OvalEdge Blog: Data Catalog and Metadata Management Tips

CCPA Data Compliance in 2026: What Businesses Need to Know

Written by OvalEdge Team | Aug 12, 2026, 10:38:34 AM

CCPA data compliance in 2026 means more than updating a privacy policy and adding an opt-out link.

New regulations that took effect January 1, 2026, introduced mandatory risk assessments, independent cybersecurity audits, and rules governing automated decision-making technology, with phased deadlines stretching through 2030.

The enforcement climate has shifted to match.

In May 2026, the California Attorney General  secured a $12.75 million settlement with General Motors, the largest CCPA penalty in history, over the undisclosed sale of drivers' location and behavioral data.

That followed a string of six- and seven-figure fines throughout 2025 for failures as specific as non-functional opt-out links and ignored browser-based privacy signals.

This guide walks compliance, legal, and data governance teams through every 2026 obligation: what each requirement demands operationally, where the deadlines fall, and the tools that make sustained compliance realistic rather than theoretical.

What is CCPA data compliance?

CCPA data compliance refers to the process of meeting the obligations established by the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), which together regulate how businesses collect, use, store, share, and delete the personal information of California residents.

Compliance applies to any covered business, regardless of its headquarters location.

It is built around the five pillars of data privacy compliance for organizations:

  • Transparency and disclosure: telling consumers what data you collect, why, and who receives it.

  • Consumer rights fulfillment: operationalizing requests to access, delete, correct, and opt out.

  • Reasonable security safeguards: protecting personal information with controls proportionate to the data's sensitivity.

  • Accountability and documentation: maintaining records that prove compliance, including risk assessments and audit trails.

  • Vendor and service provider obligations: ensuring every downstream partner handles data under the same contractual standards.

Starting in 2026, these pillars extend into new territory. Businesses now face formal requirements for privacy risk assessments, independent cybersecurity audits, and automated decision-making technology (ADMT) disclosures, each with its own deadlines and documentation standards covered in the sections that follow.

CCPA compliance requirements 2026: What's new

The revised CCPA regulations approved by the California Office of Administrative Law in September 2025 represent the most significant expansion of the law since the CPRA took effect in 2023. Here is a fast-scan summary of CCPA compliance requirements for 2026. Each of these areas gets a dedicated deep dive later in this guide.

Immediate requirements effective January 1, 2026

Three changes took effect at the start of 2026.

First, businesses must now display a visible confirmation when a consumer's opt-out request has been processed, replacing the old "request received" pattern with proof of completion.

Second, the right-to-know window expanded, meaning consumers can now request access to personal information collected beyond the previous 12-month lookback.

Third, insurance companies received specific guidance clarifying when CCPA obligations apply to their policyholder data handling, closing a longstanding gray area.

Privacy policy and notice-at-collection updates

Privacy policies now require expanded disclosures in several areas: historical data access rights (reflecting the extended lookback), all categories of sensitive personal information collected, and any use of automated decision-making technology in decisions that affect consumers. Notice-at-collection requirements were also tightened.

Businesses must present these disclosures at or before the point of data collection, not buried in a general privacy page that consumers are unlikely to visit.

Pro tip: Treat this as an audit of every data collection touchpoint, not just your website footer. Forms, mobile apps, in-store kiosks, and call center scripts all need notice-at-collection language reviewed against the updated requirements.

 

Phased deadlines through 2030

Not everything hits at once. The CPPA structured the new obligations on a rolling timeline, giving businesses runway based on the obligation type and, for cybersecurity audits, revenue tier.

Requirement

Applies to

Deadline

Risk assessments (begin conducting)

Businesses with high-risk processing activities

January 1, 2026

Risk assessment attestations

Same as above

April 1, 2028

ADMT consumer rights compliance

Businesses using ADMT for significant decisions

January 1, 2027

Cybersecurity audit attestation

Revenue > $100M

April 1, 2028

Cybersecurity audit attestation

Revenue $50M–$100M

April 1, 2029

Cybersecurity audit attestation

Revenue < $50M

April 1, 2030

Taken together, these deadlines mean most businesses are already inside at least one compliance window, even if the furthest-out obligations don't land until 2030.

Who must comply with CCPA in 2026

CCPA applicability is threshold-based, not company-size-based. A 50-person startup can be covered, while a large manufacturer with no California consumer data is not.

The three qualifying thresholds

A business must comply with CCPA if it meets any one of these criteria:

  • Annual gross revenue exceeding $26,625,000 (adjusted for inflation from the original $25M threshold,  per the CPPA).

  • 50% or more of annual revenue is derived from selling or sharing California consumers' personal information.

  • Processing personal information of 100,000 or more California residents, households, or devices annually.

Meeting just one threshold triggers the full set of obligations, including the new 2026 requirements for risk assessments, cybersecurity audits, and ADMT disclosures.

Multi-state and out-of-state businesses

Physical presence in California is not required. Consider a SaaS company headquartered in Texas that offers a freemium product nationally. If its user base includes 100,000 or more California residents, it crosses the third threshold and falls under full CCPA jurisdiction, including the obligation to honor Global Privacy Control signals from those users' browsers and respond to DSARs within 45 days.

Did you know? The CPPA's enforcement actions already include out-of-state companies. Todd Snyder, a New York-based clothing retailer, was fined $345,178 in May 2025 for opt-out and vendor management violations on its website, despite having no California offices.

 

Core consumer rights businesses must operationalize

The seven consumer rights under CCPA are not abstract legal entitlements. They are operational obligations that require intake systems, response workflows, verification protocols, and documented timelines.

The question for compliance teams is not "what can consumers ask for" but "what does my team need to build and maintain to fulfill these requests at scale," often with the help of dedicated data privacy compliance automation built for exactly this purpose.

Right to know and access

Consumers can request the specific categories of personal information collected about them, the sources it came from, the business purposes behind collection, and every third party that received it. The 2026 regulations expanded this right by removing the previous 12-month lookback limit.

Businesses must now be prepared to surface historical data going back further, which means retention policies and data inventories need to account for records that may have previously been considered out of scope.

Right to delete

When a consumer submits a deletion request, the obligation extends beyond the business's own systems. Service providers and contractors holding downstream copies must also be notified and must delete within the same 45-day response window.

Exceptions exist for data needed for legal compliance, fraud prevention, and completing an ongoing transaction, but each exception must be documented and disclosed to the requesting consumer.

Right to correct

Consumers can request corrections to inaccurate personal information. The business must apply a verification standard proportionate to the sensitivity of the data involved and respond within 45 days.

This is the right that most teams overlook when designing their DSAR intake process, often because correction requests require write-back capabilities that delete and access workflows do not.

Right to opt out of sale and sharing

This right carries the most operational weight in 2026. Consumers can opt out through direct links, universal opt-out mechanisms, or Global Privacy Control (GPC) browser signals. The 2026 regulations now require businesses to display a visible confirmation that the opt-out has been honored, not just an acknowledgment that the request was received.

GPC signal handling is a major enforcement flashpoint. Multiple fines in 2025 and 2026 targeted businesses that either ignored GPC signals entirely or had opt-out mechanisms that did not actually stop data sharing on the backend.

One mid-size e-commerce company addressed this by pairing GPC detection with a visible "Opt-Out Honored" confirmation state, backed by automated suppression rules across its three advertising and analytics platforms, so the confirmation triggered real suppression rather than just a UI change.

Right to limit use of sensitive personal information

Sensitive personal information under CCPA includes Social Security numbers, financial account details, precise geolocation, racial or ethnic origin, and, as of 2026, neural data. When a consumer exercises this right, the business must restrict processing of their sensitive data to only the purposes disclosed at collection. Any secondary use requires separate, explicit consent.

Non-discrimination

Businesses cannot penalize consumers for exercising their privacy rights through denied service, degraded quality, or different pricing. Financial incentive programs tied to data collection remain permissible, but they face heightened scrutiny for dark-pattern risk, particularly if opting out of the incentive is harder than opting in.

DSAR workflow automation

Operationalizing these rights at scale requires centralized intake across every channel consumers use to submit requests: web portals, email, phone, and physical mail, all feeding into a single queue. Verification must be tiered proportionate to data sensitivity, with lighter checks for access requests and stronger identity confirmation for deletion or correction.

Standard response timelines are 45 days, extendable to 90 with notice. CCPA requests involving automated decision-making technology will have shorter timelines once those provisions take effect in January 2027. Building workflows around these timelines now can prevent a costly rebuild later. The right data privacy tools can automate much of the intake and verification process.

How to conduct a CCPA risk assessment

Risk assessments are now a formal, documented requirement under the revised CCPA regulations, not a best-practice suggestion. Any business engaged in one of six designated high-risk processing activities must conduct an assessment before initiating or continuing that activity, starting January 1, 2026.

Data mapping and inventory as the compliance foundation

A CCPA risk assessment is only as reliable as the data inventory underneath it. Before assessing risk, teams need a clear picture of what personal information the business holds, where it lives, and how it flows between systems and third parties. That means auditing across departments, including marketing, sales, support, HR, and finance, and centralizing the results into a single, maintained record.

Pro tip: Risk assessments fail when they are built on incomplete data maps. A data catalog that continuously inventories and classifies personal information across systems turns the assessment from a one-time scramble into a repeatable process.

The six "significant risk" processing activities that trigger a required assessment

The CPPA defined six categories of processing that require a documented risk assessment:

  1. Selling or sharing personal information

  2. Processing sensitive personal information beyond the purpose disclosed at collection

  3. Using ADMT to make significant decisions about consumers

  4. Using personal information to train ADMT

  5. Processing personal information for systematic observation of consumers (including surveillance and location tracking)

  6. Processing personal information for automated profiling in employment, credit, housing, healthcare, or education contexts

If a business engages in any of these, an assessment is mandatory, not discretionary.

Risk assessment framework

Each assessment must weigh the business purpose against consumer impact. The CPPA's required structure follows a balancing-test format:

Component

What it covers

Purpose

The specific business objective that the processing serves

Data categories

Which categories of personal and sensitive personal information are involved

Benefits

Measurable value to the business, consumers, or public

Negative impacts

Potential harms to consumer privacy, including severity and likelihood

Safeguards

Technical and organizational controls that mitigate identified risks

Decision

Whether to proceed, modify, or prohibit the processing activity

 

Pro tip: Build this as a reusable template, not a one-off document. Every new processing activity that falls into the six categories above will require its own assessment, and regulators expect consistency across them. 

 

Documentation and attestation timeline

Businesses must begin conducting assessments in 2026 for all covered processing activities. For activities initiated before January 1, 2026, assessments must be completed by December 31, 2027.

Attestations, signed by a member of the executive management team, are due to the CPPA by April 1, 2028, and annually thereafter. Sustaining this on an ongoing basis, rather than scrambling before each deadline, is easier with dedicated data privacy compliance tooling in place.

CCPA cybersecurity audit requirements

The cybersecurity audit is a separate obligation from the risk assessment. It requires an independent evaluation of a business's security program, not a self-assessment, and carries its own trigger thresholds and deadlines.

Who's required to conduct one

Under the CPPA's cybersecurity audit rules and applicability thresholds, a business must complete an annual cybersecurity audit if its processing of personal information presents "significant risk to consumers' security."

That threshold is met if either:

  • The business derives 50% or more of its annual revenue from selling or sharing personal information, regardless of consumer volume, or

  • The business has an annual gross revenue exceeding approximately $26.6 million and, in the preceding calendar year, either processed the personal information of 250,000 or more consumers or households, or processed the sensitive personal information of 50,000 or more consumers.

These thresholds apply independently of the revenue-tiered attestation deadlines below, which only govern when a covered business must submit its first certification.

Phased deadlines by revenue tier

Unlike the processing thresholds above, which apply uniformly regardless of company size, the audit certification deadlines are staggered based on annual revenue, giving larger businesses less runway and smaller ones more time to prepare.

Annual revenue

Attestation deadline

Over $100M

April 1, 2028

$50M to $100M

April 1, 2029

Under $50M

April 1, 2030

Even businesses in the 2030 tier should treat this as a near-term planning item, not a distant deadline, given how long auditor selection and remediation work typically take.

What auditors typically evaluate

Cybersecurity audits assess whether a business maintains reasonable security measures proportionate to the volume and sensitivity of personal information it processes. Auditors typically examine:

  • Access controls and authentication protocols

  • Incident detection and response plans

  • Data retention and disposal practices

  • Vendor and third-party security requirements

  • Employee training and awareness programs

Pro tip: Start audit preparation 12 to 18 months before your applicable tier deadline. Remediation timelines for access control gaps and vendor contract updates consistently run longer than teams expect.

 

ADMT compliance: automated decision-making technology rules

ADMT is the most novel obligation in the 2026 regulatory package. Most existing CCPA compliance programs were built around data collection, sharing, and deletion. Algorithmic decision-making is new territory, and the compliance infrastructure for it does not exist in most organizations yet.

What counts as ADMT under CCPA

The regulations define ADMT coverage through the decisions it produces, not the technology itself. Any automated processing that contributes to a "significant decision" about a consumer falls in scope. Significant decisions include determinations related to:

  • Employment (hiring, termination, performance evaluation)

  • Housing (rental applications, tenant screening)

  • Credit and financial services (loan underwriting, insurance pricing)

  • Healthcare (treatment eligibility, benefit determinations)

  • Education (admissions, disciplinary actions)

If a human reviews the output but routinely rubber-stamps it, that does not exempt the system from ADMT requirements. The regulations focus on whether the technology meaningfully contributes to the outcome.

Consumer rights around ADMT

Starting January 1, 2027, when California's finalized CCPA regulations on AI, cyber audits, and risk governance take full effect, consumers gain four new rights specific to automated decision-making:

  1. Pre-use notice: Businesses must disclose that ADMT will be used before the decision is made, not after.

  2. Right to opt out: Consumers can refuse ADMT-based decisions, with limited exceptions for fraud prevention and security.

  3. Right to appeal: If a consumer disagrees with an ADMT-produced outcome, the business must provide a human review process.

  4. Right to methodology information: Consumers can request a plain-language explanation of how the ADMT system reaches its decisions.

Did you know? The CCPA's ADMT provisions go further than the EU AI Act by giving consumers a direct opt-out right rather than relying mainly on system-level risk oversight.

Operational steps to prepare before the January 2027 effective date

The compliance deadline is January 2027, but the preparation work belongs in 2026. Teams should be working through four steps now:

  • Inventory all ADMT use cases across the business, including vendor-operated tools used in hiring, credit, and customer service.

  • Update consumer-facing notices to disclose ADMT use in language that meets the pre-use notice standard.

  • Build an appeal workflow with defined escalation paths, response timelines, and documentation requirements.

  • Amend vendor contracts to include ADMT cooperation clauses requiring third-party tool providers to support opt-out requests and methodology disclosures.

These four steps map directly onto the broader CCPA compliance checklist covered later in this guide, so teams tackling ADMT readiness now are also closing out several line items on that consolidated list.

A fintech lender preparing for these rules updated its underwriting-decision notices six months ahead of the deadline, adding a plain-language disclosure explaining which factors the model weighs and how applicants can request human review. The early start gave its compliance and engineering teams enough time to build the appeal queue without rushing.

CCPA compliance checklist for 2026

This checklist consolidates every action item covered in this guide into a single cross-referenced view. Use it as a tracking document across legal, IT, and privacy teams.

Requirement

Action item

Owner

Deadline

Opt-out confirmation

Display visible confirmation when opt-out is processed

IT / Privacy

January 1, 2026

Privacy policy updates

Add historical access rights, sensitive PI categories, and ADMT disclosures

Legal / Privacy

January 1, 2026

Notice-at-collection

Review and update disclosures at every data collection touchpoint

Legal / Marketing

January 1, 2026

Data mapping

Audit and centralize data inventory across all departments

Data Governance / IT

Ongoing (prerequisite for risk assessments)

DSAR workflow

Centralize intake channels, implement tiered verification, and confirm 45-day response capability

IT / Privacy

Ongoing

Vendor contract amendments

Add ADMT cooperation, opt-out honoring, subcontractor flow-down, and annual certification clauses

Legal / Procurement

Before April 1, 2028

Risk assessments

Conduct assessments for all six high-risk processing categories

Privacy / Legal

Begin January 1, 2026; complete by December 31, 2027

Risk assessment attestations

Executive-signed attestation submitted to CPPA

Legal / Executive

April 1, 2028

ADMT consumer notices

Disclose ADMT use with a pre-use notice, opt-out mechanism, and appeal workflow

Legal / IT / Product

January 1, 2027

Cybersecurity audit prep

Engage the auditor, remediate access control and incident response gaps

IT / Security

12–18 months before the tier deadline

Cybersecurity audit attestation

Submit a signed attestation to CPPA

Security / Executive

April 1, 2028 / 2029 / 2030 (by revenue tier)

Revisit this table quarterly. Deadlines and owners will shift as new processing activities and vendor relationships come online.

CCPA enforcement and penalties

Enforcement has intensified sharply since mid-2025. The CPPA and California Attorney General are no longer issuing warnings and waiting for remediation. They are issuing fines, and the cases they are choosing send clear signals about where compliance gaps trigger the most scrutiny.

Who enforces CCPA (CPPA vs. Attorney General)

Two bodies share enforcement authority. The California Privacy Protection Agency (CPPA) handles administrative investigations and can impose fines directly through its enforcement division. The California Attorney General retains parallel civil enforcement power and tends to pursue larger, higher-profile cases. Both can act on consumer complaints submitted through the CPPA's online portal, and local district attorneys can join enforcement actions as well.

Civil penalties and fine amounts

As of January 2025, CCPA fines run up to $2,663 per unintentional violation and $7,988 per intentional violation, or any violation involving a minor's data, per the CCPA's CPI adjustment. These amounts are inflation-adjusted every odd-numbered January by the CCPA.

The numbers look manageable in isolation, but penalties are assessed per violation and per affected consumer. A single compliance failure across a database of 200,000 California residents compounds quickly into a seven- or eight-figure exposure.

Recent enforcement actions and what triggered them

Three cases illustrate the pattern:

  • General Motors ($12.75M, May 2026): The largest CCPA fine to date. The California AG, CPPA, and local district attorneys jointly brought the case over the sale of driving and location data without adequate consumer notice or opt-out mechanisms. In a settlement, the AG's office titled "consumers must be in the driver's seat".
  • Tractor Supply ($1.35M, September 2025): The CPPA found that the retailer's "Do Not Sell My Personal Information" link did not actually stop data sharing on the backend, and the company failed to honor GPC signals until mid-2024.
  • Todd Snyder ($345K, May 2025): The New York-based retailer was fined for opt-out mechanism failures and inadequate vendor contract management, demonstrating that out-of-state businesses face the same enforcement standards.

The common thread across all three: the violation was not a data breach or a deliberate act of bad faith. It was a compliance mechanism that existed on paper but did not function as intended.

Data privacy compliance software and CCPA compliance tools

This is where the guide shifts from "here is what is required" to "here is how teams are operationalizing it." The sections above outlined obligations. This section covers the categories of data privacy compliance software and CCPA compliance tools that make those obligations sustainable beyond the first compliance cycle.

What to look for in CCPA compliance software

Five capabilities separate tools that check a box from tools that actually reduce compliance risk: automated data mapping and inventory, consent and GPC signal management, DSAR intake and response automation, risk assessment workflow support, and audit-readiness reporting that generates the documentation regulators expect to see.

Categories of tools

Most compliance programs draw from four broad tool categories, each built around a different piece of the obligations covered earlier in this guide.

Category

What it does

Primary use case

Consent management platforms

Collect, store, and honor consumer consent and opt-out preferences, including GPC signals

Opt-out compliance, cookie management

Privacy governance suites

Centralize policy management, data mapping, and regulatory change tracking

Cross-regulation compliance programs

DSAR automation

Route, verify, and fulfill consumer requests across systems within statutory timelines

Rights fulfillment at scale

Cybersecurity audit / GRC tools

Assess security controls, track remediation, and generate audit-ready documentation.

Cybersecurity audit preparation

No single category covers every obligation in this guide, which is why most compliance programs end up running two or three of these in parallel rather than relying on one tool alone.

Vendor and third-party contract management

The enforcement pattern is clear: regulators are looking at vendor relationships, not just internal practices. Service provider and contractor agreements must now include clauses covering ADMT compliance cooperation, subcontractor flow-down requirements, opt-out and access request honoring, and annual compliance certifications.

The Tractor Supply and Todd Snyder cases both involved vendor management failures as contributing factors in the enforcement action.

Build vs. buy considerations

Mid-market teams with limited privacy headcount generally benefit from integrated privacy governance suites that bundle data mapping, DSAR automation, and consent management in a single platform.

Enterprise teams with established privacy programs and multiple regulatory jurisdictions may prefer assembling best-of-breed tools across categories, but should account for the integration overhead of keeping those tools synchronized as regulations evolve.

Conclusion

CCPA data compliance isn't a project with a finish line. Phased deadlines running through 2030, inflation-adjusted penalties, and expanding consumer rights all point the same way: this is an ongoing operational discipline, not a one-time build.

Every obligation in this guide traces back to the same foundation: data governance. Risk assessments, cybersecurity audits, ADMT compliance, and vendor management all depend on knowing what personal information you hold, where it lives, and how it moves.

OvalEdge gives compliance and data governance teams that foundation, mapping personal information across systems, maintaining lineage, and supporting audit-ready documentation that your team maintains continuously, not rebuilds every cycle.

Book a demo to see how data governance can power your CCPA compliance program.