State privacy enforcement heats up this summer: What CA, CT settlements mean for your business

In an era of escalating data breaches, organizations must be vigilant in protecting consumer information. A comprehensive federal data privacy law would streamline compliance efforts, but Congress has yet to pass one, leaving states to fill the gap.

In an era of escalating data breaches, organizations must be vigilant in protecting consumer information. A comprehensive federal data privacy law would streamline compliance efforts, but Congress has yet to pass one, leaving states to fill the gap.

As of early 2025, 20 states had enacted consumer data privacy laws. Now, state attorneys general are ramping up on enforcement action.

Two recent examples show how these laws are being applied: a record-setting $1.55 million penalty against Healthline under the California Consumer Privacy Act, and Connecticut’s first enforcement action under its new privacy law, the Connecticut Data Privacy Act.

California’s CCPA settlement with Healthline

In July, the California Office of the Attorney General announced a settlement with Healthline Media LLC, publisher of a popular medical and health information website. The enforcement action stemmed from alleged violations of the CCPA and resulted in a record-setting $1.55 million agreed penalty – the largest CCPA settlement to date. As part of the settlement, Healthline must undertake a comprehensive CCPA compliance program and other corrective measures.

Key allegations in the enforcement action included the following:

  • Improper data sharing through tracking technologies (for example, use of cookies and pixels).
  • Inadequate consumer disclosures in privacy notices.
  • Failure to provide and honor effective opt-out mechanisms.

The focus on Healthline’s use of tracking tools, a routine online data practice, should be a concern to businesses. 

Connecticut’s CTDPA settlement

Just days after the California settlement, Connecticut announced that it had reached a settlement of its first enforcement action under the CTDPA, with TicketNetwork, a live entertainment ticketing and resale company. The state Attorney General contended that the company’s privacy notice was deficient in the following respects:

  • It was difficult to read because of poor formatting and dense language.
  • Required disclosures about consumer data rights were missing.
  • The notice had misconfigured or nonfunctional rights request mechanisms.

In the settlement, TicketNetwork will pay $85,000 and will comply with the CTDPA, and “maintain metrics for consumer rights requests received under the CTDPA [and] provide a report of these metrics to the Attorney General . . ..” The case and settlement indicate that even first-time violators are not exempt from penalties or required remediation.

Recommendations for businesses

If your organization is subject to the CCPA, the CTDPA, or any other state privacy law, you should consider the following:

  • Have we audited our use of cookies, pixels, and other tracking technologies?
  • Have we mapped our data flows to understand what we collect, use, and share?
  • Is our privacy notice accurate, easy to understand, legally compliant, and regularly reviewed?
  • Are our consumer rights request mechanisms (for example, access deletion, opt-out) available, fully functional, and regularly tested?

Addressing these issues will help to reduce the risks of enforcement actions and class action privacy litigation.

How to prepare

Many businesses may not realize that they’re already subject to multiple state privacy laws. If your organization operates in multiple jurisdictions, you will need to understand and comply with each state’s obligations. A good first step is to conduct a multi-state privacy risk assessment. The assessment will help you identify areas of weakness and allow you to make corrections before you become the target of an enforcement or class action.

The Constangy Cyber Team assists businesses of all sizes and industries with compliance needs. If you would like additional information, please contact us at cyber@constangy.com.

  • John Babione in a light gray suit with a white shirt and dark navy tie smiles against a light blue and white geometric background.
    Partner

    He regularly defends clients in a variety of complex and high-stakes privacy and cyber-related litigation, including class action data breach suits, wire fraud litigation, and employee data theft actions. John’s experience ...

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek