What the $2.75M Disney CCPA Settlement Requires
By Eli C., MarTech & Analytics Engineer
Published Updated
Quick answer: On February 11, 2026, the California Attorney General reached a $2.75 million settlement with The Walt Disney Company over three failures in honoring opt-outs from California consumers: opt-outs didn’t sync across services for logged-in accounts, web form opt-outs didn’t stop third-party ad tags, and GPC signals weren’t tied to user profiles. As of May 2026 this is the second-largest CCPA settlement on record, behind GM’s $12.75M (May 8, 2026). The key provision is CPPA regulation §7025(c)(1): if you use identity data to serve targeted ads across devices and services, you must use that same identity data to honor opt-outs across the same scope.
A brief timeline
| Date | Event |
|---|---|
| January 1, 2020 | CCPA takes effect |
| July 1, 2023 | CPRA amendments: “sharing” definition added; GPC becomes legally mandatory to honor |
| January 31, 2024 | IAB USP string (us_privacy) deprecated; GPP replaces it |
| January 1, 2026 | §7025(c)(6) “Opt-Out Preference Signal Honored” display requirement takes effect |
| February 11, 2026 | Disney $2.75M settlement announced — largest CCPA settlement at that time |
| May 8, 2026 | GM $12.75M settlement surpasses Disney as the largest CCPA settlement |
| January 1, 2027 | AB 566 (signed 2025) requires browsers to offer a built-in opt-out preference signal mechanism |
What did California find?
The California Department of Justice’s investigation identified three gaps in Disney’s opt-out handling across its streaming bundle (Disney+, Hulu, ESPN+):
1. Device and service siloing. When a logged-in user opted out on one service and device, the choice was stored locally to that application. The same account was still targeted on other services because the opt-out flag never reached the central identity record. Disney had the identity graph to link the same user across services for ad targeting — and under the settlement’s logic, that graph had to serve the opt-out too.
2. Third-party ad tags not blocked by web form opt-outs. Disney’s webform process updated Disney’s internal ad systems. It did not halt the execution of third-party ad-tech tags embedded in the streaming environment. The AG’s complaint refers to “third-party ad-tech partners” as a category; specific vendor names are not in the publicly available documents.
3. GPC not tied to logged-in profiles. The GPC signal was read correctly at the browser level for that session. When that user later authenticated, or logged in from a different device without GPC enabled, the opt-out wasn’t applied to their account.
The settlement requires a three-year compliance program, and specifies that logged-in opt-outs must propagate across all of Disney’s streaming services.
What does §7025(c)(1) actually say?
The “Single Identity Rule” framing that circulated after the settlement is not a term in the statute. The actual rule is §7025(c)(1) of the CPPA CCPA regulations. When a consumer submits an opt-out of sale or sharing, the business must treat the opt-out as covering:
- the browser or device from which the signal was sent
- any consumer profile associated with that browser or device, including pseudonymous profiles
- the consumer, if the business can identify them
The scope of the opt-out follows the scope of your identity resolution. If your system links a browser session to an account record, the opt-out must reach the account record.
What rules changed in 2026?
§7025(c)(6) — “Opt-Out Preference Signal Honored.” Since January 1, 2026, businesses that detect and honor a GPC signal must display “Opt-Out Preference Signal Honored” or equivalent language on the page. A small in-page notice or footer confirmation is enough. The requirement means detection alone is not sufficient — the user needs visible confirmation.
IAB GPP replaces USP. The old us_privacy IAB string was deprecated on January 31, 2024. If your CMP still writes us_privacy, ad partners may not read it correctly. The current standard is the IAB Global Privacy Platform (GPP), which handles multiple US state laws in a single signal.
AB 566 (effective January 1, 2027). This California law requires browser manufacturers to include a built-in mechanism for residents to set an opt-out preference signal. It extends the GPC ecosystem by making the browser UI a first-class channel for opt-outs, rather than a developer-only tool.
How do you detect GPC?
Client-side:
if (navigator.globalPrivacyControl === true) {
// visitor has set a browser-level opt-out
// block behavioral ad tags before they fire
}
navigator.globalPrivacyControl is a boolean defined in the GPC specification. The window.globalPrivacyControl variant does not exist in the spec — do not use it.
Server-side (Node.js):
const optedOut = req.headers['sec-gpc'] === '1'
if (optedOut) {
// do not route this request to ad partners
}
The Sec-GPC: 1 header is sent with every HTTP request from a browser with GPC active. Checking it server-side lets you gate ad calls before any client code runs. If the visitor is authenticated, this is also where you tie the opt-out to their account record per §7025(c)(1).
How do you stop third-party ad tags on opt-out?
Both Google and Meta have official California opt-out mechanisms.
Google Ads — Restricted Data Processing:
// Set before the Google tag fires, or on detecting opt-out
gtag('set', 'restricted_data_processing', true)
Restricted Data Processing tells Google to limit data use for that event. It applies to Google Ads, Display & Video 360 and Campaign Manager tags loaded via gtag.
Meta Conversions API — Limited Data Use:
When sending events from your server, add these fields to each event object:
{
"event_name": "Purchase",
"data_processing_options": ["LDU"],
"data_processing_options_country": 1,
"data_processing_options_state": 1000
}
"LDU" activates Limited Data Use. Country 1 is the USA; state 1000 is California. Meta will not use the event data for ad targeting under those conditions.
Server-Side GTM as a gating layer. If your opt-out state lives in a database, the sGTM server container can read it before dispatching any outbound hit. A Firestore Lookup variable — a built-in server-side variable type — reads a document from Firestore by visitor or user ID and returns its value as a tag condition. This lets you gate Meta CAPI and Google Ads hits on a stored privacy flag without a Redis cluster or custom code.
How does CCPA compare to GDPR for tag management?
| Dimension | GDPR (EU/UK) | CCPA/CPRA (California) |
|---|---|---|
| Default state | Tags blocked until consent | Tags can load by default |
| Signal type | Opt-in consent | Opt-out request or GPC |
| Opt-out scope | Per device, per controller | Follows identity graph: device → pseudonymous profile → account |
| Display requirement | Cookie banner | ”Opt-Out Preference Signal Honored” when GPC detected (§7025(c)(6)) |
| Programmatic ads | Consent per TCF purpose or Consent Mode | RDP for Google, LDU for Meta |
CCPA doesn’t replace the EU consent banner if you have European visitors. You need both: an opt-in mechanism for the EU and UK (covered in the Consent Mode post and the TCF post), and an opt-out mechanism for California. The EU rules for analytics without a banner are in the cookieless consent post.
Setting up tag gating for both opt-in and opt-out flows is part of my consent mode work.
Frequently asked questions
Does the settlement affect my site if I don't sell personal data?
Probably yes if you run behavioral ad tags. CPRA defines 'sharing' as passing personal data to third parties for cross-context behavioral advertising. Loading a Google Ads or Meta remarketing pixel counts. You need a 'Do Not Sell or Share' link and must honor GPC.
What is the 'Opt-Out Preference Signal Honored' display requirement?
§7025(c)(6), effective January 1, 2026, requires businesses to display 'Opt-Out Preference Signal Honored' — or equivalent language — on any page where they detect a GPC signal and honor it. It is a UI confirmation that the signal was received and applied.
Is the IAB USP string still valid for CCPA?
No. IAB deprecated the US Privacy string (us_privacy) on January 31, 2024. The replacement is the IAB Global Privacy Platform (GPP). If your CMP still writes us_privacy, it is using a deprecated spec. Ad partners may not read it correctly.
Does the §7025(c)(1) cross-platform rule apply to small businesses?
§7025(c)(1) describes how opt-out signals must be applied when they apply. Whether CCPA applies to your business depends on whether you meet the thresholds: annual gross revenue over $25M, handling data of 100,000+ consumers/households, or deriving 50%+ of revenue from selling/sharing personal data.
Sources
- California AG, press release: $2.75M settlement with Disney (February 2026)
- CCPA regulations, §7025 (CPPA)
- AB 566 (California, 2025)
- Global Privacy Control specification
- IAB Global Privacy Platform (GPP) specification
- Google Ads, Restricted Data Processing
- Meta, Limited Data Use for the Conversions API