The California attorney general recently secured a $1.55 million settlement from Healthline Media for CCPA violations involving online tracking and inferred sensitive personal information. This is the first U.S. regulatory action penalizing the disclosure of inferred data, not just explicit health information collected directly from users.
If you're managing a consent program, this case expands your compliance responsibilities. Inferred data, once in a regulatory gray area, is now clearly within the scope of enforcement.
What This Checklist Covers
This checklist helps you determine if your organization's handling of inferred sensitive personal information could lead to CCPA exposure similar to Healthline's. It focuses on identifying when you're creating inferred data, ensuring opt-out mechanisms work for it, and documenting your legal basis for processing it.
You'll need to work with your analytics team, ad operations, and whoever manages your Consent Management Platform (CMP). This isn't just a privacy issue.
Prerequisites
Before starting:
- Map your data flows. Identify where inference happens by documenting which systems create derived attributes from user behavior.
- Review your current opt-out implementation. Understand what happens when someone clicks "Do Not Sell or Share My Personal Information."
- Identify your sensitive categories. Under CCPA, these include health, financial, biometric, geolocation, race, religion, and union membership. Your inference systems likely touch at least one.
Compliance Checklist
1. Inventory All Inference Points
Done when: You have a documented list of every system, pixel, or algorithm that creates derived attributes about users.
Look beyond your CRM. Tag Managers, analytics platforms, and ad networks all make inferences. A user visiting your diabetes content five times doesn't explicitly tell you they have diabetes, but your retargeting system may infer it anyway.
What good looks like: A spreadsheet listing each inference system, what attributes it creates, which CCPA categories those attributes fall into, and who receives them downstream. If you can't produce this in 30 minutes, you're not ready for an AG inquiry.
2. Verify Opt-Out Scope Includes Inferred Data
Done when: Your "Do Not Sell or Share" mechanism explicitly blocks the disclosure of inferred sensitive attributes, not just raw behavioral data.
The Healthline settlement shows that regulators won't accept an opt-out that stops cookie sharing but allows inferred health conclusions to flow to ad networks. Your opt-out must cut off the entire chain.
What good looks like: When a user opts out, your Tag Manager stops firing pixels that receive inferred categories. Test it: opt out on your own site, then check your browser's network tab. You shouldn't see audience segment IDs or health-related parameters in any outbound requests.
3. Audit Third-Party Vendor Contracts for Inference Language
Done when: Every vendor contract specifies whether they're permitted to create inferred sensitive categories from your user data, and under what restrictions.
Most data processing agreements were written before inferred data became an enforcement priority. They probably don't address it. That's a gap.
What good looks like: Addenda to your vendor agreements that explicitly prohibit creating or sharing inferred sensitive personal information without documented Legal Basis for Processing. If a vendor can't agree to that restriction, you've learned something important about their business model.
4. Document Legal Basis for Each Inference Use Case
Done when: You can point to a specific CCPA exemption or consent record for every inferred sensitive attribute you process.
"We need it for analytics" isn't a legal basis. CCPA provides narrow exemptions for certain business purposes, but Behavioural Advertising isn't one of them. If you're using inferred health data to serve ads, you need Prior Consent or you need to stop.
What good looks like: A table mapping each inference type to its legal basis: consent timestamp, contractual necessity, or a cited CCPA exemption with the specific section reference. No blank cells.
5. Test Consent Notice Clarity on Inferred Data
Done when: Your Consent Notice explicitly tells users you create inferred categories and what you do with them.
Buried references to "analytics partners" don't cut it. If you're inferring someone has a medical condition based on their reading behavior and sharing that conclusion with advertisers, your Purpose Disclosure needs to say so in plain language.
What good looks like: A Consent Notice that states, "We may infer health-related interests from the articles you read and share those inferences with advertising partners." Then test comprehension: can a non-lawyer read it and understand what's happening?
6. Implement Granularity for Sensitive Inference Categories
Done when: Users can accept functional cookies while rejecting the specific processing that creates or shares inferred sensitive data.
Bundling everything into "advertising cookies" fails the Genuine Choice test. Inferred health data deserves its own toggle.
What good looks like: A CMP configuration where users see separate controls for "Analytics," "Standard Advertising," and "Health-Related Advertising Based on Content You View." The last category must default to off.
7. Validate Opt-Out Persistence Across Sessions
Done when: A user's opt-out choice for inferred data sharing survives browser restarts, cookie clearing (for consent-exempt preference cookies), and cross-device scenarios where technically feasible.
Consent Fatigue is real, but making users re-opt-out every visit is worse than fatigue. It's non-compliance.
What good looks like: Set your opt-out preference, clear your cookies except for Essential Cookies, restart your browser, and return to the site. Your preference should still be honored. Document how you achieve this technically.
8. Review Data Retention for Inferred Attributes
Done when: Inferred sensitive categories have defined retention periods and automated deletion schedules.
Just because you derived the data doesn't mean you can keep it forever. If the underlying behavioral data gets deleted, the inferences should too.
What good looks like: Your data retention policy explicitly addresses inferred categories. Example: "Inferred health interests are deleted 90 days after last user activity or immediately upon Withdrawal of Consent, whichever comes first."
Common Mistakes
Treating inferred data as "less sensitive" than declared data. Regulators clearly don't see it that way. The Healthline settlement proves that inferred health information carries the same compliance weight as explicit health disclosures.
Assuming your CMP handles this automatically. Most Consent Management Platforms weren't designed with inference in mind. You need custom configuration and vendor coordination.
Focusing only on cookies while ignoring server-side inference. Your Tag Manager might be compliant, but if your backend is still enriching user profiles with inferred categories and syncing them to ad platforms, you've solved the wrong problem.
Waiting for federal privacy law to clarify the rules. California is enforcing now. Other states with comprehensive privacy laws will likely follow this precedent.
Next Steps
Start with checklist item 1. You can't fix what you can't see, and most organizations have no idea how many inference points they operate. Schedule a meeting with your analytics lead and walk through every property where you collect behavioral data.
Then tackle your opt-out implementation. The gap between "we offer an opt-out" and "our opt-out actually stops inferred data sharing" is where the $1.55 million settlements happen.
Finally, brief your executive team. Inferred data is no longer a technical nuance. It's a material compliance risk with a price tag attached.



