If you thought CCPA compliance was a solved problem, 2026 has some surprises in store. The California Attorney General's office has ramped up enforcement, and the penalties have never been higher. Businesses that haven't updated their compliance posture are at serious risk.
What's Changed in 2026
Several key updates went into effect at the start of 2026 that every business needs to understand:
- Opt-Out Preference Signals (§ 7025): If your business sells or shares personal information and your site doesn't respond to Global Privacy Control, you're in violation, even if you have a cookie banner. This duty is not new in 2026. It has been in the CCPA regulations since 2023, and so have the conflict-resolution rules for a signal that collides with a business-specific privacy setting (§ 7025(c)(3)) and the frictionless-path exception for a link to a privacy settings page (§ 7025(f)(3)). What the January 2026 amendments changed is the status display: a business must now show whether it processed the signal as a valid opt-out (§ 7025(c)(6), which used to say "may"), and must display the status of the consumer's choice even when it lawfully sets a signal aside under § 7025(c)(3) or (c)(4). Looking ahead, AB 566 (the California Opt Me Out Act, signed October 8, 2025) requires browsers themselves to ship an opt-out preference signal from January 1, 2027, which will sharply increase how many of your California visitors send one.
- Automated Decision-Making Technology (ADMT): Sections 7200, 7220, 7221, and 7222 apply when a business uses ADMT to make a significant decision about a consumer, such as a decision on lending, housing, education, employment, or healthcare. They require a Pre-use Notice, an opt-out unless a § 7221(b) exception applies, and access to information about how the decision was made. The regulations became operative January 1, 2026, but § 7200(b) sets the compliance date: a business using ADMT for a significant decision before January 1, 2027 has until that date to comply, and one that starts on or after it must comply from the start. Privisy's audit includes a full ADMT disclosure review so you can check where your disclosures stand before then.
- Dark Pattern Enforcement: The CPRA's updated symmetry requirements (section 7004) mean your "Reject All" button must be as prominent as "Accept All."
- Under-16 Data Is Now Sensitive PI (§ 7001(bbb)(4)): The regulatory definition of sensitive personal information grew on January 1, 2026 to cover all personal information of a consumer the business actually knows is under 16 — and willfully disregarding a visitor's age counts as knowing it. If you ask for a birthdate, an age, or a grade level and then use that data for anything outside the § 7027(m) purposes, you now owe the Notice of Right to Limit and a "Limit the Use of My Sensitive Personal Information" link (§ 7014) you may not have owed in 2025. Section 7014(d) lets you post the Alternative Opt-out Link in place of that link, and § 7014(g) lists when neither is owed, including when you use sensitive personal information only for the § 7027(m) purposes and say so in your privacy policy. This one catches sites that never thought of themselves as handling sensitive data.
- Increased Penalties: The maximums in § 1798.155 are inflation-adjusted every odd-numbered year. Effective January 1, 2025 the CPPA raised them to $2,663 per violation and $7,988 per intentional violation(or violation involving a consumer under 16) — the amounts in force through 2026, with the next adjustment due January 1, 2027. The AG has signaled willingness to pursue the full amount.
The GPC Problem Most Companies Don't Know About
Here's what's catching many companies off guard: having a cookie banner is no longer enough. The law now requires that you respond to GPC signals, which is fundamentally different from just showing a consent dialog.
We audited a mid-market e-commerce company last month that had a beautifully designed cookie banner, proper privacy policy, and all the boxes checked. They were still in violation because their site fired tracking scripts before checking for GPC.
What Regulators Are Actually Looking For
Based on recent enforcement actions, here's what triggers investigations:
- Network-layer tracking: Regulators now use the same techniques we do: scanning at the network level to see what actually fires, not just what's in your consent manager.
- GPC response testing: The AG's office has automated tools that test whether sites respect GPC signals.
- Dark pattern audits: They're actively reviewing cookie banners for asymmetric design.
- Third-party data sharing: Particularly problematic: sharing consumer data with third parties without proper disclosure.
Recent Enforcement Is Getting More Aggressive
California has two CCPA enforcers, and neither is waiting for companies to self-certify compliance. CalPrivacy — the California Privacy Protection Agency — assesses administrative fines under § 1798.155; the Attorney General sues for civil penalties under § 1798.199.90. Recent actions from both show they're going after companies of all sizes, and the ceiling has moved sharply in 2026:
- General Motors (May 2026): $12.75M: An Attorney General settlement brought together with four district attorneys, with support from CalPrivacy, and the largest CCPA penalty in California history. GM's OnStar service sold the names, geolocation, and driving-behavior data of hundreds of thousands of Californians to data brokers while its privacy policy said it did not. It is also the first CCPA action built on the data-minimization and purpose-limitation duties in § 1798.100 rather than on a missing opt-out.
- Disney (February 2026): $2.75M: An Attorney General settlement, not a CalPrivacy order, and the largest CCPA penalty at the time it was announced. Failed to honor account-wide opt-out requests across devices and streaming services.
- PlayOn Sports (March 2026): $1.1M: A CalPrivacy order, and the first to address privacy violations involving students and California schools. Its GoFan ticketing platform made ticketholders accept tracking before they could view their tickets, did not recognize Global Privacy Control, and pointed consumers at third-party ad-industry tools instead of offering an opt-out of its own.
- Ford (March 2026): $375,703: A CalPrivacy order. Required consumers to verify an email address before it would process an opt-out — friction on a right that has to be frictionless — and kept selling or sharing data for some consumers after they had opted out.
- Tractor Supply Co. (September 2025): $1.35M: Still the largest fine CalPrivacy has assessed on its own authority. Failed to honor opt-out requests and improperly shared consumer data with ad-targeting third parties.
- Honda (March 2025): $632,500: A CalPrivacy order. Required consumers to provide excessive personal information just to exercise basic privacy rights, a direct CCPA violation.
Two things changed in 2026 beyond the size of the numbers. Enforcement reached past the opt-out link into how data is collected and retained at all — GM was penalized for collecting and selling more than its stated purpose supported, not for a broken toggle. And in August 2026 CalPrivacy turned to data brokers. LocateSmarter drew $116,490 in the Agency's first action against a broker under both the CCPA and the Delete Act — the CCPA half for demanding the last four digits of a Social Security number before it would process an opt-out. Cybba drew $52,400 two days later for never registering with the Data Broker Registry, a Delete Act count carrying no CCPA violation. The two total $168,890, and they put businesses that never thought of themselves as brokers inside the enforcement perimeter.
The pattern is clear: GPC non-compliance, data sharing without proper disclosure, and making it difficult for consumers to exercise their rights are the top triggers.
How to Protect Your Business
The most important step you can take is getting an independent compliance audit that tests your site the way regulators do: from the outside, at the network layer.
Most consent management platforms can't help you here because they don't see what happens at the network level. They manage consent preferences, but they can't detect when a shadow pixel fires anyway, or when a tracker loads before the consent check completes.
Not sure where to start? Work through our full CCPA compliance checklist to see exactly which requirements apply to your business.
Get Ahead of Enforcement
Our independent audit finds what CMPs miss. 24-hour turnaround.
Schedule Your Audit