California has a comprehensive consumer privacy statute, the CCPA/CPRA. This page collects our coverage touching California, alongside the federal rules that apply there. For the statute itself rather than the news, see our California privacy law page.
Dark Patterns
September 14, 2026
California, Colorado and Connecticut define a dark pattern in nearly the same words, and each treats agreement obtained through one as no consent at all. What differs is the material around that sentence: an example-driven regulation in California, design and withdrawal rules in Colorado, and in Connecticut a statute that points to the FTC.
Read more →
Adtech & Cookies
September 7, 2026
The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.
Read more →
CPPA
September 7, 2026
Proposition 24 established the California Privacy Protection Agency in December 2020, but the power to write CCPA regulations did not move to it on that date. The transfer was conditional, it completed in April 2022, and the Attorney General's own regulatory authority was never extinguished. This traces the grant, the condition, the board that exercises it, and what the agency has adopted.
Read more →
Data Brokers
September 7, 2026
Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.
Read more →
Data Brokers
September 1, 2026
California's Delete Act took an existing registry and attached machinery to it: one consumer request that reaches every registered broker, a 45-day processing cycle, a triennial third-party audit and a $200-a-day fine for not signing up. This reports what SB 362 and the 2025 amendment require, and the dates the statute and the DROP regulations set.
Read more →
CCPA / CPRA
September 1, 2026
California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.
Read more →
CCPA / CPRA
September 1, 2026
The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.
Read more →
AI & Privacy
August 24, 2026
There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.
Read more →
CAN-SPAM
August 24, 2026
CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.
Read more →
Consent Management
August 24, 2026
A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.
Read more →
Dark Patterns
August 24, 2026
Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.
Read more →
Data Brokers
August 24, 2026
Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.
Read more →
Employee Privacy
August 24, 2026
There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.
Read more →
Pixel Tracking
August 24, 2026
Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →