🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 31 sources retrieved model claude-sonnet-5 ·

Canada

CA schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 49 claims · 31 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
49Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

The California Privacy Protection Agency is understood to have brought its long-developing package of CCPA regulations covering automated decision-making technology, cybersecurity audits, and risk assessments into force on January 1, 2026. Businesses that trigger the risk-assessment thresholds must conduct and attest to those assessments beginning that same date, with attestation summaries due to the agency by April 1, 2028. Consumer-facing compliance with the automated-decision-making-technology rules is not mandatory until January 1, 2027, when covered businesses must honor new access and opt-out rights for significant automated decisions. Under the finalized rule, the opt-out applies only where the automated system replaces or substantially replaces human decision-making, and qualifying human involvement requires a reviewer able to interpret, review, and change the output.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, actively-enforced state omnibus statute with a dedicated regulator and a recently finalized major rulemaking cycle in force as of the run date.

Primary frameworkCalifornia Consumer Privacy Act of 2018 (Cal. Civ. Code §1798.100 et seq.), as amended by the California Privacy Rights Act of 2020; CPPA regulations at Cal. Code Regs. tit. 11, Div. 6
Traffic-light rationale — GreenComprehensive, actively-enforced state omnibus statute with a dedicated regulator and a recently finalized major rulemaking cycle in force as of the run date.

Sub-modules (5)

Regulator And AuthorityGreen

The CPPA administers, implements, and enforces the CCPA/CPRA through administrative actions, while the California Attorney General retains independent civil enforcement authority under Civil Code §1798.155.

Claims: CLM-CA-1a2b3c4d

Act And InstrumentsGreen

Core statute is the CCPA as amended by the CPRA (operative Jan 1, 2023); the 2025 CCPA Updates/ADMT/Cyber/Risk/Insurance regulation package became effective Jan 1, 2026.

Claims: CLM-CA-2b3c4d5e, CLM-CA-3c4d5e6f

Material ScopeGreen

Personal information is defined broadly to cover any information that identifies, relates to, or could reasonably be linked to a California resident or household.

Claims: CLM-CA-4d5e6f7a

Territorial ScopeGreen

The CCPA applies extraterritorially to any for-profit entity 'doing business in California' that meets statutory thresholds, regardless of where the entity is physically located, but only as to processing of California residents' data.

Claims: CLM-CA-5e6f7a8b

Regulator Registration And FilingGreen

Data brokers (entities selling PI of consumers with whom they lack a direct relationship) must register annually with the CPPA by January 31 and pay a fee; late registration triggers a per-day penalty.

Claims: CLM-CA-6f7a8b9c

Category narrative86 words

California operates a hybrid regime centered on the California Consumer Privacy Act of 2018 (CCPA) as substantially amended by the California Privacy Rights Act of 2020 (CPRA/Prop 24), enforced by the newly-created California Privacy Protection Agency (CPPA) with residual civil enforcement retained by the state Attorney General. The 2025 'CCPA Updates, Cyber, Risk, ADMT, and Insurance' rulemaking package took effect January 1, 2026, materially expanding the regulatory perimeter (risk assessments, cybersecurity audits, ADMT). Sectoral federal overlays (GLBA, HIPAA/CMIA, FCRA) carve out exemptions rather than being displaced.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPOne of the CPPA's functions is to administer, implement, and enforce the CCPA/CPRA through administrative actions while the Attorney General retains civil enforcement powers.
  2. ConfirmedCalifornia Department of JusticeIn November 2020, California voters approved Proposition 24 (the CPRA), which amended the CCPA and added additional privacy protections beginning January 1, 2023.
  3. ConfirmedIAPPThe CPPA Board adopted a regulation package updating CCPA rules and adding cybersecurity audit, risk assessment, ADMT, and insurance-sector provisions; the regulations went into effect January 1, 2026.
  4. ConfirmedIAPPThe CCPA broadly defines 'personal information' to include information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
  5. ConfirmedIAPPThe CCPA applies to certain controllers that 'do business in the State of California' regardless of where they are located, but only to the extent they process data of California residents.
  6. ConfirmedCPPAA data broker must register annually with the CPPA by January 31 if it operated as a data broker during the previous year; failure to register by the deadline is subject to a civil penalty of $200 per day.

#

Structurally divergent from GDPR Art 6/9/7 architecture; no enumerated lawful bases and no independent consent-as-lawful-basis regime, which is a genuine structural gap relative to the module's GDPR-derived expectations.

Primary frameworkCal. Civ. Code §§1798.100, 1798.121, 1798.140; Cal. Code Regs. tit. 11 §§7001-7004
Traffic-light rationale — AmberStructurally divergent from GDPR Art 6/9/7 architecture; no enumerated lawful bases and no independent consent-as-lawful-basis regime, which is a genuine structural gap relative to the module's GDPR-derived expectations.

Sub-modules (4)

Lawful BasesAmber

No enumerated lawful-basis list exists; processing is instead constrained by a 'reasonably necessary and proportionate' purpose-limitation/data-minimization standard tied to consumer expectations.

Claims: CLM-CA-7a8b9c0d

Special CategoriesGreen

Sensitive personal information (health, biometric, genetic, precise geolocation, racial/ethnic origin, sexual orientation, religious belief, etc.) carries a consumer right to limit use and disclosure under Civil Code §1798.121, rather than an outright processing prohibition absent explicit consent as under GDPR Art 9.

Claims: CLM-CA-9c0d1e2f

Pseudonymisation And AnonymisationGreen

De-identified and aggregated consumer information are excluded from the statutory definition of 'personal information', creating a functional anonymisation safe harbour.

Claims: CLM-CA-0d1e2f3a

Category narrative68 words

The CCPA does not adopt a GDPR-style enumerated 'lawful basis' framework (Art 6 analogue); instead it relies on a notice-and-opt-out model layered with statutory purpose-limitation and data-minimization duties, dark-pattern-free consent requirements for opt-ins, and an enumerated 'sensitive personal information' category carrying a right-to-limit rather than a per-se processing prohibition. De-identified and aggregate information are carved out of the 'personal information' definition, functioning as the CCPA's anonymisation safe harbour.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ProbableCPPABusinesses must limit the collection, use, and retention of personal information to purposes that a consumer would reasonably expect, that are compatible with disclosed purposes, or to which the consumer validly consented, and such collection/use/retention must be reasonably necessary and proportionate to those purposes.
  2. ConfirmedCPPAA user interface is a dark pattern if it has the effect of substantially subverting or impairing user autonomy, decisionmaking, or choice; the business's intent in designing the interface is a factor but not determinative.
  3. Confirmedsource not recorded — Consumers have a statutory right to limit the use and disclosure of their sensitive personal information collected about them under Civil Code §1798.121.
  4. ConfirmedIAPPPublicly available information and de-identified or aggregated consumer information are excluded from the CCPA's definition of 'personal information'.

#

Comprehensive, codified rights regime with explicit statutory deadlines and CPPA/OAG consumer-facing guidance.

Primary frameworkCal. Civ. Code §§1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121, 1798.130
Traffic-light rationale — GreenComprehensive, codified rights regime with explicit statutory deadlines and CPPA/OAG consumer-facing guidance.

Sub-modules (5)

Access RightGreen

Consumers have the right to know what personal information businesses have collected about them and how it is used and shared.

Claims: CLM-CA-1e2f3a4b

Rectification And ErasureGreen

Consumers have the right to correct inaccurate personal information and the right to delete personal information collected from them, subject to statutory exceptions.

Claims: CLM-CA-2f3a4b5c, CLM-CA-3a4b5c6d

Restriction And ObjectionGreen

Consumers may opt out of the sale of personal information and the sharing of personal information for cross-context behavioral advertising, and may limit use/disclosure of sensitive personal information.

Claims: CLM-CA-4b5c6d7e, CLM-CA-5c6d7e8f

Data PortabilityGreen

Right-to-know disclosures must be delivered free of charge within the statutory deadline in a portable, transferable electronic format.

Claims: CLM-CA-6d7e8f9a

Deadlines And Response WindowsGreen

Businesses must confirm receipt of delete/correct/know requests within 10 business days and substantively respond within 45 calendar days (extendable once by an additional 45 days); opt-out/limit requests must be honored within 15 business days.

Claims: CLM-CA-7e8f9a0b, CLM-CA-8f9a0b1c

Category narrative53 words

California consumers hold a materially GDPR-comparable rights bundle (know/access, correct, delete, limit, opt-out of sale/share/ADMT, non-discrimination) summarized by the CPPA under the 'CCPA rights' acronym. Response deadlines are codified: 45 calendar days for know/delete/correct requests (extendable once by 45 days), 10 business days to confirm receipt, and 15 business days for opt-out/limit requests.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedCalifornia Department of JusticeCalifornia residents have the right to know what personal information businesses have collected about them and how they use and share it.
  2. ConfirmedCalifornia Department of JusticeCalifornia residents have the right to correct inaccurate personal information that businesses have about them.
  3. ConfirmedCPPACalifornia residents have the right to delete personal information businesses have collected from them, subject to certain statutory exceptions.
  4. ConfirmedCalifornia Department of JusticeConsumers have the right to opt out of the sale of their personal information and the right to opt out of the sharing of their personal information for cross-context behavioral advertising.
  5. ConfirmedCalifornia Department of JusticeConsumers have the right to limit the use and disclosure of sensitive personal information collected about them.
  6. ConfirmedIAPPThe CCPA gives consumers the right to receive answers to right-to-know requests free of charge within 45 days, in an electronic format they can transfer to another business.
  7. ConfirmedCPPABusinesses must confirm receipt of a delete, correct, or know request within 10 business days and must substantively respond within 45 calendar days, extendable by another 45 days (90 days total) with notice to the consumer.
  8. ConfirmedCPPABusinesses must comply with opt-out-of-sale/sharing and limit-use requests as soon as feasibly possible, up to a maximum of 15 business days from receipt.

#

Materially strengthened accountability regime now in force (2026), though DPO-equivalent role and formal ROPA obligation are structurally absent versus GDPR.

Primary frameworkCal. Civ. Code §§1798.81.5, 1798.100, 1798.150, 1798.185; Cal. Code Regs. tit. 11 §§7120-7157
Traffic-light rationale — GreenMaterially strengthened accountability regime now in force (2026), though DPO-equivalent role and formal ROPA obligation are structurally absent versus GDPR.

Sub-modules (7)

Accountability And DpiaGreen

Businesses meeting risk-assessment thresholds (e.g., selling/sharing PI, processing sensitive PI, ADMT for significant decisions) must conduct risk assessments beginning January 1, 2026, and submit attestations/summaries to the CPPA by April 1, 2028.

Claims: CLM-CA-9a0b1c2d

Dpo RequirementsRed

No claims identified establishing a mandatory Data Protection Officer appointment threshold analogous to GDPR Art 37; searches of CPPA regulations text, FSOR, and OAG CCPA guidance found no independent DPO-designation mandate. This is treated as an explicit structural gap.

Ropa RequirementsAmber

The regulations require cybersecurity-audit and risk-assessment documentation and certification (e.g., naming a qualified individual/highest-ranking auditor) to be submitted to the Agency, functioning as a partial records-of-processing analogue, though there is no freestanding GDPR Art 30-style ROPA mandate.

Claims: CLM-CA-0b1c2d3e

Joint Controller ArrangementsGreen

The CCPA framework substitutes business/service-provider/contractor/third-party contractual distinctions for GDPR's joint-controller construct; a service provider or contractor directed to delete data must also notify its own downstream service providers, contractors, and third parties to delete the consumer's personal information.

Claims: CLM-CA-1c2d3e4f

Security MeasuresGreen

Businesses must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information, per Civil Code §1798.81.5, incorporated into CCPA §1798.100(e).

Claims: CLM-CA-2d3e4f5a

Breach NotificationGreen

California's breach notification statute (Civil Code §1798.82) requires notice to affected California residents and, for breaches affecting more than 500 California residents, electronic submission of a sample notice to the Attorney General.

Claims: CLM-CA-3e4f5a6b

Retention And DisposalAmber

Businesses must limit collection, use, and retention of personal information to purposes reasonably necessary and proportionate to disclosed/expected purposes, implying a retention-minimization duty though no fixed statutory retention ceiling was identified.

Claims: CLM-CA-4f5a6b7c

Category narrative87 words

Businesses ('controllers'-equivalent) face expanding accountability duties under the 2026-effective regulations: mandatory risk assessments for high-risk processing (selling/sharing PI, processing sensitive PI, ADMT for significant decisions) with attestation to the CPPA due by April 1, 2028, and annual cybersecurity audits with certification for qualifying businesses. Service-provider/contractor/third-party contractual cascades substitute for a GDPR-style Art 28/joint-controller regime. A general reasonable-security duty (Civil Code §1798.81.5, incorporated by §1798.100(e)/§1798.150) underpins both the private right of action and breach notification obligations. No independent statutory DPO-appointment threshold analogous to GDPR Art 37 was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedCPPABusinesses subject to risk-assessment requirements must begin compliance by January 1, 2026, and by April 1, 2028 must submit to the CPPA an attestation that required risk assessments were completed and a summary of risk-assessment information.
  2. ProbableCPPAThe 2025 regulations limit cybersecurity-audit certification requirements to naming the highest-ranking auditor and no more than three qualified individuals responsible for the business's cybersecurity audit program.
  3. ConfirmedIAPPA service provider or contractor directed by a business to delete a consumer's personal information must delete it (or enable the business to delete it) and must notify its own service providers, contractors, or third parties who may have accessed the information to also delete it, absent impossibility or disproportionate effort.
  4. ConfirmedIAPPSection 1798.100(e) of the CCPA obligates businesses collecting consumer personal information to implement reasonable security procedures and practices to protect it from unauthorized or illegal access, destruction, use, modification, or disclosure, in accordance with Section 1798.81.5.
  5. ConfirmedCalifornia Department of JusticeCalifornia law requires a business to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, and any business required to notify more than 500 California residents from a single breach must electronically submit a sample copy of that notification to the Attorney General.
  6. ProbableCPPABusinesses must comply with purpose-limitation and data-minimization rules limiting the collection, use, and retention of personal information to purposes reasonably necessary and proportionate to serve disclosed or reasonably expected purposes.

#

No comprehensive cross-border transfer regime exists in this jurisdiction; only a generic contractual-restriction mechanism functions as a partial analogue.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in this jurisdiction; only a generic contractual-restriction mechanism functions as a partial analogue.

Sub-modules (6)

Transfer MechanismsAmber

A 'service provider' is a data processor to a 'business' that receives personal information for business purposes under a written contract containing use restrictions; this contractual mechanism, not adequacy or SCCs, is the CCPA's operative transfer control.

Claims: CLM-CA-5a6b7c8d

Adequacy ReceivedRed

No claims identified; California/CCPA does not operate an adequacy-decision-receiving mechanism from other regimes. Searched CPPA regulations and OAG guidance; none found.

Adequacy GrantedRed

No claims identified; California does not issue adequacy determinations to other jurisdictions. Searched CPPA regulations and OAG guidance; none found.

Sccs And BcrsRed

No claims identified; the CCPA does not provide for Standard Contractual Clauses or Binding Corporate Rules instruments. Searched CPPA regulations text and OAG guidance; none found.

Transfer Impact AssessmentRed

No claims identified; no CCPA requirement for a formal Transfer Impact Assessment analogous to GDPR Schrems II practice was found in CPPA regulations or guidance searched.

Data LocalisationRed

No claims identified; no CCPA or California statute mandating in-state data localisation was found in the sources searched.

Category narrative87 words

California's regime does not operate a GDPR-style cross-border transfer architecture. There is no adequacy-decision mechanism (received or granted), no Standard Contractual Clauses or Binding Corporate Rules regime, no mandated Transfer Impact Assessment, and no data-localisation mandate. The CCPA's functional substitute is a contractual-restriction requirement imposed on service providers, contractors, and third parties receiving personal information, which applies regardless of the recipient's geographic location. Searches conducted: 'California cross-border data transfer adequacy CCPA', CPPA regulations pages, and OAG CCPA guidance; no adequacy, SCC/BCR, TIA, or localisation provisions were found.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableIAPPA 'service provider' under the CCPA is a processor to a 'business' that receives personal information for business purposes under a written contract containing certain mandated provisions, functioning as the CCPA's mechanism for controlling downstream data transfers.

#

Solid coverage of financial/health/credit/employment/insurance overlays; education-sector and telecoms/ePrivacy-specific overlays are only thinly evidenced.

Primary frameworkCal. Civ. Code §1798.145; Cal. Code Regs. tit. 11 Art. 12 (§§7270-7271)
Traffic-light rationale — AmberSolid coverage of financial/health/credit/employment/insurance overlays; education-sector and telecoms/ePrivacy-specific overlays are only thinly evidenced.

Sub-modules (7)

Financial Sector OverlayGreen

The CCPA contains exceptions for information governed by the Gramm-Leach-Bliley Act for financial institutions.

Claims: CLM-CA-6b7c8d9e

Health Sector OverlayGreen

The CCPA exempts medical/health information already governed by other privacy-protecting statutes (e.g., CMIA/HIPAA-adjacent frameworks).

Claims: CLM-CA-7c8d9e0f

Telecoms And EprivacyAmber

California's earlier California Online Privacy Protection Act (CalOPPA, 2003) required conspicuous privacy-policy posting for PII-collecting websites and provided the enforcement-model precedent later carried into CCPA administrative enforcement; no distinct ePrivacy/cookie-consent statute equivalent to EU ePrivacy was confirmed.

Claims: CLM-CA-1a2b3c4e

Employment DataGreen

The CCPA's exemption for employment-related personal information expired December 31, 2022, meaning employee data is now generally within CCPA scope.

Claims: CLM-CA-8d9e0f1a

Credit And ScoringGreen

The CCPA contains exceptions for consumer-reporting information already governed by the Fair Credit Reporting Act.

Claims: CLM-CA-9e0f1a2b

EducationRed

No claims identified for an education-sector-specific CCPA overlay in this research pass. Searched CPPA regulations page and OAG CCPA guidance; no dedicated education-sector provision was surfaced.

InsuranceGreen

The 2025 CCPA Updates regulation package added Article 12 clarifying general application of the CCPA to insurance companies.

Claims: CLM-CA-0f1a2b3c

Category narrative80 words

The CCPA carves out exemptions for information already governed by other sectoral privacy statutes (GLBA for financial institutions, HIPAA/CMIA for medical information, FCRA for consumer-reporting information) rather than layering additional obligations. The 2025 rulemaking specifically clarified when insurance companies must comply with the CCPA (new Article 12, §§7270-7271). Employment-related personal information lost its CCPA exemption on December 31, 2022, and is now generally covered. Education- and telecoms-specific overlays beyond the historical CalOPPA precedent were not confirmed in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedCPPAThe CCPA contains a set of nuanced exceptions for certain categories of information, including banking and financial information, that apply when the information is governed by another privacy-protecting statute such as GLBA.
  2. ConfirmedCPPAThe CCPA contains exceptions for medical records and related health information when governed by another privacy-protecting statute.
  3. ProbableIAPPThe CCPA's administrative enforcement system, including its cure-period structure, is modeled on the same §17206 Business and Professions Code mechanism used to enforce the California Online Privacy Protection Act (CalOPPA), a 2003 law requiring conspicuous privacy-policy posting by PII-collecting website operators.
  4. ConfirmedCalifornia Department of JusticeThe exemptions for employment-related personal information and personal information reflecting business-to-business transactions described in Civil Code §1798.145(m)-(n) expired on December 31, 2022.
  5. ConfirmedCPPAThe CCPA contains exceptions for consumer credit reporting information that is governed by the Fair Credit Reporting Act.
  6. ConfirmedCPPAThe 2025 CPPA rulemaking clarified when insurance companies must comply with the CCPA, adding Article 12 (General Application of the CCPA to Insurance Companies, §§7270-7271) to the regulations.

#

Active, evolving regime with binding opt-out-signal and dark-pattern rules in force, plus a live rulemaking (OOPS) signaling further tightening.

Primary frameworkCal. Civ. Code §§1798.120, 1798.135; Cal. Code Regs. tit. 11 §§7002, 7025-7027
Traffic-light rationale — GreenActive, evolving regime with binding opt-out-signal and dark-pattern rules in force, plus a live rulemaking (OOPS) signaling further tightening.

Sub-modules (6)

Cookies And TrackersAmber

The 2025 final regulations deleted the standalone defined term 'behavioral advertising' (along with 'artificial intelligence', 'deepfake', and others) as no longer necessary, folding cookie/tracker-based advertising into the general 'sale'/'sharing' and ADMT definitions.

Claims: CLM-CA-6f7a8b9d

Dark PatternsGreen

A user interface constitutes an unlawful dark pattern if it substantially subverts or impairs consumer autonomy, decisionmaking, or choice.

Claims: CLM-CA-2b3c4d5f

Opt Out SignalsGreen

Existing regulations (§7025) require businesses to process opt-out preference signals (e.g., Global Privacy Control) as valid consumer opt-out requests; a further OOPS rulemaking is currently proposed, with the preliminary comment period closed April 6, 2026.

Claims: CLM-CA-3c4d5e6a, CLM-CA-4d5e6f7b

Clean Rooms And DcrRed

No claims identified; no CCPA-specific data clean-room or data-collaboration-room regulation was found in the sources searched.

Cross Context AdvertisingGreen

Consumers have the right to opt out of the sharing of their personal information for cross-context behavioral advertising.

Claims: CLM-CA-5e6f7a8c

Direct MarketingAmber

No CCPA-specific direct-marketing consent/suppression regime distinct from the general sale/share opt-out and dark-patterns rules was identified; the opt-out-of-sale/sharing right functions as the operative direct-marketing control.

Category narrative73 words

California operates a mature commercial-privacy/adtech regime built around dark-pattern prohibitions, mandatory recognition of opt-out preference signals (Global Privacy Control), and a consumer right to opt out of 'sharing' for cross-context behavioral advertising (the CPRA's answer to CPRA 'sale'/'share'). A new Opt-out Preference Signals (OOPS) rulemaking is in progress, with its preliminary comment period closing April 6, 2026. The 2025 final regulations notably deleted the standalone defined term 'behavioral advertising' from the regulatory text.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedCPPAThe Agency deleted definitions for 'artificial intelligence,' 'behavioral advertising,' 'deepfake,' 'publicly accessible place,' and 'zero trust architecture' in the 2025 final regulations because they were no longer necessary.
  2. ConfirmedCPPAA user interface is a dark pattern if the interface has the effect of substantially subverting or impairing user autonomy, decisionmaking, or choice; a business's intent is a factor but not determinative.
  3. ProbableCPPACCPA regulations (§7025, Opt-out Preference Signals) require businesses to process consumer opt-out preference signals such as Global Privacy Control as valid opt-out-of-sale/sharing requests.
  4. ProbableCPPAThe CPPA's Opt-out Preference Signals (OOPS) rulemaking is currently in the proposed stage; its preliminary comment period closed April 6, 2026, and the amendments were noted as directly addressing Global Privacy Control support in light of recent enforcement.
  5. ConfirmedCalifornia Department of JusticeConsumers have the right to opt out of the sale of their personal information and the right to opt out of the sharing of their personal information for cross-context behavioral advertising.

#

Substantively new and significant ADMT/biometric coverage now codified, but genetic-data and state-surveillance-carveout sub-modules remain evidentiary gaps, and ADMT compliance is not fully operative until Jan 1, 2027.

Primary frameworkCal. Civ. Code §§1798.121, 1798.185(a)(15); Cal. Code Regs. tit. 11 Art. 11 (§§7220-7222)
Traffic-light rationale — AmberSubstantively new and significant ADMT/biometric coverage now codified, but genetic-data and state-surveillance-carveout sub-modules remain evidentiary gaps, and ADMT compliance is not fully operative until Jan 1, 2027.

Sub-modules (6)

Profiling RestrictionsAmber

Consumers may opt out of ADMT used to make significant decisions where the technology replaces or substantially replaces human decisionmaking; 'human involvement' requires a reviewer able to interpret, review, and change the ADMT output.

Claims: CLM-CA-0d1e2f3b

Automated Decision Making TransparencyAmber

Consumers have a right to access information about a business's use of ADMT with respect to them; ADMT-specific compliance obligations begin January 1, 2027.

Claims: CLM-CA-7a8b9c0e

Ai Risk AssessmentsAmber

Risk assessments are required whenever a business processes data that might present a risk to consumer privacy, including selling/sharing PI, processing sensitive PI, or using ADMT for a significant decision; the final rules removed explicit 'artificial intelligence' definitional language while retaining substantive coverage of AI-driven ADMT.

Claims: CLM-CA-8b9c0d1f

Biometric RegimeGreen

Sensitive personal information includes biometric information for identification purposes (subject to the right to limit); the narrower private-right-of-action personal-information definition separately captures 'unique biometric data,' as invoked in facial-recognition-scraping litigation.

Claims: CLM-CA-9c0d1e2a

Genetic DataRed

No claims identified for a California-specific genetic-data processing regime beyond inclusion in the general 'sensitive personal information' category. Searched CPPA regulations and FSOR text; no distinct genetic-data provision was surfaced.

State Surveillance CarveoutsRed

No claims identified for California-specific state-surveillance/national-security carve-outs to the CCPA in this research pass. Searched CPPA regulations and OAG guidance; none found.

Category narrative134 words

The 2026-effective ADMT regulations create a GDPR Art 22-adjacent regime: consumers gain a right to access information about a business's use of automated decisionmaking technology and a right to opt out of ADMT used for 'significant decisions' where the technology replaces or substantially replaces human decisionmaking, with 'human involvement' requiring a reviewer who can meaningfully change the outcome. ADMT-specific compliance is required from January 1, 2027. Risk-assessment triggers extend to ADMT and sensitive-data processing. Biometric information is captured within the 'sensitive personal information' category and separately within the narrower private-right-of-action 'personal information' definition (unique biometric data). Notably, the final regulations removed explicit references to 'artificial intelligence' and 'behavioral advertising' from the ADMT text, narrowing its footprint relative to the initial 2024 proposal. Genetic-data-specific rules and state-surveillance/national-security carve-outs were not separately confirmed in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedIAPPThe final ADMT rules only allow ADMT opt-outs when used in decisions where technologies replace or substantially replace human decision-making, with human involvement requiring a reviewer who can interpret, review, and change the final rendering of an ADMT-driven output.
  2. ConfirmedCPPABusinesses that use ADMT to make significant decisions must comply with the ADMT requirements, including consumer rights to access and opt out of such use, beginning January 1, 2027.
  3. ConfirmedIAPPThe regulations require a risk assessment whenever a business processes data that might present a risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, or using ADMT for a significant decision.
  4. ConfirmedIAPPThe narrower 'personal information' definition applicable to the CCPA private right of action, drawn from the Customer Records Act, includes an individual's name in combination with unique biometric data.

#

CCPA's own under-16 opt-in rule is stable and in force, but the AADCA overlay remains in ongoing, unresolved constitutional litigation with a currently-enjoined status, creating material enforceability uncertainty.

Primary frameworkCal. Civ. Code §1798.120(c); California Age-Appropriate Design Code Act, Cal. Civ. Code §1798.99.28 et seq. (substantially enjoined)
Traffic-light rationale — AmberCCPA's own under-16 opt-in rule is stable and in force, but the AADCA overlay remains in ongoing, unresolved constitutional litigation with a currently-enjoined status, creating material enforceability uncertainty.

Sub-modules (5)

Age VerificationAmber

The AADCA's age-estimation requirement was, for a period following the Ninth Circuit's 2024 ruling, enforceable notwithstanding the broader injunction; however, subsequent 2026 district court proceedings again fully enjoined the statute, placing the age-estimation mandate's current enforceability in flux.

Claims: CLM-CA-1e2f3a4c

Minor Profiling BansAmber

The Ninth Circuit's August 2024 ruling vacated the injunction as to the AADCA's provisions restricting the collection, use, and sale of children's data and geolocation collection without an obvious sign; a subsequent 2026 district-court ruling reinstated a full injunction covering the statute, so current enforceability of these restrictions is again blocked pending further appeal.

Claims: CLM-CA-3a4b5c6e

Education SettingsRed

No claims identified for a California education-settings-specific children's data provision distinct from general CCPA/AADCA rules in this research pass.

Dependent AdultsRed

No claims identified for California-specific dependent-adult/incapacitated-persons data protections in this research pass. Searched CPPA/OAG guidance; none found.

Category narrative99 words

California's children's-privacy regime is bifurcated: (1) established CCPA-specific rules requiring opt-in consent for the sale/sharing of the personal information of consumers under 16 (Article 6 special rules); and (2) the separately-enacted California Age-Appropriate Design Code Act (AADCA, 2022), whose enforceability has been highly unstable through ongoing First Amendment litigation (NetChoice v. Bonta). As of the most recent reported appellate posture, the district court's renewed injunction again fully enjoins the AADCA, reversing an earlier Ninth Circuit partial narrowing that had allowed enforcement of age-estimation, geolocation, and default-privacy-setting provisions to proceed. Education-settings-specific and dependent-adult-specific rules were not confirmed in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. UncertainIAPPAlthough the vast majority of the California AADC remains enjoined, the Ninth Circuit found important aspects enforceable, including requirements for companies to estimate user ages; a subsequent district-court ruling has again fully enjoined the statute.
  2. ConfirmedCPPAThe CCPA regulations include an Article dedicated to Special Rules Regarding Consumers Less Than 16 Years of Age, governing opt-in consent requirements for the sale/sharing of minors' personal information.
  3. UncertainCalifornia Department of JusticeThe Ninth Circuit vacated the injunction as to the AADCA's provisions restricting the collection, use, and sale of children's data and the collection of a child's geolocation information without an obvious sign to the child; a later 2026 district-court decision has again fully enjoined the law.

#

Active, well-documented enforcement program with recent significant monetary penalties and multistate coordination; regulator funding/headcount data not confirmed in this pass.

Primary frameworkCal. Civ. Code §§1798.150, 1798.155, 1798.199.90 et seq.
Traffic-light rationale — GreenActive, well-documented enforcement program with recent significant monetary penalties and multistate coordination; regulator funding/headcount data not confirmed in this pass.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General may seek civil penalties of up to $2,500 per violation (or $7,500 for intentional violations) under §1798.155(a)/(b); the CPPA independently administers administrative enforcement under §1798.155. Fine and threshold amounts are adjusted for inflation every two years (2025 increases confirmed).

Claims: CLM-CA-4b5c6d7f, CLM-CA-5c6d7e8a

Enforcement Activity IndexGreen

Reported CPPA/AG enforcement in the 2025-2026 window includes a $1.35 million fine against Tractor Supply Company, a $345,178 fine against Todd Snyder, a $632,500 fine against American Honda Motor Co., a joint investigative privacy sweep, and more than ten actions against unregistered data brokers.

Claims: CLM-CA-6d7e8f9b

Regulator Funding And CapacityRed

No claims identified regarding CPPA budget or headcount in this research pass. Searched CPPA announcements and regulations pages; specific funding/staffing figures were not surfaced.

Collective Redress And Class ActionsAmber

CCPA violations are commonly asserted as a predicate for California Unfair Competition Law (UCL) class-action claims, notwithstanding §1798.150(c)'s limitation against using the CCPA as a freestanding basis for other causes of action.

Claims: CLM-CA-7e8f9a0c

Private Right Of ActionGreen

A private right of action exists only for data breaches involving unencrypted/unredacted personal information (as defined under Civil Code §1798.81.5(d)(1)(A)) resulting from a business's failure to maintain reasonable security, with statutory damages of $100-$750 per incident and a mandatory 30-day pre-suit cure notice.

Claims: CLM-CA-8f9a0b1d

Recent Developments 180DGreen

Within the last 180 days: the OOPS opt-out-signal rulemaking's preliminary comment period closed April 6, 2026; the Delete Act's DROP consumer-deletion platform began consumer use in January 2026 with data-broker access mandated from August 1, 2026; and CPPA public communications rebranded/relocated to privacy.ca.gov ('CalPrivacy') as of January 26, 2026.

Claims: CLM-CA-9a0b1c2e

Category narrative128 words

The CPPA and Attorney General share enforcement of the CCPA. Statutory penalties are capped at $2,500 per violation ($7,500 for intentional violations), subject to a former 30-day cure period, with amounts adjusted biennially for inflation (2025 increases confirmed). A narrow private right of action exists solely for data breaches involving unencrypted/unredacted personal information (as narrowly defined by the Customer Records Act) resulting from a failure to maintain reasonable security, carrying statutory damages of $100-$750 per incident plus a mandatory 30-day cure notice. CCPA violations are also frequently pled as predicate 'unlawful practices' under California's Unfair Competition Law in private class litigation. CPPA enforcement activity has intensified through late 2025/early 2026, including multi-hundred-thousand-to-million-dollar fines against major retailers and an automaker, alongside a new bipartisan multistate 'Consortium of Privacy Regulators.'

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPUnder Section 1798.155(a), California's Attorney General may bring an action against a violator for up to $2,500 per violation, with a higher cap of $7,500 for intentional violations under Section 1798.155(b); enterprises historically had 30 days after notice of noncompliance to cure before enforcement.
  2. ConfirmedCPPABeginning in 2025, the CPPA increased monetary damages, administrative fines, civil penalties, and the business income threshold in alignment with Consumer Price Index adjustments made every other year under the CCPA.
  3. ConfirmedCPPACPPA-reported enforcement outcomes include a decision requiring Tractor Supply Company to pay a $1.35 million fine, a decision requiring Todd Snyder, Inc. to pay $345,178, and a decision requiring American Honda Motor Co. to pay $632,500, each for CCPA violations.
  4. ProbableIAPPCalifornia class-action plaintiffs have asserted that a violation of the CCPA constitutes an 'unlawful activity' or predicate act under California's Unfair Competition Law, including in cases against Zoom and in Clearview-related facial-recognition scraping litigation.
  5. ConfirmedCalifornia Department of JusticeA consumer may sue a business under the CCPA only where the consumer's nonencrypted and nonredacted personal information was stolen in a data breach due to the business's failure to maintain reasonable security procedures, recovering actual damages or statutory damages of up to $750 per incident, after providing 30 days' written notice allowing the business to cure.
  6. ConfirmedCPPAThe CPPA's Opt-out Preference Signals (OOPS) rulemaking preliminary comment period closed April 6, 2026, and, per the November 2025 Delete Act regulations, data brokers must access the DROP consumer-deletion platform at least every 45 days beginning August 1, 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 49 claim(s), 31 source(s) in the cumulative register.