Automation

CCPA Compliance in 2026: What's Changed and What's at Stake

TL;DR: The California Consumer Privacy Act, as updated by the CPPA's final regulations effective January 1, 2026, is no longer a notice-and-opt-out exercise. Covered organizations now face mandatory privacy risk assessments, cybersecurity audits, ADMT governance obligations, and phased executive certifications—making continuous, documented compliance the new standard.

California's privacy law has been expanding steadily since 2020. The CPPA's final regulations, effective January 1, 2026, represent the most significant operational shift yet—and most organizations aren't as prepared as they think.

This post explains what's actually changed, why the 2026 obligations are different in kind from earlier CCPA requirements, and what companies processing California consumer data need to do right now.

What Does CCPA Compliance Actually Require in 2026?

The CCPA—formally, the California Consumer Privacy Act as amended by the CPRA—has always required organizations to honor consumer rights, maintain a privacy policy, and provide notice at collection. Those baseline obligations haven't changed.

What the 2026 regulations add is a layer of proactive, documented governance that goes well beyond consumer-facing disclosures. The law now requires:

  • Privacy risk assessments for processing activities that present a significant risk to consumer privacy—before that processing begins

  • Mandatory cybersecurity audits for businesses meeting defined revenue and processing thresholds, conducted by qualified, independent auditors

  • ADMT governance for automated decision-making technology used in significant decisions about consumers, with phased opt-out rights beginning in 2027

  • Executive certifications submitted annually to the CPPA attesting to completion of required assessments and audits

  • Dark pattern prohibitions that explicitly target consent flows designed to make rights harder to exercise than to waive

The law is no longer asking whether you've published a privacy policy. It's asking whether you can prove your program works—and whether you're prepared to hand that proof to a regulator on short notice.

The State of GRC in the Age of AI

Only 13% of IT and security professionals are fully confident they can see every AI tool their teams use. Download The State of GRC in the Age of AI to see what 300 practitioners revealed about governing AI faster than it's outpacing them.

State of GRC 2026

Who Triggers CCPA Obligations in 2026?

The three statutory thresholds that most compliance teams know—annual gross revenue over $25 million (adjusted periodically for inflation; currently just over $26.6 million), processing data of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information—still apply. Meet any one of them and the CCPA applies to your organization.

The 2026 regulations add a second layer: activity-based applicability. Regardless of company size, engaging in specific processing activities can independently trigger enhanced obligations. Those activities include selling or sharing personal information, processing sensitive personal information (SPI), using automated decision-making technology for significant consumer decisions, profiling employees or applicants through systematic observation, and training AI or biometric systems on personal data.

The implication is significant. A company that falls below the revenue and volume thresholds may still face mandatory privacy risk assessments if it deploys ADMT in hiring decisions or processes health data at scale.

What Are the Five Core CCPA Compliance Problem Areas?

CCPA compliance spans five distinct operational challenges, each requiring separate workflows, documentation, and controls.

Consumer rights management covers the six rights California residents hold under the law—to know, delete, correct, opt-out of sale or sharing, limit use of sensitive personal information, and receive equal treatment. Each right requires a documented, repeatable process from intake to fulfillment, with responses generally required within 45 days.

Data inventory and mapping is the operational backbone. Organizations can't fulfill consumer requests, draft accurate privacy notices, or conduct meaningful risk assessments without a current map of what personal information and SPI they collect, where it flows, and who has access.

Privacy notices and consent management requires delivering accurate disclosures at or before collection across every channel—including mobile apps, connected devices, and offline touchpoints. The 2026 regulations also require businesses to technically honor Global Privacy Control (GPC) signals as valid opt-out requests. If your tag management infrastructure doesn't parse and act on GPC at the browser level, you have an active compliance gap.

Vendor and third-party risk management is where programs most commonly fail. A vendor receiving personal information for its own purposes—advertising optimization, model training, analytics—is a third party under the CCPA, not a service provider. That distinction determines whether the relationship is a "sale" requiring an opt-out mechanism. Misclassification is one of the most common enforcement vulnerabilities in CCPA programs.

Governance, risk assessments, and cybersecurity audits are the 2026 additions that transform CCPA from a consumer-rights statute into a continuous governance program.

What Are the New Cybersecurity Audit and Risk Assessment Requirements?

The cybersecurity audit obligation applies to businesses that meet the "significant risk" threshold: organizations deriving 50% or more of annual revenue from selling or sharing personal information, or organizations with annual gross revenue over $25 million that also processed in the preceding calendar year at least 250,000 consumers or households, 50,000 SPI records.

These audits must be conducted by qualified, independent auditors using recognized standards such as NIST CSF or ISO/IEC 27001. The first certifications are due on a staggered schedule by revenue:

  • Over $100M revenue: April 1, 2028 (covering 2027)

  • $50M–$100M revenue: April 1, 2029 (covering 2028)

  • Under $50M revenue: April 1, 2030 (covering 2029)

The submission deadlines are not the start dates. Organizations that wait until 2027 to begin won't have the audit history needed to support the certification.

Privacy risk assessments follow a different trigger: any processing activity presenting a significant risk to consumer privacy—selling or sharing PI, processing SPI, using ADMT for significant decisions, profiling, or training AI systems on personal data—requires a documented assessment before that processing begins. For activities already underway before January 1, 2026, the deadline to complete assessments is December 31, 2027.

Why Do Manual CCPA Programs Fail?

Spreadsheet-driven compliance programs consistently break down under three pressures: DSAR volume, multi-framework demand, and the continuous evidence requirements of the 2026 regulations.

Consumer rights requests don't arrive on a predictable schedule. Evidence for cybersecurity audits needs to reflect control performance across the full calendar year, not a pre-audit sprint. Privacy risk assessments need to be updated after every material change to covered processing activities. None of this is manageable when evidence lives in email threads and shared drives.

The organizations that get into trouble aren't usually the ones with bad intentions—they're the ones whose compliance infrastructure can't produce documentation on demand when the CPPA comes asking.

83%

3% of organizations report moderate or major delays caused by manual compliance work — and 53% dedicate the equivalent of a full-time employee exclusively to evidence collection.

RegScale State of CCM Report 2026

How Does Drata Support CCPA Compliance?

Drata's Agentic Trust Management Platform addresses the operational gaps that make CCPA programs fragile at scale.

Automated evidence collection eliminates the manual work of gathering security controls and vendor assessments that underpin the cybersecurity audit requirement. Cross-framework control mapping connects CCPA obligations to SOC 2, ISO 27001, ISO 27701, and GDPR simultaneously—work done for one framework accelerates readiness for all others, without duplicate effort. Continuous control monitoring surfaces gaps before they become enforcement findings. Vendor risk management centralizes assessments, risk tiers, and ongoing monitoring in a single system of record.

Drata's Trust Center lets organizations publish their security and privacy posture to customers and prospects cutting down the back-and-forth of manual security questionnaires—a direct differentiator when enterprise buyers require CCPA evidence as part of vendor onboarding.

Start Building a Defensible CCPA Program Now

The 2026 regulations moved the compliance bar from "did you post a privacy policy?" to "can you demonstrate your program works?" That shift rewards organizations that treat privacy as an operational discipline—and creates real exposure for those still managing compliance as a pre-audit exercise.

A few places to start: confirm whether your organization triggers activity-based obligations under the 2026 regulations, audit your third-party data relationships for misclassified "service providers," and verify that your technical infrastructure honors GPC signals in real time.

Book a demo with Drata to see how continuous automation turns CCPA compliance from a recurring scramble into a maintained, audit-ready program.

Frequently Asked Questions About CCPA Compliance in 2026

The CPRA amended and expanded the CCPA—it did not create a separate law. CPRA amendments took effect January 1, 2023, adding the right to correct, creating the CPPA as the primary enforcing agency, and strengthening data minimization requirements. The CPPA's 2026 final regulations further expanded operational obligations. The law is properly referred to as "CCPA, as amended."

Possibly. The 2026 regulations introduced activity-based triggers that apply regardless of company size. If your organization sells or shares personal information, processes sensitive personal information, uses ADMT for significant consumer decisions, or profiles employees or applicants through systematic observation, you may face enhanced compliance obligations even if you fall below the $25 million revenue threshold.

The CPPA has taken the enforcement position that businesses must honor GPC signals as valid opt-out requests—equivalent to a consumer clicking "Do Not Sell or Share My Personal Information." If your website does not technically parse and act on GPC signals in real time, you face ongoing sale and sharing compliance exposure regardless of what your Privacy Policy states. GPC compliance is an active enforcement priority.

New covered processing activities require a completed risk assessment before the processing begins. For activities that were already underway before January 1, 2026, the deadline to complete assessments is December 31, 2027. Assessments must be reviewed at least every three years and updated after any material change to the covered processing activity.

Yes, with supplementation. Existing GDPR Data Protection Impact Assessments may be leveraged for CCPA Privacy Risk Assessment purposes, provided they include all CPPA-required elements—processing purpose, categories of PI and SPI, anticipated benefits, potential negative impacts, and implemented safeguards. Cross-framework compliance platforms make this mapping significantly more efficient.


JULY 27, 2026
CCPA Collection
Navigate CCPA With Confidence
Get a Demo

Navigate CCPA With Confidence