California has finalized significant updates to the California Consumer Privacy Act (CCPA) that took effect January 1, 2026. The new regulations, issued by the California Privacy Protection Agency (CPPA), expand privacy obligations for businesses—particularly technology companies that rely on data, AI, analytics, and automated decision-making. At the same time, the CPPA has signaled a more aggressive enforcement posture, increasing compliance and operational risk for companies that are unprepared.
Why This Matters for Technology Companies
The updated CCPA framework shifts privacy compliance from a primarily policy-based exercise to an ongoing governance, risk management and operational requirement. Companies should expect regulators to examine not only disclosures, but how data is collected, processed, retained, and used across systems and platforms—especially where automation or AI is involved.
Key changes include:
- Mandatory Cybersecurity Audits (Phased based on revenue, Beginning 2027)
- Mandatory Privacy Risk Assessments (Effective 2026)
- New Rules for Automated Decision Making Technology (ADMT)
- Expanded Consumer Access Rights
- Heightened Enforcement Environment
Who Must Comply
The California Consumer Privacy Act (CCPA), as revised effective January 1, 2026, applies to for profit businesses that do business in California and meet the following criteria:
- Activities that trigger a risk assessment:
- Processing sensitive personal information
- Selling or sharing personal information
- Profiling / automated decision-making (ADMT) impacting consumers in a significant way
- Any processing that could present a material risk to consumer privacy
- Activities that trigger a cyber audit:
- Derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal information
OR
-
- As of January 1 of the calendar year, had annual gross revenues in excess of $25M in the preceding calendar year (adjusted for inflation)
AND
-
- Processed the personal information of 250,000 or more consumers or households in the preceding calendar year
OR
-
- Processed the sensitive personal information of 50,000 or more consumers in the preceding calendar year.
A physical presence in California is not required. As a result, many technology companies—including those operating SaaS platforms, data driven services, digital advertising models, AI enabled products, or automated decision making technologies—fall within scope based on their scale, data practices, or interactions with California residents.
What Technology Companies Should Be Doing Now
- Identify high risk data processing and AI/automation use cases
- Assess readiness for formal privacy risk assessments
- Understand the scope of where California consumer personal information is stored
- Review data retention, access, and deletion practices
- Align privacy, security, and governance functions
Bottom Line
The updated CCPA represents a meaningful shift toward operational privacy and cybersecurity governance, particularly for data-driven and AI-enabled technology companies. Early action in 2026 will be critical to managing compliance, risk management, avoiding enforcement exposure, and maintaining customer trust.
How Small and Medium-Sized California Businesses May Be Affected
While the CCPA is often associated with larger companies and technology businesses, small and medium-sized businesses in California should not assume they are automatically unaffected. The law generally applies to for-profit businesses that do business in California and meet the certain thresholds, including annual gross revenue over $25 million, buying, selling, or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
Even businesses that fall below these thresholds may still feel the impact indirectly. For example, a smaller company that serves as a vendor, service provider, or contractor to a larger CCPA-covered business may be asked to follow privacy-related contract terms, data security requirements, or documentation standards. California regulators note that the CCPA applies differently to businesses, service providers, contractors, and third parties, making it important for companies to understand their role in handling personal information.
Small and mid-size businesses should also pay attention to their website and marketing practices. Companies using online forms, email marketing platforms, CRMs, analytics tools, cookies, advertising pixels, or other tracking technologies may be collecting or sharing personal information in ways that create privacy obligations or contractual risk. The 2026 regulations place greater emphasis on how data is collected, used, retained, shared, and protected, especially when automated decision-making, risk assessments, or cybersecurity requirements are involved.
For many businesses, the practical takeaway is this: privacy compliance is no longer just a concern for large technology companies. It is becoming part of basic business operations, vendor management, website governance, and customer trust. Small and medium-sized businesses may benefit from reviewing their privacy policies, website disclosures, vendor agreements, data retention practices, and internal procedures now—before a client, regulator, or legal claim forces the issue.