PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations

Posted on May 11, 2025 by Dissent

Libbie Canter, Lindsey Tonsager, Jayne Ponder, and Natalie Maas of Covington and Burling write:

On May 6, 2025, the California Privacy Protection Agency (“CPPA”) announced a decision and $345,178 fine related to allegations that Todd Snyder, Inc. violated the California Consumer Privacy Act (“CCPA”) and requirements to change its business practices.

As summarized in the consent order, the CPPA alleged the following:

  • Despite engaging in activities that Todd Snyder characterized as a “sale” or “sharing” through “automated tracking technologies” installed on its website, the website opt-out mechanism was not properly configured.  The CPPA states that Todd Snyder “would have known” that the opt-out did not function correctly, but it “instead deferred to third-party privacy management tools without knowing their limitations or validating their operation.”
  • The consumer rights request form required consumers to provide information to validate their identity (e.g., first and last name, email, photograph of the consumer holding their “identity document”) for all requests, including opt-out of sale/sharing requests.
  • Todd Snyder allegedly collected more information than required – including government identification – to exercise privacy rights.

Read more at Inside Privacy.

Category: BreachesBusinessFeatured NewsLawsU.S.

Post navigation

← US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
ARC sells airline ticket records to ICE and others →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

RSS Recent Posts on DataBreaches.net

  • McLaren provides written notice to 743,131 patients after ransomware attack in July 2024
  • A state forensics lab was leaking its files. Getting it locked down involved a number of people.
  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
©2025 PogoWasRight.org. All rights reserved.