16.3 CCPA/CPRA, CAADCA, and the Delete Act

Key Takeaways

  • The CCPA as amended by the CPRA uses a three-prong business test: prior-year gross revenue of $26,625,000 or more (CPI-adjusted effective 1 January 2025), or buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing that information — not a stale $25 million-only shortcut
  • Distinguish personal information from sensitive personal information, a sale from a share, and a service provider from a contractor from a third party; the CPPA and the California Attorney General share public enforcement, and Civil Code § 1798.150 adds only a limited security private right of action (statutory range $100–$750, CPI-adjusted to $107–$799 as of 1 January 2025)
  • The California Age-Appropriate Design Code Act (A.B. 2273, 2022) is BoK-listed but is not fully operative as of August 2026: after NetChoice v. Bonta, the DPIA, best-interests / materially-detrimental data-use limits, default anti-profiling rule, and dark-patterns ban remain preliminarily enjoined
  • The Delete Act (SB 362, 2023) requires annual data-broker registration and a public registry and created DROP; DROP has been live for consumers since 1 January 2026, and brokers must access DROP at least every 45 days and process deletions beginning 1 August 2026
Last updated: August 2026

CCPA as Amended by the CPRA

The California Consumer Privacy Act of 2018 (CCPA), Civil Code § 1798.100 et seq., is the United States’ first comprehensive consumer-privacy statute. The California Privacy Rights Act of 2020 (CPRA) (Proposition 24) amended it, created the California Privacy Protection Agency (CPPA), added sensitive personal information, a correction right, a limit-use right, and the concept of a share, and moved most of those amendments into force on 1 January 2023. Teach the amended statute, not a 2018 outline. Official Agency FAQ: https://cppa.ca.gov/faq.html. Official CPI table: https://cppa.ca.gov/regulations/cpi_adjustment.html.

A business is a for-profit entity that does business in California, collects consumers’ personal information (or has it collected), determines the purposes and means of processing, and meets any one of three thresholds. Civil Code § 1798.199.95(d) adjusts the dollar figures every odd-numbered year. Effective 1 January 2025 — and still the posted figure as of August 2026 — those prongs are:

  1. Annual gross revenue of $26,625,000 or more in the preceding calendar year (the original $25,000,000 statutory figure, CPI-adjusted).
  2. Annually buys, sells, or shares the personal information of 100,000 or more California consumers or households.
  3. Derives 50 percent or more of annual revenue from selling or sharing California consumers’ personal information.

Revenue is worldwide gross, not California-source only. A company with $20 million in revenue that sells 120,000 Californians’ records is in on prong two. Reciting “only if we hit $25 million” is the stale shortcut Chapter 14 already flagged.

Personal information (PI) is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Sensitive personal information (SPI) is a defined subset: Social Security, driver’s license, state-ID, or passport number; account log-in, financial-account, debit, or credit-card number in combination with any required access code; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, or union membership; contents of mail, email, and text messages (unless the business is the intended recipient); genetic data; biometric information processed to uniquely identify; PI collected and analyzed concerning health; and PI collected and analyzed concerning sex life or sexual orientation. Consumers have a right to limit the use and disclosure of SPI to uses necessary to perform the services or provide the goods reasonably expected, plus listed business uses. SPI is not a second statute. It is a second control surface on top of the PI rights.

Those rights, as amended, are: know / access (categories and specific pieces); delete; correct (CPRA); opt out of sale or sharing; limit use and disclosure of SPI; data portability; and no retaliation for exercising a right, with a bona-fide loyalty-program exception that must be reasonably related to the value of the data. A sale is disclosing PI to a third party for monetary or other valuable consideration. A share is disclosing PI to a third party for cross-context behavioral advertising, whether or not money changes hands. CPRA added “share” so that a cookie-sync or clean-room audience that never issues an invoice is still an opt-out event. Honor opt-out preference signals (including Global Privacy Control) as valid sale/share opt-outs.

Downstream labels matter. A service provider processes PI on behalf of the business for a business purpose under a written contract that prohibits selling the PI, retaining or using it for any purpose other than the specified business purpose, and combining it except as the regulations allow. A contractor is the CPRA sibling: a person to whom the business makes PI available for a business purpose under a similar contract, plus a certification that the contractor understands the restrictions. A third party is everyone else — and a third-party disclosure is what becomes a sale or a share. Calling an ad-tech partner a “vendor” in a slide deck does not make it a service provider. The contract and the actual use do.

Public enforcement is concurrent: the CPPA (rulemaking, investigations, audits, administrative fines) and the California Attorney General. CPI-adjusted administrative and civil-penalty caps as of 1 January 2025 are not more than $2,663 per violation, or $7,988 for an intentional violation and for a violation involving a consumer the violator actually knows is under 16. The only private right of action is Civil Code § 1798.150, and it is not a general rights PRA. It applies to certain security incidents — unauthorized access and exfiltration, theft, or disclosure — involving nonencrypted and nonredacted PI in the older identity-theft sense (name plus SSN, driver’s license, financial-account number with access code, and listed medical, health-insurance, and unique-biometric elements). Statutory damages are not less than $100 and not greater than $750 per consumer per incident, or actual damages, whichever is greater. The CPPA’s 2025 CPI table adjusts that range to $107–$799. A 30-day written notice-and-cure is a precondition to the private action. Access, deletion, correction, and opt-out failures still go to the Agency and the AG, not to a § 1798.150 plaintiff.

CAADCA: BoK-Listed, Not Fully Operative in August 2026

The California Age-Appropriate Design Code Act (CAADCA), Assembly Bill 2273 (2022), is the BoK-listed children’s design-code statute. It would apply to a business that provides an online service, product, or feature likely to be accessed by children (under 18) and would have required the business to act in the best interests of children, complete a data protection impact assessment (DPIA) before launching a product likely to be accessed by children, configure default high-privacy settings, estimate age with a reasonable level of certainty or apply child-level protections to everyone, avoid dark patterns that lead children to surrender privacy, and limit profiling and secondary use of a child’s PI. That is what the 2022 statute would have required if it were fully in force.

It is not fully in force. NetChoice, LLC v. Bonta produced a rolling injunction. In September 2023 the Northern District of California preliminarily enjoined the statute in full. In 2024 the Ninth Circuit left the DPIA / risk-mitigation requirement (and provisions it held not grammatically severable from it) enjoined, along with the 90-day AG notice-and-cure clause, and remanded the rest. The district court then re-enjoined the statute. On 12 March 2026 the Ninth Circuit issued a second opinion. As of August 2026 the accurate teaching point is:

Still preliminarily enjoined: the DPIA and related assessment-production duties (§ 1798.99.31(a)(1)–(4)); the data-use restrictions in § 1798.99.31(b)(1)–(4) (no use the business has reason to know is materially detrimental to a child’s physical health, mental health, or well-being; no profiling by default; no processing beyond what is necessary for the service the child is actively using, and no secondary use, unless the business shows a compelling best-interests-of-children reason); and the dark-patterns ban in (b)(7). The panel held the open-ended “materially detrimental,” “well-being,” and “best interests of children” standards likely void for vagueness.

No longer covered by the broad whole-statute injunction after the 2026 opinion: the age-estimation requirement (estimate with a reasonable level of certainty or apply child-level protections to all users), high-privacy default settings, child-appropriate privacy disclosures, monitoring and precise-geolocation signals, and tools for children and parents to exercise rights. The panel vacated the facial injunction against the coverage definition and the age-estimation clause and remanded for further development and severability analysis. Litigation remains live in the Northern District of California. Do not recite A.B. 2273 as a fully operative 2022 code. Do not tell a candidate the entire statute vanished. Teach the injunction map and the would-have-required list.

Scenario. A social app “likely to be accessed by children” asks in 2026 whether it must file CAADCA DPIAs with the Attorney General and turn off default profiling because “best interests of children” so require. As of August 2026 those are the enjoined pieces. A slide that says “CAADCA is live, run the 2022 checklist” is wrong. A slide that says “CAADCA was repealed” is also wrong.

The Delete Act and DROP

The Delete Act, Senate Bill 362 (2023), rebuilt California’s data-broker regime. Official CPPA broker page: https://cppa.ca.gov/data_brokers/. Official consumer DROP page: https://privacy.ca.gov/drop/. A data broker is a CCPA business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. Brokers must register annually with the CPPA (the 2026 window was 1–31 January; the 2026 registration fee is $6,000 plus processing) and appear in a public registry. Failure to register by 31 January can draw administrative fines. SB 361 (2025) expanded the registration disclosures (sensitive-data types, foreign actors, law enforcement, generative-AI developers) and increased certain daily non-registration fines.

The Act also directed the Agency to build an accessible deletion mechanism. That system is the Delete Request and Opt-Out Platform (DROP). DROP launched for consumers on 1 January 2026. A California resident (or a parent or authorized person on a resident’s behalf) submits one verifiable request that directs every registered broker — and the broker’s service providers and contractors — to delete the resident’s PI, subject to limited statutory exceptions. Beginning 1 August 2026, brokers must access that accessible deletion mechanism at least once every 45 days and process the deletion requests (Cal. Civ. Code § 1798.99.86(c)). The consumer site states that, starting 1 August 2026, brokers must delete matching data within 90 days, and going forward they delete on the 45-day access cycle. Independent third-party compliance audits begin 1 January 2028 and recur every three years.

Do not invert the calendar. Consumers have been able to file since 1 January 2026. Broker processing is the 1 August 2026 duty. The access cadence is 45 days, not “whenever legal has time.” DROP is not a CCPA “request to delete” sent to a first-party retailer with whom the consumer has an account. It is a broker-registry tool.

California instrumentWhat it does in 2026What it is not
CCPA / CPRAThree-prong business coverage; PI and SPI rights; sale and share; service provider / contractor / third party; CPPA + AG; limited § 1798.150 security PRA ($100–$750 statutory, $107–$799 CPI)A general private right for every access or opt-out miss
CAADCA (A.B. 2273)BoK-listed children’s design code; partially enjoined after NetChoice v. Bonta (March 2026)A fully operative 2022 statute, or a repealed statute
Delete Act / DROP (SB 362)Annual broker registration, public registry, centralized deletionA first-party CCPA deletion form; processing did not start on 1 January 2026

Exam traps

  • The revenue prong is $26,625,000 (CPI, effective 1 January 2025), and it is only one of three prongs.
  • A share for cross-context behavioral advertising is an opt-out event even when no money is paid.
  • Section 1798.150 is a security-incident PRA, not a private CCPA-rights action.
  • CAADCA’s DPIA and best-interests data-use rules remain enjoined as of August 2026.
  • DROP was live for consumers on 1 January 2026; brokers access at least every 45 days and process beginning 1 August 2026.
Loading diagram...
CCPA/CPRA, CAADCA Injunction Map, and Delete Act DROP
Test Your Knowledge

A for-profit analytics company does business in California, collects California residents’ personal information, and decides the purposes of that processing. Prior-year worldwide gross revenue is $18 million. Last year it sold the personal information of 140,000 California consumers. Is it a CCPA “business,” and why?

A
B
C
D
Test Your Knowledge

A social platform likely to be accessed by children asks whether, as of August 2026, it must treat the California Age-Appropriate Design Code Act as a fully live compliance program, including pre-launch DPIAs and a default ban on profiling justified by the “best interests of children.” Which statement matches the live litigation status?

A
B
C
D
Test Your Knowledge

A registered California data broker asks when consumers could first use DROP and what the broker must do once processing begins. Which timeline is correct under the Delete Act?

A
B
C
D