19% of online shoppers abandoned checkout in the past three months specifically because they did not trust the site with their credit card information, according to Baymard Institute's Cart Abandonment Rate Statistics, last updated September 2025 from an aggregate of 50 separate studies. That distrust sits alongside slower-moving but larger problems: hundreds of confirmed retail data breaches a year and a wave of new CCPA fines aimed squarely at online stores. Below is what the checkout data, the breach data, and the enforcement record actually show.
Why do online shoppers abandon checkout over trust and data concerns?
Extra costs at checkout remain the single biggest reason shoppers walk away, at 40% of abandonment cases. Payment trust ranks third on Baymard's list, ahead of forced account creation (18%) and a checkout process that felt too long or complicated (17%), and behind only extra costs and a slow delivery window (20%).
That 19% figure has stayed remarkably stable across the studies Baymard aggregates, which suggests it is not a one-time reaction to a bad headline but a persistent baseline level of payment-page skepticism that e-commerce checkouts have to design around. Sites that display a clear, current privacy policy and visible payment-security signals at the point of card entry directly address the objection this statistic measures, since a generated privacy policy covering data handling and payment processors gives shoppers the disclosure Baymard's respondents said they were missing.
Figure: Top reasons online shoppers abandon checkout, ranked by share of respondents citing each reason (excluding the separate "just browsing" segment, which accounts for 42% of cart abandonment overall). Source: Baymard Institute, Cart Abandonment Rate Statistics, updated September 2025.
How many retail data breaches happen each year?
Verizon's 2025 Data Breach Investigations Report Retail Snapshot recorded 837 security incidents and 419 confirmed data breaches in the retail sector (NAICS 44-45) for the period from November 1, 2023, through October 31, 2024. Three attack patterns, System Intrusion, Social Engineering, and Basic Web Application Attacks, accounted for 93% of all confirmed retail breaches.
The data types attackers actually took skew away from the payment card numbers retailers spend the most on protecting. Internal data (business records, not customer-facing information) showed up in 65% of breaches, followed by an "other" category at 30%, login credentials at 26%, and payment data at just 12%.
Figure: Share of confirmed retail data breaches involving each data type, percentages do not sum to 100 because a single breach can expose more than one type. Source: Verizon 2025 Data Breach Investigations Report, Retail Snapshot (NAICS 44-45), incident window November 2023 to October 2024.
Verizon's own analysis calls this out directly: attackers who get access to a retail environment increasingly go after credentials and internal business data rather than payment card numbers, which the report attributes to payment data having become harder to reach after years of tokenization and PCI DSS hardening.
Who is behind retail data breaches?
External threat actors were responsible for 96% of confirmed retail data breaches, against 3% internal and 1% partner-involved, and every single one of those breaches in the sector was financially motivated. Espionage-motivated activity, still a minority factor, rose from a negligible 1% of retail incidents in the prior year's report to 9% in 2025, which Verizon attributes partly to a broader contributor base rather than a sudden shift in retail-specific targeting.
Figure: Threat actor origin in confirmed retail data breaches. Source: Verizon 2025 Data Breach Investigations Report, Retail Snapshot (NAICS 44-45).
For a category built almost entirely around outside attackers with a financial motive, the practical defense is the same one that shows up in small business privacy statistics: limiting what customer data gets collected and retained in the first place shrinks what an external attacker can take, regardless of how they got in.
What happens to online retailers that violate privacy law?
California's privacy regulator has now issued three of its highest-profile enforcement actions against retailers, and the fines have grown each time. The California Attorney General's 2022 settlement with Sephora, the first public CCPA enforcement decision, was $1.2 million over selling personal information without honoring opt-out signals. Three years later, the California Privacy Protection Agency fined clothing retailer Todd Snyder $345,178 in May 2025, then fined Tractor Supply Company $1.35 million in September 2025, its largest CCPA fine to date.
Tractor Supply's violations, per the CPPA's announcement, included failing to maintain a privacy policy that notified consumers of their CCPA rights, failing to provide an effective opt-out mechanism including opt-out preference signals, and disclosing personal information to other companies without the data-sharing contracts CCPA requires. All three of those failures are disclosure and consent-flow problems, not breach or hacking incidents, meaning they were avoidable with correct paperwork rather than better security tooling.
| Retailer | Year | Fine | Core violation |
|---|---|---|---|
| Sephora | 2022 | $1.2 million | Sold data without honoring opt-out signals |
| Todd Snyder | 2025 | $345,178 | Multiple CCPA compliance failures |
| Tractor Supply | 2025 | $1.35 million | No compliant privacy policy or opt-out mechanism |
The trend line matters as much as any single fine: three years separate the first CCPA enforcement decision from the largest one, and the amount has climbed each time a retailer has been the target rather than settling into a predictable flat penalty.
Figure: CCPA fines against retailers, in order issued. Sources: California Office of the Attorney General (Sephora, 2022), California Privacy Protection Agency (Todd Snyder and Tractor Supply, 2025).
Do shoppers trust e-commerce sites with their personal data?
Trust remains conditional, not absolute. Cisco's 2025 Data Privacy Benchmark Study, based on responses from 2,600 privacy and security professionals across 12 countries, found that 53% of consumers report being aware of their country's privacy laws, the first time that figure has crossed a majority since the study began in 2019, and awareness correlates directly with confidence: 81% of consumers who know their local privacy laws say they can protect their own data, against just 44% of those who do not.
Figure: Share of consumers who report being aware of their country's privacy laws, the first time this has crossed a majority since Cisco's study began in 2019. Source: Cisco 2025 Data Privacy Benchmark Study.
Qualtrics XM Institute's 2025 Global Consumer Study, surveying more than 23,000 consumers worldwide, found the same pattern from a different angle: comfort with data-driven personalization tracks closely with how much a shopper trusts a retailer's data practices in general, and that comfort level varies significantly by country. Neither study isolates e-commerce specifically, but both point to the same underlying mechanic driving Baymard's 19% checkout-abandonment figure: shoppers are not rejecting data collection outright, they are rejecting it from sites that have not earned the trust first.
The Bottom Line
E-commerce privacy in 2026 is less about a single catastrophic breach and more about accumulated friction: a fifth of shoppers walking away at checkout over unresolved trust, 419 confirmed retail breaches a year that mostly take credentials rather than card numbers, and CCPA fines against retailers that grew from $1.2 million to $1.35 million over three years, all triggered by paperwork failures rather than hacking. A current, accurate privacy policy addresses the checkout-abandonment statistic and the enforcement statistic at the same time, since the same disclosure gaps CPPA cited against Tractor Supply are what Baymard's respondents said they were missing at the point of card entry. Store owners who have not reviewed their privacy policy and opt-out mechanism since before 2025 are looking at exactly the gap regulators have been fining.
Frequently Asked Questions
What percentage of online shoppers abandon checkout over data trust? 19% of online shoppers abandoned a checkout in the past three months specifically because they did not trust the site with their credit card information, per Baymard Institute's Cart Abandonment Rate Statistics, updated September 2025 from an aggregate of 50 studies.
How many retail data breaches happen each year? Verizon's 2025 Data Breach Investigations Report Retail Snapshot recorded 837 security incidents and 419 confirmed data breaches in the retail sector (NAICS 44-45) for the period from November 2023 through October 2024.
What is the largest CCPA fine issued against a retailer? The California Privacy Protection Agency fined Tractor Supply Company $1.35 million in September 2025, its largest CCPA fine to date, for failing to post a compliant privacy policy, failing to provide an effective opt-out mechanism, and sharing personal information without CCPA-required contracts.
Who is responsible for most retail data breaches? External threat actors were responsible for 96% of confirmed retail data breaches in Verizon's 2025 Data Breach Investigations Report, compared to 3% internal and 1% partner-related, and 100% of breaches in the sector were financially motivated.
Where the Numbers Come From
- Baymard Institute. "Cart Abandonment Rate Statistics." Updated September 22, 2025. Average abandonment rate 70.22% aggregated from 50 studies; checkout abandonment reasons including 19% credit card trust.
- Verizon. (2025). "2025 Data Breach Investigations Report, Retail Snapshot." 837 incidents, 419 confirmed breaches, NAICS 44-45, incident window November 1, 2023 to October 31, 2024.
- California Privacy Protection Agency. (2025). Enforcement actions against Tractor Supply Company ($1.35 million, September 2025) and Todd Snyder, Inc. ($345,178, May 2025).
- California Office of the Attorney General. (2022). "Attorney General Bonta Announces Settlement with Sephora." $1.2 million settlement, first public CCPA enforcement decision, August 24, 2022.
- Cisco. (2025). "2025 Data Privacy Benchmark Study." 2,600 privacy and security professionals surveyed across 12 countries; 53% consumer awareness of local privacy laws.
- Qualtrics XM Institute. (2025). "Consumer Preferences for Privacy and Personalization." Global Consumer Study, over 23,000 consumers surveyed.
Note: All figures verified as of July 2026. Verizon's retail breach figures cover the report's November 2023 to October 2024 incident window, not calendar year 2025. CCPA fine figures are current as of their respective announcement dates and are not adjusted for any later appeal.