CCPA/CPRA Compliance in 2026: What Businesses Still Get Wrong | By: Jeffrey R. Glassman
CCPA/CPRA Compliance in 2026: What Businesses Still Get Wrong | By: Jeffrey R. Glassman

Several years into the CCPA and CPRA regime, most companies have the basics in place: a privacy policy, a cookie banner, and a process for responding to consumer requests. Enforcement activity over the past year, however, has made clear that having the paperwork is not the same as being compliant in practice. The California Privacy Protection Agency and the Attorney General's office have both signaled that they are looking past the privacy policy and into how the business actually operates. Below are the gaps we see most often.

Treating the Privacy Policy as the Compliance Program

A privacy policy describes practices; it does not create them. Regulators have shown increasing interest in whether a company's actual data flows match what its policy discloses, including how data moves to service providers, contractors, and third parties, and whether opt-out signals are honored across every channel where data is collected, not just on the main website.

Global Privacy Control Signals

Honoring the Global Privacy Control is no longer optional for businesses that sell or share personal information. Enforcement sweeps have specifically targeted sites that display a cookie banner but fail to recognize a GPC signal as a valid opt-out of sale or sharing. Businesses should test their own sites periodically, since GPC handling is often implemented once and never revisited as vendors and ad tech partners change.

Service Provider and Contractor Agreements

The CPRA's contractual requirements for service providers, contractors, and third parties are specific, and a generic data processing addendum is often not enough. Agreements need to restrict use of personal information to the purposes disclosed to consumers, prohibit combining data across clients in ways not permitted by the statute, and include the specific certification language the regulations require. Companies that have not refreshed vendor agreements since the CPRA regulations were finalized should assume they have gaps.

Sensitive Personal Information Limitations

The right to limit use of sensitive personal information is frequently overlooked because it applies more narrowly than the general opt-out right, but it still requires a functioning mechanism and correct handling on the back end. Businesses that collect precise geolocation, certain health information, or government identifiers should confirm that a limitation request actually changes how that data is used internally, not just what is displayed to the consumer.

Employee and B2B Data

Now that the CPRA's temporary exemptions for employee and B2B personal information have expired, many companies still have not extended their consumer-facing compliance program to cover HR data and business contact information. This includes updating notices at collection for employees and applicants, and confirming that the same request-handling process applies to those populations.

Risk Assessments and Cybersecurity Audits

The CPRA regulations addressing risk assessments and annual cybersecurity audits for businesses engaged in higher-risk processing are being phased in, and the businesses that will be in scope should not wait for the compliance deadline to begin. Building the underlying data inventory and risk assessment process now makes the eventual filing exercise far less disruptive.

The Takeaway

CCPA and CPRA compliance is no longer a documentation exercise; it is an operational one. A periodic audit that tests actual data flows, vendor contracts, and consumer-facing mechanisms against what the privacy policy promises is the most reliable way to find gaps before a regulator does.

This post is intended for general informational purposes and does not constitute legal advice. Please contact Jeffrey R. Glassman, Esq. in our Privacy and Data Compliance group to discuss your specific compliance obligations.

Subscribe

Recent Posts

Blogs

Contributors

Archives

Jump to PageX

Ervin Cohen & Jessup LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek