Skip to content
← Back to blog
Regulation·October 7, 2026·7 min read

What California's PlayOn Sports order tells a SaaS team to build: a quarterly tracker scan, an opt-out that works, and a risk assessment

California's PlayOn Sports order reads like a build spec: scan trackers quarterly, honor opt-out signals, and document a risk assessment.

The California Privacy Protection Agency (CPPA) fined a high school ticketing company $1.1 million for a tracking setup that most product teams would call ordinary: a cookie banner with one button, a phone number for opt-outs, and a privacy policy that pointed people to an industry opt-out site. The more useful part of the order is the second half. It lists what the company must now build, and that list is a spec any SaaS team with California users can run against its own site this week.

This is a builder's read of a public enforcement order, not legal advice. Counsel decides whether the rules cover you. This is what the order says engineering has to be ready to show.

What did the PlayOn order actually find?

The Board of the CPPA adopted a stipulated final order against 2080 Media, Inc., which does business as PlayOn Sports, on 27 February 2026 (Case No. ENF24-S-PL-24). The relevant period in the order is 1 January 2023 to 31 December 2024. PlayOn's GoFan platform sells tickets to school events, and the order says about 1,400 California schools had contracted with it.

Four findings carry the engineering lessons:

  • One way to agree, no way to refuse. The banner on GoFan pages offered a single "Agree" button. On a phone, the banner covered the part of the screen used to redeem the ticket, so a student had to click Agree to get into the game.
  • Opt-out by phone and email only. Those were the only methods PlayOn offered for opting out of sale or sharing. The order says they did not reach the cookies, pixels and similar trackers on its sites, so a person who phoned in still had their data shared.
  • A pointer instead of a mechanism. The privacy policy told people to opt out through the Network Advertising Initiative and the Digital Advertising Alliance. The order treats that as a failure to provide a method.
  • No opt-out preference signal. The sites were not configured to honor a browser-sent signal such as Global Privacy Control, which the regulations (section 7025) require a business that sells or shares data online to process.

The order also records that the privacy policy had not been updated between July 2022 and February 2024, and that it said PlayOn did not sell personal information. PlayOn admitted only the background facts about its platform (paragraphs 29 to 36) and neither admitted nor denied the rest. The CPPA credited it for rebuilding the site in December 2024, before the Enforcement Division contacted it.

Why did one ad campaign make this a sale or share?

The detail that should worry a small team is in paragraph 45. The order says PlayOn ran only one targeted advertising campaign on its ticketing platform in the period, and that its use of certain trackers was still a sale and a share under the statute. So the volume of advertising was not the test. The presence of a tracker passing personal information to an ad or analytics partner was.

Picture a 24-person Series A HR-tech company that added a retargeting pixel and a session-replay script to its marketing site two years ago, for a campaign that ended. If the scripts are still firing, the company is in PlayOn's position whether or not anyone remembers the campaign. Nobody decided to keep them. Nobody decided to remove them either.

What does the remediation list ask you to build?

Paragraph 67 of the order is the part to print. In plain terms, PlayOn must:

  1. 1.Scan its properties at least quarterly to keep a full and current inventory of tracking technologies.
  2. 2.Hold compliant contracts with every third party that receives personal information through those trackers, meeting section 7053(a)(1) to (6).
  3. 3.Configure each tracker that shares data so an opt-out preference signal, and PlayOn's other opt-out methods, actually stop the sharing.
  4. 4.Keep a "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" link that lets people exercise the choice.
  5. 5.Review its privacy policy, notices, consent management platform and rights-request mechanisms within 90 days.

Paragraph 71 gives it 180 days to finish the process and system changes. Paragraph 70 requires it to publish annual request metrics under section 7102 for three years.

Read as a ticket list, that is a recurring job (the scan), a mapping job (tracker to vendor to contract), and a wiring job (signal to tracker). The wiring is where teams fail. A banner that records a refusal in one database while the tag manager keeps firing is a banner that works for the screenshot. If you have not tested this end to end, the Honda and Todd Snyder orders describe the same failure from two other companies.

Where does the risk assessment come in?

Paragraph 68 is the one that connects this order to the 2027 rules. It says that from 1 January 2026, selling or sharing personal information is itself a trigger for a risk assessment under section 7150(b). PlayOn must complete one for its ticketing and streaming services within a year of the order, update it before any material change, and have its Board of Directors review it, with the review date and the reviewers' names written into the document.

The order also tells PlayOn to weigh whether it is coercing people into sharing, and gives an example: whether users must consent to sharing with one or more parties to take part in an event. That is the agree-to-enter banner, now treated as a harm to assess rather than a design choice. If you want the full list of what the document must hold, what actually goes in a CCPA risk assessment walks through it.

Here is the opinion we would defend: the tracker inventory is the highest-return piece of work in the whole order, because everything else hangs off it. You cannot write contracts for vendors you have not found, wire an opt-out to scripts you cannot list, or assess risk for processing you have not mapped. If a team has one sprint, spend it on the inventory.

What if you are a vendor, not the site owner?

This changes the picture. If your product only processes data on a customer's instructions, as a service provider, the sale-and-share duties in this order sit mostly with your customer. Your obligations are in the contract. The vendor contract requirements post covers what California requires in it, and the customers who read this order will ask you the same questions PlayOn's contracts now have to answer.

There is one situation where this work is the wrong answer. If your site has no advertising or analytics trackers that pass personal information to third parties, a quarterly scan will find nothing to govern, and the time belongs on the automated decision features that arrive on 1 January 2027 instead. Run the scan once to prove the negative, then stop.

What should you do before the next sprint?

Run a crawler or your browser's network panel across your logged-out marketing pages and your signed-in product. List every third-party request, who it goes to, and whether a signed contract covers it. Send a test browser with Global Privacy Control switched on and see which requests stop. Then open your banner on a phone, because the PlayOn failure was partly a layout bug.

If you sell to California employers, lenders, landlords or insurers, the same inventory habit is the first step toward the ADMT work due by 1 January 2027. The ADMT coverage checker is a quick way to see whether your product's features are in scope, and our ADMT compliance engineering service describes how we build the notice, opt-out and logging pieces for teams without the capacity. If you would rather talk it through, send us the scope.

Sources

Frequently asked questions.

The California Privacy Protection Agency's Board adopted a stipulated final order against 2080 Media, Inc. (PlayOn Sports) on 27 February 2026. It covers 1 January 2023 to 31 December 2024 and found that PlayOn offered only phone and email opt-outs, did not honor opt-out preference signals, and used a banner with a single Agree button. PlayOn admitted only background facts about its platform and neither admitted nor denied the rest.

The regulations do not name a scan schedule, but the CPPA's PlayOn order of 27 February 2026 required PlayOn to scan its digital properties at least quarterly to keep a full and current inventory of tracking technologies. That is the clearest signal of what the agency treats as a reasonable control. Treat it as a floor for any site that shares data with advertising or analytics partners.

Not for a business that collects personal information online through trackers. The CPPA's February 2026 PlayOn order found phone and email opt-outs did not reach the cookies and pixels on PlayOn's sites, and that sending people to industry opt-out sites did not count as a method. Under the order's reading of section 7026, an online business also has to honor an opt-out preference signal.

According to the CPPA's PlayOn order, yes: from 1 January 2026, selling or sharing personal information is a trigger for a risk assessment under section 7150(b) of the CCPA regulations. The order gave PlayOn one year from 27 February 2026 to complete one and required Board of Directors review with the date and reviewers named.

Mostly through your contracts. The sale and sharing duties in the order fall on the business that decides how trackers collect and pass on data. Customers that read the order will ask a vendor to confirm its contract terms meet section 7053, so be ready to show them. Counsel should confirm where your role sits.