California built US privacy law’s reference implementation, then built the first agency dedicated to enforcing it. Since the CPRA’s rules became operative in 2023, the practical CCPA has been defined less by its text than by its enforcement pattern: regulators keep landing on the ad stack. Sephora, DoorDash, Honda, and Healthline were all, at core, cases about trackers, opt-outs, and the gap between what the privacy policy said and what the website actually transmitted.
| Regulation | CCPA, as amended by CPRA (Cal. Civ. Code 1798.100 et seq.) |
|---|---|
| Max penalty | $2,500 / $7,500 per violation; $100-$750 per consumer for breaches |
| Enforcers | CPPA + California AG |
| Statute | Civ. Code 1798.100 et seq. |
The compliance core
Notices. A notice at collection (categories, purposes, retention, sale/sharing status) and a privacy policy updated at least annually with rights metrics disclosures for larger businesses. The Healthline settlement shows what fails: disclosing “advertising cookies” generically while shipping article titles implying health conditions to ad networks.
Rights plumbing. Know/access, delete (with a duty to push deletion to service providers and third parties), correct, opt out of sale/sharing via a “Do Not Sell or Share My Personal Information” link and GPC, and limit SPI. Verified requests get 45 days (extendable once). California adds household-level requests, unusual among the states, and 2026 brings the Delete Act’s DROP mechanism for data brokers.
Contracts. Every disclosure of personal information needs paper: service-provider/contractor agreements with purpose limitation, no-sale certification, and audit rights, or the recipient is a “third party” and the disclosure is a sale. The specifics are in the service-provider agreements guide.
Risk work. CPPA regulations finalized in 2025 phase in cybersecurity audits, risk assessments for high-risk processing (including behavioral advertising and ADMT), and automated decision-making rights, the closest US analog to GDPR accountability. See CPRA risk assessments.
Enforcement pattern, and what it predicts
Four public actions define the priority list: honor GPC (Sephora); recognize non-cash consideration as a sale (DoorDash); make opt-outs symmetrical and stop demanding excess verification data (Honda); and align tracker behavior with disclosures, especially for health-adjacent inference (Healthline, which also invoked the CCPA’s purpose-limitation principle for the first time). The CPPA has also swept data-broker registration and announced ADMT rulemaking, so agentic and AI processing is next. The CPPA enforcement priorities page tracks this in detail.
The fastest way to see your own Sephora exposure is to look at what your site transmits before consent: run a free scan and compare the tracker inventory against your notice at collection.