惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
A
About on SuperTechFans
GbyAI
GbyAI
宝玉的分享
宝玉的分享
爱范儿
爱范儿
博客园 - 【当耐特】
博客园 - 司徒正美
博客园 - 聂微东
P
Proofpoint News Feed
WordPress大学
WordPress大学
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
Jina AI
Jina AI
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
博客园 - 叶小钗

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
Sephora - First Public CCPA Enforcement Action | iubenda
Jessica Ryder · 2022-08-31 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

One of the world’s largest cosmetics retailers, Sephora, will have to pay $1.2 million in fines for violating California Consumer Privacy Act (CCPA) by selling customers’ personal information and failing to comply with opt-out requests.

Sephora CCPA

According to California Attorney General Rob Bonta, in exchange for benefits like targeted advertising and discounted analytics, Sephora made its users’ personal information available to online third-party trackers without telling them it was doing so. The global privacy control browser extension automatically communicates users’ privacy preferences to all websites they visit without requiring them to click on each website’s opt-out link manually. It could also not execute opt-out requests sent to Sephora.

On August 24, 2022, Bonta announced that it had negotiated a $1.2 million settlement with Sephora, Inc. on claims that the company had broken the Business and Professions Code’s (BPC) Sections 17200 et seq. and the California Consumer Privacy Act (CCPA).

Bonta pointed out that the charges surfaced after an enforcement sweep of online merchants as part of its continuing CCPA enforcement.

After an investigation, Bonta concluded that Sephora failed to warn customers about selling their personal information and did not offer them an obvious “Do Not Sell My Personal Information” link on its website or mobile application. Additionally, Bonta found that Sephora did not correct the infractions within the 30-day window currently permitted by the CCPA since Sephora did not execute user requests to opt-out of sale via the user-enabled global privacy controls.

In addition to the previous, Bonta emphasized that it had reached a settlement in which Sephora was required to pay $1.2 million in fines and adhere to Sections 1798.20 and 1798.135 of the California Consumer Privacy Act and Regulations 7011, 7012, 7026, and 7051 of the California Consumer Privacy Act. Additionally, Bonta required that Sephora must abide by the following conditions:

  • providing mechanisms for users to opt-out of the sale of personal information, including via global privacy control;
  • clarifying its online disclosures and privacy policy to include an affirmative representation that it sells data;
  • conforming its service provider agreements to the CCPA’s requirements; and
  • providing annual reports to the attorney general regarding its sale of personal information, its service provider relationships status, and its efforts to improve data security.

In addition, the settlement mandates that Sephora implement and maintain a program to evaluate and track whether it is successfully handling opt-out requests for sales, as well as conduct an annual review of its websites and mobile apps to identify the entities with which it shares personal information, within 180 days of the settlement’s effective date and for the following two years.