California: What CCPA and CPRA Change for Performance Marketers
California regulators issued over $4 million in fines in the first quarter of 2026 alone for failures to implement opt-out mechanisms properly — including a $2.75 million settlement with Disney, the largest in CCPA history. The finding in that case is the one every digital marketing team should read twice: investigators concluded the company’s opt-out processes did not fully stop data sale and sharing when consumers were logged into their accounts. The banner worked. What happened behind it did not — which is a performance marketing failure as much as a legal one, because the tags kept firing.
A state analysis from Digital, Ecommerce & Performance Marketing in the United States. This is marketing commentary, not legal advice. California privacy obligations depend on your specific business, data practices and thresholds — engage qualified privacy counsel. Regulations are changing rapidly; verify current requirements with CalPrivacy directly. Last reviewed August 2026.
1. Why California sets your national standard
As of March 2026, twenty states have comprehensive privacy laws, and all of them provide some form of opt-out right — but the specifics diverge considerably.
| Requirement | States |
|---|---|
| Universal opt-out mechanism required | California, Colorado, Connecticut, Delaware, Montana, Nebraska, New Hampshire, New Jersey, Texas, Oregon, Minnesota, Maryland |
| Opt-out of sale only | Virginia, Indiana, Iowa, Tennessee, Kentucky, Rhode Island, Oklahoma |
| GPC or similar signal recognised | California, Colorado, Connecticut, Montana, Texas |
Source: state privacy law comparison as published March 2026. Note this figure of twenty states supersedes the nineteen-or-more figure cited on earlier pages in this cluster — the count moves as legislatures act, which is itself the point.
California is the practical benchmark for three reasons: it has the first dedicated state privacy enforcement agency, the most detailed regulations, and by far the most active enforcement record. For any national digital marketing programme, building to California generally satisfies the others; building to a weaker state and hoping does not work in reverse.
The count of states with privacy laws changed while this cluster was being written. That is not a research failure — it is the operating condition.
2. What counts as a sale or share
The most common and expensive misunderstanding in California compliance is assuming no sale occurs because no money changes hands. The CCPA’s definitions reach considerably further than financial transactions, covering the ordinary machinery of ecommerce marketing — retargeting pixels, audience sharing, analytics integrations and conversion feeds all sit within scope depending on the arrangement.
| Assumption | Why it is risky |
|---|---|
| We do not sell data, no money changes hands | Definitions extend beyond financial exchange |
| Analytics is not advertising | Depends on the data flow and recipient |
| It is a service provider, not a third party | Depends on contract terms and actual practice |
| Retargeting pixels are just functionality | Cross-context behavioural advertising is covered by sharing |
| Our partners follow an industry framework | Enforcement suggests this is not sufficient alone |
Based on published analysis of CCPA sale and sharing definitions in 2026, which note that the definitions cover common marketing and website operations beyond monetary transactions, and that sharing specifically addresses cross-context targeted advertising. Whether any specific activity constitutes a sale or share for your business is a legal determination.
3. What changed on 1 January 2026
Updated CCPA regulations took effect at the start of 2026 and are described as ending the era of compliance by documentation. The single most operationally significant change for marketers is small and easy to miss.
Sources: Greenberg Traurig analysis of revised CCPA regulations effective 1 January 2026, noting that confirmation of opt-out processing — previously discretionary — becomes mandatory, with the CPPA citing display of an Opt-Out Request Honored message or a toggle in privacy settings as examples. The regulations’ phrasing suggests other methods may be acceptable.
Alongside this, the 2026 package introduces cybersecurity audit requirements and risk assessments for processing that presents significant risk, with assessments required for new processing activity from 1 January 2026.
4. Global Privacy Control is binding
Businesses must treat a GPC signal as a valid, binding request to opt out of the sale or sharing of personal information — and, under the updated rules, of the use of automated decision-making technology for profiling. These are machine-readable signals sent by browsers such as Brave or DuckDuckGo, or via extensions.
This is not a new idea in California. Sephora settled for $1.2 million in 2022 partly for failing to process GPC signals, in what is described as the first major enforcement action specifically targeting GPC non-compliance. Four years later it remains a stated enforcement priority.
A browser signal your website never listens for is a compliance failure that requires no consumer complaint to discover. Regulators can test it themselves, at scale, from anywhere.
5. Dark patterns: intent does not matter
The updated regulations clarify that a user interface is a dark pattern if it subverts or impairs user choice even if the business did not intend it to. Cited examples include confirmshaming, confusing language, and obstructive consent banners that hide the opt-out option behind multiple clicks.
| Pattern | Why it fails | Fix |
|---|---|---|
| Opt-out buried behind several clicks | Obstructive by effect | Parity with the accept path |
| Confirmshaming language | Subverts autonomy | Neutral wording both ways |
| Accept button prominent, decline greyed | Impairs choice visually | Equal visual weight |
| Confusing double negatives | Users cannot tell what they chose | Plain language |
| Banner reappearing after opt-out | Pressures reversal | Respect the stored preference |
Based on CPPA guidance that a user interface constitutes a dark pattern where its effect subverts or impairs consumer autonomy regardless of intent, with confirmshaming, confusing language and obstructive banners cited as examples. Specific design compliance should be reviewed by counsel.
The design implication is uncomfortable for conversion-focused teams: a consent flow optimised for acceptance rate is, almost by definition, moving toward the thing being described.
6. The enforcement record
California is no longer a theoretical compliance risk. The published record is specific.
| Action | Amount | Reported basis |
|---|---|---|
| Disney (2026) | $2.75M | Opt-out did not fully stop sale and sharing for logged-in users |
| PlayOn Sports (2026) | $1.1M | Opt-out mechanism failures |
| Ford (2026) | $375K | Opt-out mechanism failures |
| Sephora (2022) | $1.2M | Failure to process GPC signals |
Sources: reported California privacy enforcement actions, with over $4 million in fines issued in Q1 2026 for opt-out implementation failures. The Disney settlement is described as the largest CCPA settlement in California history.
Two further developments signal direction. CalPrivacy launched a Data Broker Enforcement Strike Force in November 2025 with further actions in January 2026, and formed a new Audits Division in February 2026 under a newly appointed Chief Auditor. Separately, a 2025 joint investigative sweep saw California, Colorado and Connecticut regulators coordinate on businesses refusing to honour opt-outs — multi-state enforcement rather than a single-state problem.
7. ADMT and the 2027 deadline
Automated decision-making technology requirements bring pre-use notice, opt-out rights and appeals for automated decisions. The consumer opt-out rights for ADMT carry a separate compliance date of 1 January 2027.
For marketers using algorithmic profiling this is the deadline worth diarising now, because the work — documenting pre-use notices, building opt-out handling, running an appeals process — is systems work rather than policy work.
8. Vendor contracts and the Healthline lesson
Enforcement commentary makes a pointed observation about relying on industry frameworks: Healthline reportedly believed its partners followed a standard privacy code, and the absence of contract terms and evidence became part of the problem.
| Contract term | Purpose |
|---|---|
| Use limited to your defined business purpose | Prevents scope creep |
| Ban on onward sale or sharing | Stops downstream leakage |
| Deletion or suppression after opt-out | Makes the opt-out real |
| No combining with other sources without approval | Limits enrichment you did not authorise |
| Audit and evidence rights | Lets you verify rather than trust |
Based on published guidance on CCPA vendor contract requirements for ad tech, agencies, analytics firms and processors, including the recommendation to reserve audit rights and obtain evidence that vendors honour opt-out signals. Contract drafting is a legal task.
9. What this page does not cover
| Not covered | Why |
|---|---|
| Whether CCPA applies to your business | Depends on thresholds and activity |
| Contract drafting | Legal work |
| Cybersecurity audit specifications | Technical and legal specialism |
| Risk assessment methodology | Prescribed content; needs counsel |
| Sensitive data categories in detail | Sector-specific implications |
| Data broker registration duties | Separate regime under the Delete Act |
Scope statement. This page describes the marketing implications of published requirements. It does not assess legal applicability to any business and is not a substitute for advice.
10. The compliance sequence
Indicative sequencing for marketing teams, to be run with legal oversight. Technical verification is placed first because the Disney finding concerned what happened after the opt-out was recorded, not the opt-out interface itself.
11. Mistakes to avoid
| Mistake | Why it happens | What it costs |
|---|---|---|
| Assuming no sale because no money moves | Plain reading of the word sale | Definitions reach further |
| Testing opt-out only when logged out | Easier test case | The Disney finding concerned logged-in users |
| Recording consent without enforcing it | CMP looks configured | Tags keep firing regardless |
| Optimising consent UI for acceptance | Conversion instinct | Moves toward dark pattern territory |
| Silent opt-out processing | Was permitted before 2026 | Confirmation is now mandatory |
| Trusting a vendor’s framework claim | Reduces contracting effort | Evidence, not assurance, is what counts |
Recurring errors in California privacy compliance for marketing teams; illustrative.
12. What changes next
ADMT opt-out rights arrive 1 January 2027. Pre-use notices, opt-out handling and appeals processes for automated decisions need building before then, and that is systems work with a lead time.
Audits become real. With a dedicated Audits Division formed in February 2026 and cybersecurity audit requirements in force, the enforcement model shifts from complaint-driven toward proactive examination.
Data broker deletion obligations bite. The Delete Act’s DROP platform launched in January 2026, with registered data brokers required to begin processing deletion requests by 1 August 2026 and to check every 45 days.
Key Takeaways
- Over $4M in California privacy fines in Q1 2026 alone, led by a $2.75M Disney settlement — the largest in CCPA history.
- The Disney finding was about what happened after the opt-out: processes reportedly did not fully stop sale and sharing for logged-in users.
- Opt-out confirmation became mandatory on 1 January 2026. Silent processing is no longer sufficient.
- GPC signals are binding for sale, sharing and ADMT profiling — and regulators can test compliance without a complaint.
- A dark pattern is judged on effect, not intent. A consent flow optimised for acceptance is heading somewhere dangerous.
- No money changing hands does not mean no sale. The definitions cover ordinary marketing operations.
- ADMT consumer opt-out rights apply from 1 January 2027. Start now; it is systems work.
Frequently Asked Questions
We do not sell data. Does CCPA still affect our advertising?
Probably. The definitions of sale and sharing extend beyond transactions where money changes hands, and sharing specifically covers cross-context behavioural advertising. Common marketing operations including retargeting can fall within scope. Whether yours do is a legal question for counsel.
What actually changed in January 2026?
Updated regulations took effect adding cybersecurity audit requirements, risk assessments for significant-risk processing, ADMT provisions, and — most immediately relevant to marketers — a mandatory requirement to confirm to the consumer that an opt-out request has been processed.
Do we have to honour Global Privacy Control?
Yes. Businesses must treat GPC as a valid, binding opt-out request for sale and sharing, and under updated rules for ADMT profiling as well. Sephora’s $1.2 million settlement in 2022 was the first major action specifically on GPC non-compliance.
Our consent banner records opt-outs. Is that enough?
Not on its own. The Disney matter reportedly turned on opt-out processes not fully stopping data sale and sharing for logged-in users. If your platform records a preference while tags continue firing, the record is not the compliance — the behaviour is.
Can a consent banner be a dark pattern unintentionally?
Yes. Regulators have clarified that intent does not matter — what matters is whether the interface’s effect subverts or impairs consumer choice. Confirmshaming, confusing language and burying the opt-out behind multiple clicks are all cited examples.
Is this only a California problem?
No. Twenty states now have comprehensive privacy laws, twelve require a universal opt-out mechanism, and in 2025 California, Colorado and Connecticut ran a coordinated investigative sweep on businesses refusing to honour opt-outs. Multi-state enforcement is already happening.
What should we do about vendors?
Get the obligations into contracts rather than relying on framework membership, and reserve the right to see evidence. Enforcement commentary on Healthline notes that believing partners followed a standard privacy code, without contract terms or proof, became part of the problem.
When do ADMT requirements apply?
Consumer opt-out rights for automated decision-making technology carry a compliance date of 1 January 2027, separate from the January 2026 regulations. Pre-use notices, opt-out handling and appeals all need building, so the lead time matters.
What is the single most useful thing to do this week?
Send a GPC signal to your own site while logged into an account, then watch what your tags actually do. That test replicates the fact pattern behind the largest CCPA settlement to date and costs nothing but an afternoon.
Conclusion
California has moved from a compliance regime you could satisfy with a policy document to one that is tested against what your website actually does. The 2026 regulations demand visible confirmation rather than silent processing, judge interface design on effect rather than intent, and sit behind an agency that has built an audits division and issued over $4 million in fines in a single quarter.
For marketing teams the practical translation is short. The consent banner is not the compliance; the tag behaviour behind it is. Test it while logged in, because that is where the largest settlement in the law’s history was found. And treat California as your national baseline — twenty states now have comparable laws, they are increasingly coordinating enforcement, and building to the strictest one is considerably cheaper than discovering the difference through an investigation.
This page sits inside a wider US digital, ecommerce and performance marketing cluster. For what to build once the constraints are understood, see performance marketing in a consent-required market and measurement under privacy constraints.
Work With Me
If nobody has tested what your tags do after a California opt-out — particularly for logged-in users — that is a short piece of work with a large downside attached.
