The California Privacy Protection Agency (CPPA) fined a high school ticketing company $1.1 million for a tracking setup that most product teams would call ordinary: a cookie banner with one button, a phone number for opt-outs, and a privacy policy that pointed people to an industry opt-out site. The more useful part of the order is the second half. It lists what the company must now build, and that list is a spec any SaaS team with California users can run against its own site this week.
This is a builder's read of a public enforcement order, not legal advice. Counsel decides whether the rules cover you. This is what the order says engineering has to be ready to show.
What did the PlayOn order actually find?
The Board of the CPPA adopted a stipulated final order against 2080 Media, Inc., which does business as PlayOn Sports, on 27 February 2026 (Case No. ENF24-S-PL-24). The relevant period in the order is 1 January 2023 to 31 December 2024. PlayOn's GoFan platform sells tickets to school events, and the order says about 1,400 California schools had contracted with it.
Four findings carry the engineering lessons:
- One way to agree, no way to refuse. The banner on GoFan pages offered a single "Agree" button. On a phone, the banner covered the part of the screen used to redeem the ticket, so a student had to click Agree to get into the game.
- Opt-out by phone and email only. Those were the only methods PlayOn offered for opting out of sale or sharing. The order says they did not reach the cookies, pixels and similar trackers on its sites, so a person who phoned in still had their data shared.
- A pointer instead of a mechanism. The privacy policy told people to opt out through the Network Advertising Initiative and the Digital Advertising Alliance. The order treats that as a failure to provide a method.
- No opt-out preference signal. The sites were not configured to honor a browser-sent signal such as Global Privacy Control, which the regulations (section 7025) require a business that sells or shares data online to process.
The order also records that the privacy policy had not been updated between July 2022 and February 2024, and that it said PlayOn did not sell personal information. PlayOn admitted only the background facts about its platform (paragraphs 29 to 36) and neither admitted nor denied the rest. The CPPA credited it for rebuilding the site in December 2024, before the Enforcement Division contacted it.
Why did one ad campaign make this a sale or share?
The detail that should worry a small team is in paragraph 45. The order says PlayOn ran only one targeted advertising campaign on its ticketing platform in the period, and that its use of certain trackers was still a sale and a share under the statute. So the volume of advertising was not the test. The presence of a tracker passing personal information to an ad or analytics partner was.
Picture a 24-person Series A HR-tech company that added a retargeting pixel and a session-replay script to its marketing site two years ago, for a campaign that ended. If the scripts are still firing, the company is in PlayOn's position whether or not anyone remembers the campaign. Nobody decided to keep them. Nobody decided to remove them either.
What does the remediation list ask you to build?
Paragraph 67 of the order is the part to print. In plain terms, PlayOn must:
- 1.Scan its properties at least quarterly to keep a full and current inventory of tracking technologies.
- 2.Hold compliant contracts with every third party that receives personal information through those trackers, meeting section 7053(a)(1) to (6).
- 3.Configure each tracker that shares data so an opt-out preference signal, and PlayOn's other opt-out methods, actually stop the sharing.
- 4.Keep a "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" link that lets people exercise the choice.
- 5.Review its privacy policy, notices, consent management platform and rights-request mechanisms within 90 days.
Paragraph 71 gives it 180 days to finish the process and system changes. Paragraph 70 requires it to publish annual request metrics under section 7102 for three years.
Read as a ticket list, that is a recurring job (the scan), a mapping job (tracker to vendor to contract), and a wiring job (signal to tracker). The wiring is where teams fail. A banner that records a refusal in one database while the tag manager keeps firing is a banner that works for the screenshot. If you have not tested this end to end, the Honda and Todd Snyder orders describe the same failure from two other companies.
Where does the risk assessment come in?
Paragraph 68 is the one that connects this order to the 2027 rules. It says that from 1 January 2026, selling or sharing personal information is itself a trigger for a risk assessment under section 7150(b). PlayOn must complete one for its ticketing and streaming services within a year of the order, update it before any material change, and have its Board of Directors review it, with the review date and the reviewers' names written into the document.
The order also tells PlayOn to weigh whether it is coercing people into sharing, and gives an example: whether users must consent to sharing with one or more parties to take part in an event. That is the agree-to-enter banner, now treated as a harm to assess rather than a design choice. If you want the full list of what the document must hold, what actually goes in a CCPA risk assessment walks through it.
Here is the opinion we would defend: the tracker inventory is the highest-return piece of work in the whole order, because everything else hangs off it. You cannot write contracts for vendors you have not found, wire an opt-out to scripts you cannot list, or assess risk for processing you have not mapped. If a team has one sprint, spend it on the inventory.
What if you are a vendor, not the site owner?
This changes the picture. If your product only processes data on a customer's instructions, as a service provider, the sale-and-share duties in this order sit mostly with your customer. Your obligations are in the contract. The vendor contract requirements post covers what California requires in it, and the customers who read this order will ask you the same questions PlayOn's contracts now have to answer.
There is one situation where this work is the wrong answer. If your site has no advertising or analytics trackers that pass personal information to third parties, a quarterly scan will find nothing to govern, and the time belongs on the automated decision features that arrive on 1 January 2027 instead. Run the scan once to prove the negative, then stop.
What should you do before the next sprint?
Run a crawler or your browser's network panel across your logged-out marketing pages and your signed-in product. List every third-party request, who it goes to, and whether a signed contract covers it. Send a test browser with Global Privacy Control switched on and see which requests stop. Then open your banner on a phone, because the PlayOn failure was partly a layout bug.
If you sell to California employers, lenders, landlords or insurers, the same inventory habit is the first step toward the ADMT work due by 1 January 2027. The ADMT coverage checker is a quick way to see whether your product's features are in scope, and our ADMT compliance engineering service describes how we build the notice, opt-out and logging pieces for teams without the capacity. If you would rather talk it through, send us the scope.
Sources
- California Privacy Protection Agency: Order of Decision and Stipulated Final Order, In the Matter of 2080 Media, Inc. d/b/a PlayOn Sports, Case No. ENF24-S-PL-24, adopted 27 February 2026
- California Privacy Protection Agency: CCPA statute and regulations, effective 1 January 2026