Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Six CCPA Myths That Will Cost You in 2026Laws and Regulations
5 min readFor Compliance Managers

Six CCPA Myths That Will Cost You in 2026

You've read the summaries, skimmed the vendor decks, and maybe even sat through a webinar. But compliance managers still walk into CCPA audits carrying assumptions that haven't been true since the CPRA amendments took effect, or that were never true at all.

These myths persist because they're comforting. They let you defer hard conversations about data retention, vendor contracts, and opt-out infrastructure. But California's enforcement record shows a pattern: the Attorney General and CalPrivacy target the gap between what businesses think they've done and what the statute actually requires.

Here are six myths that will expose you in 2026, and what the regulations actually say.

Myth 1: "We're too small for the CCPA to apply"

Reality: The CCPA's $26,625,000 revenue threshold (adjusted for inflation as of January 1, 2025) doesn't include a data-volume floor. If your company crossed that revenue line last year and you collect personal information from California consumers, you're covered, even if you only have a few hundred California customers.

More surprising: you can meet the 100,000-consumer threshold through your website alone, at any revenue level. That count includes every consumer whose data your advertising tags share, whether they bought anything or not. If your analytics and ad pixels send visitor data to third parties, you're likely counting impressions, not just transactions.

Nonprofits and government agencies generally fall outside the definition of a business, but a for-profit subsidiary of a nonprofit doesn't get the same exemption.

Myth 2: "Our privacy policy covers the notice-at-collection requirement"

Reality: The notice at collection is a separate disclosure, shown at or before the moment you collect data. Under 11 CCR § 7012, it has to appear beside the signup form, the checkout flow, or wherever the data enters your system, not buried three clicks deep in your privacy policy.

You can link to your privacy policy from the notice, but only if that link lands directly on the relevant section, not the top of the page. And if you haven't given the notice at or before collection, you can't collect the data at all.

Adding a new category of personal information or an incompatible purpose requires an updated notice first. Tractor Supply's $1.35 million fine, the largest administrative penalty CalPrivacy has issued, included failing to give job applicants the required notice at collection.

Myth 3: "We don't sell data, so we don't need an opt-out"

Reality: The CCPA defines "sharing" separately from "sale," and sharing triggers the same opt-out duty. Sharing means disclosing personal information for cross-context Behavioural Advertising, whether or not money changes hands.

If your advertising pixels send visitor data to an ad platform that uses it to target ads based on activity across other sites, that's sharing. A vendor running that kind of advertising can't qualify as a service provider for it under 11 CCR § 7050(b), which means you're sharing, and you owe an opt-out.

Since January 1, 2026, the new regulations require any business that sells or shares personal information to show visitors it honored their opt-out signal. That's not just a technical toggle, it's a visible confirmation that the signal worked.

Myth 4: "We can keep data as long as it might be useful"

Reality: The CCPA's necessity limit extends to retention. You can't keep personal information past what each disclosed purpose reasonably requires, and your notice at collection has to state how long you keep each category or the criteria that set the period.

General Motors' $12.75 million settlement in May 2026, the largest CCPA penalty so far, turned on this principle. The Attorney General said GM kept drivers' location and driving data long after OnStar needed it, then sold that data to Verisk and LexisNexis. It was California's first data-minimization enforcement.

Run your data map against the necessity test in 11 CCR § 7002: the minimum data the purpose needs, the possible harm to consumers, and the safeguards in place. Every field that serves no disclosed purpose is a field you shouldn't be holding.

Myth 5: "Sensitive personal information requires opt-in consent"

Reality: California keeps sensitive data on an opt-out model for adults, not opt-in. Consumers can limit how you use their sensitive personal information, but you don't need Prior Consent to collect it for disclosed purposes.

Civil Code § 1798.140(ae) lists the categories: Social Security numbers, account logins with passwords, precise geolocation within 1,850 feet, racial or ethnic origin, mail or email contents (when you're not the intended recipient), genetic and biometric data, health information, and sex life or sexual orientation.

The 2026 regulations added one more: personal information of consumers you know are younger than 16, under 11 CCR § 7001(bbb)(4). CalPrivacy's guidance says that data may be subject to the consumer's right to limit use.

Many other state privacy laws, including Virginia's, do require opt-in consent for sensitive data. If you operate in multiple states, you're managing two different models.

Myth 6: "Financial incentives are basically banned"

Reality: Loyalty programs and discounts tied to personal information are still allowed when they meet specific conditions under Civil Code § 1798.125(b) and 11 CCR §§ 7004, 7016, and 7080.

You need the consumer's opt-in first, and they can withdraw at any time. You have to provide a notice of financial incentive before sign-up. The join option can't be preselected or shown more prominently than the decline option. After a consumer says no, you wait 12 months before asking again.

The hard part: you need a documented good-faith estimate of what the consumer's data is worth, and you can't offer the incentive without one. That's not a back-of-the-envelope calculation, it's a defensible methodology that ties the incentive's value to the data's commercial benefit.

What to do instead

Start with your data map. List every category of personal information you collect, its source, purpose, storage location, retention period, and recipients. Mark which flows are sales, which are sharing, and which go to service providers or contractors.

Check your notices. Confirm that your notice at collection appears at or before the point of collection, not just in your privacy policy. Update it whenever you add a new category or purpose.

Test your opt-outs. If you sell or share, verify that your opt-out mechanisms work and that you honor opt-out preference signals like Global Privacy Control. Since January 1, 2026, you're required to show visitors you honored their signal.

Set retention limits. For each category on your data map, document how long you keep it and why that period is reasonably necessary for the disclosed purpose. Delete data when its purpose expires.

Review your vendor contracts. Sales and sharing require one set of terms; service providers and contractors require another, spelled out in Civil Code § 1798.100(d). Your contract has to restrict the vendor's use, prohibit further sale or sharing, and require security measures.

The myths persist because they're easier than the work. The regulations don't care.

CCPA Regulations

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like