California residents got the strongest data privacy rights in the United States on January 1, 2026, when new California Consumer Privacy Act (CCPA) regulations took effect. The updates add mandatory automated-decision opt-outs, expanded historical data access back to 2022, and — most importantly for data broker exposure — the DELETE Act's DROP system, which lets you erase yourself from every registered California data broker with a single request starting August 1, 2026. Here is exactly what changed and how to use each new right.
What Is the California Consumer Privacy Act (CCPA)?
The California Consumer Privacy Act, first passed in 2018 and significantly expanded by the California Privacy Rights Act (CPRA) in 2020, is the nation's strongest state privacy law. It gives California residents legal rights to know what personal data businesses collect, delete that data on request, correct inaccuracies, opt out of sale or sharing, and limit the use of sensitive personal information. The California Privacy Protection Agency (CPPA), the country's only dedicated state privacy regulator, enforces it.
Any for-profit business that does business in California and meets one of these thresholds is covered: annual gross revenue over $26.625 million, buys/sells/shares personal information on 100,000 or more consumers or households, or derives 50%+ of revenue from selling or sharing personal information. That definition sweeps in essentially every consumer-facing digital company that operates nationally.
What Changed on January 1, 2026
The CPPA approved sweeping new regulations in September 2025 that took effect at the start of 2026. The big changes:
- Automated Decision-Making Technology (ADMT) rights. Companies using AI or algorithms to make significant decisions about you — hiring, lending, insurance, housing — must give pre-use notice, honor opt-out requests, and let you appeal adverse decisions to a human reviewer.
- Risk assessments for six categories of "significant risk" processing, including selling personal information, processing sensitive personal information, and profiling employees or students.
- Mandatory cybersecurity audits for large processors, phasing in from 2028 through 2030.
- Expanded right to know: businesses must now provide historical data going back to January 1, 2022 — not just the previous 12 months.
- Neural data was added to the definition of "sensitive personal information," the first state law to explicitly cover brain-computer interface data.
- Broader data broker definition that captures companies that had previously argued they were exempt.
Your Core Rights Under CCPA in 2026
The Right to Know
You can request that any covered business tell you what personal information it has collected about you, where it got the data, the categories of third parties it shared or sold it to, and — as of 2026 — what it has done with that data going back to January 1, 2022. Businesses must respond within 45 days.
The Right to Delete
You can request that a business delete the personal information it holds about you. There are legal exceptions (records they must keep for tax or compliance reasons), but the default is deletion. This right also flows through to service providers and contractors, which must delete the data too.
The Right to Correct
If a business has inaccurate personal information about you, you can require them to fix it. This is especially useful for data brokers whose profiles routinely mash together relatives, addresses, and phone numbers from other people with the same name.
The Right to Opt Out of Sale or Sharing
Businesses that sell or share your personal information (including for cross-context behavioral advertising) must honor an opt-out. In 2026, they must also honor the Global Privacy Control (GPC) browser signal automatically — the CPPA has fined companies for ignoring GPC.
The Right to Limit Use of Sensitive Personal Information
You can restrict how a business uses your sensitive personal information — Social Security number, precise geolocation, race, religion, health data, and (new in 2026) neural data.
The Right to Opt Out of Automated Decision-Making (2026)
When a business uses ADMT to make a significant decision about you — a job screening algorithm, an auto insurance risk model, an apartment rental scoring system — you have the right to opt out and demand human review of any adverse outcome.
The CCPA Applies Even If a Company Is Based Elsewhere
You do not need to live near a company's headquarters or use a "California" product. If you are a California resident and the company meets the CCPA thresholds, your rights apply — even if the business is based in Texas, New York, or Ireland.
The DELETE Act: One Request, Every Data Broker
California's DELETE Act (SB 362), passed in 2023, is the most consequential new data broker law in the country. It requires every data broker doing business in California to register with the CPPA and honor a universal deletion request through a single state-run system called the Delete Request and Opt-Out Platform (DROP).
Key DROP dates you need to know:
- January 1, 2026: DROP is technically live for early access
- August 1, 2026: All registered data brokers must comply with DROP requests and delete a consumer's information within 45 days (or 90 days with a written extension)
- Every 45 days thereafter: Data brokers must re-check DROP and delete any newly collected information matching your original request
Fines are steep: $200/day for failure to register, and $200/day per consumer for failure to delete. This is the first US law that treats data broker profiles as something you can universally erase — not one broker at a time.
Skip the manual work
PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.
Start your free scan★★★★★ 4.8/5 · Trusted by thousands of families
How to File a CCPA Request (Step by Step)
Step 1: Confirm the Company Is Covered
Almost every major consumer business is. Check the company's privacy policy for a "California Privacy Rights" or "Do Not Sell or Share My Personal Information" section — if it exists, they are covered.
Step 2: Find the Request Form
Covered businesses must provide at least two ways to submit requests. Look for a link at the bottom of the privacy policy, a dedicated privacy request form, or a customer support email address specifically for privacy requests.
Step 3: Verify Your Identity
Businesses can require identity verification — usually a copy of your ID, or matching account details. Provide only what is necessary; refuse to send Social Security numbers or unrelated documents.
Step 4: Wait for the Response (45 Days)
Businesses have 45 days to respond, with a one-time 45-day extension if they notify you. For a right-to-know request, you get a copy of your data. For deletion, you get confirmation that data was deleted (or a legally justified explanation of what they kept and why).
Step 5: Escalate if Ignored
If a business ignores your request or wrongly denies it, file a complaint with the CPPA at cppa.ca.gov and the California Attorney General at oag.ca.gov/privacy/ccpa. Enforcement has real teeth — Sephora paid $1.2 million in 2022 for CCPA violations, and DoorDash was fined $375,000 in 2024 for selling data without proper opt-out disclosures.
Using DROP to Delete Yourself From Data Brokers
Once DROP is fully operational on August 1, 2026, you will be able to submit one deletion request through the CPPA-run portal that flows to every registered California data broker. To submit a request:
- Step 1: Go to the CPPA DROP portal at cppa.ca.gov (link goes live when DROP opens for consumer requests)
- Step 2: Verify your California residency through the state's verification system
- Step 3: Submit your deletion request — one submission covers every registered broker
- Step 4: Wait 45 days for brokers to delete your information
- Step 5: DROP re-runs the request every 45 days — brokers must delete any newly collected data on you going forward, without you resubmitting
DROP Has Real Gaps You Need to Cover
DROP only reaches data brokers that register with California. Non-broker aggregators, background check sites that classify themselves as "consumer reporting agencies," out-of-state brokers that dodge California registration, and international data collectors are not covered. And people-search sites frequently relist information from sources DROP does not touch — so you still need continuous monitoring even after you use DROP.
How PrivacyOn Complements CCPA and DROP
CCPA and DROP are powerful — but they are enforcement mechanisms, not maintenance services. Your data will keep reappearing on people-search sites because new records are constantly being scraped from public sources. That is where PrivacyOn fits.
- Covers 100+ broker sites — including sites that are not registered California data brokers and are therefore outside DROP
- Continuous monitoring: re-checks brokers 24/7 and re-submits removal requests when your data reappears
- Works for non-California residents too — CCPA and DROP only apply to California residents, PrivacyOn works nationwide
- Family plans covering up to 5 people
- Starts at $8.33/month — a fraction of the time it takes to file individual CCPA requests to every broker manually
Combine Your Rights With Continuous Removal
Use CCPA and DROP for one-time universal deletion. Use PrivacyOn to keep your data off broker sites permanently. Start your free scan to see how much of your data is currently exposed.
Frequently Asked Questions
Who has to comply with the CCPA in 2026?
Any for-profit business that does business in California and meets one of three thresholds: annual gross revenue over $26.625 million, buys/sells/shares personal information on 100,000+ consumers or households, or derives 50% or more of revenue from selling or sharing personal information. Almost every major consumer-facing digital business meets at least one threshold.
Do I have to live in California to use CCPA rights?
Yes. CCPA rights are limited to California residents. However, businesses often extend CCPA-style rights to all US customers because it is easier than maintaining separate policies. Check the privacy policy — many companies apply CCPA rights nationwide. Non-California residents can also use similar rights under Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other state laws.
What is the difference between CCPA and CPRA?
CCPA is the original 2018 law. CPRA is the 2020 amendment that added the right to correct, the right to limit sensitive personal information, created the CPPA regulator, and expanded enforcement. When people say "CCPA" today they usually mean CCPA-as-amended-by-CPRA. The 2026 regulations build on both.
When does the California DROP system go live?
DROP is technically available January 1, 2026, and data broker compliance becomes mandatory August 1, 2026. From that date forward, registered data brokers must delete your information within 45 days of receiving a DROP request and must re-check DROP every 45 days to delete any newly collected data.
Can I still use PrivacyOn if I use CCPA and DROP?
Yes — and you probably should. CCPA and DROP handle registered California data brokers, but hundreds of people-search and aggregation sites either fall outside those categories or find loopholes to keep reposting your data. PrivacyOn continuously scans 100+ broker sites, submits removals as they reappear, and works for non-California residents too. Use CCPA and DROP for the legal universal delete; use PrivacyOn for the ongoing maintenance.
What are the penalties if a business ignores my CCPA request?
The CPPA can levy administrative fines of up to $2,500 per violation, or up to $7,500 for intentional violations or violations involving minors under 16. The California Attorney General can also bring civil actions. Consumers do not have a direct right to sue for most CCPA violations, but you can sue when a data breach exposes non-encrypted personal information due to a company's failure to maintain reasonable security. Real enforcement examples: Sephora paid $1.2 million in 2022, and DoorDash was fined $375,000 in 2024.