---------------------------
Title: California Privacy Law in 2026: CPRA Enforcement, New Rules, and What to Do Now
URL: https://usercentrics.com/us/knowledge-hub/california-privacy-rights-act-cpra-enforcement/
---------------------------

# California Privacy Law in 2026: CPRA Enforcement, New Rules, and What to Do Now

The California Privacy Rights Act (CPRA) amended the California Consumer Privacy Act (CCPA), and two regulators now enforce it with fines and settlements that reach into the millions of dollars. New rules on opt-out signals, automated decision-making, and website tracking lawsuits take effect in 2027. This guide covers who must comply, what penalties apply, and how to prepare.

### At a Glance

- The California Privacy Rights Act (CPRA) amended the California Consumer Privacy Act (CCPA) and took effect on January 1, 2023.
- Two regulators enforce it: the California Privacy Protection Agency (CPPA, which operates publicly as CalPrivacy) and the California Attorney General.
- Administrative fines and civil penalties can reach USD 2,663 per violation and USD 7,988 per intentional violation or violation involving consumers known to be under 16, and there is no mandatory cure period.
- Enforcement has centered on opt-out mechanisms, including opt-out preference signals, with fines and settlements ranging from hundreds of thousands to millions of dollars.
- New requirements arrive on January 1, 2027, including automated decision-making rules, a browser opt-out signal mandate, and a change to website tracking lawsuits under the California Invasion of Privacy Act (CIPA).
- Practical priorities: test whether opt-outs stop data flows, honor opt-out preference signals, offer symmetrical choices, and update notices and contracts.

California privacy law is now well established and still evolving. Since 2024, its regulators have answered the question of whether they will enforce it, and the record now includes actions against retailers, a streaming company, automakers, and a youth sports ticketing platform.

This guide explains who must comply with the [California Consumer Privacy Act (CCPA)](https://usercentrics.com/us/knowledge-hub/california-consumer-privacy-act/) as amended by the CPRA, who enforces it, what penalties apply, and what regulators have targeted so far. It also covers the requirements arriving through 2028 and the steps that help businesses prepare.

A note on names: voters approved the CPRA in 2020 as Proposition 24, and it amended the CCPA. The statute is still formally the CCPA, and regulators use that name, so this article uses "CCPA" when describing their actions and "CPRA" when describing the amendments.

## Who Needs to Comply With the CPRA?

The law applies to for-profit businesses that do business in California, collect consumers' personal information, and meet at least one of three thresholds. It does not require a physical presence in the state, so a business anywhere that serves California residents can be covered.

A business meets the threshold if it:

- Had annual gross revenue above USD 26,625,000 in the preceding calendar year (the original USD 25 million figure is adjusted for inflation every odd-numbered year, most recently in January 2025, with the next adjustment due January 2026)
- Buys, sells, or shares the personal information of 100,000 or more consumers or households each year
- Derives 50 percent or more of its annual revenue from selling or sharing personal information

Here, "sharing" refers to disclosing personal information for cross-context behavioral advertising, and it triggers the right to opt out in the same way a sale does. The law also defines a consumer as any California resident, which includes employees, job applicants, and contractors, not only customers.

## Who Enforces California's Privacy Law?

Two regulators enforce the CCPA, and they can act independently or together.

The [California Privacy Protection Agency (CPPA)](https://usercentrics.com/us/knowledge-hub/california-privacy-protection-agency/), now operating publicly as CalPrivacy, was created by the CPRA to enforce the law through administrative actions. It is governed by a five-member board, and it also appoints a Chief Privacy Auditor. The Attorney General keeps authority to bring civil actions, and a business cannot be required to pay both an administrative fine and a civil penalty for the same violation.

Coordination is increasingly common. In May 2026, the Attorney General announced a settlement with General Motors together with four county district attorneys and with support from CalPrivacy.

### How Enforcement Got Started

The path to enforcement was not smooth. In June 2023, a lower court stayed enforcement of the Agency's regulations for one year, in a case brought by the California Chamber of Commerce. On February 9, 2024, the Third District Court of Appeal reversed that decision and restored the Agency's authority to enforce its regulations. The Agency has said it was enforcing the statutory rights throughout. The stay concerned the regulations that explain how businesses must meet them.

## What Are the Penalties for Violating the CPRA?

Administrative fines and civil penalties can reach USD 2,663 per violation, or USD 7,988 per intentional violation and per violation involving consumers the business knows are under 16. The Agency adjusts these amounts for inflation every odd-numbered year, and the figures above took effect on January 1, 2025. Penalties apply per violation, so totals can grow quickly when a practice affects many consumers.

### No Mandatory Cure Period

The CPRA removed the mandatory 30-day cure period that businesses could once rely on. Regulators may still allow a business to cure a violation, and they may consider good-faith cooperation, but they are not required to.

### Data Breach Damages

Separately, consumers can sue after certain data breaches. Statutory damages range from USD 107 to USD 799 per consumer per incident, or actual damages if greater. The CCPA does not give consumers a private right of action for other violations. These amounts are also adjusted for inflation.

Website tracking carries a different kind of litigation risk under a separate California law, the California Invasion of Privacy Act (CIPA), which we'll also cover more below.

## What Rights Do Consumers Have Under the CCPA and CPRA?

California consumers have a broad set of rights over their personal information, and businesses must give them clear ways to exercise those rights. Consumers can request the following.

## CPRA Consumer Rights

### Right to Access

Know what personal information a business collects, uses, sells, or shares, and request a copy

### Right to Delete

Delete personal information, with some exceptions

### Right to Correct

Correct inaccurate personal information

### Right to Opt Out

Opt out of the sale or sharing of personal information

### Right to Limit

Limit the use and disclosure of sensitive personal information

### Right to Nondiscrimination

Receive equal service and pricing without discrimination for exercising these rights

### Rights Regarding ADMT

Starting January 1, 2027, access information about, and opt out of, the use of automated decision-making technology (ADMT) for significant decisions, subject to the exceptions in the regulations

The law also sets stronger rules for children and teens. Businesses need opt-in consent before selling or sharing the personal information of consumers they know are under 16.

Timing matters as much as the rights themselves. Businesses must confirm receipt of a request to know, delete, or correct within 10 business days and respond within 45 calendar days. If necessary, they can take up to 45 more days, for a maximum of 90, provided they notify the consumer and explain the reason.

## Do you know what your site is tracking?

Scan your site for free and see what cookies, trackers, and scripts are active. Get your customized report and compliance risk level in minutes so you can start closing gaps.

## What Has CPRA Enforcement Looked Like So Far?

Regulators have moved from announcing sweeps to issuing decisions. The table summarizes the larger actions announced since 2025.

DATEBUSINESSREGULATORAMOUNTFOCUSMarch 2025[American Honda Motor Co.](https://cppa.ca.gov/announcements/2025/20250312.html)CalPrivacyUSD 632,500Handling of privacy requests and opt-outsMay 2025[Todd Snyder, Inc.](https://cppa.ca.gov/announcements/2025/20250506.html)CalPrivacyUSD 345,178Handling of opt-out requestsSeptember 2025[Tractor Supply Company](https://cppa.ca.gov/announcements/2025/20250930.html)CalPrivacyUSD 1.35 millionOpt-out mechanisms, opt-out preference signals, and privacy notices for job applicantsFebruary 2026[The Walt Disney Company](https://oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million)Attorney GeneralUSD 2.75 millionOpt-outs that did not stop sale or sharing across all streaming servicesMarch 2026[PlayOn Sports](https://privacy.ca.gov/2026/03/youth-sports-media-company-to-pay-1-1-million-fine-change-practices-over-privacy-violations/)CalPrivacyUSD 1.10 millionOpt-out rightsMarch 2026[Ford Motor Company](https://privacy.ca.gov/2026/03/ford-to-change-practices-pay-fine-for-adding-unnecessary-friction-to-opt-out-process/)CalPrivacyUSD 375,703Unnecessary friction in the opt-out processMay 2026[General Motors](https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general)Attorney General, with four district attorneys and support from CalPrivacyUSD 12.75 million (subject to court approval when announced)Sale of driving and location data without notice or consent; first data minimization case

The Attorney General's earlier CCPA settlements include Sephora, DoorDash, Healthline, Sling TV, Jam City, and Tilting Point Media. The Attorney General described the General Motors settlement as its eighth CCPA enforcement action.

### What the Pattern Shows

Across these cases, several themes repeat.

## California Enforcement Patterns

### Opt-outs must work in practice

Regulators test whether a consumer’s opt-out stops the sale or sharing of data across every service, device, and vendor, not whether an opt-out link exists.

### Opt-out preference signals are part of the test

The Tractor Supply decision found fault with the lack of an effective opt-out mechanism, including through signals such as Global Privacy Control.

### Workforce data is in scope

The same decision addressed privacy notices for job applicants.

### Data minimization is now an enforcement theme

The General Motors settlement is the Attorney General’s first action on the principle that businesses cannot retain data and reuse it for an unrelated purpose.

### Investigations are continuing

The Attorney General has run sweeps on location data, streaming apps and devices, employee information, and surveillance pricing, and CalPrivacy has brought more than a dozen actions against unregistered data brokers.

For marketing teams, these cases matter beyond the penalties. An opt-out that does not reach advertising partners affects audiences, measurement, and attribution as well as legal exposure.

## What Do Regulators Expect From Consent and Opt-Out Interfaces?

Regulators have been specific about how privacy choices should look and behave.

The CPRA added a statutory definition of consent: a freely given, specific, informed, and unambiguous indication of the consumer's wishes. Agreement obtained through [dark patterns](https://usercentrics.com/knowledge-hub/dark-patterns-and-how-they-affect-consent/) does not count as consent, and neither does acceptance of general terms of use that bundle in descriptions of data processing.

In September 2024, the Agency's Enforcement Division issued Enforcement Advisory No. 2024-02, which reminds businesses that interfaces deployed through service providers, such as consent management platforms, can be dark patterns.

The advisory points to the regulations' principle of "symmetry in choice": the path to a more privacy-protective option should not be longer or harder than the path to a less protective one. A banner with "Accept All" and "Decline All" is symmetrical. A prompt offering "yes" and "ask me later" is not, and neither is an opt-out that takes more steps than opting back in.

Opt-out preference signals, such as [Global Privacy Control (GPC)](https://usercentrics.com/us/knowledge-hub/global-privacy-control-gpc-usercentrics-signaling/), are a separate requirement. The CCPA regulations already require businesses to honor them. From January 1, 2027, the [Opt Me Out Act (AB 566)](https://usercentrics.com/us/knowledge-hub/california-opt-me-out-act/) requires browser developers to offer a setting that sends the signal, which may increase the number of visitors who send it. Other states, including Colorado and Connecticut, also require or will require businesses to honor these signals, so a setup that works in California supports multi-state programs.

A [consent management platform](https://usercentrics.com/us/knowledge-hub/what-is-consent-management/) can help present clear, symmetrical choices, record visitors' decisions, and pass them to the tags and vendors that depend on them. Configuration still matters, because regulators look at the live experience rather than the tool behind it.

> **Twice as many consumers grant AI access reluctantly as willingly. Call it resigned consent.** [**Learn more with**](https://usercentrics.com/us/resources/resigned-consent/) **[Usercentrics Resigned Consent Report for 2026](https://usercentrics.com/us/resources/resigned-consent/).**

## What New Requirements Are Coming?

Several California requirements begin or take effect between now and 2030. The table lists them in date order. The regulations also updated existing rules on opt-out preference signals and on contracts with suppliers, so they are worth reading in full with qualified legal counsel.

DATEREQUIREMENTWHO IT AFFECTSJanuary 1, 2026 (in effect)Updated CCPA regulations on risk assessments, cybersecurity audits, and ADMT took effect, and risk assessment compliance beganBusinesses that meet the regulations' criteriaJanuary 1, 2026 (in effect)SB 446: notify affected consumers of a data breach within 30 calendar days, and notify the Attorney General within 15 days when 500 or more California residents are notifiedBusinesses that suffer a breachAugust 1, 2026 (in effect)Data brokers began processing deletion requests through the Delete Request and Opt-out Platform (DROP)Registered data brokersJanuary 1, 2027ADMT requirements applyBusinesses that use ADMT to make significant decisionsJanuary 1, 2027AB 566: browsers must offer an opt-out preference signal settingBrowser developers; businesses should expect more signalsJanuary 1, 2027AB 1043 (Digital Age Assurance Act): age bracket signals collected at device setup and shared with appsOperating system providers, app stores, and app developersJanuary 1, 2027SB 690 takes effect (see below)Businesses with websites and appsApril 1, 2028Risk assessment attestations and summaries due to the AgencyBusinesses required to perform risk assessmentsApril 1, 2028
April 1, 2029
April 1, 2030Cybersecurity audit certifications due, by revenue:

2028: over USD 100 million
2029: USD 50 million to USD 100 million
2030: under USD 50 millionBusinesses required to complete cybersecurity audits

## How Does the California Invasion of Privacy Act Fit In?

The [California Invasion of Privacy Act (CIPA)](https://usercentrics.com/us/knowledge-hub/california-invasion-of-privacy-act-cipa/) is a separate 1967 law that has become a major source of website litigation, because it allows private lawsuits with statutory damages of USD 5,000 per violation.

On September 30, 2026, Governor Newsom signed [SB 690](https://usercentrics.com/us/knowledge-hub/knowledge-hub-sb-690-cipa-lawsuit-risk/). Starting January 1, 2027, claims under CIPA's pen register and trap-and-trace provision (Penal Code § 638.51) that arise from conduct on a website, online application, or mobile application can be brought only by the Attorney General. The change applies retroactively to pending claims in actions filed on or after January 1, 2025.

SB 690 does not make the underlying conduct lawful, and it does not touch CIPA's wiretapping and eavesdropping provisions (Sections 631 and 632). Those remain available to private plaintiffs and are often cited against pixels, chat tools, and session replay software.

> **The [Usercentrics CIPA Consent Template](https://usercentrics.com/us/knowledge-hub/cipa-vppa-consent-template/) is built to close exactly the gaps that CIPA claims are built on.**

## What Should Businesses Do Now?

The enforcement record points to a short list of priorities. None of them replaces advice from qualified legal counsel, but each addresses something regulators have already acted on.

### Test Opt-Outs From End to End

Submit an opt-out on a test device and confirm that it stops the sale or sharing of data on every site, app, and service tied to the account, and that your advertising and analytics vendors receive it. The Disney settlement turned on opt-outs that did not reach all services.

### Honor Opt-Out Preference Signals

Confirm that your websites detect signals such as Global Privacy Control and treat them as valid opt-out requests. Test with a browser that sends the signal rather than assuming the setup works.

### Offer Symmetrical Choices in Plain Language

Review banners and preference centers against the symmetry principle: no more steps to decline than to accept, no "ask me later" in place of "no," and wording a visitor can understand without legal training.

### Update Privacy Notices and Cover Your Workforce

Check that your privacy policy describes what data you process, why, who receives it, how long you keep it, how consumers exercise their rights, and how you handle opt-out preference signals. Include notices for California employees, job applicants, and contractors, because enforcement has already reached them.

### Review Vendor and Service Provider Contracts

Contracts with service providers, contractors, and third parties should cover restrictions on use, sale, sharing, and disclosure, and how consumer requests pass through. The updated regulations changed required contract terms, so contracts written for the original CCPA are worth a fresh review.

### Prepare for Requests, Data Minimization, and the 2027 Deadlines

Check that your process confirms requests within 10 business days and responds within 45 calendar days. Map the personal information you collect and retain, and ask whether each use fits the purpose for which it was collected, since data minimization is now an enforcement theme. Then place the January 1, 2027 and April 1, 2028 dates on your roadmap, starting with whether you use ADMT for significant decisions.

The [Usercentrics Consent Management Platform](https://usercentrics.com/us/website-consent-management/), with geotargeting capabilities, can support California regulatory requirements by detecting, categorizing, and blocking tracking until visitors consent. It also handles opt-out signal detection, consent documentation, and customized banner configurations that adapt to each applicable law’s requirements.

*Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.*

## Get your privacy compliance program California-ready

Usercentrics supports opt-out workflows, notice and disclosures, consent documentation, and geotargeted configurations across California and other U.S. state privacy laws. Start your 14-day free trial today.

---

## Footer

### Products
- [Usercentrics Web CMP](https://usercentrics.com/us/website-consent-management/)
- [Usercentrics App CMP](https://usercentrics.com/us/in-app-sdk/)
- [Usercentrics CTV CMP](https://usercentrics.com/us/usercentrics-ctv-cmp/)
- [Usercentrics Privacy Policy Generator](https://usercentrics.com/us/privacy-policy-generator/)
- [Server-side Tagging Solution](https://usercentrics.com/us/server-side-tracking-solution/)
- [Integrations](https://usercentrics.com/us/integrations/)
- [Web compliance scan](https://usercentrics.com/us/privacy-compliance-scanner/)
- [App compliance scan](https://usercentrics.com/us/app-data-privacy-audit/)
- [ROAS calculator](https://usercentrics.com/us/roas-calculator/)

### Solutions
- [Data Privacy Regulatory Compliance](https://usercentrics.com/us/data-privacy-regulatory-compliance/)
- [Marketing Performance Optimization](https://usercentrics.com/us/marketing-performance-optimization/)
- [Migration](https://usercentrics.com/us/migration/)
- [Media & Publishing](https://usercentrics.com/us/media-publishing/)
- [Retail &amp; Ecommerce](https://usercentrics.com/us/retail-ecommerce/)
- [Banking, Finance &amp; Insurance](https://usercentrics.com/us/banking-finance-insurance/)
- [Healthcare & Pharmaceuticals](https://usercentrics.com/us/healthcare-pharmaceuticals/)
- [Gaming](https://usercentrics.com/us/gaming/)
- [Education](https://usercentrics.com/us/education/)
- [Automotive](https://usercentrics.com/us/automotive/)
- [Travel & Hospitality](https://usercentrics.com/us/travel/)

### Regulations
- [CCPA (California)](https://usercentrics.com/us/ccpa/)
- [GDPR (EU)](https://usercentrics.com/us/gdpr/)
- [CPRA (California)](https://usercentrics.com/us/cpra)
- [CPA (Colorado)](https://usercentrics.com/us/cpa/)
- [DMA (EU)](https://usercentrics.com/us/digital-markets-act-dma/)
- [FADP (Switzerland)](https://usercentrics.com/us/fadp/)
- [PIPEDA (Canada)](https://usercentrics.com/us/pipeda/)
- [TCF v2.4 (IAB)](https://usercentrics.com/us/cmp-for-publishers/)
- [Google Consent Mode (EU)](https://usercentrics.com/us/usercentrics-cmp-and-google-consent-mode-v2/)
- [Microsoft UET Consent Mode (EU)](https://usercentrics.com/us/usercentrics-cmp-and-microsoft-consent-mode/)
- [View all regulations](https://usercentrics.com/us/regulations-and-frameworks/)

### Resources
- [Blog](https://usercentrics.com/us/knowledge-hub/)
- [Whitepapers](https://usercentrics.com/us/whitepapers/)
- [Checklists](https://usercentrics.com/us/checklists/)
- [Courses](https://courses.usercentrics.com)
- [Customer stories](https://usercentrics.com/us/customer-stories/)
- [Privacy-Led Marketing](https://usercentrics.com/us/privacy-led-marketing/)
- [Events](https://usercentrics.com/us/webinar/)
- [CONSENTED podcast](https://usercentrics.com/us/consented/)
- [Guides](https://usercentrics.com/us/guides/)
- [Release notes](https://releases.usercentrics.com/en)
- [Developer documentation](https://usercentrics.com/docs/)
- [RFI template](https://usercentrics.com/us/resources/usercentrics-rfi-template/)
- [Customer directory](https://usercentrics.com/us/usercentrics-customer-directory/)

### Company
- [About us](https://usercentrics.com/us/about-us/)
- [Press](https://usercentrics.com/us/press/)
- [Our offices](https://usercentrics.com/us/contact/)
- [Trust center](https://trust.usercentrics.com/)
- [Careers](https://usercentrics.com/us/career/)
- [Open positions](https://apply.workable.com/usercentrics/)
- [Diversity and inclusion](https://usercentrics.com/us/dei/)

### Support
- [General support](https://support.usercentrics.com/hc/en-us)
- [Contact sales](https://usercentrics.com/us/book-a-consultation/)
- [Technical support](https://support.usercentrics.com/hc/en-us/requests/new)
- [Billing and account](https://support.usercentrics.com/hc/en-us/categories/12253804608156-Account-and-billing)
- [Suggest a feature](https://support.usercentrics.com/hc/en-us/requests/new?ticket_form_id=10610312381340)
- [Partner login](https://partnerportal.usercentrics.com/)
- [Partner program](https://usercentrics.com/us/partner-program-overview/)
- [Affiliate program](https://usercentrics.com/us/affiliates/)