Close Menu
    What's Hot

    OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign

    September 28, 2026

    Viral “Rent A Garba Partner” Post Raises Cybersecurity Questions Amid Navratri Scam Warnings

    September 19, 2026

    Azure AI Foundry Vulnerability: CVSS 10.0

    September 18, 2026

    T-Mobile Rewards Phishing: Fake Expiry Scam Texts

    September 18, 2026

    Docker Sandboxes Vulnerabilities: Critical Flaws

    September 17, 2026
    Facebook X (Twitter) Instagram
    Monday, September 28
    CyberNexora News
    X (Twitter) Instagram LinkedIn
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us
    Get Cyber Alerts
    CyberNexora News
    Home»Penalties»GoFan Fined $1.1 Million by California for Selling High School Students’ Data

    GoFan Fined $1.1 Million by California for Selling High School Students’ Data

    Zeel_CyberexpertBy Zeel_CyberexpertMarch 7, 20263 Mins Read
    Facebook Twitter LinkedIn Email Telegram

    The California Privacy Protection Agency has fined the digital ticketing platform GoFan $1.1 million for violating state privacy laws after the service collected and sold personal data from high school students using the platform to attend school events.

    GoFan, operated by PlayOn Sports, is widely used by schools to sell digital tickets for events such as football games, theater performances, and school prom. Students and parents typically use the platform to purchase and display digital tickets for entry to these events.

    Privacy Violations

    According to regulators, GoFan required users to accept certain conditions before they could complete their ticket purchases. These conditions allowed the company to collect users’ personal information and share it with advertising partners.

    Users were prompted to click an “agree” button that authorized the collection and commercial use of their data. The system did not provide users with an option to refuse tracking or opt out of the data-sharing process.

    The regulator concluded that this approach violated the California Privacy Protection Act, which grants residents the right to know when their personal information is collected and allows them to prevent companies from selling that data.

    Findings From the Investigation

    The enforcement order stated that GoFan’s practices led to repeated violations of California privacy law during 2023 and 2024. Regulators also found that the company’s privacy policy contained inaccurate statements.

    According to the order, the company claimed in its privacy policy that it did not sell users’ personal information. Investigators determined that this statement was incorrect.

    The policy also failed to clearly inform users about their right to opt out of having their data sold and was not updated regularly as required under state law.

    The California Privacy Protection Agency began investigating the company in 2024 after receiving complaints from users about the platform’s data-collection practices.

    Regulatory Action

    As part of the enforcement action, regulators ordered the company to pay a $1.1 million penalty and update its privacy practices to comply with California law.

    Under the settlement, the company must ensure that users are given proper mechanisms to opt out of the sale or sharing of their personal data. The platform must also improve transparency in its privacy disclosures and ensure compliance with data-protection requirements.

    Company Response

    In a statement, PlayOn Sports said it takes the privacy and safety of students and school communities seriously.

    The company said the regulator’s inquiry focused on certain privacy practices that existed before December 2024 and stated that those issues have since been addressed. PlayOn also said it cooperated with authorities during the investigation and implemented changes to resolve the concerns raised by regulators.

    Platform Reach

    According to the enforcement order, the GoFan platform has sold more than 30 million tickets to high school events across the United States. The company also maintains contracts with approximately 1,400 schools in California.

    Related Articles

  • Illuminate Education Data Breach 2026: FTC Finalizes Settlement Introduction: Illuminate Education Data Breach 2026 — Why It Matters...
  • Uber Fined €290 Million for Data Transfer Violations – A Major Cybersecurity and Privacy Case Study (2024) In one of the most significant recent enforcement actions in...
  • GDPR Compliance in 2026: 7 Rules, Penalties & Why Every Website Needs It Introduction GDPR compliance has become mandatory for every website in...
  • Temu Fine EU 2026: European Commission Imposes €200 Million Penalty Over Digital Services Act Violations Introduction The Temu Fine EU announcement has become one of...
  • Instagram Instants Privacy Concerns: What Users Should Know About Meta’s New Feature Instagram has officially started rolling out its new “Instants” feature,...
  • Share. Facebook Twitter LinkedIn Email Telegram

    latest news

    OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign

    September 28, 2026

    Viral “Rent A Garba Partner” Post Raises Cybersecurity Questions Amid Navratri Scam Warnings

    September 19, 2026

    Azure AI Foundry Vulnerability: CVSS 10.0

    September 18, 2026

    T-Mobile Rewards Phishing: Fake Expiry Scam Texts

    September 18, 2026

    Docker Sandboxes Vulnerabilities: Critical Flaws

    September 17, 2026

    HEAVYGRAM Malware: Telegram Surveillance Backdoor

    September 17, 2026

    SparroWocky Backdoor: FamousSparrow Targets Governments

    September 17, 2026

    CenterPoint Energy Data Breach: Customer Data Exposed

    September 16, 2026

    BambooToken Malware: Critical MQTT C2 Campaign

    September 16, 2026

    WordPress Plugin Attacks: Critical RCE Flaws Exposed

    September 16, 2026
    Recent Posts
    • OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign
    • Viral “Rent A Garba Partner” Post Raises Cybersecurity Questions Amid Navratri Scam Warnings
    • Azure AI Foundry Vulnerability: CVSS 10.0
    Top Posts

    OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign

    September 28, 2026

    Unauthorized Access Incident at Coupang Exposes Customer Data

    December 29, 2025

    Significant Data Breach at Korean Air Subcontractor Exposes Employee Records

    December 29, 2025
    About

    CyberNexora Blog provides trusted cybersecurity news, attack analysis, and security awareness updates. Our goal is to educate and inform readers about emerging cyber threats and best protection practices.

    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Pages
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us

    Get Cyber Security Alerts

    Thanks! Please check your email to confirm subscription.

    • About CyberNexora News
    • Privacy Policy
    © 2026 CyberNexora News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.