
When the Harvest Brings in Privacy Violations — and a Record $1.35M Fine
Peter Bogdasarian and David D. Piper
share this page
The California Privacy Protection Agency (CPPA) is back with a new settlement, this time with the largest rural lifestyle retailer in the United States, Tractor Supply Co. In the settlement, announced September 30, Tractor Supply agreed to a $1.35 million fine — the largest in the CPPA’s history, according to the agency. Tractor Supply also agreed to implement broad remedial privacy measures and to have a corporate officer or director certify compliance with the settlement for the next four years. The CPPA noted the decision is the first to address the significance of CCPA privacy notices and job applicants’ privacy rights.
A Question of Temporal Scope
In its press release announcing the settlement, the CPPA indicated that it opened its investigation into the company after receiving a consumer complaint. Back in August, the CPPA went to court to enforce an investigative subpoena against Tractor Supply seeking information on the company’s compliance dating all the way back to January 1, 2020. In its subpoena enforcement action, the CPPA alleged that Tractor Supply resisted the five-year lookback as outside the scope of the CPPA’s enforcement authority (since the CPPA’s regulations implementing the California Consumer Privacy Act (CCPA) were not finalized until March 2023).
The settlement between the CPPA and Tractor Supply terminated that litigation and covers only the period from January 1, 2023, through July 1, 2024. Interestingly, the settlement requires Tractor Supply to acknowledge that the CPPA’s authority to investigate potential violations of the CCPA includes the period prior to January 1, 2023. Given the parties’ agreement to a temporal limitation on the conduct that favored Tractor Supply’s interpretation of the CPPA’s authority and the CPPA’s voluntary dismissal of its subpoena enforcement action, the CPPA appears to have been willing to compromise on this point to reach a resolution.
The (Alleged) Violations
The settlement alleges two broad categories of violations of Californians’ privacy rights by Tractor Supply: the handling of consumer requests to opt out of the sale/sharing of their personal data and the notifications to consumers (including job applicants) of their personal privacy rights.
Opt-out requests have been a regulatory priority for the CPPA in 2025. Earlier this year, the CPPA settled with American Honda Motor Co. and Todd Snyder Inc. over (among other things) those companies’ handling of consumer opt-out rights.
In settling with Tractor Supply over the handling of opt-out requests, the CPPA identified three types of violations:
- While Tractor Supply included a form on its website to allow a consumer to opt out of the sale of his or her personal information, the submission of that form did not interact with the third-party tracking technologies used by Tractor Supply for advertising and the form had no impact upon how the company shared consumers’ personal information.
- Until July 2024, Tractor Supply’s website did not process opt-out preference signals and the company did not explain in its privacy policy how opt-out preference signals would be processed (for example, if the signal applied to the device, browser, consumer account and/or offline sales).
- Tractor Supply did not include the necessary provisions required by the CCPA to protect consumer personal data in its contracts with third parties, service providers and contractors. (These provisions must identify the limited and specified purposes for which the personal information can be used, limit the recipient’s use of the personal information to the specified purposes, and require compliance with the CCPA, including that the third party must offer the same level of privacy protection as its principal.)
With respect to Tractor Supply’s privacy policy, the CPPA noted that it failed to provide the detailed disclosures required and failed to apprise consumers of their rights under the CCPA. These disclosures must include the categories of personal information the business collected in the preceding 12 months, the categories of sources from which the information was collected, and the specific business or other purpose for which the information was collected. The policy must also affirmatively state whether the business sold, shared or disclosed personal information over the preceding 12 months. The policy must identify the categories of recipients to whom personal information was sold, shared or disclosed and the specific business purpose behind that sharing. A company is required to update its privacy policy on an annual basis but allegedly Tractor Supply published its original privacy policy in September 2018, updated it in November 2021, and then had not updated it again until after it learned of the CPPA’s investigation.
Tractor Supply also allegedly failed to notify job applicants of their rights under the CCPA. The company had a pop-up disclosure in place for job applicants from California, but this disclosure did not provide job applicants with any detail regarding their CCPA rights or a description of how to exercise those rights.
The Settlement Terms
As aforementioned, the penalty levied on Tractor Supply is the largest obtained by the CPPA to date. In a departure from its past practices in the Honda and Todd Snyder settlements, the CPPA did not tie any of the $1.35 million fine to a specific number of violations or to its statutory authority, making it difficult to ascertain how the CPPA calculated this figure.
Also as noted above, Tractor Supply also agreed to detailed undertakings to bring it into compliance with the CCPA. These include modifying its existing practices, conducting a detailed inventory of its own tracking technologies, modifying the design of its website to address opt-out requests, and taking certain steps to notify affected consumers. Tractor Supply also agreed that it will provide the CPPA’s Enforcement Division with a written certification of compliance with the settlement for the next four years, along with certain additional reporting.
Lessons Learned
The CPPA’s latest settlement confirms that it continues to engage in granular investigations that delve into the design and operation of a company’s website and the accompanying structure of its consumer privacy program to determine if the company is actually operating in a manner that complies with the CCPA. Privacy programs must therefore be implemented in a holistic fashion where the different pieces (such as opt-out forms) handshake with other aspects of the company’s web presence (such as its analytics) and also reach into the company’s contractual relationships and information-sharing practices. This puts further emphasis on the importance of building good privacy hygiene into a company’s products and operations from their inception, rather than attempting to bolt it on later in the life cycle.
This enforcement action demonstrates that the handling of the rights of an individual consumer can lead to an investigation. There is a much larger community of privacy enthusiasts out there who will take heart from the story the CPPA tells in this settlement. The investigation that led to the settlement was based on a complaint from a single consumer. This story will certainly encourage amateur (and professional) students of privacy rights to look for additional problems for the CPPA to investigate. And while the CPPA found itself facing some resistance with respect to the temporal scope of its enforcement authority, it still harvested the most significant settlement in its history from the fertile fields of Tractor Supply’s own privacy program.