{
 "jurisdiction_id": "CA",
 "jurisdiction": "Canada",
 "url": "https://dataprotection.gi/jurisdictions/canada/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 49,
  "sub_modules": 57,
  "source_register": 31
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, actively-enforced state omnibus statute with a dedicated regulator and a recently finalized major rulemaking cycle in force as of the run date.",
   "claims": [
    {
     "statement": "One of the CPPA's functions is to administer, implement, and enforce the CCPA/CPRA through administrative actions while the Attorney General retains civil enforcement powers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In November 2020, California voters approved Proposition 24 (the CPRA), which amended the CCPA and added additional privacy protections beginning January 1, 2023.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA Board adopted a regulation package updating CCPA rules and adding cybersecurity audit, risk assessment, ADMT, and insurance-sector provisions; the regulations went into effect January 1, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA broadly defines 'personal information' to include information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cpras-top-operational-impacts-part-2-defining-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA applies to certain controllers that 'do business in the State of California' regardless of where they are located, but only to the extent they process data of California residents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-california-consumer-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data broker must register annually with the CPPA by January 31 if it operated as a data broker during the previous year; failure to register by the deadline is subject to a civil penalty of $200 per day.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2024/20241030.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Structurally divergent from GDPR Art 6/9/7 architecture; no enumerated lawful bases and no independent consent-as-lawful-basis regime, which is a genuine structural gap relative to the module's GDPR-derived expectations.",
   "claims": [
    {
     "statement": "Businesses must limit the collection, use, and retention of personal information to purposes that a consumer would reasonably expect, that are compatible with disclosed purposes, or to which the consumer validly consented, and such collection/use/retention must be reasonably necessary and proportionate to those purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A user interface is a dark pattern if it has the effect of substantially subverting or impairing user autonomy, decisionmaking, or choice; the business's intent in designing the interface is a factor but not determinative.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/20230329_final_regs_text.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have a statutory right to limit the use and disclosure of their sensitive personal information collected about them under Civil Code §1798.121.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": null,
     "source_url": null,
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Publicly available information and de-identified or aggregated consumer information are excluded from the CCPA's definition of 'personal information'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cpras-top-operational-impacts-part-2-defining-business",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Comprehensive, codified rights regime with explicit statutory deadlines and CPPA/OAG consumer-facing guidance.",
   "claims": [
    {
     "statement": "California residents have the right to know what personal information businesses have collected about them and how they use and share it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California residents have the right to correct inaccurate personal information that businesses have about them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California residents have the right to delete personal information businesses have collected from them, subject to certain statutory exceptions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have the right to opt out of the sale of their personal information and the right to opt out of the sharing of their personal information for cross-context behavioral advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have the right to limit the use and disclosure of sensitive personal information collected about them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA gives consumers the right to receive answers to right-to-know requests free of charge within 45 days, in an electronic format they can transfer to another business.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-cacpa-part-3-responding-to-consumers-personal-information-access-requests",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Businesses must confirm receipt of a delete, correct, or know request within 10 business days and must substantively respond within 45 calendar days, extendable by another 45 days (90 days total) with notice to the consumer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Businesses must comply with opt-out-of-sale/sharing and limit-use requests as soon as feasibly possible, up to a maximum of 15 business days from receipt.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Materially strengthened accountability regime now in force (2026), though DPO-equivalent role and formal ROPA obligation are structurally absent versus GDPR.",
   "claims": [
    {
     "statement": "Businesses subject to risk-assessment requirements must begin compliance by January 1, 2026, and by April 1, 2028 must submit to the CPPA an attestation that required risk assessments were completed and a summary of risk-assessment information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2025/20250923.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2025 regulations limit cybersecurity-audit certification requirements to naming the highest-ranking auditor and no more than three qualified individuals responsible for the business's cybersecurity audit program.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_fsor_and_uid.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A service provider or contractor directed by a business to delete a consumer's personal information must delete it (or enable the business to delete it) and must notify its own service providers, contractors, or third parties who may have accessed the information to also delete it, absent impossibility or disproportionate effort.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-8-rights-to-delete-no-retaliation-and-childrens-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 1798.100(e) of the CCPA obligates businesses collecting consumer personal information to implement reasonable security procedures and practices to protect it from unauthorized or illegal access, destruction, use, modification, or disclosure, in accordance with Section 1798.81.5.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California law requires a business to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, and any business required to notify more than 500 California residents from a single breach must electronically submit a sample copy of that notification to the Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/databreach/reporting",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Businesses must comply with purpose-limitation and data-minimization rules limiting the collection, use, and retention of personal information to purposes reasonably necessary and proportionate to serve disclosed or reasonably expected purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists in this jurisdiction; only a generic contractual-restriction mechanism functions as a partial analogue.",
   "claims": [
    {
     "statement": "A 'service provider' under the CCPA is a processor to a 'business' that receives personal information for business purposes under a written contract containing certain mandated provisions, functioning as the CCPA's mechanism for controlling downstream data transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-california-consumer-privacy-act",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Solid coverage of financial/health/credit/employment/insurance overlays; education-sector and telecoms/ePrivacy-specific overlays are only thinly evidenced.",
   "claims": [
    {
     "statement": "The CCPA contains a set of nuanced exceptions for certain categories of information, including banking and financial information, that apply when the information is governed by another privacy-protecting statute such as GLBA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/20220708_npr.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA contains exceptions for medical records and related health information when governed by another privacy-protecting statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/20220708_npr.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA's administrative enforcement system, including its cure-period structure, is modeled on the same §17206 Business and Professions Code mechanism used to enforce the California Online Privacy Protection Act (CalOPPA), a 2003 law requiring conspicuous privacy-policy posting by PII-collecting website operators.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-cacpa-part-5-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The exemptions for employment-related personal information and personal information reflecting business-to-business transactions described in Civil Code §1798.145(m)-(n) expired on December 31, 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA contains exceptions for consumer credit reporting information that is governed by the Fair Credit Reporting Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/pdf/business_comply.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2025 CPPA rulemaking clarified when insurance companies must comply with the CCPA, adding Article 12 (General Application of the CCPA to Insurance Companies, §§7270-7271) to the regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/ccpa_updates.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "green",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Active, evolving regime with binding opt-out-signal and dark-pattern rules in force, plus a live rulemaking (OOPS) signaling further tightening.",
   "claims": [
    {
     "statement": "The Agency deleted definitions for 'artificial intelligence,' 'behavioral advertising,' 'deepfake,' 'publicly accessible place,' and 'zero trust architecture' in the 2025 final regulations because they were no longer necessary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_fsor_and_uid.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A user interface is a dark pattern if the interface has the effect of substantially subverting or impairing user autonomy, decisionmaking, or choice; a business's intent is a factor but not determinative.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/20230329_final_regs_text.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CCPA regulations (§7025, Opt-out Preference Signals) require businesses to process consumer opt-out preference signals such as Global Privacy Control as valid opt-out-of-sale/sharing requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA's Opt-out Preference Signals (OOPS) rulemaking is currently in the proposed stage; its preliminary comment period closed April 6, 2026, and the amendments were noted as directly addressing Global Privacy Control support in light of recent enforcement.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have the right to opt out of the sale of their personal information and the right to opt out of the sharing of their personal information for cross-context behavioral advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Substantively new and significant ADMT/biometric coverage now codified, but genetic-data and state-surveillance-carveout sub-modules remain evidentiary gaps, and ADMT compliance is not fully operative until Jan 1, 2027.",
   "claims": [
    {
     "statement": "The final ADMT rules only allow ADMT opt-outs when used in decisions where technologies replace or substantially replace human decision-making, with human involvement requiring a reviewer who can interpret, review, and change the final rendering of an ADMT-driven output.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Businesses that use ADMT to make significant decisions must comply with the ADMT requirements, including consumer rights to access and opt out of such use, beginning January 1, 2027.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2025/20250923.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The regulations require a risk assessment whenever a business processes data that might present a risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, or using ADMT for a significant decision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The narrower 'personal information' definition applicable to the CCPA private right of action, drawn from the Customer Records Act, includes an individual's name in combination with unique biometric data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ccpa-litigation-shaping-the-contours-of-the-private-right-of-action",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "CCPA's own under-16 opt-in rule is stable and in force, but the AADCA overlay remains in ongoing, unresolved constitutional litigation with a currently-enjoined status, creating material enforceability uncertainty.",
   "claims": [
    {
     "statement": "Although the vast majority of the California AADC remains enjoined, the Ninth Circuit found important aspects enforceable, including requirements for companies to estimate user ages; a subsequent district-court ruling has again fully enjoined the statute.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-youth-privacy-in-california-rises-again-kind-of",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CCPA regulations include an Article dedicated to Special Rules Regarding Consumers Less Than 16 Years of Age, governing opt-in consent requirements for the sale/sharing of minors' personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_ins_notice.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ninth Circuit vacated the injunction as to the AADCA's provisions restricting the collection, use, and sale of children's data and the collection of a child's geolocation information without an obvious sign to the child; a later 2026 district-court decision has again fully enjoined the law.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/news/press-releases/attorney-general-bonta-and-governor-newsom-issue-statement-appellate-court",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, well-documented enforcement program with recent significant monetary penalties and multistate coordination; regulator funding/headcount data not confirmed in this pass.",
   "claims": [
    {
     "statement": "Under Section 1798.155(a), California's Attorney General may bring an action against a violator for up to $2,500 per violation, with a higher cap of $7,500 for intentional violations under Section 1798.155(b); enterprises historically had 30 days after notice of noncompliance to cure before enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-cacpa-part-5-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Beginning in 2025, the CPPA increased monetary damages, administrative fines, civil penalties, and the business income threshold in alignment with Consumer Price Index adjustments made every other year under the CCPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2024/20241217.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CPPA-reported enforcement outcomes include a decision requiring Tractor Supply Company to pay a $1.35 million fine, a decision requiring Todd Snyder, Inc. to pay $345,178, and a decision requiring American Honda Motor Co. to pay $632,500, each for CCPA violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California class-action plaintiffs have asserted that a violation of the CCPA constitutes an 'unlawful activity' or predicate act under California's Unfair Competition Law, including in cases against Zoom and in Clearview-related facial-recognition scraping litigation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ccpa-litigation-shaping-the-contours-of-the-private-right-of-action",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A consumer may sue a business under the CCPA only where the consumer's nonencrypted and nonredacted personal information was stolen in a data breach due to the business's failure to maintain reasonable security procedures, recovering actual damages or statutory damages of up to $750 per incident, after providing 30 days' written notice allowing the business to cure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/ccpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA's Opt-out Preference Signals (OOPS) rulemaking preliminary comment period closed April 6, 2026, and, per the November 2025 Delete Act regulations, data brokers must access the DROP consumer-deletion platform at least every 45 days beginning August 1, 2026.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}