What is CCPA Compliance?

September 8, 2026 | Compliance, Cybersecurity, Privacy

Safeguarding personal data is more crucial than ever. The California Consumer Privacy Act (CCPA) gives California residents greater control over their personal information while requiring qualifying businesses to implement privacy and data protection practices.

Since the CCPA took effect in 2020, California has continued to expand its privacy requirements through the California Privacy Rights Act (CPRA) and regulations issued by the California Privacy Protection Agency (CPPA). In 2026, new requirements addressing privacy risk assessments, cybersecurity audits, data minimization, and automated decision-making technology (ADMT) have further expanded the scope of CCPA compliance.

The CPRA amended the CCPA rather than creating a separate privacy law, and the CPPA is responsible for implementing and enforcing the CCPA and its regulations. 

Understanding the Scope and Impact of the CCPA

The CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds:

  • Annual gross revenues of $26.625 million or more in the preceding calendar year;
  • Buy, sell, or share the personal information of 100,000 or more California residents or households; or,
  • Derive 50% or more of annual revenues from selling or sharing California residents’ personal information.

The law can apply to organizations located outside California if they meet the applicable requirements and process California residents’ personal information.

CCPA compliance is not just a legal requirement—it is a business imperative. Noncompliance can result in regulatory penalties, legal exposure, and reputational damage. Organizations should view privacy as an ongoing component of their broader risk management program.

Building a Privacy-First Culture Across Your Organization

Achieving and maintaining CCPA compliance requires more than technical controls; it demands a privacy-centric mindset throughout the organization. Leadership commitment, employee training, clear policies, and regular communication can help embed privacy into everyday business practices.

Organizations should also incorporate data minimization and purpose limitation into their privacy programs. Businesses should evaluate whether the personal information they collect, use, disclose, and retain is reasonably necessary and proportionate to the purpose for which it is processed.

This means regularly asking:

  • What personal information are we collecting?
  • Why do we need it?
  • How long should we retain it?
  • Who has access to it?
  • Can we accomplish the same objective with less personal information?

Embedding these practices into product development, marketing, customer support, procurement, and other business processes can help reduce privacy risk while strengthening customer trust.

Implementing Robust Consumer Rights Management Processes

A cornerstone of the CCPA is empowering consumers with rights over their personal information. These include the right to:

  • Know/access personal information and information about how it is used;
  • Delete personal information, subject to applicable exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information in applicable circumstances;
  • Limit certain uses and disclosures of sensitive personal information; and
  • Exercise these rights without unlawful discrimination.

Organizations should maintain transparent processes to receive, verify, track, and respond to consumer requests within required timeframes.

Managing Third-Party Risk and Personal Information

Third-party relationships can create significant privacy risks. Organizations should maintain an inventory of vendors, service providers, contractors, advertising partners, analytics providers, and other third parties that receive personal information.

Contracts and operational processes should address applicable requirements for the use, disclosure, retention, deletion, and security of personal information. Organizations should also determine whether third-party relationships constitute a sale or sharing of personal information under the CCPA.

This is particularly important for digital advertising and marketing technologies, where personal information may be transmitted through cookies, pixels, SDKs, analytics tools, or other tracking technologies.

Organizations that may qualify as data brokers should also evaluate their separate obligations under California’s Delete Act and Delete Request and Opt-Out Platform (DROP).

Preparing for New 2026 CCPA Requirements

The CCPA regulations that took effect January 1, 2026, introduced significant new requirements for certain businesses.

Privacy Risk Assessments

Certain businesses must conduct privacy risk assessments for processing activities that present significant risks to consumers’ privacy. These assessments should evaluate the benefits and risks of processing and the safeguards used to mitigate those risks.

Applicable businesses must begin complying with these requirements in 2026, with specified attestations and summaries due beginning April 1, 2028.

Cybersecurity Audits

The new regulations also establish annual cybersecurity audit requirements for certain businesses whose processing presents significant cybersecurity risks. Certification deadlines are phased according to revenue, beginning April 1, 2028, for businesses with annual gross revenue exceeding $100 million.

Organizations should begin evaluating their cybersecurity controls, risk management practices, testing, and documentation well before their applicable deadline.

Automated Decision Making and AI

The CCPA’s new ADMT requirements address certain uses of automated decision-making technology, including technology used to make significant decisions about consumers. Applicable requirements begin January 1, 2027.

Organizations using AI or other automated decision-making systems should begin identifying where these technologies are used, what personal information they process, what decisions they influence, and whether applicable consumer notices, opt-out mechanisms, or other requirements apply.

Ongoing Monitoring and Adapting to Regulatory Changes

CCPA compliance is not a one-time project. California’s privacy landscape continues to evolve, and organizations should regularly monitor regulatory developments, assess their compliance posture, and update policies and controls.

For 2026 and beyond, organizations should pay particular attention to privacy risk assessments, cybersecurity audits, data minimization, sensitive personal information, automated decision-making and AI, advertising and tracking technologies, and data broker requirements.

A proactive approach can help organizations identify compliance gaps before they become regulatory or operational problems.

How BARR Advisory Can Help

BARR Advisory helps organizations assess their privacy posture, identify compliance gaps, and strengthen privacy and cybersecurity programs. Our team can support data assessments, consumer-rights processes, third-party risk management, and readiness for applicable CCPA risk assessments and cybersecurity audits.

Contact us to discuss your organization’s privacy and compliance needs.

Let's Talk