California has settled eight CCPA enforcement actions since 2022, seven of them since July 2025. The most recent, against General Motors in May 2026, was 12.75 Mio. US$, nearly five times the largest that came before it. CCPA compliance means giving California residents rights over the personal information you store, and it applies to any for-profit business in California that meets one of three thresholds.
Companies tend to buy a privacy tool, switch it on, and assume they are covered. That is where most of the recent settlements went wrong, including the General Motors case. Buying the tool is not enough. You have to set it up to match the regulation. Below, I cover who is in scope, your obligations, what it costs, and what changed in January 2026.
What is CCPA compliance?
CCPA compliance means following the rules for businesses that handle California residents’ personal information. In practice, you do four things: tell people what you collect and why, honor their requests to access, delete or correct it, let them opt out of sale or sharing, and protect the data with reasonable security.
Two things to know before you go further. First, the Kalifornisches Gesetz über Datenschutzrechte (CPRA) did not replace the CCPA. It amended it. There is still one law, with rules from before and after the 2020 changes. The CPRA section below covers what changed.
Second, your office location does not matter. If you do business in California and handle California residents’ personal information, you are in scope. A company based in Austin or Berlin with California customers is treated the same as one in San Francisco. Where you sit does not change your obligations.
Personal information covers more than most teams expect. It includes anything that identifies, relates to, or could reasonably be linked to a consumer or household, including:
- Names, email addresses, and account identifiers
- IP-Adressen und Geräte-IDs
- Browsing and purchase history
- Geolokalisierung
- Inferences drawn from any of the above
Employees, job applicants, and business contacts count as consumers. That means your HR and applicant tracking systems are in scope, not just your customer database.
What changed in the CCPA in 2026?
Three new obligations took effect on 1. Januar 2026: cybersecurity audits, Risikobewertungen, and rules for automated decision-making. CalPrivacy, the state privacy regulator, wrote these regulations under the existing statute rather than a new law, and each has its own scope test, so being subject to the CCPA does not automatically put you in scope for any of them.
1. Cybersecurity audits (Artikel 9): Businesses whose processing presents significant risk to consumers’ security must complete an annual audit performed by a qualified, objective, independent professional. That scope test is narrower than the three tests above. You are in scope if half or more of your revenue comes from selling or sharing personal information, or if you are above the revenue threshold and process the personal information of 250,000 or more California residents or households, or the sensitive personal information of 50,000 or more. Clearing the 100,000 data-traded test on its own does not put you in scope. Deadlines are staggered by revenue. If your 2026 gross revenue was above $100 million, your first audit covers January 1, 2027 through January 1, 2028, and the report is due April 1, 2028. Two later tiers follow in 2029 and 2030.
2. Risk assessments (Article 10): You must document a risk assessment before starting any processing that involves selling or sharing personal information, processing sensitive personal information, or using automated decision-making for significant decisions. You must assess processing you started before January 1, 2026, that is still running has to be assessed by December 31, 2027, and submit the first reports to the agency by April 1, 2028.
3. Automated decision-making (Article 11): Where software makes decisions with legal or similarly significant effects, covering employment, credit, housing, education and healthcare, consumers get notice, a right to opt out, and a right to an explanation of the logic. If you were already using it before January 1, 2027, you have to be compliant by that date, which makes this the earliest of the three deadlines.
The audit covers a full calendar year. For the $100 million-and-above tier, you need evidence from January 1, 2027 onward. April 1, 2028 is the filing date, not the start date.

Who has to comply with the CCPA?
You are covered if you are a for-profit business, you do business in California, and you decide how California residents’ personal information gets processed. After that, you only need to clear one of three thresholds. The first two are gateway conditions. The third is where you check if any of the three tests apply.
The gateway conditions are what cause companies outside California to rule themselves out too early. Sephora, the first business California settled with, runs its US operation from San Francisco. General Motors, the largest settlement so far at $12.75 million, is headquartered in Detroit. Neither test asked where the company is headquartered, and the second case shows it: a Michigan manufacturer settled a California privacy action for more money than the other seven combined.
What are the three CCPA thresholds:
| Test | Was es braucht |
|---|---|
| Firmengröße | Your gross revenue was above $26,625,000 in the preceding calendar year |
| Data traded | You buy, sell or share the personal information of 100,000 or more consumers or households in a year |
| Revenue from data | Half or more of your annual revenue comes from selling or sharing personal information |
You only need to clear one of these three, not all three. A company with $40 million in revenue and 60,000 California customers is in scope on threshold 1 alone.
Three qualifiers on the revenue figure, because each is a common misreading:
- Bruttoeinnahmen: Total revenue before costs. Not profit, not ARR.
- Weltweit: From all sources, including revenue earned outside California.
- Preceding calendar year: The test looks backward at a closed year.
The number goes up every two years. The statute set it at $25 million, and the agency adjusts it for inflation in odd-numbered years, so $26,625,000 is what applies through the end of 2026. The next adjustment lands on January 1, 2027.
The CPRA amendments changed a few things. The count doubled from 50,000 to 100,000, ‘devices’ was removed entirely, and so was ‘receives for commercial purposes’. Only buying, selling, and sharing count now, so collecting data directly from your own users does not clear this test, no matter how many users you have.
Rabatt means disclosing personal information to a third party for monetary or other valuable consideration. Teilen is narrower and newer, meaning disclosure for cross-context behavioral advertising, whether or not money changes hands. If you run retargeting through an ad exchange, you are sharing, even if nobody pays you for the data.
Also, on ‘doing business in California’, the CCPA does not define it. During lawmaking, the Attorney General’s position was that the phrase takes its meaning from plain language and other California law, which reads it broadly. In practice, selling to, employing, or collecting data from people in California is treated as enough, and there is no published minimum. If you clear the company-size test on worldwide revenue and have any California presence, assume you are in scope.
Let’s look at an example. You run a subscription software company headquartered in Denver. Last year you did $41 million in worldwide gross revenue. You hold account records for about 62,000 California residents; you do not sell or share data, and advertising is a rounding error. You clear the company-size test but not the other two. The CCPA applies to you. If your revenue is $18 million (which is below the company-size threshold) and you run retargeting that passes identifiers to ad platforms for 140,000 California consumers, the CCPA still applies. Because that is treated as sharing.

The question to answer is whether für of the three is true, and you need to re-answer it every year, because revenue and customer counts move.
Welche Anforderungen gelten für die Einhaltung des CCPA?
The CCPA gives California residents seven rights, and it gives you deadlines for honoring them: ten business days to acknowledge a request, 45 calendar days to answer it, 15 business days to act on an opt-out. Around those deadlines sits the machinery that makes them work: a notice at collection, a privacy policy, a contract with every vendor you hand data to, and a retention rule.
One detail inside the deadlines is easy to miss. The 45 days start the day the request arrives, and verification time comes out of those 45, not in addition to them. An identity check that takes three weeks does not give you three extra weeks at the end; it uses up three of the weeks you already had. That is why you need a request-handling process before the first request lands, which is step 5 below.
What are the seven consumer rights under the CCPA?
1. Right to know: Consumers can ask what personal information you collected, where it came from, why you collected it, who you disclosed it to, and what you sold or shared. By default, you look back 12 months from the request. For information collected on or after January 1, 2022, a consumer can ask you to go further back, and you have to unless doing so is impossible or takes disproportionate effort.
2. Right to access: A subset of the above: the specific pieces of personal information you hold, delivered in a portable, readily usable format.
3. Right to delete: Delete the information you collected from the consumer, and direct your service providers and contractors to do the same. Exceptions include completing a transaction, detecting security incidents, fixing errors, and complying with a legal obligation.
Hinweis: California calls this the right to delete. “Right to be forgotten” is GDPR language and does not appear in this statute.
4. Right to correct: Consumers can ask you to fix inaccurate information. You take commercially reasonable steps to correct it and pass the instruction down to your service providers and contractors.
5. Right to opt out of sale or sharing: Consumers can tell you to stop selling or sharing their personal information, including for cross-context behavioral advertising. Once someone opts out, you have to wait 12 months before asking them to reconsider.
6. Right to limit use of sensitive personal information: Where you use sensitive personal information beyond a set of permitted purposes, consumers can tell you to stop. Sensitive personal information covers government identifiers, account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of private messages, genetic and biometric data, health information, and sexual orientation.
7. Right to non-discrimination: You cannot deny service, charge a different price, or lower quality because someone exercised a right. Financial incentive programs are allowed where the incentive is reasonably related to the value of the data and the consumer opts in.
How long do you have to respond to a CCPA request?
You have 10 business days to acknowledge and 45 calendar days to respond. You may extend this once by a further 45 days, so the outer limit is 90 days from receipt.
| Verpflichtung | Frist |
|---|---|
| Acknowledge a request to know, delete, correct, or appeal an automated decision | 10 business days, with your verification process and expected timing |
| Substantive response | 45 calendar days from receipt, regardless of how long verification took |
| Erweiterung | Once, by a further 45 days, with notice and a reason. 90 days total |
| Effectuate an opt-out or a request to limit sensitive information | 15 Werktagen |
| Free requests to know | Twice per consumer per 12 months. Civil Code 1798.130 caps this for right-to-know requests specifically, not for every request type |

Do you need a toll-free number for privacy requests?
Not always. The general rule is two methods for submitting requests, one of them a toll-free telephone number. There is an exemption that covers a large share of software companies. If your business operates exclusively online and the people whose personal information you collect are people you have a direct relationship with, Section 7020(a) says an email address is the only method you have to provide for requests to know, delete, and correct. The toll-free number is removed from the list.
Do you have to honor Global Privacy Control?
Yes, if you sell or share personal information. You must honor opt-out preference signals sent by a consumer’s browser or extension have to be honored, and Global Privacy Control is the signal in general use. Treat an incoming signal exactly as you would treat someone clicking your “Do Not Sell or Share My Personal Information” link. No identity verification is required to act on an opt-out.
This deserves more attention than its length here suggests. Failures to honor opt-out signals and broken opt-out mechanisms feature in more enforcement actions than any other provision, including the Healthline, Traktor-Versorgung und Disney Siedlungen.
How do you classify vendors under the CCPA?
Every recipient of personal information is a service provider, a contractor, or a third party. The category determines whether the disclosure counts as a sale.
| Kategorie | Was es bedeutet | Is it a sale or sharing? |
|---|---|---|
| Dienstleister | Processes on your behalf under a written contract limiting use to specified business purposes | Nein |
| Auftragnehmer | Receives information under a contract prohibiting other uses, and certifies compliance | Nein |
| Dritte Seite | Jeder andere | Möglicherweise ja |
Remember, a vendor providing cross-context behavioral advertising is a third party, regardless of what the contract says. Restricted-use contract language cannot convert advertising disclosures into service-provider processing. Service providers can still run contextual advertising and non-behavioral marketing.
If your contracts say one thing and your data flows say another, the data flow decides the classification, and the paperwork stops protecting you. Section 7051(c) is explicit about the second half: a business that never enforces its contract terms and never exercises its rights to audit or test a vendor’s systems may not be able to rely on the defense that it had no reason to believe the vendor intended to misuse the data. So audit the vendor list against where the data actually goes rather than against what you signed, and keep the record showing you did it.
What do your notices and privacy policy have to say?
You need two documents, and they overlap:
- Hinweis bei Abholung, given at or before the point you collect anything: the categories collected, the purposes, whether you sell or share, and your retention periods.
- Datenschutzerklärung: the same material, plus your rights-request process and contact details. Update it every 12 months.
Retention is the newest of these requirements and the easiest to miss. The CPRA added it in 2023, and it asks for something specific: the length of time you keep each category of personal information, or, if you cannot give a length, the criteria you use to decide. A line reading “as long as necessary for business purposes” restates the obligation without meeting it. If your policy says that, fix it first. It is the cheapest fix, because it is a drafting problem, not an engineering one.
For retention limits and data minimization, collect only what is adequate, relevant, and necessary for the purpose you disclosed. Keep it only as long as you reasonably need it, and publish the retention period or the criteria you use to set it. Collecting less is the cheapest compliance decision you can make, because every record you do not hold is one you never have to find, produce, correct, or delete.
Do note that selling or sharing the personal information of consumers under 16 requires opt-in and parental consent for those under 13. If you get this wrong, the Strafe is automatically the higher one.
How do you comply with the CCPA: 8 steps
Appoint an owner, map your data, classify your vendors, update your notices, build a request-handling process, honor opt-outs, assess and close risk, and train your people.
Do step 2 first, and give it more time than its position on the list suggests. Most of what follows depends on the map. You cannot classify a vendor you have not listed, publish a retention period for a system you forgot about, or honor a deletion request across databases nobody ever wrote down. The map is the one artifact on this list that has to be rebuilt every time your architecture changes.
1. Appoint an owner
Assign one named person accountable for privacy, with a team behind them if the scale warrants it. The CCPA does not require a data protection officer the way the GDPR does, but requests come with a 10-business-day clock attached, and someone has to watch for them.
The regulations do name a duty here, and it reaches further than the job title. Under section 7100(a), everyone responsible for handling consumer inquiries about your information practices has to be informed of the CCPA’s requirements and of how to direct a consumer to exercise a right. If privacy questions arrive in a shared support inbox, that duty covers the support team, not only the person whose name is on the program.
2. Map what you hold and where it came from
Build an inventory of the personal information you collect, where it comes from, the systems it sits in, and the purposes you use it for. Include HR and applicant tracking, since employees and applicants are consumers in California.
Let the notice at collection dictate the columns. That notice has to state the categories of personal information you collect, the purpose for each category, whether each is sold or shared, and how long you keep each one. If your map does not hold those four facts per category, you will be writing the notice from memory, which is how a map’s gaps end up published.
3. Inventory your vendors and classify them
List everyone you disclose personal information to and classify each as a service provider, contractor, or third party using the table above. Then check each classification against where the data really goes, particularly anything in the advertising stack.
The contract is what carries the classification, and section 7051(a)(2) is stricter than most templates are. It requires the contract to name the specific business purposes the vendor is processing for, and it says those purposes cannot be described generically or by pointing to the agreement as a whole. A data processing addendum that authorizes the vendor to process “for the purposes of the Services” does not meet it. Reading your own addenda for that one clause is a fast way to find out how many of your service providers are legally third parties.
4. Update your notices and privacy policy
Rewrite the notice at collection and the privacy policy to cover categories, purposes, retention periods, the rights, and how to exercise them. Add the “Do Not Sell or Share My Personal Information” link, and the “Limit the Use of My Sensitive Personal Information” link where sensitive data is in play.
Watch where the notice at collection sits, because the regulations attach a consequence to getting it wrong that they attach to almost nothing else. Section 7012(d): if you do not give the notice at or before the point of collection, you are not permitted to collect the personal information at all. A privacy policy linked in the footer is not a notice at the point of collection. The notice belongs at the form, the checkout, the job application, and the support widget, wherever the data is being taken.
5. Build the request-handling process
Stand up the intake channels, the verification steps, and the workflow that gets a request answered within 45 days. Verification is tiered:
- Two matching data points for lower-risk requests, such as asking which categories of information you hold.
- Three data points plus a signed declaration under penalty of perjury for specific pieces of personal information, or a request to access automated decision-making.
- Deletion and correction sit on a sliding scale. The standard rises with how sensitive the data is and how much harm a wrongful deletion would do. The regulations contrast deleting family photographs, which needs the higher standard, with deleting browsing history, which does not.
- Deny deletion requests you cannot verify is denied as a deletion, but still treat them as opt-outs where that applies.
Log every request and every response. The record is your evidence.
6. Honor opt-outs and preference signals
Open your own site in a browser with Global Privacy Control turned on, and watch whether your advertising tags still fire. The check takes about ten minutes. Broken opt-out mechanisms and ignored preference signals appear in more of California’s settled enforcement actions than any other failure, and a consent banner that renders correctly tells you nothing about whether the tags behind it stopped.
Three things have to hold for that check to pass. The opt-out has to be wired into your consent or preference management platform. Global Privacy Control has to be detected and treated exactly like a click on your “Do Not Sell or Share My Personal Information” link. And the instruction has to reach your service providers and contractors within 15 business days. Test the first two from the browser rather than from the vendor dashboard, which reports what it was told to do.
7. Assess and mitigate risk
Run a risk assessment against your processing, then close what it finds: governance, access controls, encryption, vendor management, incident response. If you sell or share, process sensitive personal information, or use automated decision-making for significant decisions, the 2026 regulations require you to document that assessment before processing starts.
The part to plan for is the maintenance, not the first one. Section 7155 sets two clocks. Every risk assessment has to be reviewed and updated as needed at least once every three years. And any material change to the processing triggers an update within 45 calendar days. A material change means a change of purpose, a change in the minimum data needed for that purpose, or a rise in the privacy risk to consumers, which the regulation illustrates with consumers complaining to you about it. A risk assessment written once and filed is out of compliance the first time the product team changes what a feature does with the data.
Two techniques worth knowing while you are closing findings:
- Mask data in non-production environments: development, test, and reporting systems often hold production data with no business need for it.
- Delete what you no longer need: it shrinks every other obligation at once.
8. Train the people who touch the data
Section 7100(a) is the requirement, and it points to a specific group: everyone responsible for handling consumer inquiries about your information practices must be informed of the CCPA’s requirements and how to direct a consumer to exercise a right. That is the same group step 1 asked you to identify. No method or frequency is prescribed, so what you can show an investigator is a record of who was trained, on what, and when.
Above 10 million consumers, the rules stop being general. A business that buys, receives for commercial purposes, sells, shares, or otherwise makes available the personal information of 10 million or more consumers in a calendar year has to establish and document a written training policy under section 7100(b). Under section 7102, it also has to count its rights requests, recording for each type how many it received, how many it complied with, how many it denied, and the average or median days it took to respond. Every type is listed: deletions, corrections, requests to know, opt-outs of sale or sharing, requests to limit, and both kinds of automated-decision requests. Those numbers go in the privacy policy, or on a page linked from it, by July 1 every year. It is the one CCPA obligation that publishes your own performance for anyone to read, including a regulator deciding where to look next.
Underneath all of that, and regardless of size, Section 7101 requires every business to keep records of the requests it received and how it responded for at least 24 months. A ticket log satisfies it, as long as each entry includes the request date, what was asked, how it arrived, the date and nature of your response, and the reason for any denial.

The data map and the vendor list are the two that go stale fastest.
If you are unsure about those, book 30 minutes and bring whatever you already have.What does CCPA compliance look like in practice?
Three situations, each showing a different rule operating: a pricing decision that becomes discrimination, an opt-out link that has to work when someone clicks it, and a privacy policy with holes in it.
Read the third one closely. The company in it is already HIPAA-compliant, and that changes nothing about its position, because the CCPA’s health carve-out covers protected health information handled by a covered entity or business associate and stops there. The website analytics, the marketing list, and the job applications sitting in the same company are ordinary personal information under California law. That is where the missing disclosures in the example live, and it is why a telehealth company with a clean HIPAA posture can still be the one with the problem.
Example 1: Right to non-discrimination
Companies may not mistreat consumers for exercising CCPA-granted rights. If a consumer opts out of the sale of their personal information, you cannot change how you treat them afterward: no different price, no reduced service, no denial, and no suggesting that any of those might follow.
Financial incentive programs are one route through this, and they are narrow. The incentive has to be reasonably related to the value of the data, the consumer has to opt in after being told the material terms, and they have to be able to withdraw. Rewarding someone for sharing data is permitted. Charging someone more because they stopped is the same arrangement described backward, and it is not.
Example 2: The “Do Not Sell My Personal Information” Link
Consumers have the right to opt out of having their personal information sold to third parties. You need to include a clear “Do Not Sell My Personal Information” link on your online platforms, an entry point for customers to use this right.
This link is a mandatory component of the CCPA privacy policy and should be easy to access on the business’s website or app. If a user clicks it, it should lead them to a webpage where they can opt out of selling their personal information.
Example 3: Privacy policy lacking important details
Now, let’s say you are a telehealth company that is already HIPAA compliant. The link on your site led customers to the wrong part of the privacy policy page because of to website issue. What’s more, you also forgot to include some crucial information on the privacy page.
Sie haben nicht mitgeteilt, welche Angaben die Verbraucher für Auskunftsersuchen machen müssen oder welche personenbezogenen Daten Sie im vergangenen Jahr erhoben und weitergegeben haben. Auch wurde nicht erwähnt, an wen Sie diese Daten weitergegeben haben.
Was sollten Sie also jetzt tun? Sie müssen den Link korrigieren, sodass er an die richtige Stelle in der Datenschutzerklärung führt, und alle fehlenden Informationen hinzufügen.
What is the difference between the CCPA and the CPRA?
The CPRA is a 2020 ballot measure, Proposition 24, that amended the CCPA, effective January 1, 2023. It created the California Privacy Protection Agency and gave it the power to write the rules that keep arriving.
Six things changed:
| Verpflegung | Before the CPRA | After the CPRA |
|---|---|---|
| Volumenschwelle | 50,000 consumers, households or devices | 100,000 consumers or households; devices removed |
| Ihre Rechte | Know, access, delete, opt out of sale, non-discrimination | Adds correction, limiting sensitive personal information, and rights around automated decision-making |
| Sensible persönliche Informationen | Not a separate category | Defined category with its own restrictions |
| Disclosure covered | Sale only | Rabatt und sharing for cross-context behavioral advertising |
| Regler | Attorney General only | California Privacy Protection Agency created, with rulemaking and enforcement powers; the Attorney General retains authority |
| Heilungsdauer | Automatic 30 days | Automatic cure removed; now discretionary |
There is no longer an automatic right to fix a problem after being told about it. When the agency decides whether to take action, it weighs two things: whether you intended to violate the law and whether you voluntarily fixed the problem before anyone contacted you. Work you do before a regulator calls counts for more than work you do after.
What does CCPA compliance cost?
The California Privacy Protection Agency estimates that getting the three 2026 obligations set up costs between about $6,000 and $65,000, and that running them afterward costs roughly $16,000 to $20,000 a year, averaged across ten years. That is for the 2026 additions on their own, on top of the baseline CCPA work most covered businesses have been carrying since 2020.
The interesting part of that estimate is how wide it is. Everyone in scope owes the same obligations, so a tenfold spread in setup cost is measuring something other than the regulation. It is measuring how differently the same work lands depending on the company.
What decides where you fall is how scattered your data is. A company whose customer records sit in three systems, with a vendor list someone still maintains, gets through this quickly. A company carrying fifteen years of accumulated tooling and an advertising stack nobody has audited pays for each of those places twice, once to find out what is in it and again to keep the answer current. Same regulation, same obligations, ten times the bill.
Welche Anforderungen gelten für die Einhaltung des CCPA?
The CCPA gives California residents seven rights, and it gives you deadlines for honoring them: ten business days to acknowledge a request, 45 calendar days to answer it, 15 business days to act on an opt-out. Around those deadlines sits the machinery that makes them work: a notice at collection, a privacy policy, a contract with every vendor you hand data to, and a retention rule.
One detail inside the deadlines is easy to miss. The 45 days start the day the request arrives, and verification time comes out of those 45, not in addition to them. An identity check that takes three weeks does not give you three extra weeks at the end; it uses up three of the weeks you already had. That is why you need a request-handling process before the first request lands, which is step 5 below.
What are the penalties for violating the CCPA?
$2,663 per violation, and $7,988 per intentional violation, effective January 1, 2025, and adjusted for inflation in odd-numbered years. Penalties are assessed per violation and per consumer, which is what turns a single misconfigured opt-out into a large number.
Two things sit alongside that:
- Minderjährige: when you know a consumer is under 16, a violation involving their personal information carries the $7,988 figure whether or not it was intentional.
- Private right of action, for data breaches only: where unencrypted personal information is exposed because a business failed to maintain reasonable security, consumers can claim $107 to $799 per consumer per incident, or actual damages if higher. These cases are class-action eligible.
Who enforces the CCPA?
Two regulators: the Attorney General has enforced the CCPA since 2020, and since 2023, the California Privacy Protection Agency has had independent administrative enforcement authority and brought its own actions.
| Geschäft | Summe | Gebracht von | Datum |
|---|---|---|---|
| Sephora | $ 1.2M | Generalstaatsanwalt | August 24, 2022 |
| Healthline-Medien | $ 1.55M | Generalstaatsanwalt | Juli 1, 2025 |
| Traktor-Versorgung | $ 1.35M | Kalifornien Datenschutzbehörde | September 30, 2025 |
| Sling TV and Dish Media Sales | $530,000 | Generalstaatsanwalt | 30. Oktober 2025 |
| Jam City | $ 1.4M | Generalstaatsanwalt | November 21, 2025 |
| Disney | $ 2.75M | Generalstaatsanwalt | 11. Februar 2026 |
| PlayOn Sports | $ 1.1M | Kalifornien Datenschutzbehörde | 3. März 2026 |
| General Motors | $ 12.75M | Attorney General and four district attorneys | May 8, 2026 |
CalPrivacy supported the General Motors case but was not a settling party; the four district attorneys were San Francisco, Los Angeles, Napa, and Sonoma.
Read the reasons, not the totals. Opt-out mechanisms that did not work, preference signals that were not honored, and disclosures to advertising partners without a contract come up again and again. None of these is unusual. They are the parts of a privacy program that quietly stop working when nobody is checking, which is why the ninety minutes you spend testing your own opt-out from a clean browser is the highest-return ninety minutes on this page.
Is there such a thing as CCPA certification?
No. Nothing in the CCPA or its regulations provides for a third party to certify a business as compliant, and no accreditation scheme exists behind such a claim.
The confusion is understandable. The GDPR does provide for certification mechanisms at Article 42, and plenty of vendors sell things with “certified” in the name. The one place these regulations use the word is in Article 9 certification of completion, where a member of a business’s own executive management certifies to the agency, under penalty of perjury, that the required cybersecurity audit was done. That is a business certifying itself to a regulator, not a badge anyone awards you.
What you can show a customer instead:
- A documented privacy program, with the data map and vendor classifications behind it
- A current privacy policy and notice at collection
- Working rights-request and opt-out mechanisms, tested
- A recognized security attestation such as SOC 2 or ISO 27001 covering the systems that hold the data
You maintain each is those; you don’t obtain them. That is what a certificate would have saved you.
How does Sprinto help with CCPA compliance?
Sprinto ist ein Autonome Vertrauensplattform that offers a CPRA program. The platform maps obligations to controls in your environment and monitors them, not just checks them once a year. The platform drafts policies and notices from templates and versions them. Vendor records are available in one place, and the platform collects evidence for each control from the systems you already run.
The most important part of this framework is the ongoing work. A privacy program does not usually fail on the day it is built. It fails eight months later, when an opt-out link breaks in a release, a new advertising vendor is added without a contract review, or a retention period quietly stops being enforced. Continuous checks catch these problems while they are still cheap to fix. That is the same failure mode the settlements above keep describing.

Häufig gestellte Fragen.
Autorin
Meeba Gracy
Meeba, eine ISC2-zertifizierte Cybersicherheitsspezialistin, analysiert und vermittelt mit Leidenschaft wirkungsvolle Inhalte zu Compliance und komplexen digitalen Sicherheitsthemen. Sie versteht es, komplizierte Konzepte verständlich zu erklären und ihre Leser zu inspirieren. In ihrer Freizeit liest sie gerne Thriller oder erkundet neue Orte in der Stadt.Mehr erfahren
Recherchen und Erkenntnisse, die Ihnen helfen sollen, sich einen Platz am Tisch zu sichern.




























