The Challenge
In August 2022, the California Attorney General announced a $1.2 million settlement with Sephora, marking the first CCPA enforcement action focused on Global Privacy Control (GPC) compliance. The cosmetics retailer faced three violations, but the standout issue was the website's failure to detect or process any GPC signals.
Testing made the problem clear. When investigators enabled GPC in their browsers, nothing changed. The site continued selling and sharing personal information as if no opt-out request had been sent. The HTTP header Sec-GPC: 1 reached Sephora's servers, but no system was listening for it.
This wasn't a technical glitch or delay. The infrastructure to honor the signal simply didn't exist.
The Environment and Constraints
Sephora operated under California's CCPA regulations, which clearly require businesses that sell or share personal information online to treat a qualifying opt-out preference signal as a valid opt-out request. GPC qualifies under Regulation 7025.
The regulations impose six duties, but three were immediately pressing:
- Act on an opt-out as soon as possible, no later than 15 business days after receiving it.
- Don't require extra information or a verifiable consumer request before honoring the signal.
- The opt-out applies to the browser or device that sent the signal and any profile tied to it.
Sephora's challenge wasn't technical complexity. The GPC specification defines two signals: an HTTP header and a JavaScript property. Both are straightforward to detect. The issue was organizational: prioritizing GPC detection, allocating resources, and implementing the check before the Attorney General's investigation.
The Approach Taken
The enforcement documents don't detail Sephora's internal actions before the investigation. What's clear is what they didn't do: build a system to detect the Sec-GPC: 1 header or check the navigator.globalPrivacyControl property.
A minimal implementation requires two steps. On the server side, check incoming requests for the GPC header. On the client side, read the JavaScript property and suppress non-essential cookies if it's true. Neither step is complex, but both require deliberate action.
The Attorney General's testing was straightforward. Investigators enabled GPC in a browser, visited Sephora's site, and checked if the signal changed the site's behavior. It didn't. Cookies facilitating data sales and sharing continued to load. The opt-out preference signal went unprocessed.
Results and Metrics
The settlement cost Sephora $1.2 million. This figure reflects three violations, not just the GPC failure. The California Privacy Protection Agency's August 2026 briefing specifically highlights this case as the Attorney General's first CCPA settlement.
Beyond the financial penalty, the case set a precedent, showing that California would enforce GPC requirements through formal action. The settlement came about 20 months after the GPC project launched in October 2020, after California's regulations made the signal mandatory for covered businesses.
The $1.2 million penalty fits within California's fine structure. Violations carry penalties up to $2,500 per violation and $7,500 per intentional violation. Inflation adjustments put those figures at $2,663 and $7,988, respectively. The settlement amount suggests either a negotiated resolution or a violation count based on affected consumers or time periods.
What Your Team Should Do Differently
A business facing similar requirements today should start with detection. You need server-side logic to check for the Sec-GPC: 1 header on every request. If present, suppress third-party cookies and scripts that facilitate data sales or sharing.
On the client side, check navigator.globalPrivacyControl before loading any non-essential tags. If true, your tag manager should block everything except consent-exempt cookies. This isn't about asking permission again; it's about respecting the browser's instruction.
The conflict rule is crucial. California's regulation says if the signal conflicts with a consumer's setting that allows sale or sharing, you must process the signal. You can inform the consumer about the conflict and offer a chance to consent, but you can't ignore the signal while waiting for their response.
Testing should mirror regulators' methods. Enable GPC in Firefox or Brave, visit your site, and watch the network tab. Do tracking pixels still fire? Do third-party domains still receive requests? If yes, you're broadcasting non-compliance.
Documentation is key during an investigation. Log when you receive a GPC signal, what action you took, and when. If you show a notice saying "opt-out preference signal was honored," ensure your backend actually did something.
Takeaways for Your Team
The Sephora case reveals a pattern in GPC enforcement actions: regulators test the signal directly. They don't rely on your privacy policy or assurances. They turn GPC on and observe what happens.
This creates a binary outcome. Either your site detects the signal and changes its behavior, or it doesn't. There's no partial credit for good intentions or having a Do Not Sell or Share link. California's regulations say the link alone is never enough. A business that posts the link must also process the signal.
Your implementation checklist should cover both the header and the JavaScript property. Some browsers send one but not the other, and privacy extensions work differently on mobile. Test across browsers and devices, not just desktop Chrome with an extension.
The 15-business-day deadline applies to all opt-outs, but GPC demands faster action. The regulation says a business must act "as soon as feasibly possible." When the signal arrives with every page request, feasible means immediate. You can't batch GPC requests for weekly processing.
If you sell or share personal information and collect it online, you're a covered business under California's rules. This duty applies whether you're headquartered in California or not. Colorado, Connecticut, Delaware, Minnesota, Montana, New Hampshire, and Oregon have similar requirements. Texas and Nebraska reach GPC indirectly through their authorized-agent rules.
The $1.2 million settlement wasn't the end of GPC enforcement. The California Privacy Protection Agency's order against Todd Snyder in May 2025 imposed a $345,178 penalty for a site that ignored GPC for 40 days. The Attorney General's July 2025 action against Healthline Media resulted in a $1.55 million settlement. Disney and PlayOn Sports faced actions in 2026.
Your legal exposure increases with every page view from a California resident who has GPC enabled. The violation isn't sending the signal; it's continuing to sell or share data after you receive it.



