Privisy Field Notes

CCPA compliance, with the evidence attached

Enforcement breakdowns, implementation guides, and original research on California privacy law, written from primary sources: the statute, the regulator's filing, and what a site actually loads.

Subscribe via RSS

Start here

Reading paths

Short sequences that take one problem from first principles to a fix. Read them in order.

Browse

By topic

Enforcement

CalPrivacy and Attorney General actions, broken down by what regulators cited and what it means for a live website.

All 6 articles in Enforcement

Chat widgets in California are still wiretapping

Governor Newsom signed SB 690 on September 30, 2026. From January 1, 2027, CIPA section 638.51 pen register claims over website and app tracking belong to the Attorney General alone. Section 631 wiretapping claims keep their private right of action.

AdTech Firms Are the New Data-Broker Enforcement Target

In early September CalPrivacy fined a B2B contact-data company $36,400 for never registering as a data broker, then its Enforcement Division issued an advisory warning that a registry filing carrying wrong information can draw $200 a day. Both moves point straight at adtech and lead-gen companies that don't think of themselves as brokers.

Updated

First CCPA Fine Hits a Data Broker: $116K in a Week

In a single week, CalPrivacy fined two out-of-state data brokers a combined $168,890 — LocateSmarter $116,490 in the Agency's first action under both the CCPA and the Delete Act, Cybba $52,400 for never registering. The data-minimization holding reaches far beyond brokers. Here's what changed and who's exposed.

How-to guides

Step-by-step implementation: detecting and honoring opt-out signals, and testing what fires before a visitor chooses.

All 7 articles in How-to guides

How to Check What Fires Before a Visitor Consents

A DevTools walkthrough for finding out which trackers your own site contacts before a visitor touches your consent interface: the exact steps, what a failure looks like on the wire, and the false negatives a manual check quietly produces.

How to Honor the GPC Signal: A Practical Guide

Honoring Global Privacy Control means three things: read the signal, suppress the sale and sharing that follows, and say so on the page. Here is how each one lands in Google Tag Manager, in server-side code, and in a consent platform.

The Sec-GPC Header Explained: Request to Response

GPC travels two ways at once: a Sec-GPC request header and a navigator.globalPrivacyControl property in JavaScript. Here is what each one carries, what a correct response from your site looks like, and what the .well-known resource is for.

Compliance guides

What the CCPA, CPRA, and neighboring California laws require, explained in plain language with the statute cited.

All 8 articles in Compliance guides

Connecticut Privacy Law Changes: July and October 2026

Connecticut's second round of Data Privacy Act amendments takes effect October 1, 2026. Selling precise geolocation data is banned, purpose limitation tightens, and data brokers must register. Here is what changes on your website.

AB 883 and AB 2561: DROP Hits 30 Days, Settings Stick

Governor Newsom signed AB 883 and AB 2561 on September 27, 2026. Data brokers get 30 days instead of 45 to work DROP deletion requests, and apps and operating systems can no longer quietly reset a privacy setting a user turned on. Both take effect January 1, 2027.

SB 923 Signed: CCPA Deletion Now Covers Bought Data

Governor Newsom signed SB 923 on September 27, 2026. From January 1, 2027, a CCPA deletion request reaches personal information a business got from third parties, and online-only businesses must offer a web form for privacy requests, not just an email address.

CMP blind spots

Where a consent platform's configuration and a site's production behavior drift apart, and how to verify it independently.

All 2 articles in CMP blind spots

Research & case studies

Original benchmarks and audits built from real scans, with the methodology published alongside the numbers.

All 2 articles in Research & case studies

GPC Benchmark: 45.7% of Enterprise Domains Fail Opt-Outs

A scan of 1,019 commercial domains found 466 still loading marketing trackers after receiving a Global Privacy Control signal. Here is the benchmark methodology, the three recurring failure modes, and the remediation steps.

Updated

Archive

Every article

25 articles, newest first.

October 20261 article

September 20266 articles

August 20269 articles

July 20261 article

April 20262 articles

February 20266 articles

Put it to work

Test your own site's Global Privacy Control handling

The free check sends a real GPC signal to one URL and shows whether marketing trackers stop. The full audit runs free from our homepage with no account; paying unlocks its evidence.