The Opt-Out Mistake That Just Cost a Company $116,490

On August 11, 2026, California's privacy regulator announced its first enforcement action under the state's Delete Act. Most of the coverage focused on the headline: a data broker that failed to register and had to pay $116,490. That part is specific to data brokers, and most businesses will read it and move on.
They shouldn't. Buried in the same action is a finding that applies to almost every website that collects personal information - and it is the opposite of what most people assume. The company was penalized not for hiding an opt-out, but for asking for too much information before it would honor one.
That single detail is the most useful compliance lesson of the year, because the mistake behind it is one that careful, well-intentioned teams make constantly.
What actually happened
According to the regulator, the company required consumers to hand over their full name, the last four digits of their Social Security number, and their address before it would let them opt out of the sale or sharing of their personal information. On its face that sounds responsible - you want to be sure a request is genuine before acting on it. Under the CCPA, it is a violation.
The action cited two separate problems with that flow. The first is an unlawful barrier to a right that is supposed to be easy to exercise. The second is a data minimization failure - collecting far more sensitive data than the task required. Asking for a Social Security number to process an opt-out is exactly the kind of over-collection the law is designed to prevent. The company took a right that should cost a consumer almost nothing to use and turned it into a form that most people would abandon halfway through.
The rule most sites get backwards
Here is the distinction that trips people up. The CCPA treats requests differently depending on what they ask for:
Requests to know or delete personal information can be verified, because you are about to hand over or erase someone's data and you need to be sure you have the right person.
Requests to opt out of sale or sharing are not subject to a verification requirement. The consumer is not asking for anything back - they are asking you to stop. Making them prove who they are first turns a one-click right into a form full of sensitive fields.
So the instinct to "verify everything" is not just unnecessary for opt-outs - it is the thing that gets penalized. The more you ask for, the bigger the exposure, because now you are also collecting sensitive data you had no legitimate reason to collect. Two violations grow from one well-meaning design choice.
What "sale or sharing" really covers
Part of why this catches people out is that "sale" is much broader than most businesses assume. Under the CCPA, a "sale" does not require money to change hands. Disclosing personal information to a third party in exchange for anything of value can count. "Sharing" specifically covers passing personal information to third parties for cross-context behavioral advertising - the targeted ads that follow people around the web.
In practice, that means a huge number of ordinary websites are engaged in "sale or sharing" without ever thinking of it that way. If your site loads third-party advertising pixels, analytics that build audience profiles, or social media trackers that fire before a visitor consents, you are very likely in scope. And if you are in scope, your opt-out has to work - simply, and automatically where the law requires it.
The signal most sites quietly ignore
The opt-out that fails most often is the one a site never realizes it is failing: the Global Privacy Control.
GPC is a signal a visitor's browser sends on their behalf. In California, when a browser sends GPC, that counts as a valid opt-out of sale and sharing on its own. The consumer does not have to find your link, fill out your form, or click anything on your page. Your site is expected to detect the signal and act on it automatically.
This is where a lot of otherwise careful sites fall down. A business can have a polished "Do Not Sell or Share My Personal Information" page and still be non-compliant because nothing in its stack ever listens for GPC. The page looks perfect. The behavior underneath it is broken. From the outside, there is no way to tell the difference without actually sending the signal and watching what the site does.
What a compliant opt-out actually looks like
You do not need a Social Security number. You do not need an account. You need a path that a reasonable person can complete without friction. In practice that means:
A clear "Do Not Sell or Share My Personal Information" link that is easy to find, not buried three menus deep.
An opt-out that works without requiring the person to log in, create an account, or verify their identity.
Collecting only what you genuinely need to apply the opt-out - and nothing more. If you can honor the request with an email or a device-level signal, do not ask for anything else.
Honoring the Global Privacy Control signal automatically, as a valid opt-out in its own right.
Acting on the request promptly and stopping the third-party sharing that triggered the obligation in the first place - not just recording the preference and continuing to fire the same pixels.
Why this keeps happening
Almost nobody sets out to build an unlawful opt-out. These flows drift into non-compliance one reasonable-sounding decision at a time. Someone adds an identity check to "reduce fraud." A vendor's default consent tool asks for an email to "confirm the request." A marketing tag gets added to the site months after the privacy review, and no one revisits the opt-out. A GPC signal arrives and nothing in the stack is set up to act on it. Each step feels prudent. Together they add up to exactly the pattern the regulator just fined.
The deeper problem is that compliance is treated as a launch-day event rather than an ongoing state. A site that was compliant when it shipped can quietly fall out of compliance the next time a tag manager change goes live, and nobody notices because nothing visibly breaks.
The math on getting it wrong
California penalties are assessed per violation. As of 2026, the amounts are roughly $2,663 for an unintentional violation and about $7,988 for an intentional one, or any violation involving a consumer under 16, adjusted for inflation. On a single consumer that sounds survivable. But a broken opt-out is not a single-consumer problem - it is a design flaw that applies to every visitor who tried to exercise the right. The per-violation structure is what turns a small design mistake into a large number very quickly, which is exactly why regulators favor it.
How to check your own site
The practical takeaway is simple: stop assuming your opt-out works, and go verify it the way a consumer would.
Walk your own opt-out from a fresh browser. Count how many fields it demands. If it asks for anything sensitive, or forces an account or an identity check, that is a red flag.
Turn on Global Privacy Control in a browser that supports it, visit your site, and confirm the site actually treats you as opted out.
Check what third-party trackers fire before and after the opt-out. If the same advertising pixels keep firing after someone opts out, the preference is cosmetic.
Re-check after any change to your tag manager, consent tool, or ad stack. Compliance is a state you maintain, not a box you tick once.
This is exactly the kind of behavior Complyy tests automatically. We visit your live site the way a real visitor would, exercise the opt-out, check whether the Global Privacy Control signal is honored, watch which third-party trackers fire, and capture timestamped evidence of what actually happened - so you find the gap before a regulator does, and you keep finding it every time your site changes.
Run a free CCPA scan of your website and see how your opt-out holds up.
This article is for general information and is not legal advice. Enforcement details are based on the California Privacy Protection Agency's public announcement of its August 11, 2026 action. Penalty amounts are approximate and adjusted periodically for inflation.
