California has emerged as one of the world's toughest privacy enforcement jurisdictions, sending a clear message that organizations must treat consumer data as a protected asset rather than a commercial commodity. Through laws such as the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the California Invasion of Privacy Act (CIPA), regulators are aggressively pursuing organizations that misuse personal information, fail to honor consumer rights, or neglect adequate security controls. Civil penalties can range from $2,500 to nearly $8,000 per violation, while large-scale enforcement actions have resulted in multimillion-dollar settlements.
One of the most significant recent cases involved General Motors, which agreed to pay $12.75 million to resolve allegations that it unlawfully collected and sold the driving behavior and location data of hundreds of thousands of California motorists through its OnStar platform. Regulators alleged that between 2020 and 2024, GM shared highly sensitive information—including GPS locations, speed, braking patterns, acceleration data, names, phone numbers, and home addresses—with third-party data brokers without obtaining meaningful consumer consent. Authorities argued that consumers were led to believe the information would be used only for vehicle safety and connected services, not for commercial sale.
The settlement underscores California's position that personal data generated by connected vehicles belongs to consumers, who must be given clear notice, meaningful choice, and the ability to opt out of data sharing. The case also demonstrates that privacy obligations extend beyond websites and mobile applications into connected devices, IoT platforms, and automotive ecosystems.
The Walt Disney Company also faced major regulatory action. In California, Disney agreed to pay $2.75 million after authorities concluded that it failed to fully honor consumers' requests to opt out of the sale or sharing of personal information across its digital platforms. Separately, Disney reached a $10 million federal settlement over alleged violations involving children's privacy, where regulators claimed the company failed to properly identify kid-directed YouTube content, enabling the collection of children's personal information without verified parental consent.
Other enforcement actions reinforce the breadth of California's privacy regime. Healthline agreed to a $1.55 millionsettlement after regulators found that consumer information was used beyond its original purpose and that required third-party data processing agreements were inadequate. Tractor Supply Company paid $1.35 million after failing to properly process consumer requests submitted under California's "Do Not Sell My Personal Information" requirements. These cases demonstrate that compliance failures involving consent management, third-party governance, and consumer rights can result in substantial financial penalties.
California's privacy enforcement also reflects lessons from historic breaches. Equifax paid $175 million in nationwide penalties following its 2017 data breach, which exposed the personal information of millions of Americans, including approximately 15 million Californians. The case highlighted how inadequate cybersecurity controls can trigger both regulatory action and long-term reputational damage.
The broader message from California is unmistakable. Privacy is no longer simply a compliance exercise—it is a governance responsibility. Organizations are expected to demonstrate transparent consent management, secure data handling, timely fulfillment of consumer requests, strong third-party oversight, and privacy-by-design across every digital service. As similar regulations emerge worldwide, California continues to set the benchmark for data protection enforcement, proving that failure to respect consumer privacy can carry severe financial, legal, and reputational consequences.