🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-CA · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 26 sources retrieved model claude-sonnet-5 ·

United States – California

US-CA schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 48 claims · 26 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
48Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core CCPA/CPRA regime is in force and being actively enforced, but major implementing regulations (ADMT, risk assessments, cybersecurity audits) only became applicable January 1, 2026 (ADMT opt-out/access duties phase in further to January 1, 2027), and several rulemakings (Delete Act DROP mechanics, opt-out preference signal 'OOPS' rulemaking, SB 976 age-assurance rules) remain in progress in mid-2026.

Primary frameworkCalifornia Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CPRA), Cal. Civil Code § 1798.100 et seq.; Title 11, California Code of Regulations, Division 6
Traffic-light rationale — AmberCore CCPA/CPRA regime is in force and being actively enforced, but major implementing regulations (ADMT, risk assessments, cybersecurity audits) only became applicable January 1, 2026 (ADMT opt-out/access duties phase in further to January 1, 2027), and several rulemakings (Delete Act DROP mechanics, opt-out preference signal 'OOPS' rulemaking, SB 976 age-assurance rules) remain in progress in mid-2026.

Sub-modules (5)

Regulator And AuthorityGreen

The CPPA is the first U.S. state agency dedicated exclusively to privacy, created by Prop 24 to implement and enforce the CCPA/CPRA; the California Attorney General retains civil enforcement authority for CCPA/CPRA and for related statutes such as SB 976.

Claims: CLM-US-CA-a1b2c3d4

Act And InstrumentsGreen

Primary instruments are the CCPA (2018), CPRA (2020, effective Jan 1 2023), the Delete Act (SB 362, 2023) creating data broker obligations, and Title 11 CCR regulations including the September 2025 CCPA Updates/Cyber/Risk/ADMT/Insurance package.

Claims: CLM-US-CA-b2c3d4e5, CLM-US-CA-c3d4e5f6

Material ScopeGreen

The CCPA/CPRA covers 'personal information' relating to California consumers (residents) collected by covered 'businesses,' with the employment and B2B data exemptions having expired.

Claims: CLM-US-CA-d4e5f6a7

Territorial ScopeAmber

Applicability turns on statutory revenue/volume/data-sale thresholds under Civil Code § 1798.140 rather than physical presence in California; out-of-state and non-U.S. businesses meeting the thresholds and processing California residents' data are covered.

Regulator Registration And FilingAmber

Data brokers must register annually with the CPPA and, since the Delete Act's accessible deletion mechanism (DROP) went live, must honor consumer opt-out/deletion requests submitted through the CPPA's centralized portal; failure to register or comply carries per-incident penalties.

Claims: CLM-US-CA-e5f6a7b8

Category narrative99 words

California operates a hybrid regime: the California Consumer Privacy Act of 2018 (CCPA), as substantially amended and expanded by the 2020 ballot initiative CPRA (Proposition 24), is administered by a dedicated agency, the California Privacy Protection Agency (CPPA/'CalPrivacy'), alongside continuing civil enforcement authority held by the state Attorney General. The regime is overlaid by sector-specific federal statutes (HIPAA, GLBA, FCRA) and California sectoral laws (CMIA, ICCRAA, Insurance Code). The CPPA has an active and expanding rulemaking docket (cybersecurity audits, risk assessments, ADMT, insurance, data broker registration) plus an active enforcement division including a dedicated Data Broker Enforcement Strike Force.

Sources and claims (5)
  1. ConfirmedCalifornia Privacy Protection AgencyThe California Privacy Protection Agency (CPPA) is the state's dedicated privacy regulator responsible for administrative enforcement of the CCPA/CPRA, operating alongside the Attorney General's continuing civil enforcement role.
  2. ConfirmedCalifornia Privacy Protection AgencyIn November 2020, California voters passed Proposition 24 (CPRA), which amended the CCPA of 2018 and established the CPPA, with the CPPA authorized to adopt and amend regulations under both the CCPA/CPRA and the Delete Act.
  3. ConfirmedCalifornia Privacy Protection AgencyThe Office of Administrative Law approved the CPPA's regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), and insurance companies in September 2025.
  4. ConfirmedCalifornia Privacy Protection AgencyThe exemptions for employment-related personal information and personal information reflecting business-to-business transactions under Civil Code § 1798.145(m)-(n) expired on December 31, 2022, bringing employee and B2B data within CCPA scope.
  5. ConfirmedIAPPData brokers under the Delete Act must honor opt-out and deletion requests submitted through the CPPA's DROP portal, which applies requests across all registered brokers, with per-incident penalties for non-compliant or unregistered brokers.

#

Sensitive-data and consent-quality rules are well developed and recently strengthened via the 2025 regulations package, but California has no GDPR Article 6-style enumerated lawful-basis catalogue, which is a structural divergence from omnibus regimes.

Primary frameworkCal. Civil Code §§ 1798.121, 1798.135, 1798.140; Title 11 CCR §§ 7000-7004
Traffic-light rationale — AmberSensitive-data and consent-quality rules are well developed and recently strengthened via the 2025 regulations package, but California has no GDPR Article 6-style enumerated lawful-basis catalogue, which is a structural divergence from omnibus regimes.

Sub-modules (4)

Lawful BasesRed

No enumerated Article 6-equivalent lawful-basis list exists; processing is generally permitted subject to consumer opt-out/opt-in and purpose-limitation duties rather than an ex-ante lawful basis requirement.

Special CategoriesGreen

The CPRA introduced 'sensitive personal information' (SPI) as a defined category (e.g., precise geolocation, racial/ethnic origin, health, biometric, sexual orientation) carrying a consumer right to limit use and disclosure.

Claims: CLM-US-CA-b8c9d0e1

Pseudonymisation And AnonymisationGreen

AB 713 created a safe harbor exempting deidentified information derived from HIPAA/CMIA-protected patient data and created under HIPAA's expert-determination or safe-harbor deidentification methods, so long as it is not re-identified.

Claims: CLM-US-CA-c9d0e1f2

Category narrative51 words

The CCPA/CPRA does not adopt a GDPR-style enumerated lawful-basis framework; instead it relies on a notice-plus-choice model (opt-out of 'sale'/'share', opt-in consent for minors and for use of sensitive personal information beyond permitted purposes) built around defined categories of 'sensitive personal information' (SPI) and strict rules against dark patterns invalidating consent.

Sources and claims (4)
  1. ConfirmedCalifornia Privacy Protection AgencyUnder the 2026 CCPA regulations, consent/opt-out methods must not use double negatives, misleading statements, omissions, affirmative misstatements, or deceptive language, and a consumer's silence or failure to act affirmatively does not constitute consent.
  2. ConfirmedCalifornia Privacy Protection AgencyThe regulations require 'symmetry in choice,' meaning the path to exercise a more privacy-protective option cannot be longer, more difficult, or more time-consuming than the path to a less privacy-protective option.
  3. ConfirmedIAPPThe CPRA created a new 'sensitive personal information' category and corresponding right to correct and heightened protections beyond the CCPA baseline.
  4. ConfirmedIAPPAB 713 exempts information deidentified in accordance with HIPAA's expert-determination or safe-harbor methods, where the underlying data was derived from HIPAA, CMIA, or Common Rule-protected patient information, and this exemption is lost if the information is re-identified.

#

Core rights are well codified and enforced, though ADMT-specific access/opt-out rights do not become mandatory until January 1, 2027.

Primary frameworkCal. Civil Code §§ 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121, 1798.130
Traffic-light rationale — GreenCore rights are well codified and enforced, though ADMT-specific access/opt-out rights do not become mandatory until January 1, 2027.

Sub-modules (5)

Access RightGreen

Consumers have the right to know what personal information is collected, sold, or shared, and to whom, under Civil Code §§ 1798.110 and 1798.115.

Claims: CLM-US-CA-d0e1f2a3

Rectification And ErasureGreen

Consumers have a right to delete personal information (§1798.105) and, since the CPRA, a right to correct inaccurate personal information (§1798.106).

Claims: CLM-US-CA-e1f2a3b4

Restriction And ObjectionAmber

Consumers may opt out of sale/sharing (§1798.120) and limit use/disclosure of sensitive personal information (§1798.121); the 2025 ADMT regulations add an opt-out right for significant automated decisions, applicable January 1, 2027.

Claims: CLM-US-CA-f2a3b4c5

Data PortabilityGreen

The right to know includes a portability component allowing consumers to obtain a copy of collected personal information in a portable format under §1798.130.

Deadlines And Response WindowsGreen

Businesses generally must respond to verified consumer requests within 45 days, extendable by another 45 days with notice to the consumer.

Claims: CLM-US-CA-a3b4c5d6

Category narrative45 words

The CCPA/CPRA provides consumers rights to know/access, delete, correct, opt out of sale/share, limit use of sensitive personal information, data portability, non-discrimination, and (as of the 2025 regulations, applicable January 1 2027) access to and opt-out of automated decisionmaking technology (ADMT) used for significant decisions.

Sources and claims (4)
  1. ConfirmedCalifornia Department of JusticeThe CCPA confers on consumers the right to know what personal information businesses are collecting about them and how that information is being used and shared.
  2. ConfirmedCalifornia Department of JusticeConsumers have the right to delete personal information held by businesses and to stop the sale of that information, and the CPRA introduced the right to correct inaccurate personal information.
  3. ConfirmedCalifornia Privacy Protection AgencyIf a business uses ADMT to make significant decisions about a consumer (e.g., employment, housing, financial services, education, or healthcare), the consumer has the right to notice, to opt out where applicable, and to request meaningful information about how the ADMT functioned; businesses must comply with ADMT-specific requirements by January 1, 2027.
  4. ProbableCalifornia Privacy Protection AgencyBusinesses must generally respond to verifiable consumer requests within 45 days, with the possibility of a 45-day extension, per the CCPA request-handling regulations.

#

Security, breach-notification, and new risk-assessment/cyber-audit duties are robust and now in force, but DPO appointment and formal ROPA are structural gaps relative to GDPR-style omnibus regimes.

Primary frameworkCal. Civil Code §§ 1798.100(d)-(e), 1798.81.5, 1798.82, 1798.150, 1798.185; Title 11 CCR (risk assessment/cyber audit regulations, Sept 2025)
Traffic-light rationale — AmberSecurity, breach-notification, and new risk-assessment/cyber-audit duties are robust and now in force, but DPO appointment and formal ROPA are structural gaps relative to GDPR-style omnibus regimes.

Sub-modules (7)

Accountability And DpiaAmber

The September 2025 regulations implement mandatory risk assessments for higher-risk processing (selling/sharing PI, processing SPI, ADMT for significant decisions, training ADMT on personal information) and annual cybersecurity audits for qualifying businesses.

Claims: CLM-US-CA-b4c5d6e7

Dpo RequirementsRed

The CCPA/CPRA does not impose a GDPR Art. 37-style mandatory Data Protection Officer appointment requirement on covered businesses.

Ropa RequirementsRed

There is no explicit statutory or regulatory requirement analogous to GDPR Art. 30 Records of Processing Activities; documentation duties arise indirectly through risk-assessment and audit recordkeeping obligations.

Joint Controller ArrangementsAmber

Instead of a joint-controller regime, the CCPA imposes contractual due-diligence and flow-down obligations on 'service providers,' 'contractors,' and 'third parties' receiving personal information from a business.

Claims: CLM-US-CA-c5d6e7f8

Security MeasuresGreen

Businesses must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information, per Civil Code §1798.100(e)/§1798.81.5, underlying both regulatory enforcement and the narrow private right of action.

Claims: CLM-US-CA-d6e7f8a9

Breach NotificationGreen

California's long-standing breach notification statute (Civil Code §§1798.29/1798.82) requires notice to affected residents in the most expedient time possible, and a sample notice to the Attorney General if more than 500 residents are affected.

Claims: CLM-US-CA-e7f8a9b0

Retention And DisposalAmber

The CPRA embeds a purpose-limitation/storage-limitation principle requiring that collection, use, retention, and sharing be reasonably necessary and proportionate to the disclosed purposes.

Claims: CLM-US-CA-f8a9b0c1

Category narrative58 words

The CPRA introduced accountability-style obligations new to the U.S. state landscape: mandatory risk assessments, cybersecurity audits for higher-risk processing, and contractual flow-down duties on service providers/contractors/third parties, alongside a long-standing 'reasonable security' duty and breach notification law. California has no GDPR-style mandatory DPO or formal ROPA requirement, and joint-controller concepts are handled instead through CCPA's contractual service-provider/contractor/third-party framework.

Sources and claims (5)
  1. ConfirmedIAPPThe CPPA's 2025 regulations require a risk assessment whenever a business processes personal information presenting heightened risk, including selling/sharing personal information, processing sensitive personal information, using ADMT for a significant decision, or using personal information to train ADMT.
  2. ConfirmedIAPPThe CPRA expands contractual requirements for service providers, contractors, and third parties, including new due-diligence duties and enforceable obligations governing downstream data flows.
  3. ConfirmedIAPPCivil Code §1798.100(e) of the CPRA obligates businesses collecting consumers' personal information to implement reasonable security procedures and practices appropriate to the nature of the information.
  4. ConfirmedCalifornia Department of JusticeCalifornia law requires a business or agency to notify affected California residents whenever their unencrypted personal information was acquired, or reasonably believed to have been acquired, by an unauthorized person, and requires submission of a sample notice to the Attorney General when more than 500 residents are affected by a single breach.
  5. ProbableIAPPCPPA enforcement leadership has signaled increased focus on data minimization and purpose limitation as 'fundamental' CCPA principles going forward, alongside opt-out compliance.

#

No CCPA/CPRA adequacy, transfer-impact-assessment, or localisation regime exists; this is a genuine structural gap relative to omnibus regimes and is not a research omission.

Primary frameworkCal. Civil Code § 1798.100(d) (contractual flow-down); no dedicated transfer-mechanism statute
Traffic-light rationale — RedNo CCPA/CPRA adequacy, transfer-impact-assessment, or localisation regime exists; this is a genuine structural gap relative to omnibus regimes and is not a research omission.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border/cross-state transfers are governed via the CCPA's contractual requirements binding service providers, contractors, and third parties, rather than a dedicated transfer-mechanism regime.

Claims: CLM-US-CA-a9b0c1d2

Adequacy ReceivedRed

No jurisdiction has issued a formal 'adequacy' finding in respect of California under a GDPR-style framework; this is a genuine gap, not a research omission.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , r, e, g, u, l, a, t, i, o, n, s, ,, , c, r, o, s, s, -, b, o, r, d, e, r, , t, r, a, n, s, f, e, r, , p, r, o, v, i, s, i, o, n, s, ;, , n, o, , a, d, e, q, u, a, c, y, -, d, e, c, i, s, i, o, n, , m, e, c, h, a, n, i, s, m, , l, o, c, a, t, e, d, , f, o, r, , U, S, -, C, A.

Adequacy GrantedRed

California/CCPA does not issue outbound adequacy determinations to other jurisdictions; there is no CPPA adequacy-granting power under current statute.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , r, e, g, u, l, a, t, i, o, n, s, , a, n, d, , c, r, o, s, s, -, b, o, r, d, e, r, /, a, d, e, q, u, a, c, y, , m, e, c, h, a, n, i, s, m, s, ;, , n, o, n, e, , f, o, u, n, d, , f, o, r, , o, u, t, b, o, u, n, d, , a, d, e, q, u, a, c, y.

Sccs And BcrsRed

CCPA/CPRA does not mandate SCCs or BCRs; businesses subject to both GDPR and CCPA may use GDPR SCCs for EU transfers, but this is not a CCPA requirement.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , c, r, o, s, s, -, b, o, r, d, e, r, , t, r, a, n, s, f, e, r, , r, u, l, e, s, ;, , n, o, , S, C, C, /, B, C, R, , m, a, n, d, a, t, e, , f, o, u, n, d, , i, n, , C, C, P, A, /, C, P, R, A, , t, e, x, t, , s, e, a, r, c, h.

Transfer Impact AssessmentRed

No CCPA/CPRA requirement for a formal transfer impact assessment analogous to EU Schrems II practice exists; general risk-assessment rules under the 2025 regulations focus on domestic processing risk categories, not cross-border transfer risk specifically.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , r, e, g, u, l, a, t, i, o, n, s, , s, c, o, p, e, ;, , n, o, , d, e, d, i, c, a, t, e, d, , T, I, A, , r, e, q, u, i, r, e, m, e, n, t, , i, d, e, n, t, i, f, i, e, d.

Data LocalisationRed

California imposes no data-localisation mandate under the CCPA/CPRA.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , r, e, g, u, l, a, t, i, o, n, s, ;, , n, o, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , f, o, u, n, d.

Category narrative44 words

Unlike GDPR-style omnibus regimes, the CCPA/CPRA does not establish an adequacy framework, government-to-government adequacy decisions, mandated SCC/BCR transfer mechanisms, or a data-localisation mandate; international/interstate data transfer is governed instead through the same service-provider/contractor/third-party contractual flow-down duties applicable to any onward disclosure of personal information.

Sources and claims (1)
  1. ProbableIAPPThe CPRA's expanded contractual requirements for service providers, contractors, and third parties govern onward disclosure of personal information, including due-diligence duties over downstream data flows, functioning as California's de facto transfer-control mechanism in place of a dedicated cross-border transfer regime.

#

Sectoral overlays are data-level rather than entity-level in most cases, creating residual CCPA exposure (e.g., non-PHI health data, employee data) that businesses frequently misjudge.

Primary frameworkCal. Civil Code § 1798.145 (exemptions); Cal. Civil Code § 56 et seq. (CMIA); Cal. Insurance Code § 791 et seq.; 15 U.S.C. §6801 et seq. (GLBA, federal overlay)
Traffic-light rationale — AmberSectoral overlays are data-level rather than entity-level in most cases, creating residual CCPA exposure (e.g., non-PHI health data, employee data) that businesses frequently misjudge.

Sub-modules (7)

Financial Sector OverlayAmber

The CCPA/CPRA provides only a partial, data-level exemption for information subject to GLBA, and financial institutions must still comply with CCPA data-security requirements; this is narrower than the broader GLBA exemptions offered by some other state comprehensive privacy laws.

Claims: CLM-US-CA-b0c1d2e3

Health Sector OverlayAmber

The CCPA exempts protected health information held by HIPAA covered entities/business associates and medical information held by CMIA-covered providers, but this exemption does not extend to non-HIPAA/non-CMIA health-adjacent businesses such as wearables, fitness apps, or DTC genetic-testing companies.

Claims: CLM-US-CA-c1d2e3f4, CLM-US-CA-d2e3f4a5

Telecoms And EprivacyAmber

California lacks a dedicated ePrivacy-style cookie/communications statute analogous to the EU regime; instead, cookie/tracking and communications-interception issues are increasingly litigated under the older California Invasion of Privacy Act (CIPA) wiretap provisions alongside CCPA opt-out/sale-sharing rules.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , t, h, i, s, , r, u, n, , f, o, c, u, s, e, d, , o, n, , C, C, P, A, /, C, P, R, A, , r, e, g, u, l, a, t, o, r, y, , p, a, c, k, a, g, e, ;, , t, a, r, g, e, t, e, d, , C, I, P, A, , w, i, r, e, t, a, p, , l, i, t, i, g, a, t, i, o, n, , t, r, e, n, d, , s, e, a, r, c, h, , n, o, t, , s, e, p, a, r, a, t, e, l, y, , r, u, n.

Employment DataGreen

The CCPA's employment-data exemption expired December 31, 2022, meaning employee, applicant, and contractor personal information is now generally subject to full CCPA obligations.

Claims: CLM-US-CA-e3f4a5b6

Credit And ScoringAmber

Consumer credit reporting is separately governed by the federal FCRA and California's Investigative Consumer Reporting Agencies Act (ICCRAA); the CCPA/CPRA exempts data covered by these regimes at the data level.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , t, h, i, s, , r, u, n, , c, o, v, e, r, e, d, , C, C, P, A, /, C, P, R, A, , r, e, g, u, l, a, t, o, r, y, , p, a, c, k, a, g, e, , g, e, n, e, r, a, l, l, y, ;, , I, C, C, R, A, A, -, s, p, e, c, i, f, i, c, , s, e, a, r, c, h, , n, o, t, , s, e, p, a, r, a, t, e, l, y, , r, u, n.

EducationAmber

Education-sector data intersects with federal FERPA and California's Student Online Personal Information Protection Act (SOPIPA); ADMT profiling of students for education/employment inference is separately flagged as risk-assessment-triggering under the 2025 CPPA regulations.

Claims: CLM-US-CA-f4a5b6c7

InsuranceGreen

The September 2025 CPPA regulations clarify when insurance companies must comply with the CCPA, supplementing the pre-existing California Insurance Information and Privacy Protection Act.

Claims: CLM-US-CA-a5b6c7d8

Category narrative86 words

California layers sectoral carve-outs and overlay statutes onto the CCPA/CPRA baseline: GLBA-regulated financial data receives a partial data-level exemption; HIPAA/CMIA-regulated health data receives a data- and entity-level exemption (with residual coverage for non-HIPAA health data such as wearables and DTC genetic tests); the Insurance Code and new 2025 CPPA insurance-company regulations clarify CCPA applicability to insurers; FCRA/ICCRAA governs credit reporting; education records intersect with FERPA and California's Student Online Personal Information Protection Act (SOPIPA); and employment data lost its CCPA exemption at the start of 2023.

Sources and claims (6)
  1. ProbableDataGuidance / OneTrustThe CCPA/CPRA provides only partial exemptions for financial institutions, applying solely to data subject to GLBA, while still requiring compliance with CCPA data-security requirements, in contrast to broader entity-level exemptions offered by some other state privacy laws.
  2. ConfirmedIAPPProtected health information collected by a covered entity governed by HIPAA or medical information governed by California's Confidentiality of Medical Information Act (CMIA) is exempt from the CCPA, but this exemption does not extend to entities not covered by HIPAA or CMIA, such as pharmaceutical companies, wearables, fitness apps, or genetic test services.
  3. ConfirmedIAPPThe CPRA's HIPAA-related exemptions apply at the data level rather than the entity level, exempting protected health information and CMIA-governed medical information while leaving other personal information held by the same health care entities subject to CPRA obligations.
  4. ConfirmedCalifornia Privacy Protection AgencyThe exemptions for employment-related personal information and B2B personal information under Civil Code §1798.145(m)-(n) expired on December 31, 2022.
  5. ConfirmedIAPPThe 2025 CPPA risk-assessment regulations specifically flag automated processing used to infer attributes about a person during education, job seeking, employment, or independent contracting as a risk-assessment-triggering use of ADMT.
  6. ConfirmedCalifornia Privacy Protection AgencyThe CPPA's September 2025 regulations include provisions clarifying when insurance companies must comply with the CCPA.

#

Core cookie/cross-context-advertising and dark-pattern rules are in force, but the OOPS and friction-reduction rulemakings remain preliminary/not-yet-formal as of mid-2026, and clean-room/data-collaboration-room practices are not directly addressed by any CCPA provision identified in research.

Primary frameworkCal. Civil Code §§ 1798.120, 1798.135, 1798.140; Title 11 CCR Articles 1-4 (dark patterns, notices, opt-out signals)
Traffic-light rationale — AmberCore cookie/cross-context-advertising and dark-pattern rules are in force, but the OOPS and friction-reduction rulemakings remain preliminary/not-yet-formal as of mid-2026, and clean-room/data-collaboration-room practices are not directly addressed by any CCPA provision identified in research.

Sub-modules (6)

Cookies And TrackersAmber

Cookie-based cross-context behavioral advertising generally falls within the CCPA's 'sale' or 'share' definitions, triggering opt-out rights rather than being governed by a separate ePrivacy-style cookie-consent statute.

Claims: CLM-US-CA-b6c7d8e9

Dark PatternsGreen

The 2026-effective regulations provide an extensive, illustrative list of prohibited dark-pattern methods and state that any agreement obtained through such methods does not constitute valid consumer consent.

Claims: CLM-US-CA-c7d8e9f0

Opt Out SignalsAmber

Mandatory recognition of opt-out preference signals (e.g., Global Privacy Control) has been enforceable since the first CPRA regulations took effect following the 2023 appellate ruling, and a further 'Opt-out Preference Signals (OOPS)' rulemaking was in preliminary comment stage through April 6, 2026.

Claims: CLM-US-CA-d8e9f0a1, CLM-US-CA-e9f0a1b2

Clean Rooms And DcrRed

No CCPA/CPRA provision specifically addresses data clean rooms or data-collaboration-room arrangements; this is a genuine regulatory gap rather than a research omission.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , o, n, , C, P, P, A, , r, e, g, u, l, a, t, i, o, n, s, , a, n, d, , r, u, l, e, m, a, k, i, n, g, , t, o, p, i, c, s, ;, , n, o, , c, l, e, a, n, -, r, o, o, m, /, D, C, R, -, s, p, e, c, i, f, i, c, , r, u, l, e, , i, d, e, n, t, i, f, i, e, d.

Cross Context AdvertisingGreen

Cross-context behavioral advertising is captured by the CCPA's 'share' definition (added by the CPRA), giving consumers an opt-out right distinct from the 'sale' opt-out.

Claims: CLM-US-CA-f0a1b2c3

Direct MarketingAmber

Direct marketing built on 'financial incentive' programs must comply with CCPA notice-of-financial-incentive disclosure rules, including a good-faith value estimate; no CCPA-specific suppression-list regime parallels CAN-SPAM.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , t, h, i, s, , r, u, n, , c, o, v, e, r, e, d, , C, P, P, A, , r, u, l, e, m, a, k, i, n, g, , g, e, n, e, r, a, l, l, y, ;, , d, i, r, e, c, t, -, m, a, r, k, e, t, i, n, g, , s, u, p, p, r, e, s, s, i, o, n, , l, i, s, t, , s, e, a, r, c, h, , n, o, t, , s, e, p, a, r, a, t, e, l, y, , r, u, n.

Category narrative73 words

California is the most developed U.S. state jurisdiction for adtech-adjacent privacy rules: the CCPA/CPRA's 'sale' and 'share' definitions specifically capture cross-context behavioral advertising, mandatory recognition of opt-out preference signals (e.g., Global Privacy Control) has been enforced since the first CPRA rulemaking, dark-pattern prohibitions are extensively codified in the 2026-effective regulations, and a further 'Opt-out Preference Signals' (OOPS) rulemaking and a 'Reducing Friction' rulemaking were both in preliminary comment stages as of April 2026.

Sources and claims (5)
  1. ProbableIAPPThe CPRA's 2025 rulemaking removed prior draft references to 'behavioral advertising' and 'artificial intelligence' as standalone defined terms in the ADMT text while retaining coverage of tools that place consumers into audience groups to target ads via the sale/share framework.
  2. ConfirmedCalifornia Privacy Protection AgencyUnder the 2026 CCPA regulations, a method that does not comply with the required consent/opt-out standards may be considered a dark pattern, and any agreement obtained through dark patterns does not constitute valid consumer consent.
  3. ConfirmedIAPPA California appellate court ruled in 2023 that the CPPA could immediately enforce its first set of CPRA regulations, which include mandatory recognition of opt-out preference signals, ending a period of suspended enforcement.
  4. ConfirmedCalifornia Privacy Protection AgencyAs of April 2026, the CPPA's 'Opt-out Preference Signals (OOPS)' rulemaking remained at the preliminary comment stage, with the preliminary comment period closing April 6, 2026, and no proposed regulation package yet advanced to formal rulemaking.
  5. ConfirmedCalifornia Privacy Protection AgencyThe Notice of Right to Opt-out of Sale/Sharing and associated 'Do Not Sell or Share My Personal Information' link inform consumers of their right to direct a business to stop selling or sharing their personal information, including for cross-context behavioral advertising.

#

ADMT/AI-risk rules are finalized but not fully phased in (opt-out/access duties effective 2027); the final ADMT text notably removed express references to 'artificial intelligence' as a defined term, narrowing the regulation's direct AI framing even though its substantive scope covers many AI use cases.

Primary frameworkTitle 11 CCR (ADMT/risk assessment/cyber audit regulations, Sept 2025); Cal. Civil Code §§ 1798.121, 1798.145
Traffic-light rationale — AmberADMT/AI-risk rules are finalized but not fully phased in (opt-out/access duties effective 2027); the final ADMT text notably removed express references to 'artificial intelligence' as a defined term, narrowing the regulation's direct AI framing even though its substantive scope covers many AI use cases.

Sub-modules (6)

Profiling RestrictionsAmber

ADMT regulations govern profiling used for significant decisions and, as originally drafted, publicly-accessible-place profiling and behavioral-advertising profiling; the final rules narrowed these categories relative to the 2023 draft.

Claims: CLM-US-CA-a1b2c3e4

Automated Decision Making TransparencyAmber

Businesses using ADMT for significant decisions must provide pre-use notices and, on request, meaningful information about how the ADMT functioned and affected the consumer, with human-review standards requiring a qualified reviewer able to change the outcome.

Claims: CLM-US-CA-b2c3e4f5, CLM-US-CA-c3e4f5a6

Ai Risk AssessmentsAmber

The 2025 regulations require risk assessments for ADMT-related processing including training ADMT on personal information, with projected 10-year compliance costs to business of approximately $4.8 billion versus estimated economic benefits of $282 billion, according to CPPA figures.

Claims: CLM-US-CA-d4f5a6b7

Biometric RegimeAmber

Biometric identifiers fall within the CPRA's 'sensitive personal information' category, triggering the right to limit use and disclosure; draft ADMT rules originally addressed facial-recognition and emotion-assessment profiling in publicly accessible places before the final scope narrowed.

Claims: CLM-US-CA-e5a6b7c8

Genetic DataAmber

California maintains a separate Genetic Information Privacy Act (GIPA) applicable to direct-to-consumer genetic testing companies; this run did not execute a dedicated search confirming GIPA's current enforcement posture, so this finding is flagged with reduced confidence.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , t, h, i, s, , r, u, n, , t, a, r, g, e, t, e, d, , C, C, P, A, /, C, P, R, A, , r, e, g, u, l, a, t, o, r, y, , p, a, c, k, a, g, e, , a, n, d, , A, A, D, C, /, S, B, 9, 7, 6, ;, , n, o, , d, e, d, i, c, a, t, e, d, , G, I, P, A, , s, e, a, r, c, h, , e, x, e, c, u, t, e, d.

State Surveillance CarveoutsAmber

The CCPA contains statutory exemptions for compliance with federal, state, or local law and for cooperating with law enforcement, functioning as California's national-security/law-enforcement carve-out; the scope of these exemptions was not independently verified via a dedicated search this run.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , t, h, i, s, , r, u, n, , d, i, d, , n, o, t, , s, p, e, c, i, f, i, c, a, l, l, y, , t, a, r, g, e, t, , C, i, v, i, l, , C, o, d, e, , §, 1, 7, 9, 8, ., 1, 4, 5, , l, a, w, -, e, n, f, o, r, c, e, m, e, n, t, , e, x, e, m, p, t, i, o, n, , s, c, o, p, e.

Category narrative73 words

The CPPA's 2025 ADMT/risk-assessment/cybersecurity-audit regulations represent California's primary vehicle for algorithmic governance, providing consumers pre-use notice, opt-out, and access rights for significant automated decisions (phasing in through January 1, 2027), while sensitive personal information rules capture biometric identifiers, and the CCPA's law-enforcement/national-security exemptions provide the surveillance carve-out. Genetic data receives separate treatment under California's Genetic Information Privacy Act, though this run did not conduct a dedicated search to confirm current GIPA enforcement status.

Sources and claims (5)
  1. ConfirmedIAPPThe CPPA's final ADMT rules only allow ADMT opt-outs when the technology is used in decisions where it replaces or substantially replaces human decision-making, narrower than the 2023 draft's broader profiling triggers.
  2. ConfirmedIAPPUnder the final ADMT rules, 'human involvement' requires a reviewer who knows how to interpret an ADMT-driven output, reviews the output and related information, and has authority to change or correct the final decision.
  3. ConfirmedIAPPThe final ADMT regulations removed prior draft references to artificial intelligence and behavioral advertising as defined terms while widening the scope of circumstances in which ADMT can be used.
  4. ProbableIAPPCPPA Executive Director Tom Kemp indicated the projected economic impact of the final ADMT/risk-assessment/cyber-audit rules decreased to about $4.8 billion in compliance costs over 10 years, against an estimated $282 billion in economic benefits over the same period.
  5. ConfirmedCalifornia Privacy Protection AgencyThe CPPA's original 2023 draft ADMT regulations proposed coverage of profiling consumers in publicly accessible places (e.g., shopping malls, medical offices, stadiums) using technologies such as facial recognition or automated emotion assessment.

#

The regulatory picture for minors is unusually dynamic: AADCA is only partially operative pending further litigation, SB 976's core protections are in force but its implementing age-assurance regulations are still in rulemaking, and dependent-adult protections are a genuine gap.

Primary frameworkCal. Civil Code § 1798.120(c) (CCPA minors' opt-in); Cal. Bus. & Prof. Code §§ 22580-22582 (AADCA); Cal. Health & Safety Code §§ 27000-27007 (SB 976)
Traffic-light rationale — AmberThe regulatory picture for minors is unusually dynamic: AADCA is only partially operative pending further litigation, SB 976's core protections are in force but its implementing age-assurance regulations are still in rulemaking, and dependent-adult protections are a genuine gap.

Sub-modules (5)

Age VerificationAmber

SB 976 requires the Attorney General to adopt regulations on age assurance and parental consent by January 1, 2027; proposed regulations were released with a 45-day comment period and a June 30, 2026 public hearing. Separately, the Ninth Circuit's March 2026 ruling upheld the AADCA's age-estimation mandate against First Amendment challenge.

Claims: CLM-US-CA-f5a6b7c8, CLM-US-CA-a6b7c8d9

Minor Profiling BansAmber

The Ninth Circuit found the AADCA's data-protection and dark-patterns provisions unconstitutionally vague and left the law's core Data Protection Impact Assessment requirement enjoined as not severable from the rest of the statute, while vacating the injunction on the Act's restrictions on collection, use, and sale of children's data and undisclosed geolocation collection.

Claims: CLM-US-CA-c8d9e0f1, CLM-US-CA-d9e0f1a2

Education SettingsAmber

Education-specific ADMT profiling (e.g., inferring attributes about students) is flagged as risk-assessment-triggering under the 2025 CPPA regulations, but no children-specific education statute beyond FERPA/SOPIPA was independently verified this run.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , t, h, i, s, , r, u, n, , d, i, d, , n, o, t, , s, p, e, c, i, f, i, c, a, l, l, y, , t, a, r, g, e, t, , S, O, P, I, P, A, /, F, E, R, P, A, , C, a, l, i, f, o, r, n, i, a, , i, m, p, l, e, m, e, n, t, a, t, i, o, n.

Dependent AdultsRed

No CCPA/CPRA-specific provision addressing dependent adults (elderly or mentally incapacitated persons) was identified; general Elder Abuse and dependent-adult civil protections exist under separate California statutes outside the DP regime, but this run found no data-protection-specific dependent-adult rule.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , q, u, e, r, i, e, s, , t, h, i, s, , r, u, n, , c, o, v, e, r, e, d, , C, C, P, A, /, C, P, R, A, ,, , A, A, D, C, A, ,, , a, n, d, , S, B, , 9, 7, 6, ;, , n, o, , d, e, p, e, n, d, e, n, t, -, a, d, u, l, t, -, s, p, e, c, i, f, i, c, , d, a, t, a, -, p, r, o, t, e, c, t, i, o, n, , p, r, o, v, i, s, i, o, n, , l, o, c, a, t, e, d.

Category narrative86 words

California layers multiple children's-privacy statutes: the CCPA/CPRA's opt-in consent requirement for selling/sharing the personal information of consumers under 16 (with heightened penalties for violations involving minors), the litigation-embattled Age-Appropriate Design Code Act (AADCA, most provisions now unenjoined after the March 2026 Ninth Circuit ruling except the vague data-protection-impact-assessment and dark-patterns provisions), and SB 976 (Protecting Our Kids from Social Media Addiction Act), whose age-assurance and parental-consent implementing regulations remained in a 45-day comment/hearing process through June 30, 2026. No CCPA-specific dependent-adult (elderly/incapacitated) privacy provision was identified.

Sources and claims (5)
  1. ConfirmedCalifornia Department of JusticeSB 976 requires the California Attorney General to adopt regulations regarding age assurance and parental consent methods by January 1, 2027, with a written comment period on proposed regulations closing June 30, 2026.
  2. ConfirmedDataGuidance / OneTrustIn its March 2026 decision in NetChoice v. Bonta, the Ninth Circuit found that NetChoice did not show the AADCA's coverage or age-estimation mandate violated the First Amendment.
  3. ConfirmedCalifornia Department of JusticeSB 976 makes it unlawful for online platforms to provide addictive feeds and certain features to minors without first obtaining verifiable parental consent, and prohibits sending notifications between midnight and 6am to users not established to be over 18 absent parental consent.
  4. ConfirmedDataGuidance / OneTrustThe Ninth Circuit in NetChoice v. Bonta found the AADCA's data protection and dark patterns provisions unconstitutionally vague, and held that NetChoice failed to prove the law's remaining provisions were severable from the enjoined Data Protection Impact Assessment requirement.
  5. ConfirmedCalifornia Department of JusticeThe Ninth Circuit's March 2026 ruling specifically vacated the injunction as to the AADCA's provisions restricting the collection, use, and sale of children's data and the collection of a child's geolocation information without an obvious sign to the child.

#

Enforcement is active, well-resourced, and escalating, with a clear penalty structure and a track record of publicized settlements through 2025-2026, though the narrow private right of action and reliance on UCL-based class actions constrain direct consumer litigation.

Primary frameworkCal. Civil Code §§ 1798.150, 1798.155, 1798.199.40 et seq.
Traffic-light rationale — GreenEnforcement is active, well-resourced, and escalating, with a clear penalty structure and a track record of publicized settlements through 2025-2026, though the narrow private right of action and reliance on UCL-based class actions constrain direct consumer litigation.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The CPPA can investigate on its own initiative or upon sworn complaint, and may impose administrative fines of up to $2,500 per violation, or $7,500 for intentional violations, with enhanced penalties for violations involving consumers under 16; the CCPA prohibits a business from being required to pay both an administrative fine and a civil penalty for the same violation.

Claims: CLM-US-CA-e0f1a2b3, CLM-US-CA-f1a2b3c4

Enforcement Activity IndexGreen

Recent CPPA enforcement actions include a $1.35 million fine against Tractor Supply Company, a $632,500 fine against American Honda Motor Co., a $345,178 fine against Todd Snyder, Inc., and multiple data-broker fines (Datamasters $45,000, S&P Global $62,600) secured via the Data Broker Enforcement Strike Force.

Claims: CLM-US-CA-a2b3c4d5, CLM-US-CA-b3c4d5e6

Regulator Funding And CapacityAmber

The CPPA is the first dedicated U.S. state privacy agency, with its own Board, Executive Director, and Enforcement Division including a specialized Data Broker Enforcement Strike Force; specific budget/headcount figures were not independently verified this run.

Absence provenance: not recorded. Searched: w, e, b, _, s, e, a, r, c, h, , t, h, i, s, , r, u, n, , d, i, d, , n, o, t, , t, a, r, g, e, t, , C, P, P, A, , b, u, d, g, e, t, , a, p, p, r, o, p, r, i, a, t, i, o, n, , o, r, , h, e, a, d, c, o, u, n, t, , f, i, g, u, r, e, s, , s, p, e, c, i, f, i, c, a, l, l, y.

Collective Redress And Class ActionsAmber

Numerous CCPA-based class actions have been pled as predicate violations under California's Unfair Competition Law (UCL) even where a standalone CCPA claim is barred, per early litigation such as Kirpekar v. Zoom and Burke v. Clearview AI.

Claims: CLM-US-CA-c4d5e6f7

Private Right Of ActionAmber

Only consumers whose nonencrypted, nonredacted personal information (using the narrower Customer Records Act definition) is subject to unauthorized access, exfiltration, theft, or disclosure due to a business's failure to maintain reasonable security may bring a private civil action under §1798.150; this does not extend to other CCPA violations.

Claims: CLM-US-CA-d5e6f7a8

Recent Developments 180DGreen

Within the last 180 days, the CPPA launched a Data Broker Enforcement Strike Force (Nov 2025) and issued new decisions in January 2026 against Datamasters and S&P Global; the Delete Act's DROP portal became operational for consumers in January 2026, and CCPA regulations on ADMT, risk assessments, and cybersecurity audits became applicable January 1, 2026.

Claims: CLM-US-CA-e6f7a8b9, CLM-US-CA-f7a8b9c0

Category narrative93 words

The CPPA and Attorney General share dual civil/administrative enforcement authority, with a maximum administrative fine of $2,500 per violation ($7,500 per intentional violation, with enhanced penalties for violations involving consumers under 16). Enforcement activity has escalated markedly through 2025-2026, including six-figure and seven-figure settlements (Tractor Supply $1.35M, American Honda $632,500, Todd Snyder $345,178) and a newly launched Data Broker Enforcement Strike Force generating numerous smaller data-broker fines. The CCPA's private right of action remains narrowly limited to unauthorized breach of certain non-encrypted/non-redacted personal information caused by a business's failure to maintain reasonable security.

Sources and claims (8)
  1. ConfirmedIAPPThe CPPA can investigate possible violations on its own initiative or upon the sworn complaint of any person, and the potential administrative fine is up to $2,500 per violation or $7,500 per intentional violation, with increased potential fines for violations involving consumers under 16.
  2. ConfirmedIAPPA business shall not be required by the agency, a court, or otherwise to pay both an administrative fine and a civil penalty for the same violation.
  3. ConfirmedCalifornia Privacy Protection AgencyRecent CPPA enforcement actions include a $1.35 million fine and business-practice changes required of Tractor Supply Company, a $632,500 fine against American Honda Motor Co., and a $345,178 fine against Todd Snyder, Inc. for CCPA violations.
  4. ConfirmedCalifornia Privacy Protection AgencyThe CPPA Board issued decisions requiring Rickenbacher Data LLC (d/b/a Datamasters) to pay a $45,000 fine and stop selling all Californians' personal information, and S&P Global, Inc. to pay a $62,600 fine, both for failing to register as data brokers.
  5. ProbableIAPPPlaintiffs have pled CCPA violations as predicate 'unlawful activity' under California's Unfair Competition Law even in cases like Almeida v. Slickwraps and Burke v. Clearview AI where a standalone CCPA private right of action claim may not lie.
  6. ConfirmedIAPPSection 1798.150(a)(1) limits the CCPA private right of action to consumers whose nonencrypted and nonredacted personal information (as defined by the narrower Customer Records Act at §1798.81.5(d)(1)(A)) is subject to unauthorized access and exfiltration, theft, or disclosure due to a business's failure to implement reasonable security procedures.
  7. ConfirmedCalifornia Privacy Protection AgencyIn November 2025, CalPrivacy launched a Data Broker Enforcement Strike Force, and in November 2025 California approved final Delete Act regulations governing the DROP accessible-deletion mechanism.
  8. ConfirmedIAPPAs of the start of 2026, California's Delete Act delete-request/opt-out platform (DROP) launched and CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – California
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 48 claim(s), 26 source(s) in the cumulative register.