California Consumer Privacy: 2026 CCPA/CPRA Compliance Guide
Introduction
As of January 1, 2026, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), entered its most significant enforcement phase yet. The California Privacy Protection Agency (CPPA) has issued final regulations that took effect this year, expanding obligations for businesses and ramping up enforcement actions. This guide covers what “California consumer privacy” compliance looks like in 2026, with practical steps for covered businesses.

Key 2026 Regulatory Changes
Mandatory Privacy Risk Assessments
Businesses must now conduct detailed risk assessments for processing activities that present a “significant risk” to consumers, including:
- Processing sensitive personal information (SPI)
- Selling or sharing personal information
- Using Automated Decision-Making Technology (ADMT) for significant decisions
Assessments for activities beginning before January 1, 2026 must be completed by December 31, 2027. Annual summary reports are due to the CPPA starting April 1, 2028.
“The CPPA’s enforcement division will continue using all the tools at its disposal to protect Californians’ privacy, including publishing advisories to help stop violations from happening in the first place.” — Michael Macko, CPPA Enforcement Division Head
Mandatory Cybersecurity Audits
Annual cybersecurity audits are now required for businesses whose processing presents “significant risk.” Deadlines are phased by revenue:
| Revenue Tier | First Audit Due | |————–|—————–| | Over $100M (2026) | April 1, 2028 | | $50M–$100M (2027) | April 1, 2029 | | Under $50M (2028) | April 1, 2030 |
ADMT & Automated Decision-Making Rules
Effective January 1, 2026, businesses using ADMT for “significant decisions” (employment, credit, healthcare, insurance) must:
- Provide pre-use notice to consumers
- Allow opt-out of ADMT processing
- Enable access to information about the logic and outcomes
Existing ADMT uses must comply by January 1, 2027.

Expanded Sensitive Personal Information Definition
The SPI definition now includes:
- Neural data (new for 2026)
- Data from consumers under 16 (where business has actual knowledge of age)
Dark Pattern Restrictions
Regulations explicitly prohibit dark patterns — interface designs that manipulate users into less privacy-protective choices (e.g., making “Accept All” more prominent than “Decline”). These rules became fully effective January 1, 2026.
Global Privacy Control (GPC) Enforcement
Businesses must automatically recognize GPC browser signals as valid opt-out requests for sale/sharing of personal information. This preference must apply across a consumer’s entire relationship with the business — not just the device where the signal originated.
Early 2026 enforcement actions have targeted failures to honor GPC signals. The CPPA voted in August 2026 to name GPC explicitly in CCPA regulations.
Delete Request and Opt-Out Platform (DROP)
Launched January 2026, DROP is a centralized system for California residents to delete personal information held by data brokers. Data brokers must access DROP every 45 days starting August 1, 2026 to process deletion requests.
2026 Enforcement Actions (Notable Cases)
| Company | Date | Penalty | Violation | |———|——|———|———–| | Disney DTC / ABC | Feb 2026 | $2.75M | Opt-out not applied account-wide; GPC ignored | | PlayOn Sports | Mar 2026 | $1.10M | No effective opt-out; GPC not honored; dark patterns | | Ford Motor Co. | Mar 2026 | — | Unnecessary verification steps for opt-out | | Rickenbacher Data | Jan 2026 | $45K | Unregistered data broker; sold sensitive health data | | LocateSmarter | Aug 2026 | $116,490 | Unregistered broker; required partial SSN for opt-out | | Cybba, Inc. | Aug 2026 | $52,400 | Unregistered data broker | | General Motors | Sep 2026 | $12.75M | Connected vehicle data sharing practices | | Tractor Supply | 2026 | $1.35M | Opt-out failures; inadequate notices | | Todd Snyder, Inc. | 2026 | $345,178 | CCPA violations including opt-out failures |
The Disney settlement established a critical precedent: “Partial compliance is non-compliance.” Opt-outs must work uniformly across every device and service, and honor GPC signals.
Compliance Checklist for 2026
Immediate Actions (Q1–Q2 2026)
- [ ] Conduct privacy risk assessments for SPI, sale/sharing, and ADMT
- [ ] Implement GPC signal recognition across all properties
- [ ] Audit cookie banners and consent interfaces for dark patterns
- [ ] Update privacy policies with required SPI categories and ADMT disclosures
- [ ] Add visible opt-out confirmation messages (“Opt-Out Request Honored”)
- [ ] Remove unnecessary verification steps for opt-out requests
- [ ] Ensure opt-out applies account-wide, not per-device
Near-Term (Q3–Q4 2026)
- [ ] Complete ADMT compliance for existing uses (deadline: Jan 1, 2027)
- [ ] Register as data broker if applicable; begin DROP access every 45 days
- [ ] Prepare for cybersecurity audit planning based on revenue tier
- [ ] Train vendors/contractors on CCPA/CPRA obligations
Ongoing
- [ ] Annual privacy risk assessment reviews
- [ ] Annual cybersecurity audits (per revenue tier schedule)
- [ ] Monitor CPPA advisories and enforcement trends
- [ ] Re-verify consent cannot be re-requested within 6 months for same purpose
Internal Links
- GDPR vs. CCPA/CPRA 2026: Complete Compliance Comparison Guide
- California Privacy Law: Delete Data Requirements
- California Web Privacy Law Updates
Conclusion
The 2026 CCPA/CPRA landscape demands a shift from documentation-based compliance to operational, verifiable privacy programs. With the CPPA’s aggressive enforcement posture — $2.75M to $12.75M penalties for opt-out and GPC failures — businesses must prioritize:
- Account-wide opt-out mechanics that honor GPC
- Risk assessments and cybersecurity audits on regulatory timelines
- ADMT transparency and opt-out before the 2027 deadline
- Dark pattern elimination from all consent interfaces
California consumer privacy compliance in 2026 is no longer about posting a privacy policy — it’s about building privacy into the architecture of every data flow.
—
Published: September 29, 2026 Primary Keyword: california consumer privacy