Safeguarding personal data is more crucial than ever. The California Consumer Privacy Act (CCPA) gives California residents greater control over their personal information while requiring qualifying businesses to implement privacy and data protection practices.
Since the CCPA took effect in 2020, California has continued to expand its privacy requirements through the California Privacy Rights Act (CPRA) and regulations issued by the California Privacy Protection Agency (CPPA). In 2026, new requirements addressing privacy risk assessments, cybersecurity audits, data minimization, and automated decision-making technology (ADMT) have further expanded the scope of CCPA compliance.
The CPRA amended the CCPA rather than creating a separate privacy law, and the CPPA is responsible for implementing and enforcing the CCPA and its regulations.
The CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds:
The law can apply to organizations located outside California if they meet the applicable requirements and process California residents’ personal information.
CCPA compliance is not just a legal requirement—it is a business imperative. Noncompliance can result in regulatory penalties, legal exposure, and reputational damage. Organizations should view privacy as an ongoing component of their broader risk management program.
Achieving and maintaining CCPA compliance requires more than technical controls; it demands a privacy-centric mindset throughout the organization. Leadership commitment, employee training, clear policies, and regular communication can help embed privacy into everyday business practices.
Organizations should also incorporate data minimization and purpose limitation into their privacy programs. Businesses should evaluate whether the personal information they collect, use, disclose, and retain is reasonably necessary and proportionate to the purpose for which it is processed.
This means regularly asking:
Embedding these practices into product development, marketing, customer support, procurement, and other business processes can help reduce privacy risk while strengthening customer trust.
A cornerstone of the CCPA is empowering consumers with rights over their personal information. These include the right to:
Organizations should maintain transparent processes to receive, verify, track, and respond to consumer requests within required timeframes.
Third-party relationships can create significant privacy risks. Organizations should maintain an inventory of vendors, service providers, contractors, advertising partners, analytics providers, and other third parties that receive personal information.
Contracts and operational processes should address applicable requirements for the use, disclosure, retention, deletion, and security of personal information. Organizations should also determine whether third-party relationships constitute a sale or sharing of personal information under the CCPA.
This is particularly important for digital advertising and marketing technologies, where personal information may be transmitted through cookies, pixels, SDKs, analytics tools, or other tracking technologies.
Organizations that may qualify as data brokers should also evaluate their separate obligations under California’s Delete Act and Delete Request and Opt-Out Platform (DROP).
The CCPA regulations that took effect January 1, 2026, introduced significant new requirements for certain businesses.
Certain businesses must conduct privacy risk assessments for processing activities that present significant risks to consumers’ privacy. These assessments should evaluate the benefits and risks of processing and the safeguards used to mitigate those risks.
Applicable businesses must begin complying with these requirements in 2026, with specified attestations and summaries due beginning April 1, 2028.
The new regulations also establish annual cybersecurity audit requirements for certain businesses whose processing presents significant cybersecurity risks. Certification deadlines are phased according to revenue, beginning April 1, 2028, for businesses with annual gross revenue exceeding $100 million.
Organizations should begin evaluating their cybersecurity controls, risk management practices, testing, and documentation well before their applicable deadline.
The CCPA’s new ADMT requirements address certain uses of automated decision-making technology, including technology used to make significant decisions about consumers. Applicable requirements begin January 1, 2027.
Organizations using AI or other automated decision-making systems should begin identifying where these technologies are used, what personal information they process, what decisions they influence, and whether applicable consumer notices, opt-out mechanisms, or other requirements apply.
CCPA compliance is not a one-time project. California’s privacy landscape continues to evolve, and organizations should regularly monitor regulatory developments, assess their compliance posture, and update policies and controls.
For 2026 and beyond, organizations should pay particular attention to privacy risk assessments, cybersecurity audits, data minimization, sensitive personal information, automated decision-making and AI, advertising and tracking technologies, and data broker requirements.
A proactive approach can help organizations identify compliance gaps before they become regulatory or operational problems.
BARR Advisory helps organizations assess their privacy posture, identify compliance gaps, and strengthen privacy and cybersecurity programs. Our team can support data assessments, consumer-rights processes, third-party risk management, and readiness for applicable CCPA risk assessments and cybersecurity audits.
Contact us to discuss your organization’s privacy and compliance needs.