California Consumer Privacy in 2026: 7 Live Checks for Rights, GPC, and Data Broker Risk
If you are reviewing california consumer privacy on August 26, 2026, the useful question is not whether your site has a privacy footer.
It is whether your notices, opt-outs, account logic, vendor controls, and deletion workflows still behave the way California now expects them to.
That is the right frame because the live baseline moved again this year. The CPPA’s regulations page shows both the California Consumer Privacy Act and the CCPA Regulations as effective on January 1, 2026. The statute now posted by the CPPA also makes some practical points harder to ignore: notice at collection must cover categories, purposes, whether data is sold or shared, and retention timing or criteria; collection, use, retention, and sharing must be reasonably necessary and proportionate; and businesses need contracts that impose CCPA-level obligations on service providers, contractors, and third parties.
California enforcement has kept the pressure on the operational side too. On January 27, 2026, Attorney General Rob Bonta announced a sweep focused on surveillance pricing and tied it to the CCPA’s purpose-limitation principle. On February 11, 2026, California announced its Disney settlement and said opt-out methods must fully stop sale or sharing across the account-linked experience. On January 8, 2026, the CPPA announced new data-broker enforcement actions. And on August 1, 2026, the Delete Act’s next live deadline arrived: data brokers must now access DROP at least every 45 days to retrieve and process consumer deletion requests.
If you want the adjacent consent layer first, start with our guides to CCPA consent requirements, GDPR vs. CCPA, and consent management provider. This article is broader. It is the seven-part live review I would run before saying a california consumer privacy program is in good shape this week.

Why this is now an operations test
California’s public materials no longer support a shallow, policy-only review.
The DOJ’s consumer guidance still lays out the core rights plainly: Californians can request access, deletion, correction, opt out of sale or sharing, and limit certain uses or disclosures of sensitive personal information. The DOJ also still says that businesses collecting personal information online must honor a valid Global Privacy Control signal as an opt-out request to stop sale or sharing.
That sounds straightforward until a real stack gets involved. A website may expose an opt-out link, while an app still has no working path. A browser signal may be recognized on the current device, while account-linked data sharing continues elsewhere. A privacy notice may describe broad categories, while actual retention and downstream vendor use have drifted. California consumer privacy breaks most often in those handoffs.
1. Recheck notice at collection against what the system actually does
The current CPPA-posted statute is a good starting point because it forces specificity.
At or before the point of collection, the notice must identify the categories of personal information to be collected, the purposes for which those categories are collected or used, whether the information is sold or shared, and the length of time the business intends to retain each category or the criteria used to determine that period.
That means california consumer privacy is not satisfied by a generic privacy-policy paragraph copied forward from last year. A useful review asks:
- What categories are we collecting now?
- What are the actual purposes in production?
- Is any data sold or shared?
- Do our retention statements still match reality?
- Are we using the data in ways consumers would reasonably expect?
That last question matters more after the January 27, 2026 surveillance-pricing sweep. The Attorney General explicitly tied individualized pricing uses to the CCPA’s purpose-limitation principle. If a business is using data for a pricing, profiling, or targeting use the consumer would not reasonably expect, the disclosure problem is usually broader than the homepage footer.
2. Treat GPC as a real product input, not a privacy-page ornament
The DOJ’s GPC page still describes the signal as a:
“stop selling or sharing my data switch.”
That should be read as a product and engineering requirement, not just a legal talking point.
For businesses collecting personal information online, California says a valid user-enabled GPC signal must be honored as a request to stop sale or sharing. So a serious california consumer privacy check should test:
- where the signal is detected;
- which systems receive it;
- whether advertising, measurement, or sharing logic changes fast enough;
- whether the request is remembered when the user logs in or moves between surfaces;
- what evidence remains that the request was honored.
If your current answer is “the CMP says it supports GPC,” that is not a complete answer yet.
3. Make opt-outs work across account-linked surfaces
The Disney settlement is the clearest live reminder here.
California said Disney failed to fully effectuate consumers’ opt-out requests across devices and streaming services associated with the consumer’s account. The state said some opt-out methods only applied to the specific service or device in use, while sale or sharing could continue elsewhere in the connected experience.
That changes how I would audit california consumer privacy this week. I would not stop at the browser or app where the user clicked a toggle. I would ask whether the opt-out follows the account relationship wherever the business sells or shares the same consumer’s data.
This is especially important for companies with:
- a website plus mobile apps;
- several logged-in products under one account;
- advertising or analytics vendors receiving events from more than one surface;
- customer profiles stitched across devices.
When those links exist, a single-page opt-out flow is rarely enough by itself.
4. Remove friction from rights requests before California removes it for you
Recent California enforcement has been unusually practical on this point.
In May 2025, the CPPA said Todd Snyder failed to process opt-out requests for 40 days because of misconfigured privacy-portal infrastructure, required consumers to submit more information than necessary, and required identity verification before consumers could opt out of sale or sharing. That is a strong warning because these are not exotic failures. They are the kinds of implementation mistakes many teams quietly accept as normal.
The DOJ’s consumer guidance also says businesses should not require consumers to create an account to submit an opt-out request and generally should not require identity verification to process it. If the path is broken, hidden, over-verified, or routed through too many screens, the program is already weaker than it looks.
5. Pull vendors and contracts into the same review
A rights flow that stops inside your own UI is not enough.
The current CPPA-posted statute says that if a business sells personal information to a third party or discloses it to a service provider or contractor for a business purpose, the business must have an agreement that limits use to specified purposes, requires the recipient to provide the same level of privacy protection required by the CCPA, requires notice if the recipient can no longer comply, and gives the business rights to stop and remediate unauthorized use.
That contract language matters, but runtime behavior matters just as much. For a live california consumer privacy review, I would trace:
- which vendors receive personal information;
- whether each relationship is classified correctly;
- which disclosures stop after an opt-out;
- which disclosures continue for a permitted business purpose;
- what the business can do if the recipient falls out of compliance.
This is where many programs discover that the website looked compliant while a downstream audience sync, SDK, or partner feed kept operating as if nothing had changed.

6. Separate minors and sensitive personal information from the general flow
California keeps making these branches impossible to treat as footnotes.
The DOJ’s CCPA guidance says businesses can sell or share the personal information of a consumer under 16 only with the required affirmative opt-in authorization. For children under 13, that opt-in must come from a parent or guardian. For consumers at least 13 but under 16, the opt-in can come from the young person. The November 21, 2025 Jam City settlement also required in-app opt-out methods and said the company must not sell or share the personal information of consumers at least 13 and less than 16 years old without affirmative opt-in consent.
California also preserves a separate right to limit certain uses or disclosures of sensitive personal information. So if your business handles location, health-related data, financial information, precise identifiers, or similar high-risk categories, do not assume the general privacy flow covers everything you need.
Bonta described the mobile-app rights flow in Jam City as something that should be:
“simple, transparent, and easy to navigate.”
That standard is worth applying well beyond gaming apps.
7. If you are anywhere near data-broker territory, operationalize DROP now
This is the most date-sensitive California branch in the stack right now.
The CPPA’s data-broker materials say California residents have been able to use DROP since January 1, 2026 to submit deletion requests to active data brokers, and that beginning August 1, 2026, data brokers must access the system at least every 45 days and process consumer deletion requests, subject to limited exceptions. The CPPA’s current information page also says data brokers must register through DROP and that the 2026 annual registration fee is $6,000 plus a processing fee.
Even if your company does not think of itself as a classic data broker, this should still trigger a scope check if you knowingly collect and sell personal information of consumers with whom you do not have a direct relationship. The CPPA’s public January 2026 enforcement announcement is a reminder that data-broker enforcement is not theoretical.
For this branch, I would ask:
- Do we meet the California definition anywhere in the business?
- Who owns DROP access and cadence?
- Can we process deletion requests within the current timing rules?
- Do our disclosures match what we actually buy, sell, or enrich?
- Have we checked whether any affiliate or business line created exposure we are ignoring?
A short review sequence for this week
If I were stress-testing a california consumer privacy program right now, I would do it in this order:
- Compare the notice at collection with the live data map and retention reality.
- Test GPC handling in a clean browser.
- Run one opt-out path in a logged-out state and one in a logged-in state.
- Check whether the request reaches all account-linked surfaces.
- Trace downstream vendor behavior after the opt-out.
- Inspect minors and sensitive-data branches separately.
- Confirm whether any data-broker or DROP workflow applies now.
That sequence usually finds more real defects than a long policy-only review.
Bottom line
California consumer privacy in 2026 is not mainly a writing project. It is a systems project.
If the notice is stale, if GPC is recognized but not propagated, if opt-outs stop at one device, if vendors keep receiving the same data, or if a hidden data-broker branch goes unmanaged after August 1, 2026, the program is more fragile than it appears.
The teams that look strongest this year are the ones that can show working rights, low-friction request paths, account-aware suppression, contract-backed vendor controls, and dated operational follow-through.
Sources
- California Privacy Protection Agency: Law & Regulations
- California Consumer Privacy Act of 2018 effective 01/01/2026 (CPPA PDF)
- California DOJ: California Consumer Privacy Act (CCPA)
- California DOJ: Global Privacy Control (GPC)
- California DOJ: On Data Privacy Day, Attorney General Bonta Focuses on Surveillance Pricing, Compliance with California Consumer Privacy Act
- California DOJ: California Won’t Let It Go: Attorney General Bonta Announces $2.75 Million Settlement with Disney
- California DOJ: Attorney General Bonta Secures $1.4 Million Settlement with Mobile App Gaming Company for Violating California’s Nation-Leading Privacy Law
- California Privacy Protection Agency: CPPA Orders Clothing Retailer Todd Snyder to Pay Six-Figure Fine, Overhaul Privacy Practices
- California Privacy Protection Agency: CalPrivacy Brings New Round of Enforcement Actions Against Data Brokers
- California Privacy Protection Agency: Delete Request and Opt-Out Platform (DROP)
This post was updated on August 26, 2026 using current official California regulator and government materials available at publication time.