August 3, 2026
California law is increasingly being used to launch administrative investigations and actions and to assert private consumer lawsuits against companies across the United States that have websites that are used by California consumers. One of those laws is the California Consumer Privacy Act (CCPA). This article discusses the CCPA, recent CCPA regulations enacted by the California Privacy Protection Agency (CPPA or CalPrivacy), investigative sweeps related to CCPA compliance and settlements, and compliance takeaways for businesses with an online presence in California.
The CCPA
California lawmakers enacted the CCPA in 2018, and it took effect on January 1, 2020. The CCPA applies to businesses with gross annual revenues of more than $25 million, or that buy, receive, or sell the personal information of 100,000 or more consumers, households, or devices, and/or that derive 50% or more of annual revenues from selling consumers’ personal information.[1] As summarized by the California Attorney General (CAG), the CCPA gives California consumers: (1) the right to know about the personal information a business collects about them and how it is used and shared; (2) the right to delete personal information collected from them (with some exceptions); (3) the right to opt-out of the sale or sharing of a consumer’s personal information; and (4) the right to non-discrimination for exercising the consumer’s CCPA rights.[2] In 2020, California voters passed Proposition 24 (known as the California Privacy Rights Act or CPRA), which amended and expanded the CCPA and provided consumers with the additional rights to: (5) correct inaccurate personal information that a business has about them; and (6) limit the use and disclosure of sensitive personal information collected about them.[3]
Among other things, businesses subject to the CCPA must protect personal information through reasonable security practices and procedures, allow consumers to opt out of having their personal information used or sold, respond to consumer requests to exercise their opt-out and other rights, and give consumers specific notices on their websites explaining the business’s privacy practices.[4] CalPrivacy and the CAG are responsible for enforcing the CCPA and CPRA. Under the law, CalPrivacy may conduct administrative proceedings, issue cease-and-desist orders, and impose fines. The CAG may investigate violations and seek civil penalties and injunctions. CalPrivacy and CAG may seek civil penalties up to either $2,663 per violation or $7,988 per intentional violation or for violations involving minors under 16.[5] In addition, the CCPA gives consumers a private right of action against businesses, allowing them to seek statutory damages between $107 and $799 for each California resident and incident, or actual damages, whichever is greater.[6] In January of every odd-numbered year, CalPrivacy adjusts these amounts to account for changes in the Consumer Price Index (CPI).[7]
Read the CCPA here.
2026 Changes to CCPA Administrative Regulations
In 2025, CalPrivacy finalized proposed changes to existing administrative regulations associated with the CCPA, and those were approved by the California Office of Administrative Law. These regulations took effect on January 1, 2026—although certain requirements are phased in over time. The regulations cover cybersecurity audits, risk assessments, and “automated decision-making technology” (ADMT).[8] They also address matters pertaining to insurance companies and make other updates to the existing CCPA regulations.[9] These regulations are detailed and should be read in their entirety, but the following changes are notable:
- Cybersecurity Audits. Under the new regulations, businesses that meet certain revenue thresholds and process information that presents a significant risk to the security of California consumers must have an independent, qualified auditor conduct a comprehensive annual cybersecurity audit and have a member of the business’s executive team certify the results of the audit to CalPrivacy. The audit must include information regarding the business’s security program and policies and a description of the information systems it uses. All audit records must be retained for at least five years. Audit requirements are to be phased in between 2028 and 2030 based on revenue thresholds. Businesses with more than $100 million in 2026 revenue must submit their audit reports by April 1, 2028. Businesses with $50 million to $100 million in 2027 revenue must submit their audit reports by April 1, 2029. Businesses with less than $50 million in 2028 revenue must submit their audit reports by April 1, 2030.
- Risk Assessments. Businesses that sell or share personal information, engage in processing “sensitive personal information,”[10] use ADMT for a “significant decision”[11] concerning a consumer, use automated processing to infer or extrapolate certain things about the consumer, process information which the business uses to train ADMT for a significant decision concerning a consumer, or process personal information to train facial- or emotional-recognition or to otherwise physically or biologically identify or profile a consumer, must conduct a risk assessment before initiating that processing. Risk assessments must contain specific information required by the regulations, be submitted timely to CalPrivacy, and must be kept and updated for a set period.
- ADMT. Starting on April 1, 2027, businesses that use ADMT must provide California consumers with a Pre-use Notice informing them about the business’s use of ADMT. Pre-use Notices must contain detailed information required by the regulations. In general, businesses that use ADMT must also give consumers the ability to request to opt out of ADMT used to make a significant decision concerning the consumer. There are, however, some exceptions to that requirement. For example, a business is not required to provide consumers with the ability to opt-out of the business’s use of ADMT to make a significant decision if the business provides the consumer with a method to appeal the decision to a qualified human reviewer who has the authority to overturn the decision. Businesses using ADMT must also allow a consumer to request access to ADMT, and the new regulations require businesses to provide specific, transparent responses to such requests.
- Other Updates. The regulations also amend other existing requirements. For example, businesses covered by the CCPA are now required to confirm to California consumers that their requests to opt out of selling or sharing their information with third parties have been processed by the business. Previously, this requirement was discretionary. The updated regulations also clarify that a consumer closing or navigating away from a pop-up window on a website that requests consent without first affirmatively selecting the equivalent of an “I accept” button shall not constitute consent because it causes customer confusion. There are also new requirements regarding the symmetry of “yes” and “no” buttons and that prohibit the use of default selections. In short, opting out must be as easy as opting in. A consumer’s silence or failure to act affirmatively is no longer allowed to constitute consent to the collection of data. In addition, consumers must now receive notice that a business sells or shares personal information that it collects through connected devices such as smart televisions, smart watches, gaming devices, and mobile apps. The new regulations also place stricter privacy compliance requirements on insurance companies.
Read the CCPA Regulations here.
Investigatory Sweeps and Enforcement Actions
CalPrivacy is actively conducting investigative sweeps of businesses that are subject to the CCPA and bringing administrative actions against non-compliant businesses.[12] These actions have resulted in unprecedented settlements with the CAG and CalPrivacy. The most notable of these actions involved the Walt Disney Company (Disney), and its story stands as a cautionary tale for businesses unaware of or refusing to comply with the CCPA.
On February 11, 2026, the CAG announced that it had reached the largest CCPA settlement in California history, which requires Disney to pay the state $2.75 million in civil penalties.[13] The CAG alleged that Disney violated the CCPA by failing to fully effectuate consumers’ requests to opt out of the sale or sharing of their data across all devices and streaming services associated with consumers’ Disney accounts.[14] More specifically, the investigation found:
- Opt-Out Toggles: If a user requested to opt-out of the sale or sharing of their data via an opt-out toggle in Disney’s websites and apps, Disney only applied the request to the specific streaming service the user was watching, and often only the specific device the consumer was using. This meant that in most instances, using the toggle would not stop selling or sharing from other devices or services connected to the consumer’s account.
- Webform: If a user opted out using Disney’s webform, Disney only stopped the sharing of personal data through the company’s own advertising platform and offerings. However, Disney continued to sell and share consumer data with specific third-party ad-tech companies whose code Disney embedded in its websites and apps. Disney also failed to provide an in-app opt-out method in many of its connected TV streaming apps, instead directing consumers to its webform, effectively leaving consumers with no way to stop Disney’s selling and sharing from these apps.
- The Global Privacy Control: For consumers who opted out via the Global Privacy Control (GPC), Disney limited the request to the specific device the consumer was using, even when the consumer was logged into their account. The GPC is an easy-to-use ‘stop selling or sharing my data switch’ that is available on some internet browsers or as a browser extension.[15]
In the face of these findings, Disney agreed to pay $2.75 million to the state in penalties and to update its opt-out mechanisms. It is also required to enter a 3.5-year compliance program to assure it is “effectively providing methods of opting out of selling and sharing [a consumer’s personal information] that are consumer-friendly, easy to execute, require minimum steps, and which, as appropriate, fully implement a consumer’s opt-out choice account-wide on each web property, application, and device.”[16]
Compliance Takeaways
Given the regulatory climate and potential exposure to significant monetary penalties, businesses using websites must prioritize compliance with state and federal privacy laws. This means that businesses need to understand the applicable privacy and data security laws and regulations to effectively comply with them. To minimize the risk of privacy and security investigations and claims against them, businesses with websites should also consider taking the following steps:
- Hire a qualified auditor to conduct annual, independent website, cybersecurity, and ADMT audits to determine what data the business is collecting, why that data is being collected, how it is being used, and who has access to it.
- Consult with the business’s corporate or data and privacy security attorney to ensure compliance with federal and state privacy laws, seek guidance on how to minimize exposure to federal and state law claims, and receive assistance making the required submissions and certifications to federal and state authorities.
- Be transparent with website visitors and let them know what data is being collected and why, and identify who has access to that data. Use a privacy policy or statement for this purpose that is easily found on the website’s home page, and that is routinely updated anytime the website changes and/or the website begins tracking new or additional data. Identify the tools your company is using to track data by name, including Meta Pixel, in the privacy policy or statement.
- Consider whether collecting consumer consent (through a cookie banner or otherwise) is necessary for using tracking cookies or similar data collection tools.
- Limit website data collection if the company is not actively using that data for business purposes.
- If consumer data is being collected, provide easy-to-use, symmetrical opt-out toggles and apply consumers’ choices across all devices and platforms.
- If a consumer opts out of data collection and selling, timely and completely cease sharing personal data through both the business’s own advertising platform and offerings and any third-party ad-tech companies whose codes are embedded in the business’s websites and apps.
- Alert consumers when their privacy choices have been implemented.
Our Team
Our Data and Privacy Security Group advises clients on compliance with privacy laws in the U.S., EU, and U.K. and represents them in a variety of privacy and security enforcement actions in federal and state court.
Sources
[1]See https://www.oag.ca.gov/system/files/attachments/press_releases/CCPA%20Fact%20Sheet%20%2800000002%29.pdf; see also https://vig.cdn.sos.ca.gov/2020/general/pdf/topl-prop24.pdf.
[2] See https://oag.ca.gov/privacy/ccpa.
[3] See id.
[4] See id.
[5] See, e.g., https://cppa.ca.gov/announcements/2024/20241217.html.
[6] See id.
[7]See id.
[8] The regulations define “automated decisionmaking technology” or “ADMT” to mean any technology that processes personal information and uses computation to replace human decisionmaking, or substantially replace human decisionmaking.
[9]See https://cppa.ca.gov/announcements/2025/20250923.html.
[10] “Sensitive personal information” includes things like social security numbers, driver’s licenses, ID cards, passports, financial information, debit or credit card information, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of certain mail, email, or text messages, genetic data, neural data, biometric information, information about health, sex life, or sexual orientation, or personal information of consumers that the business has actual knowledge are less than 16 years old.
[11] A “significant decision” means a decision that results in the provision or denial of financial or lending services, house, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.
[12] See, e.g., https://cppa.ca.gov/announcements/2025/20250909.html.
[13] https://oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million.
[14] https://oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million
[15] Id.
[16] Disney’s Final Judgment and Permanent Injunction (Paragraph 34); Cal. Civ. Code § 1798.140 subd. (ah).
This article is informational only. The information provided on this website does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only. Information on this website may not constitute the most up-to-date legal or other information. Readers of this website should contact their attorney to obtain advice with respect to any particular legal matter. No reader, user, or browser of this site should act or refrain from acting based on information on this site without first seeking legal advice from counsel in the relevant jurisdiction. Only your individual attorney can provide assurances that the information contained herein—and your interpretation of it—is applicable or appropriate to your particular situation. All liability with respect to actions taken or not taken based on the contents of this site are hereby expressly disclaimed. The content on this posting is provided “as is;” no representations are made that the content is error-free.
