{
 "jurisdiction_id": "US-CA",
 "jurisdiction": "United States – California",
 "url": "https://dataprotection.gi/jurisdictions/united-states-california/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 48,
  "sub_modules": 57,
  "source_register": 26
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core CCPA/CPRA regime is in force and being actively enforced, but major implementing regulations (ADMT, risk assessments, cybersecurity audits) only became applicable January 1, 2026 (ADMT opt-out/access duties phase in further to January 1, 2027), and several rulemakings (Delete Act DROP mechanics, opt-out preference signal 'OOPS' rulemaking, SB 976 age-assurance rules) remain in progress in mid-2026.",
   "claims": [
    {
     "statement": "The California Privacy Protection Agency (CPPA) is the state's dedicated privacy regulator responsible for administrative enforcement of the CCPA/CPRA, operating alongside the Attorney General's continuing civil enforcement role.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In November 2020, California voters passed Proposition 24 (CPRA), which amended the CCPA of 2018 and established the CPPA, with the CPPA authorized to adopt and amend regulations under both the CCPA/CPRA and the Delete Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Office of Administrative Law approved the CPPA's regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), and insurance companies in September 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/2025/20250923.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The exemptions for employment-related personal information and personal information reflecting business-to-business transactions under Civil Code § 1798.145(m)-(n) expired on December 31, 2022, bringing employee and B2B data within CCPA scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data brokers under the Delete Act must honor opt-out and deletion requests submitted through the CPPA's DROP portal, which applies requests across all registered brokers, with per-incident penalties for non-compliant or unregistered brokers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Sensitive-data and consent-quality rules are well developed and recently strengthened via the 2025 regulations package, but California has no GDPR Article 6-style enumerated lawful-basis catalogue, which is a structural divergence from omnibus regimes.",
   "claims": [
    {
     "statement": "Under the 2026 CCPA regulations, consent/opt-out methods must not use double negatives, misleading statements, omissions, affirmative misstatements, or deceptive language, and a consumer's silence or failure to act affirmatively does not constitute consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The regulations require 'symmetry in choice,' meaning the path to exercise a more privacy-protective option cannot be longer, more difficult, or more time-consuming than the path to a less privacy-protective option.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPRA created a new 'sensitive personal information' category and corresponding right to correct and heightened protections beyond the CCPA baseline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/top-10-operational-impacts-of-the-cpra",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AB 713 exempts information deidentified in accordance with HIPAA's expert-determination or safe-harbor methods, where the underlying data was derived from HIPAA, CMIA, or Common Rule-protected patient information, and this exemption is lost if the information is re-identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/california-on-the-verge-of-instituting-new-deidentification-requirements-broader-research-exemptions",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are well codified and enforced, though ADMT-specific access/opt-out rights do not become mandatory until January 1, 2027.",
   "claims": [
    {
     "statement": "The CCPA confers on consumers the right to know what personal information businesses are collecting about them and how that information is being used and shared.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/sites/all/files/agweb/pdfs/privacy/ccpa-isor-appendices.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have the right to delete personal information held by businesses and to stop the sale of that information, and the CPRA introduced the right to correct inaccurate personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/sites/all/files/agweb/pdfs/privacy/ccpa-isor-appendices.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "If a business uses ADMT to make significant decisions about a consumer (e.g., employment, housing, financial services, education, or healthcare), the consumer has the right to notice, to opt out where applicable, and to request meaningful information about how the ADMT functioned; businesses must comply with ADMT-specific requirements by January 1, 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Businesses must generally respond to verifiable consumer requests within 45 days, with the possibility of a 45-day extension, per the CCPA request-handling regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security, breach-notification, and new risk-assessment/cyber-audit duties are robust and now in force, but DPO appointment and formal ROPA are structural gaps relative to GDPR-style omnibus regimes.",
   "claims": [
    {
     "statement": "The CPPA's 2025 regulations require a risk assessment whenever a business processes personal information presenting heightened risk, including selling/sharing personal information, processing sensitive personal information, using ADMT for a significant decision, or using personal information to train ADMT.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPRA expands contractual requirements for service providers, contractors, and third parties, including new due-diligence duties and enforceable obligations governing downstream data flows.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/top-10-operational-impacts-of-the-cpra",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Civil Code §1798.100(e) of the CPRA obligates businesses collecting consumers' personal information to implement reasonable security procedures and practices appropriate to the nature of the information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California law requires a business or agency to notify affected California residents whenever their unencrypted personal information was acquired, or reasonably believed to have been acquired, by an unauthorized person, and requires submission of a sample notice to the Attorney General when more than 500 residents are affected by a single breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/privacy/databreach/reporting",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CPPA enforcement leadership has signaled increased focus on data minimization and purpose limitation as 'fundamental' CCPA principles going forward, alongside opt-out compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/higher-fines-age-assurance-on-california-s-agenda-enforcement-to-ramp-up-in-other-states",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No CCPA/CPRA adequacy, transfer-impact-assessment, or localisation regime exists; this is a genuine structural gap relative to omnibus regimes and is not a research omission.",
   "claims": [
    {
     "statement": "The CPRA's expanded contractual requirements for service providers, contractors, and third parties govern onward disclosure of personal information, including due-diligence duties over downstream data flows, functioning as California's de facto transfer-control mechanism in place of a dedicated cross-border transfer regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/top-10-operational-impacts-of-the-cpra",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are data-level rather than entity-level in most cases, creating residual CCPA exposure (e.g., non-PHI health data, employee data) that businesses frequently misjudge.",
   "claims": [
    {
     "statement": "The CCPA/CPRA provides only partial exemptions for financial institutions, applying solely to data subject to GLBA, while still requiring compliance with CCPA data-security requirements, in contrast to broader entity-level exemptions offered by some other state privacy laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://www.dataguidance.com/opinion/usa-interaction-glba-and-ccpacpra",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Protected health information collected by a covered entity governed by HIPAA or medical information governed by California's Confidentiality of Medical Information Act (CMIA) is exempt from the CCPA, but this exemption does not extend to entities not covered by HIPAA or CMIA, such as pharmaceutical companies, wearables, fitness apps, or genetic test services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/paging-all-health-care-privacy-pros-cacpa-deserves-your-attention-despite-hipaa-exemption",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPRA's HIPAA-related exemptions apply at the data level rather than the entity level, exempting protected health information and CMIA-governed medical information while leaving other personal information held by the same health care entities subject to CPRA obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/filling-the-void-the-2023-state-privacy-laws-and-consumer-health-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The exemptions for employment-related personal information and B2B personal information under Civil Code §1798.145(m)-(n) expired on December 31, 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/faq.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2025 CPPA risk-assessment regulations specifically flag automated processing used to infer attributes about a person during education, job seeking, employment, or independent contracting as a risk-assessment-triggering use of ADMT.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA's September 2025 regulations include provisions clarifying when insurance companies must comply with the CCPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/2025/20250923.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core cookie/cross-context-advertising and dark-pattern rules are in force, but the OOPS and friction-reduction rulemakings remain preliminary/not-yet-formal as of mid-2026, and clean-room/data-collaboration-room practices are not directly addressed by any CCPA provision identified in research.",
   "claims": [
    {
     "statement": "The CPRA's 2025 rulemaking removed prior draft references to 'behavioral advertising' and 'artificial intelligence' as standalone defined terms in the ADMT text while retaining coverage of tools that place consumers into audience groups to target ads via the sale/share framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the 2026 CCPA regulations, a method that does not comply with the required consent/opt-out standards may be considered a dark pattern, and any agreement obtained through dark patterns does not constitute valid consumer consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/meetings/materials/20250404_item6_draft_text.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A California appellate court ruled in 2023 that the CPPA could immediately enforce its first set of CPRA regulations, which include mandatory recognition of opt-out preference signals, ending a period of suspended enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/state-appeals-court-rules-cpra-regulations-can-take-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of April 2026, the CPPA's 'Opt-out Preference Signals (OOPS)' rulemaking remained at the preliminary comment stage, with the preliminary comment period closing April 6, 2026, and no proposed regulation package yet advanced to formal rulemaking.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Notice of Right to Opt-out of Sale/Sharing and associated 'Do Not Sell or Share My Personal Information' link inform consumers of their right to direct a business to stop selling or sharing their personal information, including for cross-context behavioral advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://www.cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_mod_txt_pro_reg.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "ADMT/AI-risk rules are finalized but not fully phased in (opt-out/access duties effective 2027); the final ADMT text notably removed express references to 'artificial intelligence' as a defined term, narrowing the regulation's direct AI framing even though its substantive scope covers many AI use cases.",
   "claims": [
    {
     "statement": "The CPPA's final ADMT rules only allow ADMT opt-outs when the technology is used in decisions where it replaces or substantially replaces human decision-making, narrower than the 2023 draft's broader profiling triggers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the final ADMT rules, 'human involvement' requires a reviewer who knows how to interpret an ADMT-driven output, reviews the output and related information, and has authority to change or correct the final decision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The final ADMT regulations removed prior draft references to artificial intelligence and behavioral advertising as defined terms while widening the scope of circumstances in which ADMT can be used.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CPPA Executive Director Tom Kemp indicated the projected economic impact of the final ADMT/risk-assessment/cyber-audit rules decreased to about $4.8 billion in compliance costs over 10 years, against an estimated $282 billion in economic benefits over the same period.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA's original 2023 draft ADMT regulations proposed coverage of profiling consumers in publicly accessible places (e.g., shopping malls, medical offices, stadiums) using technologies such as facial recognition or automated emotion assessment.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/2023/20231127.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The regulatory picture for minors is unusually dynamic: AADCA is only partially operative pending further litigation, SB 976's core protections are in force but its implementing age-assurance regulations are still in rulemaking, and dependent-adult protections are a genuine gap.",
   "claims": [
    {
     "statement": "SB 976 requires the California Attorney General to adopt regulations regarding age assurance and parental consent methods by January 1, 2027, with a written comment period on proposed regulations closing June 30, 2026.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/sb976",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its March 2026 decision in NetChoice v. Bonta, the Ninth Circuit found that NetChoice did not show the AADCA's coverage or age-estimation mandate violated the First Amendment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://www.dataguidance.com/news/california-us-court-appeals-ninth-circuit-issues",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "SB 976 makes it unlawful for online platforms to provide addictive feeds and certain features to minors without first obtaining verifiable parental consent, and prohibits sending notifications between midnight and 6am to users not established to be over 18 absent parental consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/news/press-releases/attorney-general-bonta%E2%80%99s-sponsored-bill-protect-children-social-media-addiction",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ninth Circuit in NetChoice v. Bonta found the AADCA's data protection and dark patterns provisions unconstitutionally vague, and held that NetChoice failed to prove the law's remaining provisions were severable from the enjoined Data Protection Impact Assessment requirement.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://www.dataguidance.com/news/california-us-court-appeals-ninth-circuit-issues",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ninth Circuit's March 2026 ruling specifically vacated the injunction as to the AADCA's provisions restricting the collection, use, and sale of children's data and the collection of a child's geolocation information without an obvious sign to the child.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Department of Justice",
     "source_url": "https://oag.ca.gov/news/press-releases/attorney-general-bonta-and-governor-newsom-issue-statement-appellate-court",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-california/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement is active, well-resourced, and escalating, with a clear penalty structure and a track record of publicized settlements through 2025-2026, though the narrow private right of action and reliance on UCL-based class actions constrain direct consumer litigation.",
   "claims": [
    {
     "statement": "The CPPA can investigate possible violations on its own initiative or upon the sworn complaint of any person, and the potential administrative fine is up to $2,500 per violation or $7,500 per intentional violation, with increased potential fines for violations involving consumers under 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A business shall not be required by the agency, a court, or otherwise to pay both an administrative fine and a civil penalty for the same violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Recent CPPA enforcement actions include a $1.35 million fine and business-practice changes required of Tractor Supply Company, a $632,500 fine against American Honda Motor Co., and a $345,178 fine against Todd Snyder, Inc. for CCPA violations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPPA Board issued decisions requiring Rickenbacher Data LLC (d/b/a Datamasters) to pay a $45,000 fine and stop selling all Californians' personal information, and S&P Global, Inc. to pay a $62,600 fine, both for failing to register as data brokers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Plaintiffs have pled CCPA violations as predicate 'unlawful activity' under California's Unfair Competition Law even in cases like Almeida v. Slickwraps and Burke v. Clearview AI where a standalone CCPA private right of action claim may not lie.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ccpa-litigation-shaping-the-contours-of-the-private-right-of-action",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 1798.150(a)(1) limits the CCPA private right of action to consumers whose nonencrypted and nonredacted personal information (as defined by the narrower Customer Records Act at §1798.81.5(d)(1)(A)) is subject to unauthorized access and exfiltration, theft, or disclosure due to a business's failure to implement reasonable security procedures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-cpra-part-10-enforcement-and-potential-penalties",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In November 2025, CalPrivacy launched a Data Broker Enforcement Strike Force, and in November 2025 California approved final Delete Act regulations governing the DROP accessible-deletion mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Privacy Protection Agency",
     "source_url": "https://cppa.ca.gov/announcements/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of the start of 2026, California's Delete Act delete-request/opt-out platform (DROP) launched and CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}