---
title: Sephora Fined $1.2 Million Over CCPA Violations
description: The CA Attorney General announced $1.2M in fines against makeup retailer Sephora for CCPA violations, dramatically ramping up data-privacy enforcement.
image: https://safe.truevault.com/hubfs/TrueVault-What-to-Do-If-You-Receive-a-CCPA-Cure-Notice.jpg
---

<https://safe.truevault.com/>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-pii)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/)
- Login
  
  [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com) [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

- [Resources](https://safe.truevault.com/learn/)
- Login

- Login
- [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com)
- [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

[Blog](https://safe.truevault.com/blog)

- [Home](https://www.truevault.com/index.html)
- [Blog](https://safe.truevault.com/blog)

![<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Sephora Fined $1.2 Million Over CCPA Violations</span>](https://safe.truevault.com/hubfs/TrueVault-What-to-Do-If-You-Receive-a-CCPA-Cure-Notice.jpg)

# Sephora Fined $1.2 Million Over CCPA Violations

By Phillip Walters/ Published on August 26, 2022

#### Article Highlights:

- First major fine for violation of the CCPA
- Sephora website had no method to opt-out of sale of personal information & no implementation of the Global Privacy Control standard
- Fines likely to be more common as the mandatory 30-day cure period expires

 

California Attorney General Rob Bonta [announced](https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement) that his office has recently settled a case with makeup retailer Sephora over a number of violations of the [California Consumer Privacy Act](https://safe.truevault.com/ccpa-guide) (CCPA). The settlement requires Sephora to pay $1.2 million in penalties, as well as enact numerous measures to bring the business’s online operations into compliance with the CCPA.

“I hope today’s settlement sends a strong message to businesses that are still failing to comply with California’s consumer privacy law,” said Bonta. “It’s been more than two years since the CCPA went into effect….There are no more excuses.”

According to the Attorney General, the majority of violations were related to the sale of consumers’ personal information. Through a variety of tracking technologies, Sephora was sharing data about its website visitors with third parties in exchange for advertising and analytics services, an arrangement that is considered a “[sale](https://safe.truevault.com/consumers/ccpa/what-constitutes-a-sale-of-personal-information)” under the CCPA. The company did not disclose this fact in its privacy policy, did not post a “Do not sell my personal information” link on its site, and offered consumers no way to opt out.

The Attorney General also heavily emphasized the role of [Global Privacy Control](https://globalprivacycontrol.org/) (GPC) in CCPA compliance. GPC is a user-enabled signal sent by web browsers to function as an automatic opt-out request to the site being visited. Under CCPA regulations, online businesses are required to respect the GPC signal and treat it as they would any other consumer opt-out. As part of the settlement agreement, Sephora must implement a mechanism to honor opt-outs via the GPC signal.

Before seeking any penalties or injunctions, the Attorney General’s Office first sent a [CCPA cure notice](https://safe.truevault.com/learn/ccpa/what-to-do-if-you-receive-a-ccpa-cure-notice) to Sephora. Cure notices are mandatory under the current version of the law, and give businesses 30 days to fix any alleged violations (which Sephora apparently failed to do). However, as the Attorney General noted, the CCPA provision that requires the state to send out cure notices is set to expire on January 1, 2023. Starting on that date, officials at the newly created [California Privacy Protection Agency](https://safe.truevault.com/learn/ccpa/the-california-privacy-protection-agency) may skip the 30-day cure period and proceed directly to an administrative hearing and penalty assessment.

Any businesses left in doubt should consider Mr. Bonta’s words of warning: “My office is watching, and we will hold you accountable.”

## Don’t Delay CCPA Compliance

The state’s action against Sephora marks a new point of maturity for CCPA enforcement, demonstrating that the law does, in fact, have teeth. Non-compliance has real consequences in the form of steep fines and expensive legal fees, and in the end the result is the same—your business must become CCPA compliant.

TrueVault Polaris gives small and medium-sized businesses access to the tools and expertise they need to become compliant on their own. First, businesses go through the initial onboarding process via a guided question-and-answer interface (think online tax software), which can be completed in as little as a few hours. The many diverse requirements such as incorporating GPC into your website are all accounted for. After that, Polaris makes staying compliant a simple task through process automations, privacy-request workflows, and other time-saving tools. 

[Contact our team](https://safe.truevault.com/contact-us) to learn more and view a demo.

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control)

 Phillip Walters  / November 7, 2022

## [A Cookie Banner Isn't Enough for CCPA Compliance](https://safe.truevault.com/blog/a-cookie-banner-isnt-enough)

 Phillip Walters  / October 27, 2022

## [Why CCPA Compliance Matters to HR](https://safe.truevault.com/blog/why-ccpa-matters-to-hr)

 Phillip Walters  / October 21, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2024 © All Rights Reserved.  [Privacy Policy](https://privacy.truevault.com/privacy-policy)  |  [Terms of Use](https://www.truevault.com/legal/truevault-terms-of-use)  |  [Supplemental Terms](https://www.truevault.com/legal/truevault-supplemental-terms-of-use)<https://www.truevault.com/legal/truevault-terms-of-use> | [California Privacy Notice](https://privacy.truevault.com/privacy-policy#california-privacy-notice)