BlogTwo Simultaneous Enforcement Waves Are Targeting the Same Flaw: Broken Opt-Outs and Opaque Privacy Notices
Industry News

Two Simultaneous Enforcement Waves Are Targeting the Same Flaw: Broken Opt-Outs and Opaque Privacy Notices

The EDPB activated 25 DPAs to audit GDPR transparency disclosures. California has levied over $4M in CCPA fines over broken opt-outs. Both expose the same root failure.

May 6, 2026·CookieGap Team

Regulators on both sides of the Atlantic moved in the same week of March 2026, and they hit the same target. The European Data Protection Board launched a pan-European sweep focused on how organizations disclose their data practices to users. Around the same time, California had already opened the year with more than $4 million in penalties against Disney, Ford, and PlayOn Sports. All of them came from opt-out mechanisms that failed in practice, not on paper.

If you run a consent flow today, both actions are directly relevant to your stack.

What the EDPB's CEF 2026 means for you

On 19 March 2026, the EDPB launched its Coordinated Enforcement Framework (CEF) action for the year. The topic is compliance with GDPR transparency and information rules under Articles 12, 13, and 14.

In plain terms, those articles say that when you collect personal data, you have to tell users what you collect, why, who receives it, and how long you keep it. The language has to be short, clear, and easy to find. Not buried in a 6,000-word policy, and not written for lawyers.

Here is what makes this round different from a single strongly worded letter to one company.

  • 25 national DPAs across Europe are taking part, running investigations in parallel with a shared audit method.
  • The EDPB aggregates the results, which can trigger follow-up at both national and EU level.
  • Past CEF topics (right of access in 2024, right to erasure in 2025) each produced formal investigations and, in some cases, enforcement actions.

The sweep targets Articles 12 to 14, the rules that require you to proactively inform users when their data is processed. That covers your cookie banner, your privacy policy, and every first-party collection point: forms, checkout, analytics pixels, ad tags. If your policy does not reflect your actual data flows, you are exposed.

California's $4M+ CCPA opt-out wave

While European DPAs prepared their transparency sweep, California was already issuing fines.

On 11 February 2026, California Attorney General Rob Bonta announced a $2.75 million settlement with The Walt Disney Company, the largest CCPA settlement to date. The core issue was simple. Disney could track users across all its streaming services for advertising, but when consumers used the toggles to opt out, the opt-out applied only to that one service and device. The ability to link accounts existed. Disney just did not use it to honor the user's choice.

In the first week of March, CalPrivacy announced two more actions worth nearly $1.5 million, involving Ford and PlayOn Sports.

  • Ford required consumers to complete an email verification step before it would process an opt-out, which CCPA explicitly prohibits. Valid requests went unprocessed as a result.
  • PlayOn Sports was the first CalPrivacy decision to address privacy violations involving students and California schools.

Together, these cases send a clear message. Regulators are technically testing opt-out flows, not just reading privacy policies. The investigative sweep behind the Disney case targeted streaming services and connected TV devices, and it found violations.

The common root failure

Strip away the jurisdictions and the specific statutes, and both waves react to the same pattern.

  • Controls that work on paper but not in practice. Disney's banner let you opt out. It just did not apply the choice consistently. Ford's process looked functional. It added friction that invalidated the request.
  • Disclosure that describes but does not inform. The EDPB's focus is on policies that technically mention data processing but fail to tell users what is actually happening. Think vague third-party references, missing legal bases, and boilerplate that was never updated when the data flows changed.

Both regulators are saying the same thing. We are going to look at what your system does, not what your policy says.

Four checks to run right now

With active enforcement on both Article 12 to 14 transparency and CCPA opt-outs, here is a practical starting point.

  • Audit your privacy notice against your real data flows. List every third-party tag and pixel on your site. Check whether your policy names them, explains the purpose, and states the legal basis. Vague language like "we may share data with trusted partners" will not meet the EDPB's 2026 standard.
  • Test your opt-out end to end. Submit a real opt-out or "do not sell or share" request and trace it through every downstream system: your CMP, your tag manager, your analytics, your ad stack. Confirm that cookies you block in the consent UI are actually blocked, not just labeled as blocked.
  • Remove verification friction from opt-outs. Do not make users verify their identity to exercise an opt-out. Ford's penalty is a direct precedent. CCPA prohibits it.
  • Check cross-service consistency. If a user opts out on one property or device, does that signal reach linked accounts and services? Disney's fine makes this an operational requirement, not a nice-to-have.

The practical takeaway

The EDPB CEF and the California actions line up in timing by coincidence, but not in cause. Both reflect the same shift. Regulators now run technical audits and test real user journeys instead of reviewing policy documents on their own.

For compliance and development teams, that means consent management is not a deploy-and-forget setting. Disclosures drift out of sync when new vendors are added. Opt-out signals break when tag managers are updated. A quarterly review, matching a fresh cookie scan against your live privacy notice and testing opt-out flows across devices, is now the minimum defensible standard.

If you have not scanned your site's cookies lately, now is a good time to find out what is actually firing, and whether your notice covers it.

Sources

See where your site stands

Run a free CookieGap scan and get a compliance report in under a minute.

Scan your site free