Skip to content

California Privacy · Data Privacy & Law

CCPA and CPRA in 2026: thresholds, CPRA rights, and the “sale/share” problem for ads

How US-facing businesses operationalize California consumer privacy — notices, requests, service providers, and what CPRA added beyond CCPA.

6 min read

CCPA as amended by CPRA is an operating privacy program for covered businesses handling California personal information. It affects notices, consumer rights, sensitive personal information, sale and sharing choices, vendor terms, retention, security expectations, and regulator-facing evidence.

The paired checklist helps execute obligations, but the guide covers judgment: whether the business is covered, how adtech and analytics are classified, whether vendors are service providers, contractors, or third parties, and whether the product honors Global Privacy Control signals.

In 2026, California privacy work is less about adding one link to a footer and more about aligning websites, apps, data stores, HR systems, vendors, request workflows, and notices. Stale public language is risky when operational systems have changed. For CCPA and CPRA, the guide should keep privacy operations aligned with product and marketing reality. Web tags, SDKs, CDPs, CRM exports, audience uploads, server-side events, and AI features can change the sale, sharing, sensitive PI, and notice analysis quickly. GPC handling should be tested technically, not assumed because a banner exists. Vendor status should be verified against contract terms and actual use, especially where providers improve their own products or combine data across customers. Employee and applicant data also deserve a data map, request process, retention logic, and notice review. The paired checklist should therefore run whenever teams add data flows, not only when privacy refreshes a policy page. A useful way to read the rest of this guide is to separate evidence from judgment. Evidence shows that an activity happened: a review, record, test, approval, training, scan, exercise, assessment, or decision. Judgment explains why the activity was scoped that way, why the risk treatment is proportionate, why an exception is acceptable, and what would cause the decision to change. The paired checklist should collect evidence and owners, while the guide should help teams avoid false certainty. For each topic, ask what a knowledgeable reviewer would challenge after seeing the first answer. They may ask whether the scope matches production, whether suppliers are included, whether recurring work is current, whether leadership approved trade-offs, and whether public or customer-facing claims match operations. That second layer is where preparation becomes credible. It also keeps teams from overclaiming, because a documented limitation with a plan is usually stronger than a broad statement no one can support. Keep a dated rationale beside the evidence so reviewers can see what changed, who approved the interpretation, and which operating signal would trigger a fresh review. Keep the reviewer-facing story specific enough that another team can repeat the analysis without guessing.

What CCPA and CPRA actually are

CCPA and CPRA create California consumer privacy obligations for businesses that meet coverage thresholds. They include notice, access, deletion, correction, opt-out, limitation of sensitive personal information, non-discrimination, vendor contracting, and data governance expectations.

The sale and share concepts are central for digital businesses. Adtech, analytics, retargeting, clean rooms, pixels, SDKs, and audience building may involve sharing personal information for cross-context behavioral advertising even when no money changes hands.

The program should cover more than customers. Employee and B2B personal information can be in scope, and systems such as HRIS, payroll, recruiting, support, CRM, marketing automation, and data warehouses need to be reflected in the privacy inventory.

Decisions the checklist will not make for you

The checklist cannot decide whether a vendor is a service provider, contractor, or third party. Legal, privacy, procurement, and product teams must examine contract terms, data use, instructions, onward disclosure, and whether the vendor uses data for its own purposes.

It also cannot classify every adtech flow. Teams need to inspect tags, SDKs, server-side events, consent states, identity graphs, and data-sharing settings to decide whether sale, sharing, or sensitive PI rules apply.

The checklist cannot approve notice language or consumer-response positions. The organization must align public notices, data maps, retention, identity verification, exceptions, and response workflows with current law and regulator expectations.

Where privacy programs actually fail

Ignoring Global Privacy Control is a common operational gap. The website may present choices, but the consent platform, tag manager, server-side events, and downstream ad partners do not honor browser signals consistently.

Vendor classification is another failure. Businesses call every vendor a service provider, while contracts or data uses allow independent analytics, product improvement, advertising, or onward use. Misclassification can break the opt-out and notice story.

Notices go stale. Companies launch new analytics, AI features, HR tools, data warehouses, or retention practices without updating public notices. Employee PI is also sometimes treated as exempt even though CPRA changed that assumption.

How to use the paired checklist

Use the checklist to map personal information by source, category, purpose, system, vendor, retention period, and rights workflow. Include web tags, mobile SDKs, server-side events, HR systems, support tools, and marketing platforms.

Attach evidence such as notices, data maps, GPC tests, consent configurations, vendor contracts, service-provider terms, request logs, identity verification procedures, deletion workflows, retention schedules, and training records.

Run the checklist after product and marketing changes, not only annually. New pixels, audiences, AI features, customer data platforms, HR tools, and vendors can change sale, sharing, sensitive PI, and notice obligations.

What teams get wrong

A Do Not Sell link from 2020 is enough.
CPRA added and clarified obligations around sharing, sensitive PI, correction, vendor terms, retention, and operational signal handling such as GPC.
All vendors can be labeled service providers.
Vendor status depends on contracts and actual data use. Some vendors may be contractors or third parties, especially when they use data for their own purposes.
Employee personal information is exempt.
Employee and B2B personal information should be considered in scope unless a specific current rule says otherwise for the situation.

When the checklist is enough — and when it is not

  • Use the checklist to organize data maps, notices, rights workflows, GPC handling, vendor terms, retention, and evidence.
  • Ask a privacy assessor, consultant, or technical privacy specialist when GPC testing, adtech classification, or operational readiness is unclear.
  • Ask counsel when coverage, exemptions, notices, sale or share classification, sensitive PI, vendor status, requests, enforcement, or contracts are involved.
  • Treat this guide as practical orientation, not official California legal text; use current statutes, regulations, regulator guidance, and counsel for authoritative requirements.

Related checklists

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer