covered driving data within 180 days, request deletion from LexisNexis and Verisk, and build and maintain a documented privacy program with mandatory risk assessments and reporting obligations.

Two new legal principles every website must know

The dollar amount is significant, but the legal precedents are more so. The GM settlement is explicitly the first CCPA enforcement of data minimization and purpose limitation, two principles added to the CCPA by the California Privacy Rights Act (CPRA) in 2023. What they mean practically:

1. Purpose limitation

Data you collect for one consented purpose cannot be repurposed for something else — even if your privacy policy technically discloses "data sharing" somewhere in the fine print. The AG's position in the GM case was clear: subscribers consented to their data being used for OnStar services, not for insurance risk scoring. The purpose matters as much as the disclosure. A broad "we may share your data with partners" clause does not satisfy this requirement if the actual use is materially different from what a reasonable consumer understood they agreed to.

2. Data minimization

You cannot retain personal data beyond the period necessary for its original disclosed purpose. GM retained driving and location data long after it had been used to operate OnStar — then sold that retained data to brokers. California called this a second independent violation: keeping the data too long, then monetizing the excess. The requirement is that you collect what you need, use it for what you said, and don't sit on it for future uses you haven't disclosed.

What this means for websites

These aren't just big-company problems. If your site collects visitor data for analytics — meaning you said you use it to understand site performance — and that same data is also flowing to ad partners who use it for behavioral targeting, you may have a purpose-limitation gap. The question regulators are now asking is whether the data's actual journey matches what users were told when they "consented."

The 2026 enforcement wave: GM wasn't alone

The GM settlement is the headline, but it sits atop a wave of 2026 CCPA enforcement that shows the agency operating at the pace and scale it was created for. To understand where you stand, it helps to see the pattern of what regulators found and fined:

CompanyDateFineCore violation
General Motors / OnStarMay 8, 2026$12.75MSold driving data contrary to stated purpose; data minimization failure; misled CPPA investigators
Walt Disney Co.Feb 11, 2026$2.75MDid not sufficiently provide CCPA opt-out rights
PlayOn SportsMar 3, 2026$1.10MViolated opt-out rights; student privacy (high school sports ticketing)
Ford Motor CompanyMar 5, 2026$375,703Required email verification before processing opt-out — unnecessary friction
Tractor Supply CompanyJan 8, 2026$1.35MFailed opt-out mechanisms including GPC; CCPA-non-compliant vendor contracts
American Honda Motor Co.2025$632,500Failures in data access and opt-out processes
Todd Snyder, Inc.2025$345,178Mishandled opt-out requests

Read across those cases and the enforcement map becomes clear. Regulators are moving systematically across industries — automotive, retail, media, youth sports, fashion — picking cases that signal to whole sectors. Honda signals auto. Tractor Supply signals rural retail. PlayOn signals any platform serving minors or schools. Disney signals media. GM signals: if you monetize behavioral data, your disclosed purpose had better match your actual data use.

CCPA enforcement timeline 2025–2026: fines are accelerating 2025 Honda $632K Jan 2026 Tractor Supply $1.35M Feb 2026 Disney $2.75M Mar 2026 PlayOn / Ford $1.48M May 8, 2026 GM / OnStar $12.75M Record penalty 8 enforcement actions. Fines increasing. Pace accelerating.
CCPA enforcement has moved from theory to practice — and the penalty curve is steep.

The CPPA's new Audits Division changes everything

In February 2026, the CPPA formally established its Audits Division under inaugural Chief Privacy Auditor Sabrina Boyson Ross — fulfilling an enforcement mandate built into the CPRA when voters passed Proposition 24 in 2020. For the first six-plus years of the law's existence, no dedicated audit function existed. That has changed.

The Audits Division is different from the Enforcement Division in a critical way. The Enforcement Division is largely complaint- and incident-driven — it responds to reports and investigations. The Audits Division can examine any CCPA-covered business at any time based on sector risk, regulatory priority, or independent research. That means announced and unannounced audits. You don't need to have done something obviously wrong to be selected. You don't need a complaint against you. The agency can pick your industry, pick your business, and show up.

The investigation goes back further than you might expect

When the CPPA opened the Tractor Supply investigation in 2024, it sought records going back to 2020 — the year the CCPA took effect. Prior remediation doesn't necessarily protect you either: the PlayOn Sports settlement ($1.1M) confirmed that self-identifying and fixing violations before agency contact doesn't prevent significant penalties. The question isn't just what you're doing now.

Chief Auditor Ross's background at Meta signals a methodology that goes beyond policy review into actual system architecture, data flows, and technical configurations. The CPPA's own enforcement head said in April 2026 that the agency is "just getting started," backed by more staff, the data broker registry requirements, and the new audit function. Bloomberg Law reported the enforcement head's words; the enforcement action timeline confirms them.

What the enforcement pattern tells you

Across the eight enforcement actions so far, three patterns emerge clearly enough to plan around:

  • Functional testing, not documentation review. Regulators aren't primarily reading privacy policies — they're testing whether opt-out mechanisms actually work in real user journeys, whether GPC signals propagate to ad networks, and whether data flows match representations. CPPA Research Technologist Nikita Samarin is credited in multiple enforcement actions. These are technical audits.
  • Friction in opt-out is a standalone violation. Ford was fined $375,703 for requiring email verification before processing an opt-out. That's it. No data breach, no sale to brokers — just an extra step between the user and their right. The CCPA requires opt-out to be frictionless, and regulators are testing this at the production level.
  • Remediation after investigation contact doesn't create safe harbor. PlayOn's $1.1M fine came despite the company fixing violations. Prior compliance failures in the record period are still at risk, and self-correction is taken into account in penalties but doesn't eliminate them.

What this means specifically for your website

You don't need to be GM to have a purpose-limitation gap. Most websites running third-party analytics and advertising pixels have a version of the same structural issue at a smaller scale:

  • Your privacy policy says you use analytics "to improve site performance."
  • The same analytics data flows to ad partners who use it for behavioral targeting across other sites.
  • Visitors who consented to the first use didn't understand they were consenting to the second.

That's a purpose-limitation gap. It's not as dramatic as selling driving data to insurance companies, but it's structurally identical — data collected for one disclosed purpose being used for another. And the banner that "disclosed" it is either buried in a policy or a pre-ticked box the user never read.

The data minimization gap is also common: most sites retain user data in analytics tools, CRMs, and ad platforms far beyond any operational need, because retention is the default and deletion requires intentional configuration. The GM case signals that regulators are now equipped and motivated to ask "why are you still holding this, and what are you doing with it?"

Add to this the GPC signal requirement — California now requires businesses to honor the Global Privacy Control, a browser-level opt-out, in real time across all connected vendors. The Ford and Tractor Supply cases both involved GPC non-compliance. If your consent stack doesn't propagate GPC opt-outs to every third-party in your advertising stack, that's a compliance gap the CPPA tests for technically.

What to do before they come to you

The enforcement pattern gives you a clear operational checklist — these are the exact things regulators tested in the cases that generated fines:

  • Audit what actually fires before consent. Load your site in a clean browser session and watch network traffic. If analytics or ad tags fire before the user makes a consent choice, you have an exposure. Every case in the enforcement record involves a gap between what the banner promises and what the technology actually does.
  • Map your data's actual journey. For each tracker on your site, document: what data it collects, where it goes, and what the recipient does with it. If the documented purpose in your privacy policy doesn't match the actual downstream use, you have a purpose-limitation gap.
  • Test your opt-out in production, not in documents. Submit your own opt-out request. Verify it propagates to all third parties. Confirm GPC signals honor in real time. Ford was fined because nobody appears to have tested whether the extra email verification step was actually required — regulators did.
  • Remove unnecessary friction from opt-out paths. The Ford precedent is clear: any required step beyond what's strictly necessary to process an opt-out is a violation. No mandatory email verification, no identity checks, no multi-step confirmation loops.
  • Align your retention schedules with your disclosed purposes. If you said data is used to improve performance, it shouldn't be sitting in an ad platform for two years. Document why you're keeping it and for how long.
  • Keep verifiable consent records. If the CPPA audits you, they will ask for evidence of what you disclosed, what users chose, and when. Timestamped, page-scoped consent logs are what holds up under technical scrutiny.
  • Brief counsel before a demand arrives. The GM case originated from a 2023 CPPA investigation into connected-vehicle manufacturers. If you're in a sector that's been signaled — automotive, retail, media, youth-accessible platforms, any ad-tech-heavy business — the time to prepare is now.

The bottom line

The $12.75 million GM settlement is a signal, not an anomaly. California built an enforcement agency, gave it record-setting penalties, added data minimization and purpose limitation to the law, launched an Audits Division capable of showing up unannounced, and is now systematically working through industries. The question the enforcement record answers is what regulators are looking for: whether your technology actually does what your banner says, whether users can opt out without friction, and whether the data's actual journey matches what you told people they were agreeing to. Every one of those questions has a technical answer — and a technical fix. The businesses that find those gaps themselves are in a materially better position than the ones who wait for an audit to find them first. This is informational, not legal advice; consult qualified counsel for your specific situation.

Find your gap before the CPPA does

ConsentPixel — Privacy · Verified scans your site to show exactly which trackers fire before consent — the first thing a CPPA technical audit checks. Free scan, no card required.

Scan my site free

Frequently asked questions

What is the CPPA Audits Division?

The California Privacy Protection Agency formally established its Audits Division in February 2026 under Chief Privacy Auditor Sabrina Boyson Ross. Unlike the Enforcement Division — which is largely complaint-driven — the Audits Division can proactively examine any CCPA-covered business at any time through both announced and unannounced audits. Audit findings can be referred directly to the Enforcement Division for penalties.

Why was the GM fine so large?

At $12.75 million, the GM / OnStar settlement is the largest CCPA penalty ever — nearly five times the previous record of $2.75M set by Disney in February 2026. Several factors contributed: the volume of affected drivers (hundreds of thousands), the duration of the conduct (2020–2024), the sensitivity of the data (precise geolocation, hard braking, late-night driving), the fact that GM's privacy policy explicitly stated it did not sell driving or location data, and allegations that GM initially omitted the data-broker sales from its response to CPPA investigators.

What are data minimization and purpose limitation under CCPA?

Purpose limitation means you can only use personal data for the purposes you disclosed and that consumers reasonably understood when consenting — you can't repurpose it for something materially different later. Data minimization means you can't retain personal data beyond the period necessary for those disclosed purposes. Both principles were added to CCPA by the CPRA in 2023. The GM settlement is the first CCPA enforcement of both, and California AG Rob Bonta described it as the first action enforcing the data minimization principle.

Does this apply to my website if I'm not a car manufacturer?

Yes. The purpose-limitation principle applies to any business that collects personal data from California residents. If your site tells visitors their data is used for analytics to improve performance, but that same data also flows to ad partners who use it for behavioral targeting on other sites, you may have a purpose-limitation gap structurally similar to GM's — just at a different scale. The CPPA has fined companies across retail, media, sports, and automotive; industry sector isn't the protection, privacy practice is.

What is the Global Privacy Control (GPC) and do I have to honor it?

The Global Privacy Control is a browser-level signal that lets a California consumer express a CCPA opt-out of sale and sharing once, and it propagates automatically to every site they visit. California requires CCPA-covered businesses to honor GPC in real time across all connected vendors — not just at a consumer-preference center, but at the network level in your ad stack. Both the Ford and Tractor Supply enforcement actions involved GPC non-compliance. If your consent platform doesn't propagate GPC opt-outs to every third party in your advertising stack, that's a tested compliance gap.

Does fixing violations before CPPA contact protect me?

Not fully. The PlayOn Sports settlement in March 2026 confirmed that self-identifying and correcting violations before agency contact doesn't prevent significant penalties — PlayOn paid $1.1M. Prior remediation may factor into penalty calculations, but it doesn't eliminate liability for the period during which violations occurred. The CPPA also has sought records going back to 2020 in investigations, so the relevant window is longer than many businesses assume. Consult counsel about your specific situation — this is informational, not legal advice.

ConsentPixel — Privacy · Verified
We build CIPA-first consent enforcement that blocks scripts rather than simulating consent. This article is informational and not legal advice — consult qualified counsel for your specific situation.
Scroll to Top