California Privacy Law
California Consumer Privacy Act / California Privacy Rights Act
Overview
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state privacy law in the United States. Originally enacted in 2018 and effective January 1, 2020, the CPRA amendments took effect on January 1, 2023, significantly expanding consumer rights and business obligations. California's law serves as the benchmark against which all other state privacy laws are measured.
The CCPA/CPRA grants California residents extensive rights over their personal information, including the right to know, delete, correct, and port their data, as well as the right to opt out of the sale or sharing of personal information. The law also created the California Privacy Protection Agency (CPPA, now branded as CalPrivacy), the first dedicated state privacy enforcement agency in the nation. Businesses must honor Global Privacy Control (GPC) signals as valid opt-out requests.
The CPPA has been actively issuing regulations since its creation. The most recent comprehensive regulation package — covering CCPA updates, insurance, cybersecurity audits, risk assessments, and automated decision-making technology (ADMT) — was adopted in September 2025 and took effect January 1, 2026. The agency is currently conducting preliminary rulemaking on data broker audits, reducing friction in privacy rights exercise, and opt-out preference signals (OOPS).
The law applies to for-profit businesses that collect California residents' personal information and meet one of three thresholds: annual gross revenue exceeding $25 million, buying/selling/sharing the personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Penalties can reach $7,988 per intentional violation (inflation-adjusted for 2026), and consumers have a private right of action for data breaches involving certain categories of unencrypted personal information.
What sets California apart from the other states with comprehensive privacy laws is the scope and depth of its regime. The CCPA/CPRA covers more entities (the $25 million revenue threshold is by far the lowest in the country), grants more rights (including correction, automated decision-making opt-out, and the right to limit use of sensitive personal information), and includes a private right of action for data breaches that no other state matches. California is also the only state where employee, job-applicant, contractor, and B2B contact data is fully covered by the comprehensive privacy law, after the HR and B2B exemptions sunset on December 31, 2022. Unlike Virginia, Colorado, or Connecticut, the CCPA has no cure period and is enforced by a dedicated agency with audit authority in addition to the Attorney General.
The most-misunderstood concept under California law is the distinction between "selling" and "sharing" personal information. The CCPA defines selling broadly as disclosing personal information to a third party for monetary or other valuable consideration. The CPRA added "sharing" as a separate category, defined as making personal information available to third parties for cross-context behavioral advertising — regardless of whether money changes hands. This means common ad-tech setups, including third-party cookies, tracking pixels, and pixel-based audience matching, can qualify as either a sale or a share even when the business does not see itself as selling data. CalPrivacy enforcement actions against Sephora, DoorDash, Disney, Ford, and General Motors have all hinged on the broad sale-or-share definition combined with deficient opt-out mechanisms, data minimization gaps, or undisclosed downstream data use.
In 2026, CalPrivacy's enforcement focus has shifted from notice-of-violation sweeps to systemic, well-funded investigations of opt-out friction, GPC processing, connected-vehicle data, and youth-data handling. The General Motors $12.75 million settlement in May 2026 is now the largest CCPA penalty in California history and the first major CCPA data-minimization case; Disney's $2.75 million opt-out settlement and PlayOn's $1.1 million student-privacy order show that multi-million-dollar fines are no longer unusual. Businesses operating in California in 2026 should treat the following as immediate priorities: automated GPC signal recognition and end-to-end opt-out propagation across all advertising and analytics partners; a data inventory that captures inferences, behavioral data, location data, and connected-device telemetry; risk assessments for any high-risk processing as defined in the September 2025 regulations; preparation for the cybersecurity audit requirement (first audit certifications due April 1, 2028 for businesses with $100 million or more in annual revenue); and an ADMT inventory in advance of the January 1, 2027 consumer opt-out deadline.
Applicability Thresholds
Conditions are joined by OR — meeting ANY one triggers applicability.
Consumer Rights
Key Changes in 2025-2026
- Updated CCPA text and new CCPA regulations (covering cybersecurity audits, risk assessments, and insurance) took effect January 1, 2026 — ADMT consumer opt-out rights have a separate compliance date of January 1, 2027
- Delete Act DROP platform launched January 1, 2026 — consumers can now submit one-stop deletion requests to all registered data brokers
- Data brokers must begin processing DROP deletion requests by August 1, 2026 (check every 45 days)
- CalPrivacy (formerly CPPA) launched Data Broker Enforcement Strike Force in November 2025, with new round of broker enforcement actions in January 2026
- CalPrivacy named Sabrina Boyson Ross as Chief Auditor and formed a new Audits Division (February 2026) to conduct cybersecurity audits under the new regulations
- CPPA announced inflation-adjusted fine amounts for 2026: $2,663 per unintentional violation (up from $2,500) and $7,988 per intentional violation (up from $7,500)
- Major enforcement actions in 2026: General Motors $12.75M for connected-vehicle data sales and data-minimization violations (May 2026), Ford $375K for opt-out friction (March 2026), PlayOn Sports $1.1M for youth privacy violations (March 2026), Disney $2.75M for opt-out failures (February 2026)
- CalPrivacy sponsoring AB 2021 (whistleblower protections for privacy complaints) and SB 923 (expanding deletion rights and accessibility requirements)
- Preliminary rulemaking underway on data broker audits (comment period through May 7, 2026), reducing friction in privacy rights, and opt-out preference signals (OOPS)
- Nicole Ozer appointed to CPPA Board by Assembly Speaker (January 2026), strengthening enforcement-oriented board composition
Regulatory Timeline
CCPA signed into law (AB 375)
CCPA takes effect — California becomes first state with comprehensive privacy law
Proposition 24 (CPRA) passed by California voters, creating the CPPA
CPRA amendments take effect — expanded rights, new sensitive data category, cure period eliminated
First set of CCPA regulations approved by Office of Administrative Law
California Delete Act (SB 362) signed by Governor Newsom
CPPA wins Court of Appeal decision against California Chamber of Commerce challenge to regulations
CPPA adopts data broker registration regulations and advances ADMT rulemaking
Tom Kemp named as CalPrivacy Executive Director
CalPrivacy finalizes comprehensive regulation package covering cybersecurity audits, risk assessments, ADMT, and insurance
Delete Act regulations approved
CalPrivacy launches Data Broker Enforcement Strike Force
New CCPA regulations and Delete Act DROP platform take effect — major regulatory milestone
CalPrivacy names Sabrina Boyson Ross as Chief Auditor, forms new Audits Division
Preliminary rulemaking on data broker audits opens (comment period through May 7, 2026)
California AG, four District Attorneys, and CalPrivacy announce $12.75 million General Motors CCPA / UCL connected-vehicle data settlement
Cumulative CCPA, CPRA, and Delete Act civil penalties surpass $24.6 million across more than a dozen publicly resolved actions
Enforcement Details
California CCPA/CPRAFines & Penalties(2026 inflation-adjusted)
These are the statutory per-violation amounts written into California Consumer Privacy Act / California Privacy Rights Act— in practice, aggregate fines in major enforcement actions reach into the millions. See the table below for per-incident figures and the “Notable Enforcement Actions” section for real California settlements. For the full cross-state database of CCPA/CPRA fines and privacy penalties across every US privacy law, see the penalties tracker. To weigh these penalties against what compliance would cost, estimate your CCPA/CPRA compliance cost.
Inflation-adjusted for 2026 (statutory base $7,500). The CPRA tripled this cap for violations involving consumers under 16.
Inflation-adjusted for 2026 (statutory base $2,500).
Inflation-adjusted statutory damages range for the CCPA private right of action on certain unencrypted-data breaches.
Cumulative CCPA monetary penalties in practice: General Motors $12.75M (May 2026), Disney $2.75M (Feb 2026), Healthline $1.55M (Jul 2025), Jam City $1.4M (Nov 2025), Tractor Supply $1.35M (Sep 2025), Sephora $1.2M (Aug 2022), PlayOn Sports $1.1M (Mar 2026), Honda $632.5K (Mar 2025), Sling TV $530K (Oct 2025), Tilting Point $500K (2024), Ford $375,703 (Mar 2026), DoorDash $375K (Jan 2023), S&P Global $62,600 (Jan 2026, Delete Act), and Datamasters $45,000 (Jan 2026, Delete Act). Combined CalPrivacy + CA AG civil penalties on CCPA, CPRA, and the Delete Act exceed $24.6 million since the first enforcement action in August 2022.
Notable Enforcement Actions
Source check: date_retrieved 2026-08-13. This table is generated from the canonical penalties tracker, so new AG and CalPrivacy actions appear here without duplicating state-page copy. Public monetary penalties shown below total $109,620,803.
General Motors
CCPA / UCL · Driving Data Sale / Data Minimization
California Attorney General Rob Bonta, four California District Attorneys, and CalPrivacy announced a $12.75 million General Motors settlement over allegations that GM sold Californians' OnStar location and driving behavior data to LexisNexis and Verisk in violation of the CCPA and Unfair Competition Law. The settlement bans sales of driving data to consumer reporting agencies for five years and requires a privacy program for OnStar data collection.
Ford Motor Company
CCPA · Adding Unnecessary Friction to Opt-Out Process
The California Privacy Protection Agency (CPPA) fined Ford Motor Company $375,703 for adding unnecessary friction to the consumer opt-out process. Ford required consumers to verify their email address before their opt-out requests would be processed — those who did not click the confirmation link had their requests ignored. This was CalPrivacy's second enforcement action stemming from its connected vehicles investigative sweep. Ford must process all previously unfulfilled opt-out requests, provide compliant opt-out submission methods, audit tracking technologies on its website, and ensure proper handling of opt-out preference signals.
PlayOn Sports (GoFan)
CCPA · Student Privacy / Failure to Provide Opt-Out
The California Privacy Protection Agency (CPPA) issued a $1.10 million fine against PlayOn Sports, whose GoFan platform sells digital tickets for approximately 1,400 California schools. PlayOn used tracking technologies to deliver targeted ads to ticketholders without providing a sufficient opt-out mechanism, instead directing users to third-party ad industry tools rather than operating its own opt-out. This is the first CPPA enforcement action addressing student privacy violations.
The Walt Disney Company
CCPA · Failure to Honor Opt-Out Across Services
California Attorney General Rob Bonta secured the largest CCPA settlement in state history — $2.75 million against Disney for failing to fully effectuate consumer opt-out requests across all streaming services and devices linked to their Disney accounts. When consumers opted out on one Disney streaming app, the opt-out did not carry across to other Disney platforms like Hulu or ESPN+.
Rickenbacher Data LLC (Datamasters)
California Delete Act (SB 362) · Failure to Register as Data Broker
The CPPA's Data Broker Enforcement Strike Force fined Rickenbacher Data LLC (d/b/a Datamasters) $45,000 for failing to register as a data broker under the California Delete Act (SB 362). Datamasters bought and resold names, addresses, phone numbers, and email addresses of millions of people with health conditions including Alzheimer's disease and drug addiction for targeted advertising. The company was also ordered to stop selling all Californians' personal information.
S&P Global, Inc.
California Delete Act (SB 362) · Failure to Register as Data Broker
The CPPA fined S&P Global, Inc. $62,600 for failing to register as a data broker under the California Delete Act (SB 362). The New York-based provider of data and technology failed to register due to an administrative error. After discovering the error, the company promptly registered and agreed to implement procedures to ensure ongoing compliance with California's data broker registration requirements.
Jam City, Inc.
CCPA · Children's Privacy / Failure to Honor Opt-Out
California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, a mobile gaming company, for CCPA violations including lacking opt-out mechanisms in 20 of 21 apps and selling personal information of minors aged 13-16 without obtaining required affirmative authorization.
Sling TV L.L.C. and Dish Media Sales L.L.C.
CCPA · Opt-Out Friction / Children's Privacy
California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV and Dish Media Sales for confusing CCPA opt-out flows, requiring unnecessary webform steps from logged-in users, lacking in-app opt-out methods on living-room devices, and failing to provide sufficient children's privacy protections.
Tractor Supply Company
CCPA/CPRA · Failure to Honor Opt-Out / Privacy Notice Violations
The California Privacy Protection Agency (CPPA) issued its largest monetary penalty to date — $1.35 million against Tractor Supply Company for failing to properly notify consumers and job applicants of their privacy rights, failing to maintain adequate service provider agreements, and failing to provide effective opt-out mechanisms.
Healthline Media LLC
CCPA · Failure to Honor Opt-Out Requests
California Attorney General Rob Bonta announced a $1.55 million settlement with Healthline Media LLC for violating the CCPA by failing to honor opt-out requests and improperly sharing consumer data with third parties.
American Honda Motor Co.
CCPA · Opt-Out Friction / Excessive Verification
The California Privacy Protection Agency (CPPA) fined Honda $632,500 for requiring excessive verification or personal information for privacy rights requests, using asymmetrical privacy choices, making authorized-agent requests difficult, and sharing personal information with ad tech companies without required contract terms.
Tilting Point Media
CCPA / COPPA · Children's Privacy Violation
Mobile game developer Tilting Point Media settled for $500,000 for collecting personal information from children under 13 playing its games without parental consent.
DoorDash
CCPA · Unauthorized Sale of Personal Information
DoorDash was fined for selling consumers' personal information to a marketing cooperative without providing notice or an opportunity to opt out of the sale.
Sephora
CCPA · Failure to Honor Opt-Out
Sephora settled with the California AG for $1.2 million for failing to disclose it was selling consumers' personal information, failing to process opt-out requests via Global Privacy Control (GPC), and failing to cure violations within 30 days.
Zoom Video Communications
CCPA / FTC Act · Deceptive Security Practices
Zoom settled a class action for $85 million related to privacy and security issues including sharing user data with Facebook, Google, and LinkedIn, and falsely claiming end-to-end encryption.
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
Businesses must honor Global Privacy Control (GPC) and other opt-out preference signals as valid opt-out requests under the CPRA. The CPPA has issued regulations clarifying technical requirements for recognizing these signals.
Effective: March 29, 2024
Minor / Child Protections
Businesses must obtain opt-in consent before selling or sharing personal information of consumers under 16. For children under 13, a parent or guardian must provide consent. The CPRA tripled penalties for violations involving minors to $7,500 per violation.
Compliance Checklist
- 1Conduct a CCPA-aligned data inventory mapping all 11 categories of personal information defined in Civil Code §1798.140(o), including IP addresses, browsing history, geolocation, biometric identifiers, and inferences drawn from any of the above
- 2Publish a Notice at Collection at or before the point of data collection listing the categories collected, the purposes of use, and the retention period for each category, as required by §1798.100
- 3Update the privacy policy at least every 12 months and include all CPRA-required disclosures: categories sold or shared in the past 12 months, sources of personal information, purposes of disclosure, and a description of the consumer rights request process
- 4Implement automated Global Privacy Control (GPC) signal recognition at both the server layer (Sec-GPC HTTP header) and the client layer (navigator.globalPrivacyControl), and verify that GPC suppresses sale and sharing immediately and consistently across all sub-domains and ad-tech partners
- 5Add a "Do Not Sell or Share My Personal Information" link in the website footer, and a separate "Limit the Use of My Sensitive Personal Information" link if you process sensitive PI for non-permitted purposes
- 6Establish a rights-request workflow that acknowledges consumer requests within 10 business days and substantively responds within 45 calendar days, with a documented basis for any additional 45-day extension
- 7Audit every contract with service providers, contractors, and third parties for CPRA-mandated DPA terms — purpose limitation, no further sale, certification of compliance, and audit rights — and remediate gaps before the next contract review cycle
- 8Conduct and document data protection assessments for high-risk processing — including the sale of personal data processing of sensitive data and profiling of consumers — under the September 2025 CCPA risk assessment rules and retain assessments for at least three years
- 9Prepare a written information security program; if your business has $100 million or more in annual revenue, scope the cybersecurity audit you must certify to CalPrivacy by April 1, 2028
- 10Inventory every use of automated decision-making technology (ADMT) that produces a legally or similarly significant effect on a consumer in financial services, housing, education, employment, or healthcare; document logic, training data, and human-review process before the January 1, 2027 ADMT opt-out deadline
- 11Confirm whether your business meets the data broker definition under SB 362, and if so register with CalPrivacy and integrate with the DROP platform to process universal deletion requests at least every 45 days starting August 1, 2026
- 12Provide a dedicated employee privacy notice covering HR, applicant, contractor, and B2B contact data — California is the only state where these data subjects retain full CCPA rights including access, deletion, correction, and portability
- 13Document retention periods for each category of personal information, including the criteria used and any legitimate business need that justifies retention beyond the initial collection purpose
- 14Train employees who handle consumer inquiries, marketing, ad-tech configuration, and HR on CCPA/CPRA requirements, response procedures, and the broad sale-or-share definition that catches common cookie-based and pixel-based advertising
- 15Subscribe to CalPrivacy rulemaking notices so the team is alerted to active proceedings on data broker audits, opt-out preference signals (OOPS), and friction-reduction rules expected in 2026
Termly builds and maintains a California-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests CCPA/CPRA grants.