New CPPA Decision Means Businesses Must Review Their Privacy Compliance Processes and Consent Management Tools

March 17, 2025
Privacy, Cyber & AI Decoded

What Happened?

The California Privacy Protection Agency (CPPA) issued a settlement order on March 12, 2025, with an vehicle manufacturer regarding its investigation of its privacy practices, where it agreed to a $632,500 settlement for 150 consumer violations. The vehicle manufacturer also agreed as part of the settlement to address its ongoing privacy compliance practices.

Why is This Important to Privacy Practitioners?

Many other organizations operating as businesses under the California Consumer Privacy Act (CCPA) likely have similar implementations as they attempt to comply with the increasingly complex patchwork quilt of a growing number of state privacy laws and through reliance on key privacy vendors' implementation.

The CPPA is no longer bringing enforcement actions against companies that fail to implement the CCPA. Instead, it is requiring companies to implement the nuances of the CCPA in their compliance processes.

What Do You Need to Know?

Below is a high-level summary of the CPPA "Order."

One Trust Consumer Privacy Request Form

Verification Steps for Opt-Outs of Sale and Sharing Consumer Information

One Trust Cookie Tool

CPPA Contractual Agreements

Next Steps

To meet these requirements, in light of this decision we recommend that CCPA businesses review data subject rights processes, consent management tool implementations, and service provider and third-party contracts.

Reliance on vendors that shift compliance legal burdens on your organization will not prevent CPPA investigations or subsequent CCPA violations. Across the complex patchwork quilt of US state privacy laws, we expect other state enforcement agencies to follow California’s lead.