Regulations

CCPA Basics in 2026: Rights, Scope, and the Rules Businesses Still Miss

DataShyre Staff
DataShyre Staff Jul 14, 2026
5 min read

CCPA Basics in 2026: Rights, Scope, and the Rules Businesses Still Miss

Most people searching for ccpa basics are not looking for legislative history. They want the working version: who the law covers, what Californians can ask for, and where companies still trip over the same operational mistakes.

The short answer is that the CCPA, as amended by the CPRA, is still California’s main consumer privacy law. It gives residents the right to know, delete, correct, opt out of the sale or sharing of personal information, and limit certain uses of sensitive personal information. For businesses, the basics are no longer just about publishing a privacy policy. They are about making those rights work across websites, apps, ad tech, vendors, and internal workflows.

If you need the scope question in more detail, start with our guide to CCPA who does it apply to. If your next question is website implementation, our CCPA cookie consent guide covers the banner and opt-out side. This article stays at the foundation level.

Editorial illustration showing California privacy controls, opt-out handling, and subtle DataShyre.com branding

CCPA basics: what the law covers

The California Attorney General and the CPPA both make the same important point: CPRA did not create a separate law. It amended the CCPA. That is why most current official guidance still refers to the framework as the CCPA, or the CCPA as amended.

For a business reader, the first practical question is coverage. In general, the law applies to for-profit businesses that do business in California and meet at least one threshold:

  • annual gross revenue of $26.625 million or more
  • buying, selling, or sharing the personal information of 100,000 or more California residents or households
  • deriving 50% or more of annual revenue from selling or sharing California residents’ personal information

That means a company can be well below enterprise scale and still fall inside the law because of audience size, ad-tech behavior, or data monetization. It also means the old habit of treating privacy as a footer-only problem is too small for what California expects now.

The rights businesses need to operationalize

The consumer-rights list is straightforward on paper. Californians can ask to know what data a business has collected, ask to delete it, correct inaccurate information, opt out of sale or sharing, and limit certain uses of sensitive personal information. They also have protection against discrimination for exercising those rights.

The difficult part is not memorizing that list. The difficult part is turning those rights into working flows. A valid request has to reach the right systems, the right vendors, and the right teams quickly enough to meet statutory deadlines. That is why ccpa basics now means process design as much as policy language.

California’s opt-out rules are a good example. The Department of Justice says businesses that sell or share personal information must offer at least two methods for submitting opt-out requests, and for businesses that collect personal information online, one acceptable method is a user-enabled Global Privacy Control signal. In other words, a business cannot treat browser-level privacy signals as a nice-to-have.

What changed in 2026

The updated CCPA regulations became effective on January 1, 2026. Phil Laird, the CPPA’s general counsel, said the new package would “provide clarity for businesses.” That is true, but there is an important nuance: not every new duty hits on the same day.

The core regulation updates are already in effect. Risk-assessment obligations began in 2026 for covered activities, while ADMT-specific compliance begins on January 1, 2027. Cybersecurity-audit certification deadlines are phased by revenue tier starting in 2028. The result is a more layered compliance calendar than many teams realize when they hear “new 2026 rules.”

There is also a major data-broker milestone ahead. Under the Delete Act, beginning August 1, 2026, registered data brokers must access California’s Delete Request and Opt-out Platform at least once every 45 days and process deletion requests routed through it. That deadline does not affect every business directly, but it matters to teams that buy from, sell to, or operate as data brokers.

Where the basics still break

Recent enforcement makes the pattern clear. The state is focusing on whether rights actually work, not whether a company can point to a policy page and a vendor contract.

In March 2025, the CPPA said Honda required excessive information for some privacy requests, used an interface that did not present privacy choices symmetrically, and shared personal information with ad-tech companies without the required contract terms. In May 2025, the agency said Todd Snyder failed to process some opt-out requests properly and required more information than necessary from consumers. Michael Macko put the vendor point plainly: “Using a consent management platform doesn’t get you off the hook for compliance.”

The California Attorney General added another current warning in January 2026 when his office launched a surveillance-pricing sweep. Rob Bonta said consumers have “the right to understand how their personal information is being used.” That is broader than a cookie-banner issue. It reaches how pricing, personalization, and downstream use of data line up with what consumers were told to expect.

Editorial workflow visual showing notice, consumer choice, rights handling, and audit proof with subtle DataShyre.com branding

A simple business checklist

If you are trying to turn ccpa basics into an actual work plan, start here:

  1. Recheck whether the business meets a revenue, data-volume, or sale/share threshold.
  2. Confirm your notice at collection still matches what each product, form, and tool actually gathers.
  3. Test opt-outs in logged-in and logged-out states, including Global Privacy Control handling where applicable.
  4. Make sure request intake routes to the systems and vendors that hold the data, not just to a support inbox.
  5. Review whether any 2026, 2027, or later phased obligations apply to your use of risk assessments, ADMT, or cybersecurity audits.

That is the real dividing line between surface compliance and a privacy program that can survive a regulator’s second question.

Bottom line

The cleanest way to think about the law in 2026 is this: know whether you are in scope, know which rights Californians can exercise, and know how those rights are supposed to work in practice. Everything else flows from that.

Businesses usually get into trouble when they assume the basics are already solved. In California, the basics are exactly where regulators keep looking.

Sources

  • California Privacy Protection Agency FAQ
  • California Privacy Protection Agency regulations page
  • California Privacy Protection Agency 2025 rulemaking announcement
  • California Privacy Protection Agency data brokers page
  • California Privacy Protection Agency Honda enforcement announcement
  • California Privacy Protection Agency Todd Snyder enforcement announcement
  • California Department of Justice CCPA page
  • California Department of Justice Global Privacy Control page
  • California Department of Justice surveillance pricing announcement
DataShyre Platform

Ready to fix your privacy program?

Join 3,500+ businesses using DataShyre to automate consent management, DSR fulfillment, and compliance — without the complexity.