Disney Plus Privacy Class Action Claims Streaming Data Was Disclosed to Third Parties

Disney faced $12M in privacy penalties for sharing viewer data and failing opt-out requests.

Disney Plus faced significant privacy enforcement actions related to data disclosure to third parties, resulting in substantial regulatory penalties totaling over $12 million. Between September 2025 and February 2026, the Federal Trade Commission and California Attorney General brought enforcement actions against Disney Entertainment Operations, alleging the company unlawfully collected and shared user data—including device identifiers, IP addresses, and viewing history—with advertising technology partners without proper consent or effective opt-out mechanisms. Specifically, the FTC charged Disney with violating children’s privacy laws by mislabeling YouTube videos to enable data collection from children under 13, while California regulators found that Disney’s streaming services failed to honor consumers’ requests to stop the sale and sharing of their personal information across Disney+, Hulu, and ESPN+.

These actions represent the largest privacy enforcement efforts against a streaming platform to date. The $2.75 million California settlement marked the largest civil penalty ever imposed under the California Consumer Privacy Act (CCPA), underscoring the severity of Disney’s compliance failures. Unlike traditional class action lawsuits where individual consumers seek damages, these were government enforcement proceedings that required Disney to fundamentally restructure how it handles user data and obtains consent for data sharing.

Table of Contents

What Personal Data Did Disney Collect and Share?

Disney collected extensive personal information from subscribers across its streaming services without consistent disclosure of how that data would be used. The CCPA settlement revealed that Disney shared device identifiers, device types, IP addresses, and detailed video-viewing histories with third-party advertising technology companies. This data sharing occurred across Disney+, Hulu, and ESPN+, with advertising partners embedding tracking code directly into Disney’s websites and mobile applications to monitor user behavior both on and off Disney platforms. For children’s content, the FTC enforcement action (Case No.

2:25-cv-08223) documented that Disney collected personal data from children under 13 who watched videos that should have been labeled as “Made for Kids,” then used that data for targeted advertising without parental consent—a direct violation of the Children’s online privacy Protection Rule (COPPA Rule). The scope of third-party sharing extended beyond simple analytics. Disney shared viewing behavior with external advertising platforms, social media companies, and ad networks that used the data to build consumer profiles and deliver targeted advertisements. For example, if a Disney+ subscriber watched family content, that viewing history could be transmitted to ad tech partners who would then follow that user across the internet, serving advertisements on unrelated websites. This practice violated California law because Disney’s opt-out mechanisms did not actually stop the sharing with these external partners—they only prevented Disney from using the data on its own advertising platform.

Disney’s privacy controls appeared comprehensive on the surface but failed in execution, according to the California Attorney General’s investigation. The company’s opt-out webforms allowed users to request that Disney stop selling or sharing their data, but these forms only disabled data use within Disney’s own advertising system. They did not prevent Disney from continuing to share personal information with third-party ad-tech vendors, meaning subscribers who believed they had opted out were still being tracked and profiled by external advertising companies. This represented a fundamental violation of the CCPA’s requirement that companies honor consumer opt-out requests in a meaningful way.

The implementation was further fragmented across devices and services. Opt-out toggles worked inconsistently—a user might successfully opt out on their web browser but remain tracked on the ESPN+ app or a connected TV device. Global Privacy Control (GPC) signals, which are standardized privacy settings that users can enable to signal their opt-out preference across all websites and apps, were recognized by Disney on some services but not others. Connected TV environments such as Roku and Amazon Fire TV devices lacked any in-app opt-out functionality whatsoever, leaving consumers on those platforms with no way to stop data sharing. This inconsistency meant that a household subscribing to Disney+ on multiple devices would need to manually submit separate opt-out requests across different platforms, a burden that most consumers either did not understand or could not practically manage.

Disney Privacy Enforcement Settlements by AgencyFTC/COPPA Children’s Privacy$10000000California CCPA Data Sharing$2750000Combined Total Penalties$12750000Source: Federal Trade Commission, California Attorney General (2025-2026)

Children’s Privacy Violations and YouTube Data Collection

The FTC’s COPPA enforcement action documented a specific and troubling failure: Disney systematically mislabeled videos on YouTube as “Not Made for Kids” when they should have been designated as “Made for Kids.” This mislabeling was significant because YouTube’s algorithm uses these labels to determine whether to collect personal data from viewers and serve targeted advertising. By marking child-directed content as general content, Disney enabled YouTube’s data collection systems to gather personal information from millions of children under 13, then Disney used that data for behavioral targeting. The FTC and Department of Justice complaint, filed in September 2025 and approved in December 2025, resulted in a $10 million civil penalty.

The data collected from child viewers included device identifiers, device types, and IP addresses—technical identifiers that allow advertisers to build persistent profiles of individual users. This is particularly harmful for children because their viewing patterns reveal interests, needs, and vulnerabilities that can be exploited for commercial purposes. A child who watches videos about anxiety management, dietary restrictions, or medical conditions could be identified and targeted with products that exploit those vulnerabilities. The settlement required Disney to implement a comprehensive review process to ensure videos are correctly labeled and to obtain verifiable parental consent before collecting any personal data from children under 13.

Settlement Amounts and Regulatory Accountability

The penalties imposed on Disney reflected the severity and scope of the violations. California’s $2.75 million CCPA settlement was not only the largest single penalty under that law but represented a dramatic escalation in regulatory enforcement against tech and streaming companies. The $10 million FTC/DOJ COPPA settlement added another significant penalty for the children’s privacy violations. Combined, these settlements exceeded $12 million, making Disney one of the most heavily penalized streaming services for privacy violations. These amounts are meaningful but not proportional to Disney’s revenue—the company’s annual streaming revenue exceeds $50 billion—which raises questions about whether monetary penalties alone deter privacy violations or whether structural remedies are necessary.

The regulatory agencies involved—the Federal Trade Commission, the U.S. Department of Justice, and the California Attorney General—coordinated their enforcement efforts to address different aspects of Disney’s violations. This multi-agency approach highlighted how privacy violations cut across both federal and state legal frameworks. The FTC focused on children’s protections under COPPA, while California enforced its state privacy law protecting all consumers. The coordination also signaled to other tech companies that privacy violations would face scrutiny from multiple regulators simultaneously, increasing the likelihood of comprehensive enforcement action.

Why Opt-Out Failures Matter More Than Data Collection Itself

While the collection of viewing data is routine in the digital advertising industry, the legal violations centered on Disney’s failure to honor opt-out requests and its deception about what opt-out actually prevented. The CCPA grants California consumers the right to direct companies to stop selling or sharing their personal information, yet Disney’s opt-out mechanism did not achieve this result. This violated not just the letter of the law but its fundamental purpose: empowering consumers to control their personal information. A consumer who checked Disney’s privacy settings and clicked “do not sell my data” believed they had exercised control over their information, when in fact Disney continued to share that data with advertising partners.

The warning embedded in these settlements is that companies cannot satisfy privacy laws with cosmetic compliance gestures—privacy controls that provide the appearance of user choice without actual effect. Regulators are now scrutinizing the functional effectiveness of opt-out systems, not just their existence. Companies that implement opt-outs narrowly (applying only to first-party advertising, not third-party sharing), inconsistently (working on web but not mobile or TV), or ineffectively (continuing to share data despite user requests) face significant legal liability. For consumers, the takeaway is that the presence of privacy settings does not guarantee privacy protection; the real test is whether those settings actually change how companies handle data.

The Streaming Services Privacy Enforcement Trend

Disney was not the only streaming service facing privacy enforcement in 2025-2026. The California Attorney General’s investigation that led to Disney’s settlement was part of a broader sweep of streaming companies examining CCPA compliance. This reflects an increasing regulatory focus on the streaming and streaming advertising sectors, where data collection and targeting are central to business models.

The enforcement actions signal that regulators have shifted from issuing guidance to issuing penalties, and that streaming services cannot rely on vague privacy policies or ineffective consent mechanisms. Other streaming platforms have also faced enforcement for similar violations: Amazon Prime Video, Netflix, and smaller streaming services received scrutiny during the same period for opt-out and data-sharing practices. The cumulative effect is an emerging standard in streaming privacy: companies must implement account-wide opt-out controls that are honored across all services and devices, provide meaningful parental consent for children’s data, and cease sharing personal data when consumers exercise opt-out rights. Companies that fail to meet this standard now face multimillion-dollar penalties and court-ordered structural remedies.

What Consumers Should Know About Their Disney+ Data

For Disney+ subscribers, the settlements resulted in concrete, enforceable changes. Disney must now establish a program to correctly label videos as “Made for Kids” on YouTube, implement a parental consent system for children’s data collection, and redesign its opt-out mechanisms to actually stop third-party data sharing across all devices. However, these remedies apply prospectively—they do not address the years of data that was already collected and shared from past subscribers. Consumers who subscribed to Disney+ before the settlements have no mechanism to request deletion of historical viewing data or to receive compensation for past privacy violations.

The settlements also reveal the difference between regulatory enforcement (government-initiated) and class action litigation (consumer-initiated). While the FTC and California Attorney General had power to impose penalties and order business practice changes, individual consumers did not have a private right to sue Disney for statutory damages under these specific federal and state laws. This highlights a gap in consumer protection: government settlements focus on future compliance and deterrence, not on compensating individuals for past harm. Consumers harmed by Disney’s privacy practices cannot recover damages through the regulatory settlements; their only potential remedy would be a separate private class action lawsuit, which would require proving material injury, establishing legal liability, and overcoming Disney’s defenses—a far more difficult legal path than regulatory enforcement.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase: