CCPA · By industry
CCPA compliance for ecommerce stores
CCPA compliance for an online store means the Meta, TikTok, and Google pixels on your product, cart, and checkout pages do not amount to selling or sharing a Californian's data before you have disclosed it and honored their opt-out, including the Global Privacy Control browser signal. Stores are squarely in scope because that ad telemetry is the business model. Complidar captures every tracker that fires across up to 120 pages, sends a GPC signal the way a regulator's investigator would, and shows you what a 'sale' looks like on your own checkout.
Why stores trip the CCPA
The CCPA's definition of a 'sale' or 'share' is broad enough to catch the ordinary ecommerce ad stack: a Meta or TikTok pixel, a Google Ads tag, and GA4 all transmit identifiers and behavior to third parties who use them for cross-context advertising, and that transfer is what the statute regulates. The recurring failure is timing and signal: those tags fire on product, cart, and checkout pages before any consent, and the store never changes its behavior when a visitor's browser sends a Global Privacy Control opt-out. Both are visible from outside, which is exactly why this is enforcement's favorite fact pattern.
The anchor case is a store. In re Sephora ($1.2M, 2022) was the first public CCPA enforcement, and it turned on two things an automated scan sees directly: third-party advertising trackers that amounted to a 'sale' without the required disclosures and opt-out, and a site that ignored the GPC signal. The California Attorney General named the GPC failure specifically. The follow-through is not slowing down: California v. Disney resolved for $2.75M in 2026.
Where the exposure lives on a store
On an ecommerce site the CCPA surface is concentrated in the conversion path, where the high-value tracking concentrates too. The mechanical, citable failures are:
- Meta, TikTok, and Google ad pixels firing on product, cart, and checkout pages before the visitor has consented
- GA4 and analytics loading pre-consent and passing identifiers to a third party
- A site that does not change behavior when it receives a Global Privacy Control opt-out signal from the browser
- No working 'Do Not Sell or Share My Personal Information' pathway where one is required
- Session-replay or analytics recording the checkout, capturing what shoppers type and do
What it actually costs
The statute prices each violation at $2,500, and $7,500 per intentional violation or any violation involving a minor, enforced by the Attorney General and the California Privacy Protection Agency. Because each affected consumer interaction can count, the figure compounds; a separate consumer private right of action covers data breaches at $100 to $750 per consumer per incident. The realistic number to plan against is the ad-pixel-before-consent comparable, which runs a median around $4.5 million, with the Sephora $1.2M as the public anchor for what one store paid. The headline regulatory and class figures (US v. Twitter $150M, California v. Google $93M, In re TikTok $92M) are scale illustrations of the same tracking theory, not what a typical store should expect.
What the scan checks here
- Every Meta, TikTok, Google, and analytics tracker that fires on product, cart, and checkout pages, captured from real network traffic
- Pre-consent firing flagged: which tags transmit identifiers before the shopper has opted in
- Whether the store honors the Global Privacy Control (GPC) signal the scan sends
- A 'Do Not Sell or Share My Personal Information' pathway, where required
- Privacy-policy disclosures: categories collected, sale/share language, consumer-rights mechanics
- Session-replay and analytics vendors recording the checkout flow
Honest limits: A scan verifies what your store does: which trackers fire on which pages, when, whether GPC changes anything, and what your policy says. It cannot determine whether your business meets the CCPA's revenue or volume thresholds, or how your back office handles a consumer's delete or opt-out request; those are counsel and process questions. The report labels which findings are observable site behavior and which need human review, rather than implying a clean scan equals full compliance.
Common questions
Are my Meta and Google pixels really a 'sale' under the CCPA?
They can be. The CCPA defines 'sale' and 'share' broadly enough to cover transferring identifiers to ad platforms for cross-context advertising, which is what those pixels do. That is the exact theory In re Sephora ran on. Whether it meets the statute for your business is a counsel question; whether the tags fire before consent on your checkout is what the scan settles.
I use Shopify with standard apps. Doesn't that handle the CCPA?
The platform gives you a consent banner at best; whether your pixels actually wait for that consent, and whether the store honors a GPC signal, comes down to how the apps and tags are wired on your store. Sephora ran ordinary ad trackers and still paid $1.2M. Complidar scans your store's real behavior, third-party tags included, because defaults are not a defense.
What does a CCPA violation cost an ecommerce store?
Statutory penalties are $2,500 per violation and $7,500 per intentional violation, and they compound across affected consumers. The realistic comparable for the ad-pixel-before-consent pattern runs a median near $4.5M, with Sephora's $1.2M as the public anchor. The nine-figure cases you see in headlines are large-scale illustrations of the same theory, not the typical store's number.
All 22 checks · up to 120 pages · no card
Last updated 2026-06-28 · Informational, not legal advice: how to read this