ARTICLE
13 May 2025

Suit Settled: CPPA Brings Enforcement Against Menswear Company

FK
Frankfurt Kurnit Klein & Selz

Contributor

Frankfurt Kurnit provides high quality legal services to clients in many industries and disciplines worldwide. With leading practices in entertainment, advertising, IP, technology, litigation, corporate, estate planning, charitable organizations, professional responsibility and other areas — Frankfurt Kurnit helps clients face challenging legal issues and meet their goals with efficient solutions.
On May 6, 2025, the California Privacy Protection Agency announced its second enforcement action over violations of the California Consumer Privacy Act. Menswear company Todd Snyder settled allegations that it failed to properly honor consumer opt-outs, agreeing to pay $345, 718.
United States Privacy

On May 6, 2025, the California Privacy Protection Agency announced its second enforcement action over violations of the California Consumer Privacy Act. Menswear company Todd Snyder settled allegations that it failed to properly honor consumer opt-outs, agreeing to pay $345, 718. The company must also reconfigure its opt out process and implement other internal procedures to address privacy obligations, including a contract management and tracking process.

Third-party privacy management again came under scrutiny, with the CPPA alleging that Todd Snyder violated the California Consumer Privacy Act by improperly implementing its privacy portal, resulting in a 40 day "failure to process consumer requests to opt out of sale or sharing." The Agency also alleged that Todd Snyder's privacy portal violated the CCPA by requiring an excess of personal information to process privacy requests. The company required consumers to submit their full name, email, country of residence, and a photograph of the consumer holding an identity document to opt out of sales and similarly sensitive information to exercise other privacy rights.

This decision highlights the importance of business oversight into privacy compliance, including the technical configurations of third-party solutions. According to the CPPA, Todd Snyder "would have known" of the existing issues if it had "taken steps to ensure that its mechanism . . . was properly configured and functioning." Per Michael Macko, head of the CPPA's Enforcement Division, "businesses should scrutinize their privacy management solutions to ensure they comply with the law and work as intended, because the buck stops with the businesses that use them. Using a consent management platform doesn't get you off the hook for compliance."

www.fkks.com

This alert provides general coverage of its subject area. We provide it with the understanding that Frankfurt Kurnit Klein & Selz is not engaged herein in rendering legal advice, and shall not be liable for any damages resulting from any error, inaccuracy, or omission. Our attorneys practice law only in jurisdictions in which they are properly authorized to do so. We do not seek to represent clients in other jurisdictions.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More