Disney agreed to pay $2.75 million to settle allegations by the California Attorney General that it violated the California Consumer Privacy Act (CCPA) by making it difficult for consumers to opt out of the sale/sharing of their personal data. California alleged Disney’s opt-out mechanisms contained gaps that prevented users—including those logged into their accounts—from fully stopping data sharing across Disney’s services, devices, and platforms, and that data continued to be shared with third-party ad-tech companies whose code was embedded in Disney websites and apps.
The settlement (pending court approval) requires Disney to implement a more comprehensive privacy program and provide California officials a compliance update within 60 days describing changes made to align with CCPA requirements. State officials characterized the penalty as the largest fine to date under the CCPA; Disney did not admit liability as part of the agreement and said it continues to invest in privacy protections across its streaming services.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Disney agreed to a $2.75 million settlement with the California Attorney General over alleged CCPA violations tied to ineffective opt-out mechanisms. The settlement, pending court approval, also requires Disney to implement a comprehensive privacy program and submit a compliance update within 60 days followed by recurring progress reports every 60 days until all services meet CCPA requirements.
By February 2026, California had initiated its second enforcement action against Disney in five months, alleging Disney's CCPA opt-out tools failed to fully stop the sale and sharing of personal data across accounts, devices, services, and platforms. Investigators said data could still be shared with third-party ad-tech companies even after users submitted opt-out requests.
In September 2025, the U.S. Federal Trade Commission fined Disney $10 million for child privacy violations. This was a separate federal privacy enforcement action referenced alongside the later California case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.