Blog

CalPrivacy Strike Force Issues its First Action, CNIL Fines American Express

Julie Rubash, General Counsel and Chief Privacy Officer
December 9, 2025

Want to receive these privacy recaps in your inbox each week? Subscribe here.

California’s newly formed Data Broker Strike Force delivered its inaugural enforcement action, fining marketing firm ROR Partners $56,000 for failing to register under the Delete Act, establishing that businesses cannot circumvent data broker requirements by bundling personal information sales within broader service offerings.

Meanwhile, France’s CNIL imposed a €1.5 million penalty against American Express for deploying advertising cookies without proper consent, marking the authority’s second cookie enforcement action in two weeks and signaling intensified scrutiny of consent management practices across jurisdictions.

Keep reading for more details and my takeaways on the two news stories, along with some additional data privacy news.

United States

CalPrivacy Strike Force Fines Data Broker For Failing to Register

The CalPrivacy Data Broker Strike Force fined marketing firm ROR Partners for failing to register as a data broker. According to CalPrivacy, ROR Partners built custom audience segments based on inferences derived from demographic, socioeconomic, and behavioral data collected from a combination of its clients and third-party sources and made those segments available to its clients for targeted marketing.


CalPrivacy emphasized in its Order that ROR Partners’ disclosures are sales of personal information, regardless of whether those sales are bundled with other advertising and marketing services. “A sale is a sale,” it said. “A business cannot bypass the CCPA’s and the Delete Act’s requirements by selling personal information as part of a larger suite of products and services.”

TAKEAWAY

This was the first action by the Data Broker Strike Force, established by the CalPrivacy enforcement division in November 2025. The Strike Force investigates privacy violations by the data broker industry, including compliance with the Delete Act’s data broker registration requirement and the CCPA. With this dedicated enforcement team up and running, this action is likely just the tip of the iceberg for data broker enforcement.

Europe

The French data protection authority (CNIL) issued a 1.5 million euro fine against American Express based on findings that the company placed cookies (particularly for advertising purposes) without consent or continued to read previously placed cookies despite withdrawal of consent.

TAKEAWAY

The fine amount accounted for the company’s non-compliance and corrective measures during the proceedings, as well as the fact that the CNIL’s cookie rules are well known due to their long history and widespread dissemination.


This is the CNIL’s second fine in two weeks over cookie consent failures, having issued a 750,000 euro fine against Les Publications Condé Nast on November 27, 2025, based on allegations concerning vanityfair.fr’s failure to obtain user consent before placing cookies, among other allegations.

A LITTLE MORE PRIVACY, IF YOU PLEASE

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

Data Privacy Resources and Priorities for U.S. Organizations in 2026

February 25, 2026

The U.S. Supreme Court will review a key VPPA...

California AG Announces $2.75M CCPA Settlement with Disney, Largest in State History

February 19, 2026

The U.S. Supreme Court will review a key VPPA...

Supreme Court Takes Up Paramount VPPA Case as California DOJ Targets Surveillance Pricing

February 3, 2026

The U.S. Supreme Court will review a key VPPA...

Latest White Papers

Connecting Legal & Marketing Teams on Consent and Preferences

February 4, 2025

Break down data silos and unlock better collaboration. Marketing...

Navigating Sensitive Data in the U.S.

February 4, 2025

Download our comprehensive guide to learn how different states...

Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

    First name *

    Last name *

    Email address *

    Company *

    Message *

    * indicates required fields