ARTICLE
19 September 2025

CPPA And AGs Launch Coordinated Investigation Into Corporate Global Privacy Control Failures

AP
Arnold & Porter

Contributor

Arnold & Porter is a firm of more than 1,000 lawyers, providing sophisticated litigation and transactional capabilities, renowned regulatory experience and market-leading multidisciplinary practices in the life sciences and financial services industries. Our global reach, experience and deep knowledge allow us to work across geographic, cultural, technological and ideological borders.
The California Privacy Protection Agency (CPPA) is collaborating with the Attorneys General of California, Colorado, and Connecticut in a joint investigation into businesses...
United States California Privacy
Kristina Iliopoulos’s articles from Arnold & Porter are most popular:
  • within Privacy topic(s)
  • in United States
Arnold & Porter are most popular:
  • within Insolvency/Bankruptcy/Re-Structuring and Environment topic(s)

The California Privacy Protection Agency (CPPA) is collaborating with the Attorneys General of California, Colorado, and Connecticut in a joint investigation into businesses they think may not be complying with consumers' rights to opt out of the sale of their personal information using a Universal Opt-Out Mechanism, the most popular of which is the Global Privacy Control (GPC). The joint investigation underscores a strong nationwide commitment to enforcing privacy laws and to educating consumers about their rights under the California Consumer Privacy Act (CCPA) and similar statutes.

The joint investigation aims to ensure that businesses honor GPC opt-out requests, which are designed to protect consumer privacy. The GPC is an opt-out preference signal attached to a website visitor's browser (or through an extension to that browser) that automatically informs websites of a consumer's desire to stop the sale or sharing of personal information to third parties, eliminating the need for individual opt-out requests on each website. The CCPA and eight other state statutes require website owners to recognize GPCs in certain circumstances. Consumers also have the option to manually opt out on a per-business basis through clear "Do Not Sell or Share My Personal Information" links on websites, which must be accessible without the user having to create an account. Regulators from the states involved in the investigation have issued letters to several companies they believe may not process GPC signals in compliance with applicable laws.

In California specifically, the CPPA has been active in enforcing privacy rights, having fined companies such as Todd Snyder and American Honda Motor Co. for CCPA violations. California has collaborated with other states and international data protection authorities to enforce privacy laws and educate the public on these laws and related developments, including the launch of the Consortium of Privacy Regulators. California's coordinated approach highlights its commitment to ensuring that individuals can easily and effectively enforce their privacy rights. In light of this, and with the increase in class action litigation (and one-off demand letters) alleging wiretapping violations regarding the use of online tracking technologies or other privacy law violations (like California's Shine the Light law), companies risk enforcement or litigation if tracking technologies are not effectively overseen.

Accordingly, companies should take the opportunity (before being caught up in an investigation or litigation) to audit their privacy rights request process to (1) ensure the process for verifying individuals' identities does not ask for information not necessary to comply with individuals' requests, (2) ensure they have an easy and streamlined process for effectuating privacy rights, (3) understand how they are using tracking technologies and ensure consent is being gathered, (4) ensure their online tracking technology software is operating as intended, including by recognizing GPC signals, and (5) ensure the appropriate contracts are in place with online tracking technology vendors.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More