California: What CCPA and CPRA Change for Performance Marketers

Sharing is caring!

California regulators issued over $4 million in fines in the first quarter of 2026 alone for failures to implement opt-out mechanisms properly — including a $2.75 million settlement with Disney, the largest in CCPA history. The finding in that case is the one every digital marketing team should read twice: investigators concluded the company’s opt-out processes did not fully stop data sale and sharing when consumers were logged into their accounts. The banner worked. What happened behind it did not — which is a performance marketing failure as much as a legal one, because the tags kept firing.

A state analysis from Digital, Ecommerce & Performance Marketing in the United States. This is marketing commentary, not legal advice. California privacy obligations depend on your specific business, data practices and thresholds — engage qualified privacy counsel. Regulations are changing rapidly; verify current requirements with CalPrivacy directly. Last reviewed August 2026.

$4M+California privacy fines in Q1 2026 alone
$2.75MDisney settlement, largest in CCPA history
Jan 2026New CCPA regulations took effect
Jan 2027ADMT opt-out compliance date
20States with comprehensive privacy laws
IntentIrrelevant to a dark pattern finding

1. Why California sets your national standard

As of March 2026, twenty states have comprehensive privacy laws, and all of them provide some form of opt-out right — but the specifics diverge considerably.

RequirementStates
Universal opt-out mechanism requiredCalifornia, Colorado, Connecticut, Delaware, Montana, Nebraska, New Hampshire, New Jersey, Texas, Oregon, Minnesota, Maryland
Opt-out of sale onlyVirginia, Indiana, Iowa, Tennessee, Kentucky, Rhode Island, Oklahoma
GPC or similar signal recognisedCalifornia, Colorado, Connecticut, Montana, Texas

Source: state privacy law comparison as published March 2026. Note this figure of twenty states supersedes the nineteen-or-more figure cited on earlier pages in this cluster — the count moves as legislatures act, which is itself the point.

California is the practical benchmark for three reasons: it has the first dedicated state privacy enforcement agency, the most detailed regulations, and by far the most active enforcement record. For any national digital marketing programme, building to California generally satisfies the others; building to a weaker state and hoping does not work in reverse.

The count of states with privacy laws changed while this cluster was being written. That is not a research failure — it is the operating condition.

2. What counts as a sale or share

The most common and expensive misunderstanding in California compliance is assuming no sale occurs because no money changes hands. The CCPA’s definitions reach considerably further than financial transactions, covering the ordinary machinery of ecommerce marketing — retargeting pixels, audience sharing, analytics integrations and conversion feeds all sit within scope depending on the arrangement.

AssumptionWhy it is risky
We do not sell data, no money changes handsDefinitions extend beyond financial exchange
Analytics is not advertisingDepends on the data flow and recipient
It is a service provider, not a third partyDepends on contract terms and actual practice
Retargeting pixels are just functionalityCross-context behavioural advertising is covered by sharing
Our partners follow an industry frameworkEnforcement suggests this is not sufficient alone

Based on published analysis of CCPA sale and sharing definitions in 2026, which note that the definitions cover common marketing and website operations beyond monetary transactions, and that sharing specifically addresses cross-context targeted advertising. Whether any specific activity constitutes a sale or share for your business is a legal determination.

3. What changed on 1 January 2026

Updated CCPA regulations took effect at the start of 2026 and are described as ending the era of compliance by documentation. The single most operationally significant change for marketers is small and easy to miss.

Silent compliance is no longer compliance Before 2026 Signal received Processed silently discretionary From 2026 Signal received Processed CONFIRMED The user must be able to see that it was honoured. Regulators cited an example message such as Opt-Out Request Honored, or a toggle in privacy settings showing the consumer’s current status. A CMP that records the opt-out while tags keep firing is the failure mode. Source: CPPA revised regulations effective 1 January 2026, making opt-out confirmation mandatory where previously discretionary.

Sources: Greenberg Traurig analysis of revised CCPA regulations effective 1 January 2026, noting that confirmation of opt-out processing — previously discretionary — becomes mandatory, with the CPPA citing display of an Opt-Out Request Honored message or a toggle in privacy settings as examples. The regulations’ phrasing suggests other methods may be acceptable.

Alongside this, the 2026 package introduces cybersecurity audit requirements and risk assessments for processing that presents significant risk, with assessments required for new processing activity from 1 January 2026.

4. Global Privacy Control is binding

Businesses must treat a GPC signal as a valid, binding request to opt out of the sale or sharing of personal information — and, under the updated rules, of the use of automated decision-making technology for profiling. These are machine-readable signals sent by browsers such as Brave or DuckDuckGo, or via extensions.

This is not a new idea in California. Sephora settled for $1.2 million in 2022 partly for failing to process GPC signals, in what is described as the first major enforcement action specifically targeting GPC non-compliance. Four years later it remains a stated enforcement priority.

A browser signal your website never listens for is a compliance failure that requires no consumer complaint to discover. Regulators can test it themselves, at scale, from anywhere.

5. Dark patterns: intent does not matter

The updated regulations clarify that a user interface is a dark pattern if it subverts or impairs user choice even if the business did not intend it to. Cited examples include confirmshaming, confusing language, and obstructive consent banners that hide the opt-out option behind multiple clicks.

PatternWhy it failsFix
Opt-out buried behind several clicksObstructive by effectParity with the accept path
Confirmshaming languageSubverts autonomyNeutral wording both ways
Accept button prominent, decline greyedImpairs choice visuallyEqual visual weight
Confusing double negativesUsers cannot tell what they chosePlain language
Banner reappearing after opt-outPressures reversalRespect the stored preference

Based on CPPA guidance that a user interface constitutes a dark pattern where its effect subverts or impairs consumer autonomy regardless of intent, with confirmshaming, confusing language and obstructive banners cited as examples. Specific design compliance should be reviewed by counsel.

The design implication is uncomfortable for conversion-focused teams: a consent flow optimised for acceptance rate is, almost by definition, moving toward the thing being described.

6. The enforcement record

California is no longer a theoretical compliance risk. The published record is specific.

ActionAmountReported basis
Disney (2026)$2.75MOpt-out did not fully stop sale and sharing for logged-in users
PlayOn Sports (2026)$1.1MOpt-out mechanism failures
Ford (2026)$375KOpt-out mechanism failures
Sephora (2022)$1.2MFailure to process GPC signals

Sources: reported California privacy enforcement actions, with over $4 million in fines issued in Q1 2026 for opt-out implementation failures. The Disney settlement is described as the largest CCPA settlement in California history.

Two further developments signal direction. CalPrivacy launched a Data Broker Enforcement Strike Force in November 2025 with further actions in January 2026, and formed a new Audits Division in February 2026 under a newly appointed Chief Auditor. Separately, a 2025 joint investigative sweep saw California, Colorado and Connecticut regulators coordinate on businesses refusing to honour opt-outs — multi-state enforcement rather than a single-state problem.

7. ADMT and the 2027 deadline

Automated decision-making technology requirements bring pre-use notice, opt-out rights and appeals for automated decisions. The consumer opt-out rights for ADMT carry a separate compliance date of 1 January 2027.

For marketers using algorithmic profiling this is the deadline worth diarising now, because the work — documenting pre-use notices, building opt-out handling, running an appeals process — is systems work rather than policy work.

8. Vendor contracts and the Healthline lesson

Enforcement commentary makes a pointed observation about relying on industry frameworks: Healthline reportedly believed its partners followed a standard privacy code, and the absence of contract terms and evidence became part of the problem.

Contract termPurpose
Use limited to your defined business purposePrevents scope creep
Ban on onward sale or sharingStops downstream leakage
Deletion or suppression after opt-outMakes the opt-out real
No combining with other sources without approvalLimits enrichment you did not authorise
Audit and evidence rightsLets you verify rather than trust

Based on published guidance on CCPA vendor contract requirements for ad tech, agencies, analytics firms and processors, including the recommendation to reserve audit rights and obtain evidence that vendors honour opt-out signals. Contract drafting is a legal task.

9. What this page does not cover

Not coveredWhy
Whether CCPA applies to your businessDepends on thresholds and activity
Contract draftingLegal work
Cybersecurity audit specificationsTechnical and legal specialism
Risk assessment methodologyPrescribed content; needs counsel
Sensitive data categories in detailSector-specific implications
Data broker registration dutiesSeparate regime under the Delete Act

Scope statement. This page describes the marketing implications of published requirements. It does not assess legal applicability to any business and is not a substitute for advice.

10. The compliance sequence

Test what actually fires, then fix the interface Week 0 Week 4 Week 8 Week 12 Send a GPC signal and watch the tags Test opt-out while logged in Add visible opt-out confirmation Dark pattern review of consent UI Vendor contract terms and evidence ADMT readiness before Jan 2027 Red = verify reality, amber = interface, green = supply chain, grey = next deadline. Indicative; run alongside counsel.

Indicative sequencing for marketing teams, to be run with legal oversight. Technical verification is placed first because the Disney finding concerned what happened after the opt-out was recorded, not the opt-out interface itself.

11. Mistakes to avoid

MistakeWhy it happensWhat it costs
Assuming no sale because no money movesPlain reading of the word saleDefinitions reach further
Testing opt-out only when logged outEasier test caseThe Disney finding concerned logged-in users
Recording consent without enforcing itCMP looks configuredTags keep firing regardless
Optimising consent UI for acceptanceConversion instinctMoves toward dark pattern territory
Silent opt-out processingWas permitted before 2026Confirmation is now mandatory
Trusting a vendor’s framework claimReduces contracting effortEvidence, not assurance, is what counts

Recurring errors in California privacy compliance for marketing teams; illustrative.

12. What changes next

ADMT opt-out rights arrive 1 January 2027. Pre-use notices, opt-out handling and appeals processes for automated decisions need building before then, and that is systems work with a lead time.

Audits become real. With a dedicated Audits Division formed in February 2026 and cybersecurity audit requirements in force, the enforcement model shifts from complaint-driven toward proactive examination.

Data broker deletion obligations bite. The Delete Act’s DROP platform launched in January 2026, with registered data brokers required to begin processing deletion requests by 1 August 2026 and to check every 45 days.

Key Takeaways

  • Over $4M in California privacy fines in Q1 2026 alone, led by a $2.75M Disney settlement — the largest in CCPA history.
  • The Disney finding was about what happened after the opt-out: processes reportedly did not fully stop sale and sharing for logged-in users.
  • Opt-out confirmation became mandatory on 1 January 2026. Silent processing is no longer sufficient.
  • GPC signals are binding for sale, sharing and ADMT profiling — and regulators can test compliance without a complaint.
  • A dark pattern is judged on effect, not intent. A consent flow optimised for acceptance is heading somewhere dangerous.
  • No money changing hands does not mean no sale. The definitions cover ordinary marketing operations.
  • ADMT consumer opt-out rights apply from 1 January 2027. Start now; it is systems work.

Frequently Asked Questions

We do not sell data. Does CCPA still affect our advertising?

Probably. The definitions of sale and sharing extend beyond transactions where money changes hands, and sharing specifically covers cross-context behavioural advertising. Common marketing operations including retargeting can fall within scope. Whether yours do is a legal question for counsel.

What actually changed in January 2026?

Updated regulations took effect adding cybersecurity audit requirements, risk assessments for significant-risk processing, ADMT provisions, and — most immediately relevant to marketers — a mandatory requirement to confirm to the consumer that an opt-out request has been processed.

Do we have to honour Global Privacy Control?

Yes. Businesses must treat GPC as a valid, binding opt-out request for sale and sharing, and under updated rules for ADMT profiling as well. Sephora’s $1.2 million settlement in 2022 was the first major action specifically on GPC non-compliance.

Our consent banner records opt-outs. Is that enough?

Not on its own. The Disney matter reportedly turned on opt-out processes not fully stopping data sale and sharing for logged-in users. If your platform records a preference while tags continue firing, the record is not the compliance — the behaviour is.

Can a consent banner be a dark pattern unintentionally?

Yes. Regulators have clarified that intent does not matter — what matters is whether the interface’s effect subverts or impairs consumer choice. Confirmshaming, confusing language and burying the opt-out behind multiple clicks are all cited examples.

Is this only a California problem?

No. Twenty states now have comprehensive privacy laws, twelve require a universal opt-out mechanism, and in 2025 California, Colorado and Connecticut ran a coordinated investigative sweep on businesses refusing to honour opt-outs. Multi-state enforcement is already happening.

What should we do about vendors?

Get the obligations into contracts rather than relying on framework membership, and reserve the right to see evidence. Enforcement commentary on Healthline notes that believing partners followed a standard privacy code, without contract terms or proof, became part of the problem.

When do ADMT requirements apply?

Consumer opt-out rights for automated decision-making technology carry a compliance date of 1 January 2027, separate from the January 2026 regulations. Pre-use notices, opt-out handling and appeals all need building, so the lead time matters.

What is the single most useful thing to do this week?

Send a GPC signal to your own site while logged into an account, then watch what your tags actually do. That test replicates the fact pattern behind the largest CCPA settlement to date and costs nothing but an afternoon.

Conclusion

California has moved from a compliance regime you could satisfy with a policy document to one that is tested against what your website actually does. The 2026 regulations demand visible confirmation rather than silent processing, judge interface design on effect rather than intent, and sit behind an agency that has built an audits division and issued over $4 million in fines in a single quarter.

For marketing teams the practical translation is short. The consent banner is not the compliance; the tag behaviour behind it is. Test it while logged in, because that is where the largest settlement in the law’s history was found. And treat California as your national baseline — twenty states now have comparable laws, they are increasingly coordinating enforcement, and building to the strictest one is considerably cheaper than discovering the difference through an investigation.

This page sits inside a wider US digital, ecommerce and performance marketing cluster. For what to build once the constraints are understood, see performance marketing in a consent-required market and measurement under privacy constraints.

Work With Me

If nobody has tested what your tags do after a California opt-out — particularly for logged-in users — that is a short piece of work with a large downside attached.

Comments

comments

Sharing is caring!

Leave a Reply