In short
- Collect and use only what is reasonably necessary and proportionate to purposes consumers would expect. Anything else needs consent.
- Consent screens must offer symmetrical choices. A consent obtained through a dark pattern is not consent.
- Selling or sharing data, using sensitive data, and several AI and monitoring uses require a documented risk assessment before you start.
- Using automated decisionmaking technology for significant decisions about people requires notices, opt-outs and access rights from January 1, 2027.
- Website pixels, session replay and chat tools draw lawsuits under California's wiretapping law, with $5,000 per violation in statutory damages.
Data minimization and purpose limitation
Your collection, use, retention and sharing of personal information must be "reasonably necessary and proportionate" to achieve the purposes for which it was collected, or another disclosed purpose compatible with the context of collection (Civ. Code § 1798.100(c)). The regulations explain how to apply that test (11 CCR § 7002):
- Reasonable expectations. Consider your relationship with the consumer, the type and amount of data, how you collected it, and how visible any third parties are. The regulation's example: consumers don't expect a flashlight app to collect geolocation.
- Necessary and proportionate. Consider the minimum data needed, the possible harms, and safeguards such as encryption and automatic deletion.
- Anything else needs consent, which consumers must be able to withdraw. New categories of data or new purposes need a new notice at collection.
In May 2026 the Attorney General described its $12.75 million settlement with General Motors as the first data-minimization case under the CCPA.
Consent and dark patterns
Consent must be "freely given, specific, informed, and unambiguous." Accepting general terms of use isn't consent; neither is hovering over, muting, pausing or closing content; and agreement obtained through a dark pattern isn't consent (Civ. Code § 1798.140(h), (l)). Under the regulations (11 CCR § 7004):
- Symmetry in choice: the privacy-protective path can't be longer or harder. "Accept All" paired only with "More Information" isn't symmetrical; "Accept All" and "Decline All" is.
- No confusing language, double negatives or false urgency.
- No bundling of necessary uses with unrelated ones.
- Easy to execute: broken links and unmonitored inboxes can violate the rule.
- Intent doesn't matter: an interface you know impairs choice and don't fix can be a dark pattern.
Risk assessments
Since January 1, 2026, a CCPA business must complete a risk assessment before starting processing that presents significant risk (11 CCR § 7150):
- selling or sharing personal information;
- processing sensitive personal information (with a narrow carve-out for routine employee payroll, benefits and similar uses);
- using automated decisionmaking technology for a significant decision;
- using automated processing to infer traits from "systematic observation" of job applicants, employees, contractors or students;
- using automated processing to infer traits from a person's presence at a "sensitive location," such as a healthcare facility, pharmacy, shelter or place of worship; and
- processing personal information to train automated decisionmaking technology for significant decisions, or facial-recognition, emotion-recognition or other identification technology.
The assessment documents the purpose, the data, how processing works, its benefits and negative impacts, the safeguards, and whether the business will proceed, and must be approved by someone with authority over that decision (11 CCR § 7152). The stated goal is to restrict or prohibit processing when the risks outweigh the benefits (11 CCR § 7154).
| Timing rule | Deadline |
|---|---|
| New processing | Before it starts; review at least every 3 years; update within 45 days of a material change (§ 7155(a)) |
| Processing that began before 2026 and continues | December 31, 2027 (§ 7155(b)) |
| First submission and executive attestation to CalPrivacy | April 1, 2028, covering 2026–2027; then April 1 each year (§ 7157) |
Automated decisionmaking technology
ADMT is "any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking" (11 CCR § 7001(e)). A tool "substantially replaces" human decisionmaking unless a human reviewer knows how to interpret its output, actually reviews it with other relevant information, and has authority to change the decision.
The rules apply when ADMT is used for a significant decision: providing or denying financial or lending services, housing, education, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising is not a significant decision (11 CCR § 7001(ddd)). From January 1, 2027 (11 CCR § 7200(b)):
- Pre-use notice at or before collection, explaining the specific purpose, how the ADMT works, and the consumer's rights (§ 7220).
- Opt-out right, unless an exception applies, such as a qualifying human appeal, or a hiring or work-allocation tool used solely to assess ability to perform that works as intended and doesn't unlawfully discriminate (§ 7221).
- Access right: on request, a plain-language explanation of the purpose, the logic, and how the output was used in the decision (§ 7222).
For employment uses, also see the Civil Rights Council's automated-decision system regulations in Employee data.
New kinds of sensitive data
- Neural data, meaning information generated by measuring the activity of a person's nervous system, is sensitive personal information (Civ. Code § 1798.140(ae); SB 1223, 2024).
- Precise geolocation means locating someone within a circle with a radius of 1,850 feet (§ 1798.140(w)).
- AI systems: personal information can exist in "artificial intelligence systems that are capable of outputting personal information" (§ 1798.140(v); AB 1008, 2024).
AI laws with privacy consequences
| Law | What it requires | When |
|---|---|---|
| AB 2013 (training data transparency) | Developers of public generative AI systems post documentation of their training data, including whether it contains personal information (Civ. Code § 3111). | By Jan. 1, 2026, and before each new release or substantial modification |
| SB 942, California AI Transparency Act | Covered generative AI providers offer AI-detection tools and disclosures in generated content (Bus. & Prof. Code § 22757.6). | Operative Aug. 2, 2026 (delayed by AB 853); platform duties from Jan. 1, 2027 |
| SB 243 (companion chatbots) | Disclose that a companion chatbot is AI where a reasonable person could be misled; added protections for known minors. | Enacted 2025; annual reports from July 1, 2027 |
| AB 1043 (age signals) | Operating systems send age-range signals to app developers; a developer that receives one is treated as knowing the user's age range. | Operative Jan. 1, 2027 |
Website tracking: pixels, session replay and chat
Plaintiffs regularly sue website operators under the California Invasion of Privacy Act, alleging that advertising pixels, session-replay scripts and third-party chat tools let outside companies intercept communications without consent (Penal Code § 631) or act as a "pen register" (§ 638.51). The statute allows $5,000 per violation or three times actual damages, whichever is greater, and actual damages aren't required (§ 637.2).
- In Doe v. Adventist Health System/West (Cal. Ct. App., ordered published Aug. 24, 2026), the court partly reversed the denial of class certification in a case over tracking tools on hospital websites and a patient portal, brought under § 631 and the CMIA. It was a class-certification ruling, not a decision on the merits.
- SB 690 passed the Legislature in August 2026 and, as of this review, awaits the Governor's action. As passed, it would leave § 638.51 claims based on website and app conduct to the Attorney General alone. It would not change § 631 wiretapping claims.
Tracking tools also bear on the CCPA: sending data to ad networks can be "sharing," and third-party tags on health-related pages raise medical-privacy issues. See Consumer privacy and Health information.
Children and teens
Selling or sharing the data of consumers you know are under 16 requires opt-in consent (Civ. Code § 1798.120(c)). The California Age-Appropriate Design Code Act remains partly enjoined: in March 2026 the Ninth Circuit left in place the injunction against its data-use and dark-pattern provisions, and earlier rulings had blocked its impact-assessment and notice-and-cure provisions (NetChoice v. Bonta, No. 25-2366). The case continues in the district court.
Privacy-by-design checklist
- Write down a specific purpose for each data element, and confirm consumers would expect it.Civ. Code § 1798.100(c); 11 CCR § 7002
- Collect the minimum. Record the risks and safeguards, such as encryption and automatic deletion.11 CCR § 7002(d)
- Get withdrawable consent for anything outside the expected purpose, and update the notice at collection.11 CCR § 7002(e)–(f)
- Design consent screens with equal choices, and test them.11 CCR § 7004
- Screen the feature against the risk-assessment triggers before launch.11 CCR § 7150
- If triggered, complete and approve the assessment before processing starts.11 CCR §§ 7152, 7155
- If the feature makes significant decisions without meaningful human review, build the pre-use notice, opt-out or appeal, and access workflow.11 CCR §§ 7200, 7220–7222
- Treat AI models and training data as possibly containing personal information, and map consumer rights to them.Civ. Code § 1798.140(v)
- Inventory every pixel, SDK, session-replay and chat vendor; get consent or configure them appropriately; honor opt-out signals.Penal Code §§ 631, 638.51; 11 CCR § 7025
- If minors may use the product, plan for opt-in consent and age signals.Civ. Code §§ 1798.120(c), 1798.500 and following
Related guides
- ExplainerHonoring Global Privacy Control and other opt-out signalsCalifornia requires businesses that sell or share personal information to honor Global Privacy Control, display that they did, and apply it across devices for known users.
- Topic guideEmployee dataCalifornia employee privacy: CCPA rights for workers since 2023, notices to applicants, personnel and payroll record deadlines, employee medical information, and AI hiring rules.