FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
40of40items
Across 13 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
California Data Brokers: CCPA, Registration, and DROP Duties

What should teams do about Data Broker Crossover under the US CCPA?

Apply the definition to the entity, not to a product label. Confirm that the entity is a CCPA business, knowingly collects personal information, sells that information to third parties, and lacks a direct relationship with the affected consumers. Then check the statute's exclusions, including specified consumer-reporting, financial, insurance, and health-data activities.

A direct relationship exists when the consumer intentionally interacts with the business, but the exact facts matter. Buying data indirectly, collecting it from public sources, or operating a consumer-facing site does not by itself resolve whether the business has a direct relationship with each affected consumer.

  • Register with CalPrivacy between January 1 and January 31 after each year in which the entity met the data-broker definition.
  • Publish the required prior-year request metrics by July 1 and report them during annual registration.
  • Beginning August 1, 2026, access DROP at least once every 45 days and process each matched deletion or fallback opt-out request within 45 days after receiving it through the platform, subject to statutory exceptions. The two periods can result in up to 90 days from the consumer's submission.
  • Direct associated service providers and contractors to delete covered information or process the required opt-out.
  • Prepare for independent audits beginning January 1, 2028 and every three years thereafter; keep the audit report and related materials for at least six years.
Citations
California Data Brokers: CCPA, Registration, and DROP Duties

What evidence should teams keep for Data Broker Crossover under the US CCPA?

Keep separate evidence for the data-broker classification and for each recurring duty. A registration receipt does not show that DROP requests, vendor instructions, or ordinary CCPA requests were handled.

  • Entity-level definition analysis, direct-relationship evidence, sale mapping, and any relied-on exclusion.
  • Annual registration submission, fee record, public registry entry, and the website privacy page containing required disclosures and metrics.
  • DROP access logs, match results, deletion decisions, statutory exception codes, completion dates, and directions sent to service providers or contractors.
  • Independent audit reports from 2028 onward and proof that reports and related materials are retained for at least six years.
Citations
California Data Brokers: CCPA, Registration, and DROP Duties

Which mistakes create risk when handling Data Broker Crossover under the US CCPA?

Do not collapse the two regimes into one generic privacy workflow. The CCPA and Delete Act use related concepts but impose different submissions, dates, system interactions, and records.

  • Assuming that registration satisfies the business's CCPA notice, access, deletion, correction, opt-out, or limit duties.
  • Treating every indirect-data business as a data broker without testing the statutory definition and exclusions.
  • Missing the January registration window, July metrics disclosure, 45-day DROP access cycle, or 2028 audit schedule.
  • Deleting only the broker's copy while failing to direct service providers and contractors as the Delete Act requires.
  • Deleting information covered by an exception without recording the legal basis, or using an exception more broadly than the statute allows.
Citations
CCPA Dark Patterns: Rules, Examples, and Review Checklist

What should teams do about Dark Patterns under the US CCPA?

Review every interface used to obtain CCPA consent or let a consumer exercise a right. The regulations require easy-to-understand communications, plain and straightforward language, and symmetry in choice so the interface does not impair the consumer's ability to select the more privacy-protective option.

Intent is not the test. An interface can be a dark pattern because of its effect even if no one designed it to mislead. Consent gathered through that interface does not satisfy the CCPA.

  • Compare font size, color, contrast, placement, labels, and defaults for each pair of choices.
  • Count the screens, clicks, and time required for each path; the privacy-protective path should not be longer or harder.
  • Use specific labels such as "Decline All" instead of ambiguous controls such as "More Options" when an equivalent accept choice is immediate.
  • Do not use double negatives, unrelated bundled terms, repeated prompts, or a default enrollment in a financial incentive.
  • Test withdrawal, opt-out, and account settings as well as the initial consent screen.
Citations
CCPA Dark Patterns: Rules, Examples, and Review Checklist

What evidence should teams keep for Dark Patterns under the US CCPA?

Keep evidence that shows what a consumer saw and how each path behaved at release time. A policy alone cannot show the wording, visual hierarchy, number of steps, default state, or whether a preference persisted.

  • Screenshots or recordings of every branch on desktop, mobile, and other supported interfaces.
  • A step count and comparison of the privacy-protective and less privacy-protective paths.
  • Approved copy, accessibility results, default-state tests, and evidence that withdrawal is as easy to find and use.
  • Release version, owner, review date, defects, remediation tickets, and regression tests.
Citations
CCPA Dark Patterns: Rules, Examples, and Review Checklist

Which mistakes create risk when handling Dark Patterns under the US CCPA?

A screen can look balanced in isolation and still be part of a dark pattern. Review the full sequence, the consequences of each selection, and what happens when a consumer returns later.

  • Making "Accept All" prominent while placing "Decline All" behind a settings screen.
  • Preselecting participation in a financial incentive or using toggles whose on and off states are unclear.
  • Asking the consumer to confirm the privacy-protective choice repeatedly while accepting the other choice immediately.
  • Using a broad terms-of-use acceptance as consent for a separate, narrowly defined processing purpose.
  • Fixing the first screen but leaving cancellation, withdrawal, or opt-out controls harder to use.
Citations
CCPA Do Not Sell or Share: Scope and Implementation

What should teams do about Do not sell or share under the US CCPA?

Inventory each disclosure by recipient, data category, purpose, consideration, advertising context, contract, and actual recipient use. A vendor label does not decide the analysis. A service provider or contractor must meet the statutory definition and written-contract restrictions; otherwise the recipient may be a third party.

A business that sells or shares must provide two or more designated opt-out methods suited to how it interacts with consumers. For online collection, those methods include processing a qualifying opt-out preference signal and providing an interactive form through the required link, alternative link, or privacy policy. A business may omit the link only if it meets every condition for frictionless signal processing; posting a cookie banner alone is not an opt-out method.

The request applies without identity verification, although the business may ask for information reasonably necessary to complete it. Stop covered transfers as soon as feasibly possible and no later than 15 business days, give the consumer a way to confirm completion, notify affected downstream third parties as required, use request data only to comply, and wait at least 12 months before asking the consumer to authorize sale or sharing again, subject to the regulations.

  • Map browser, app, account, offline, advertising, analytics, and vendor transfers separately.
  • Classify each recipient as a third party, service provider, or contractor from the facts and contract.
  • Offer the required link or compliant alternative and honor Global Privacy Control and other qualifying signals.
  • Propagate the opt-out to tags, audiences, APIs, data warehouses, and downstream recipients that can sell or share.
  • Retest after changes to consent tools, advertising partners, identity resolution, or data flows.
Citations
CCPA Do Not Sell or Share: Scope and Implementation

What evidence should teams keep for Do not sell or share under the US CCPA?

Keep transaction-level scope evidence and end-to-end opt-out test results. A homepage link does not prove that advertising tags, server-side transfers, offline systems, and known accounts stopped the covered activity.

  • Transfer inventory with recipient, purpose, consideration, advertising use, role, contract, and classification rationale.
  • Screenshots and versioned copy for the notice, privacy policy, and opt-out link or alternative.
  • Tests showing link and preference-signal requests reach browser, device, known account, offline, and downstream systems as applicable.
  • Request timestamps, completion status, propagation logs, exceptions, failures, remediation, and the date on which re-consent may first be requested.
Citations
CCPA Do Not Sell or Share: Scope and Implementation

Which mistakes create risk when handling Do not sell or share under the US CCPA?

Scope errors usually come from classifying a transfer by vendor name or payment method instead of the recipient, purpose, consideration, advertising context, contract, and actual use.

  • Assuming there is no sale because no money changes hands, while ignoring other valuable consideration.
  • Ignoring sharing because an advertising transfer is unpaid.
  • Treating every analytics or advertising vendor as a service provider without checking the contract and actual use.
  • Stopping client-side tags but leaving server-side, audience, account, or offline transfers active.
  • Requiring identity verification, account creation, or unnecessary fields before accepting an opt-out.
Citations
CCPA Financial Incentives: Notice, Consent, and Data Value

When does the CCPA require a financial incentive notice?

Start with the actual exchange. Identify the personal information the program collects, retains, sells, or shares; the benefit, payment, price, or service difference the consumer receives; and whether the difference is reasonably related to the value that the data provides to the business.

Give the Notice of Financial Incentive before the consumer opts in. The notice must summarize the program, describe its material terms and implicated personal-information categories, explain how to opt in and withdraw, state a good-faith estimate of the value of the consumer's data, and explain the calculation method and why the price or service difference is reasonably related to that value. Consent must be prior, affirmative, specific to the program, and revocable at any time.

Section 7081 permits several valuation approaches, including marginal or average value, aggregate value divided by the number of consumers, revenue or profit generated from the data, expenses connected to the data, and the cost of the incentive. A business may use another practical and reasonably reliable good-faith method. The calculation must support the actual benefit or difference offered; naming a method without its inputs and relationship to the program is not enough.

  • Map the benefit to the personal information that creates value for the business.
  • Choose and document a permitted valuation method, the inputs, period, assumptions, and good-faith estimate.
  • Present the material terms before enrollment and keep the choice free of preselected controls or unequal emphasis.
  • Record opt-in consent and make withdrawal available at any time through an easy method.
  • Wait at least 12 months before asking again after a consumer refuses opt-in consent, unless regulations prescribe otherwise.

Does every loyalty or discount program require a CCPA Notice of Financial Incentive?

No. The notice is required when the program is a financial incentive or price or service difference connected to collecting, selling, sharing, or retaining personal information. A business should map the data required for the program, the benefit offered, and the value the data provides. A discount unrelated to personal information does not become a CCPA financial incentive merely because the business offers a lower price.

What must a Notice of Financial Incentive say?

Before enrollment, the notice must give a succinct program summary; the material terms, including the implicated personal-information categories and the value of the consumer's data; instructions for opting in; the right and method to withdraw at any time; a good-faith value estimate; the valuation method; and an explanation of how the price or service difference is reasonably related to that value.

How can a business calculate the value of consumer data?

Section 7081 allows a reasonable, documented, good-faith method using one or more listed measures: marginal value, average value, aggregate value divided by the number of consumers, revenue, expenses, profit, the cost of the incentive, or another practical and reasonably reliable method. Keep the period, inputs, assumptions, calculation, approval, and explanation connecting the result to the actual price or service difference.

Can a consumer leave a CCPA financial incentive program?

Yes. Prior opt-in consent may be revoked at any time. The notice must explain how to withdraw, and the business should stop the program's data-dependent processing and apply the disclosed withdrawal consequences across the affected systems. If a consumer initially refuses opt-in consent, Civil Code section 1798.125 requires the business to wait at least 12 months before asking again, unless regulations prescribe otherwise.

When is a price or service difference discriminatory under the CCPA?

A difference is prohibited when it penalizes a consumer for exercising a CCPA right unless the difference is reasonably related to the value of that consumer's data. If the business cannot calculate a good-faith value estimate or show that relationship, section 7080 says it must not offer the difference. A difference directly resulting from compliance with state or federal law is not discriminatory under section 7080.

Citations
CCPA Financial Incentives: Notice, Consent, and Data Value

What evidence should teams keep for Financial Incentives under the US CCPA?

Keep the commercial analysis, consumer-facing notice, consent event, and live program behavior together. The notice should match the benefit, eligibility, data uses, withdrawal result, and valuation method that the program actually uses.

  • Program terms, eligibility, benefit, covered data, processing purposes, retention, sale or sharing, and withdrawal consequences.
  • Good-faith data-value calculation with method, inputs, assumptions, period, and approval.
  • Versioned notice, enrollment screen, unselected default state, consent timestamp, withdrawal record, and suppression of repeat prompts.
  • Tests showing price and service differences match the approved program and valuation analysis.
Citations
CCPA Financial Incentives: Notice, Consent, and Data Value

Which mistakes create risk when handling Financial Incentives under the US CCPA?

Classify each discount from the actual exchange. The business must connect the specific difference to the value of the consumer's data and operate the program consistently with the disclosed terms.

  • Calling a loyalty program ordinary pricing without testing whether personal information drives the benefit.
  • Using a revenue estimate with no documented method, inputs, or relationship to the consumer's data.
  • Preselecting enrollment or making refusal less prominent, which can undermine consent.
  • Hiding withdrawal or continuing the data practice after withdrawal.
  • Charging or degrading service after a rights request without a documented, reasonably related price or service difference.
Citations
CCPA Global Privacy Control (GPC): team obligations and technical implementation

What is GPC and how should teams handle it under the US CCPA?

Process the signal for the browser or device that sends it and every consumer profile, including a pseudonymous profile, associated with that browser or device. If the business knows the consumer, treat the signal as applying to the consumer, their account, and identifiable offline sale or sharing. Do not wait for a separate form, account creation, or identity verification.

A qualifying signal must use a format commonly used and recognized by businesses, such as an HTTP header or JavaScript object, and the sending mechanism must tell the consumer that the signal is meant to opt out of sale and sharing. The regulations do not require the disclosure to mention California. The GPC specification expresses the signal through the Sec-GPC header and the navigator.globalPrivacyControl JavaScript property, but the legal test is section 7025 rather than a product name alone.

If the signal conflicts with a business-specific setting that permits sale or sharing, process the opt-out first. The business may explain the conflict and seek fresh consent through a compliant choice. A financial-incentive conflict has a separate confirmation branch. Absence of the signal on a later visit is not consent to opt in when the consumer is known to the business.

GPC is not a delete request and does not by itself withdraw every form of consent or limit every use of sensitive personal information. Scope it to the CCPA sale and sharing opt-out unless another applicable signal or consumer instruction communicates an additional choice. Stop covered sale or sharing as soon as feasibly possible and no later than 15 business days after receipt.

  • Detect the Sec-GPC signal and any other signal that meets the regulatory requirements.
  • Apply the opt-out before covered advertising or other sale or sharing occurs.
  • Link the status to a known consumer profile when the regulations require it, while avoiding unnecessary identity collection.
  • Propagate the choice to tag managers, consent tools, APIs, audience systems, data stores, and downstream recipients.
  • Disclose in the privacy policy how preference signals are processed, including browser, device, account, and offline scope.

Must a business honor Global Privacy Control under the CCPA?

A business that sells or shares personal information must process Global Privacy Control when the signal meets section 7025's format and consumer-disclosure requirements. The business must treat it as a valid request to opt out of sale or sharing for the sending browser or device and associated profiles, including pseudonymous profiles. If the consumer is known, the request also applies to that consumer.

Can a business require a form, login, or identity check before honoring GPC?

No. The business cannot require information beyond what is necessary to send the signal and cannot make the consumer submit a separate form or verifiable consumer request. It may offer an optional way to identify the consumer so the opt-out can reach offline activity, but it must still honor the signal for the browser or device and associated profiles if the consumer provides nothing further.

How far does a GPC opt-out apply?

At minimum, it applies to the browser or device that sent the signal and every profile the business associates with that browser or device. When the consumer is known, it also applies to the consumer, the account, and identifiable offline sale or sharing. A later visit from a device without the signal does not reverse the choice for a known consumer.

What happens when GPC conflicts with an account setting or financial incentive?

For a conflicting account setting that allows sale or sharing, the business must process GPC as an opt-out but may notify the consumer and request compliant consent to change the choice. If GPC conflicts with a financial incentive that requires consent to sale or sharing, the business may ask whether the consumer intends to leave the program. If the business cannot identify the consumer after cookies are cleared, it must honor GPC for the new browser or device.

Does honoring GPC let a business remove its privacy-choice link?

Only if the business meets the statute and section 7025 rules for frictionless processing. It must honor the signal without a fee, degraded experience, or responsive pop-up; explain the practice in its privacy policy; and let the signal fully effectuate the opt-out, including offline sale or sharing when applicable. Otherwise, the business must honor GPC and keep the required Do Not Sell or Share or alternative privacy-choice link.

How quickly must a GPC opt-out take effect?

The business must stop selling or sharing the consumer's personal information as soon as feasibly possible and no later than 15 business days after receiving the request. It must also notify third parties that received the information during the interval between receipt and compliance and direct them to honor and forward the request as required by section 7026.

Citations
CCPA Global Privacy Control (GPC): team obligations and technical implementation

What evidence should teams keep for GPC under the US CCPA?

Keep end-to-end evidence for recognized and unrecognized users. A server log showing that the header arrived does not prove that downstream sale or sharing stopped.

  • Raw request showing the signal, detection result, timestamp, browser or device, and known-account status.
  • Before-and-after network tests for advertising tags, server-side events, APIs, audiences, and downstream transfers.
  • Preference records and propagation logs showing which systems received the opt-out and when.
  • Conflict handling, consumer notices, privacy-policy disclosure, defects, remediation, owner, and review date.
Citations
CCPA Global Privacy Control (GPC): team obligations and technical implementation

Which mistakes create risk when handling GPC under the US CCPA?

A confirmation in one layer does not cure sale or sharing that continues through another layer. Test the full transfer path.

  • Displaying a confirmation while advertising tags or server-side events continue covered transfers.
  • Applying the signal only to the current page instead of the browser or device, or failing to associate it with a known consumer when required.
  • Requiring a form, account login, or identity verification before processing the signal.
  • Treating GPC as consent withdrawal, deletion, or a blanket sensitive-information limit without a separate legal and technical basis.
  • Overwriting the signal with a less privacy-protective default or failing to explain a genuine conflict with a business-specific setting.
Citations
Page 1 of 3
Previous123Next