Skip to main content
Privacy Compliance

What the $2.75M Disney CCPA Settlement Requires

By , MarTech & Analytics Engineer

Published Updated

Quick answer: On February 11, 2026, the California Attorney General reached a $2.75 million settlement with The Walt Disney Company over three failures in honoring opt-outs from California consumers: opt-outs didn’t sync across services for logged-in accounts, web form opt-outs didn’t stop third-party ad tags, and GPC signals weren’t tied to user profiles. As of May 2026 this is the second-largest CCPA settlement on record, behind GM’s $12.75M (May 8, 2026). The key provision is CPPA regulation §7025(c)(1): if you use identity data to serve targeted ads across devices and services, you must use that same identity data to honor opt-outs across the same scope.

A brief timeline

DateEvent
January 1, 2020CCPA takes effect
July 1, 2023CPRA amendments: “sharing” definition added; GPC becomes legally mandatory to honor
January 31, 2024IAB USP string (us_privacy) deprecated; GPP replaces it
January 1, 2026§7025(c)(6) “Opt-Out Preference Signal Honored” display requirement takes effect
February 11, 2026Disney $2.75M settlement announced — largest CCPA settlement at that time
May 8, 2026GM $12.75M settlement surpasses Disney as the largest CCPA settlement
January 1, 2027AB 566 (signed 2025) requires browsers to offer a built-in opt-out preference signal mechanism

What did California find?

The California Department of Justice’s investigation identified three gaps in Disney’s opt-out handling across its streaming bundle (Disney+, Hulu, ESPN+):

1. Device and service siloing. When a logged-in user opted out on one service and device, the choice was stored locally to that application. The same account was still targeted on other services because the opt-out flag never reached the central identity record. Disney had the identity graph to link the same user across services for ad targeting — and under the settlement’s logic, that graph had to serve the opt-out too.

2. Third-party ad tags not blocked by web form opt-outs. Disney’s webform process updated Disney’s internal ad systems. It did not halt the execution of third-party ad-tech tags embedded in the streaming environment. The AG’s complaint refers to “third-party ad-tech partners” as a category; specific vendor names are not in the publicly available documents.

3. GPC not tied to logged-in profiles. The GPC signal was read correctly at the browser level for that session. When that user later authenticated, or logged in from a different device without GPC enabled, the opt-out wasn’t applied to their account.

The settlement requires a three-year compliance program, and specifies that logged-in opt-outs must propagate across all of Disney’s streaming services.

What does §7025(c)(1) actually say?

The “Single Identity Rule” framing that circulated after the settlement is not a term in the statute. The actual rule is §7025(c)(1) of the CPPA CCPA regulations. When a consumer submits an opt-out of sale or sharing, the business must treat the opt-out as covering:

  • the browser or device from which the signal was sent
  • any consumer profile associated with that browser or device, including pseudonymous profiles
  • the consumer, if the business can identify them

The scope of the opt-out follows the scope of your identity resolution. If your system links a browser session to an account record, the opt-out must reach the account record.

What rules changed in 2026?

§7025(c)(6) — “Opt-Out Preference Signal Honored.” Since January 1, 2026, businesses that detect and honor a GPC signal must display “Opt-Out Preference Signal Honored” or equivalent language on the page. A small in-page notice or footer confirmation is enough. The requirement means detection alone is not sufficient — the user needs visible confirmation.

IAB GPP replaces USP. The old us_privacy IAB string was deprecated on January 31, 2024. If your CMP still writes us_privacy, ad partners may not read it correctly. The current standard is the IAB Global Privacy Platform (GPP), which handles multiple US state laws in a single signal.

AB 566 (effective January 1, 2027). This California law requires browser manufacturers to include a built-in mechanism for residents to set an opt-out preference signal. It extends the GPC ecosystem by making the browser UI a first-class channel for opt-outs, rather than a developer-only tool.

How do you detect GPC?

Client-side:

if (navigator.globalPrivacyControl === true) {
	// visitor has set a browser-level opt-out
	// block behavioral ad tags before they fire
}

navigator.globalPrivacyControl is a boolean defined in the GPC specification. The window.globalPrivacyControl variant does not exist in the spec — do not use it.

Server-side (Node.js):

const optedOut = req.headers['sec-gpc'] === '1'
if (optedOut) {
	// do not route this request to ad partners
}

The Sec-GPC: 1 header is sent with every HTTP request from a browser with GPC active. Checking it server-side lets you gate ad calls before any client code runs. If the visitor is authenticated, this is also where you tie the opt-out to their account record per §7025(c)(1).

How do you stop third-party ad tags on opt-out?

Both Google and Meta have official California opt-out mechanisms.

Google Ads — Restricted Data Processing:

// Set before the Google tag fires, or on detecting opt-out
gtag('set', 'restricted_data_processing', true)

Restricted Data Processing tells Google to limit data use for that event. It applies to Google Ads, Display & Video 360 and Campaign Manager tags loaded via gtag.

Meta Conversions API — Limited Data Use:

When sending events from your server, add these fields to each event object:

{
	"event_name": "Purchase",
	"data_processing_options": ["LDU"],
	"data_processing_options_country": 1,
	"data_processing_options_state": 1000
}

"LDU" activates Limited Data Use. Country 1 is the USA; state 1000 is California. Meta will not use the event data for ad targeting under those conditions.

Server-Side GTM as a gating layer. If your opt-out state lives in a database, the sGTM server container can read it before dispatching any outbound hit. A Firestore Lookup variable — a built-in server-side variable type — reads a document from Firestore by visitor or user ID and returns its value as a tag condition. This lets you gate Meta CAPI and Google Ads hits on a stored privacy flag without a Redis cluster or custom code.

How does CCPA compare to GDPR for tag management?

DimensionGDPR (EU/UK)CCPA/CPRA (California)
Default stateTags blocked until consentTags can load by default
Signal typeOpt-in consentOpt-out request or GPC
Opt-out scopePer device, per controllerFollows identity graph: device → pseudonymous profile → account
Display requirementCookie banner”Opt-Out Preference Signal Honored” when GPC detected (§7025(c)(6))
Programmatic adsConsent per TCF purpose or Consent ModeRDP for Google, LDU for Meta

CCPA doesn’t replace the EU consent banner if you have European visitors. You need both: an opt-in mechanism for the EU and UK (covered in the Consent Mode post and the TCF post), and an opt-out mechanism for California. The EU rules for analytics without a banner are in the cookieless consent post.

Setting up tag gating for both opt-in and opt-out flows is part of my consent mode work.

Frequently asked questions

Does the settlement affect my site if I don't sell personal data?

Probably yes if you run behavioral ad tags. CPRA defines 'sharing' as passing personal data to third parties for cross-context behavioral advertising. Loading a Google Ads or Meta remarketing pixel counts. You need a 'Do Not Sell or Share' link and must honor GPC.

What is the 'Opt-Out Preference Signal Honored' display requirement?

§7025(c)(6), effective January 1, 2026, requires businesses to display 'Opt-Out Preference Signal Honored' — or equivalent language — on any page where they detect a GPC signal and honor it. It is a UI confirmation that the signal was received and applied.

Is the IAB USP string still valid for CCPA?

No. IAB deprecated the US Privacy string (us_privacy) on January 31, 2024. The replacement is the IAB Global Privacy Platform (GPP). If your CMP still writes us_privacy, it is using a deprecated spec. Ad partners may not read it correctly.

Does the §7025(c)(1) cross-platform rule apply to small businesses?

§7025(c)(1) describes how opt-out signals must be applied when they apply. Whether CCPA applies to your business depends on whether you meet the thresholds: annual gross revenue over $25M, handling data of 100,000+ consumers/households, or deriving 50%+ of revenue from selling/sharing personal data.

Sources

  1. California AG, press release: $2.75M settlement with Disney (February 2026)
  2. CCPA regulations, §7025 (CPPA)
  3. AB 566 (California, 2025)
  4. Global Privacy Control specification
  5. IAB Global Privacy Platform (GPP) specification
  6. Google Ads, Restricted Data Processing
  7. Meta, Limited Data Use for the Conversions API