California’s new CCPA risk-assessment rules took effect January 1, 2026, creating a fundamental shift in how regulators evaluate privacy compliance. Rather than focusing on policy language and public statements, enforcement is now targeting the technical reality of how data flows across websites.
Lokker, experts in online data privacy and compliance, has just released new data showing most S&P 500 U.S. companies are not technically compliant, despite their consent banners and privacy policies.
The Enforcement Landscape Is Shifting
Lokker’s Quarterly Risk Report – Q1 2026 examines how privacy risk is shifting from written commitments to technical reality. With CCPA risk assessment requirements now in effect, it looks at both what regulators, courts, and plaintiffs are now looking for, and what organizations must be able to demonstrate across their web properties.
The timing is significant. In September 2025, the California Privacy Protection Agency (CPPA) approved a record $1.35 million settlement with Tractor Supply Company-the largest penalty in the agency’s history. The settlement centered on failures in opt-out mechanisms and inadequate vendor contracts, but the key insight is that Tractor Supply had proper privacy disclosures and consent banners. Regulators simply discovered that these technical controls didn’t function in practice.
Earlier in 2025, the CPPA issued a $632,500 fine against Honda for deliberately obscuring opt-out mechanisms-requiring two clicks to opt out but only one to opt in. Meanwhile, the California Attorney General announced a $1.55 million settlement with Healthline, an online health publisher. Healthline had a functioning privacy notice, but investigation revealed that despite offering opt-outs through multiple channels, over 118+ third-party cookies and pixels continued firing data to advertisers after consumers attempted to opt out.
These cases reveal an uncomfortable pattern: companies with publicly defensible privacy policies are failing under technical scrutiny.
What Lokker Scans Reveal
Based on continuous scans of S&P 500 websites, Lokker found that over 90 percent load third-party trackers before consent, and roughly 80 percent rely on consent tools that actually fail in practice.
Using continuous scanning across large enterprise websites, Lokker analyzed how tracking technologies behave in real-world conditions, not audit snapshots. The results are sobering.
Across industries, Lokker consistently observed that trackers initiate data collection before meaningful consent is obtained. Consent management tools often appear compliant on the surface, yet fail under technical scrutiny. In many cases, third-party scripts activate on page load, across subdomains, or during specific user interactions that bypass consent controls entirely.
These failures are rarely intentional. They arise from complex modern web stacks, fragmented ownership of tracking tools, and constant changes introduced by marketing, analytics, and third-party vendors. A single misconfiguration in a vendor script or a delay in implementing consent logic across all domains can expose an entire organization.
The Litigation Risk Is Real and Accelerating
An absence of intent isn’t a standard that regulators are likely to apply-and the courts are proving even less forgiving.
The regulatory environment is intersecting with an aggressive litigation landscape that’s increasingly receptive to claims that web tracking technologies operate as unlawful surveillance mechanisms when deployed without proper notice and consent.
Recent district court decisions have dramatically expanded the scope of CCPA private litigation. In cases like Shah v. Capital One Financial Corp. and M.G. v. Therapymatch, courts rejected arguments that the CCPA only covers data breaches. Instead, judges interpreted the law to cover disclosure of personal information to third parties via embedded tracking technologies-like Google Analytics, Facebook Pixel, and Microsoft trackers-without consumer consent. This interpretation opens the door to statutory damages of $100 to $750 per consumer per violation.
Recent cases have seen claims proceed based on the mere presence of certain tracking technologies on a website. This means that a single misconfiguration or script can expose an organization to regulatory inquiry and/or class action litigation.
What Companies Must Do Now
The convergence of aggressive regulatory enforcement and expanded private litigation creates an immediate compliance imperative. The Tractor Supply settlement explicitly required the company to conduct quarterly scanning of digital properties to maintain a current inventory of tracking technologies and configure systems to properly honor opt-out preference signals.
This is no longer aspirational. Regulators and courts expect:
- Technical proof of consent functioning: Not just a consent banner, but evidence that trackers don’t fire before consent is obtained
- Vendor contract reviews: All contracts with third parties must include CCPA-mandated privacy protections
- Multi-channel opt-out testing: Opt-outs must work across webforms, consent tools, and global privacy control (GPC) signals
- Continuous scanning: Regular audits to catch misconfigurations before regulators do
For S&P 500 companies, the cost of noncompliance is now measured not just in potential fines but in class action exposure and regulatory distraction. As the enforcement environment matures, the companies that act now-implementing technical controls that match their public commitments-will separate themselves from the growing group exposed to both regulatory and litigation risk.





