In this article

Sign up for our newsletter

Share this article

In its most-recent enforcement report, the California Privacy Protection Agency (CPPA, or CalPrivacy) disclosed that it’s received over 12 thousand consumer complaints since the CCPA went into effect. Consumers are raising the alarm over data privacy practices, and regulators are listening.

If a consumer complained about your business, how does a regulator investigate the complaint? Before they launch a formal audit, an investigation starts with a very simple step: visiting your website. Often, regulators can see whether a website is in violation of data privacy law straightaway.

When you look at what actually tripped up the companies that got fined, a pattern shows up again and again: most companies were making an effort, most thought they were compliant, most appeared compliant–but what was actually happening on the backend told a different story.

That gap between policy, appearance, and practice is good news, in a strange way. It means you don't need a crystal ball to find your own exposure. You need to look at your own site the way a regulator would. Here's what they're checking for.

1. When Users Opt Out on Your Website, Does It Stop Trackers From Firing?

A "Do Not Sell" link that's present on the page isn't the same thing as an opt-out that actually works. Several of the largest settlements this year hinged on that exact gap.

Regulators found that Healthline Media's website fired 118 tracking cookies even after visitors used all three available opt-out methods at once: a Do Not Sell link, a Global Privacy Control (GPC) signal, and the cookie banner itself. They got hit with a $1.55 million fine as a result. Similarly, Disney was fined $2.75 million after regulators discovered opt-outs only extended to the individual services and devices they were submitted on, while tracking persisted across users accounts on other services and devices.

None of these were policy failures. They were technical ones. A consent management platform that renders a banner correctly but never confirms the tracking actually stops is giving you false confidence, and regulators have made clear they're testing the mechanism, not reading the copy.

Osano and InfoTrust recently teamed up to audit a real-world website with the types of broken opt-outs regulators have called out in enforcement actions. In fact, in our Marketing & Consent webinar series, we disclosed research showing that 79% of websites keep firing tracking tags after a user opts out–which means 79% of websites are fair game for a regulator to penalize.

2. Is Your Website Accepting Universal Opt-Out Preference Signals?

Universal opt-out signals like the GPC let a person set their opt-out preference once, in their browser, instead of clicking through a thousand and one banners for every site they visit. Twelve states now require businesses to honor GPC signals.

Last year, the California Attorney General, the Colorado Attorney General, and the Connecticut Attorney General ran a coordinated sweep specifically checking GPC compliance, the first joint initiative from what's since become a broader regulator coalition. GPC failures showed up explicitly in the Tractor Supply settlement ($1.35 million) and the Healthline Media settlement ($1.55 million).

3. Consent Flows Riddled with Dark Patterns

Once you know what to look for, you’ll be able to spot this on sight (just like regulators). If accepting cookies takes one click and rejecting them takes four, that's not a neutral design. It's what’s known as a dark pattern, and regulators now treat it as one.

The Sling TV settlement is a clean example. Sling TV’s opt-out was buried inside a general cookie preferences center instead of standing on its own, and completing the request required a name, address, email, and phone number, information the company had no real reason to ask for. CCPA amendments that went into effect at the start of 2026 now codify explicitly that dark patterns are non-compliant.

Our rundown of nine dark pattern examples is a good gut check: confirm-shaming, hard-to-cancel patterns, forced action, preselected boxes, and a few others you'll probably recognize once you see them named. In SlingTV’s case, the hard-to-cancel and obstruction patterns were the most obvious dark patterns in play.

4. Are There Ad-Tech Tags on Your site?

Having trackers on your site that send data to external parties isn’t in and of itself a violation. You’re supposed to honor consent preferences and provide notice for the use of ad-tech tags, of course. But if you aren’t doing that, or have some other violation, the presence of tags that transfer data to third-parties gives regulators a clear pointer to what to look for first in an investigation: Your contracts.

Data privacy regulations have strict requirements around what your vendor contracts need to contain, and what responsibilities and permissions they give vendors with respect to consumer data.

Healthline's ad-tech contracts let partners use shared data for "any business purpose," language that directly conflicts with the purpose limitation principle regulators are now enforcing. Honda, which was fined for over $600,000, lacked required contractual language with its ad-tech partners. And in the largest CCPA penalty in California history at $12.75 million, General Motors sold OnStar location and driving data to data brokers for insurance rate-setting despite their contracts explicitly forbidding this practice.

The tags themselves are the visible part of this problem. The contract behind each one is where the actual risk lives.

These actions (and every other enforcement action described in this article) are analyzed in depth in our State of US Privacy Enforcement 2026 report. If you want to learn exactly how and why GM, Healthline, and Honda’s contractual practices failed to meet CCPA standards, give it a read.

5. Are You Securing Opt-In Consent Based on State Definitions for Children and Sensitive Data?

Most businesses still treat age screening as a COPPA question, meaning it only matters if a user is under 13. That's no longer where the bar sits. Under the CCPA, you need affirmative opt-in consent before selling or sharing the data of anyone between 13 and 16.

Regulators have enforced that standard directly–not just for the under-13 threshold most people have in mind.

Jam City sold the data of 13-to-16-year-olds without that consent. PlayOn Sports tracked minors at high school athletic events. Roku collected from users it had actual knowledge were children, without parental authorization.

Sensitive data categories, like health, geolocation, and biometric information, also require an opt-in standard of consent under most state data privacy laws. Violations associated with sensitive data consent failures drew some of the steepest penalties. Healthline's sharing of health-article URLs with advertisers was the largest AG penalty of the year, precisely because that use fell outside what the data was originally collected for.

In our emerging data privacy trends for 2026 blog, we called out that there would be a shift toward broader age-assurance enforcement, among other predictions. Not to pat ourselves on the back, but a lot of them are coming true.

6. Is Your Privacy Policy up to Date and Accurate?

You knew this one was going to show up on this list. But it’s a shockingly common data privacy violation, and if you aren’t a privacy or legal professional, you might be underestimating the work involved in keeping a policy accurate and up to date. It certainly takes more effort than just changing the date next to the phrase Last Updated.

The real challenge of privacy policies is that their maintenance has two fronts:

  1. Ensuring the privacy policy accurately describe the processing activities your company engages in
  2. Ensuring your company’s processing activities adhere to the policy

Achieving those two goals isn’t just a matter of editing a document–it takes data mapping/inventorying, training, privacy impact assessments, vendor management, and more. Since privacy policies live on your website for all to see, regulators love to review what privacy practices you’ve publicly claimed to practice.

Connecticut's first CTDPA penalty went to TicketNetwork partly because its notice was, in the Attorney General's own words, "largely unreadable." Oregon's cure letters most often cite notices that list other states' privacy rights while leaving Oregon off the list entirely. And Tractor Supply got flagged for two separate gaps: a notice that hadn't been updated in the required annual window, and a failure to tell job applicants, not just customers, that CCPA rights applied to them too.

These are examples where the privacy policy can be determined as non-compliant on-sight. But privacy notice violations are nearly universal in enforcement actions. After all, nobody’s privacy policy says, “Hey, we’re actually not honoring opt-outs” or “We don’t manage our vendor contracts compliantly.” When a privacy policy promises compliance and real practices are non-compliant, that is in and of itself a violation.

7. Do Subject Rights Requests Follow a Compliant Workflow?

Honoring subject rights requests (SRRs, sometimes referred to as DSARs), just like opt-outs and privacy policies, aren’t about the existence of a user interface and the right language. Compliant SRR workflows are about what happens when a request is submitted. It’s easy enough for regulators to check for an SRR form, submit a request, and see what comes back.

Recently, regulators have done businesses the favor of letting them know that SRRs are a major focus for them.

On July 21, 2026, the California Privacy Protection Agency's newly formed Audits Division opened its first sectoral audit, targeting gig economy platforms. The audit’s stated purpose is to check whether people can actually exercise their right to access their own data. CalPrivacy’s Chief Privacy Auditor stated that the audit will focus on whether access requests get honored within the 45-day statutory window and whether the responses are actually complete, not just technically on time.

Audit findings can be referred straight to enforcement, and CalPrivacy has already said this is the first in a series, meaning gig platforms won't be the last sector it looks at. A consent banner can be flawless and still not matter here. This is about whether the request-handling process behind your site actually works when someone uses it.

Test Your Own Site Before Someone Else Does

To reiterate what we said in the introduction of this article: most businesses aren’t non-compliant on purpose. Most businesses don’t realize they aren’t compliant until a regulatory notice lands in their inbox. There are two reasons why this happens:

  1. Businesses don’t know what data privacy regulations require, and with 23 state privacy laws, each with varying requirements written in legalese, that’s more than understandable–it’s practically to be expected.
  2. Businesses don’t audit themselves before a regulator does.

You can avoid falling prey to these two traps with Osano’s Compliance Check. It runs regular scans against your website to see if it passes or fails common standards that regulators are testing for.

Run a free Compliance Check scan to see whether your site honors GPC signals, avoids dark patterns, and holds up against the issues regulators are actively enforcing right now.

Scan your site for compliance issues

State of US Privacy Enforcement

Read our report breaking down 2026's major data privacy enforcement actions and what they mean for your compliance.

Download Your Copy
Resource Listing - State of US Privacy Enforcement
Share this article