At its August 6–7, 2026, board meetings, the California Privacy Protection Agency (CalPrivacy) Board directed staff to prepare formal rulemaking to name Global Privacy Control (GPC) in the California Consumer Privacy Act (CCPA) regulations and tighten how opt-out preference signals must be honored. It also advanced separate rulemaking on data broker deletion audits and Delete Request and Opt-out Platform (DROP) rule amendments. Finally, the Board raised annual data broker registration and DROP access fees from $6,000 to $9,500 for 2027 and previewed its audit program.
Formal Rulemaking on Opt-Out Preference Signals (OOPS)
The Board voted 4–0 to direct staff to prepare formal rulemaking, including draft text, on four OOPS recommendations.
- Name GPC as a valid OOPS. The anticipated regulations would identify GPC by name, codifying the agency’s standing position and easing recognition across the 13 other states with universal opt-out requirements. These updates are occurring in the context of looming AB 566 (the “California Opt Me Out Act”), which will require browser developers to build a universal opt-out signal into their browsers starting January 1, 2027.
- Clarify OOPS for pseudonymous, cross-device profiles. CalPrivacy staff proposed to add an example to the CCPA regulations to clarify how OOPS obligations apply to pseudonymous profiles. The California Attorney General enforced this standard in the February 2026 Disney settlement: where a business links consumer personal information across devices and identifiers for advertising, it must honor opt-out rights at the same scope.
- New OOPS/GPC reporting threshold and new metrics. Under the anticipated regulations, businesses would have to report how many opt-outs came via OOPS/GPC, and the current 10-million-consumer threshold for annual metrics reporting would be replaced by the “significant risk to consumer security or privacy” standard used for cybersecurity audits and risk assessments.
- Detect and honor GPC before firing trackers. Staff also proposed to add another example to illustrate that businesses must honor GPC before deploying cookies or trackers that sell or share personal information. This example would reinforce the existing requirement in Section 7026(f)(1) to stop selling or sharing “as soon as feasibly possible.” CalPrivacy takes the position that ignoring the GPC, allowing the sale or share, and then chasing it down within the required 15-business-day period is not complying with the “as soon as feasibly possible” language of the regulations.
DROP Is Live and the Delete Act’s Penalties Carry No Cure Period
As of August 7, DROP has received roughly 450,000 deletion requests covering more than 200 million identifiers. Nearly 30 percent of registered brokers are already processing DROP requests, and registration has climbed to roughly 600 brokers. Registered brokers have 45 days to download deletion lists and 45 days from download to report back. The Delete Act’s $200-per-request-per-day penalty currently carries no cure period. So, failure to process requests within the 45-day period can carry fines in the tens of millions of dollars per day.
Data Broker Registration and Access Fees Rise to $9,500
The Board amended Sections 7600 and 7611 to raise the data broker registration and access fees each by 58 percent to $9,500, up from $6,000. The access fee is set at $9,500 in January and is prorated by $792 each month thereafter. Because the Delete Act funds the platform through fees, CalPrivacy raised them to cover the higher cost of running a now-live DROP. The fee increase is final starting in 2027, and the Board approved it over broker objections that a flat fee disadvantages small data brokers.
New Rulemaking Would Require Independent Data Broker Deletion Audits and Amend the DROP Rules
The Board advanced draft regulations to formal rulemaking and authorized a 45-day comment period. The proposed rules would amend Sections 7601–7622 and adopt new Sections 7630–7633. The package does two things. First, registered data brokers would have to retain an independent, qualified third party to audit whether they processed DROP deletion requests correctly and on time. Findings must be evidence-based, with system logs, hashing evidence, deletion commands, status reports, and personnel interviews, and may not rest primarily on management attestations or the mere existence of a policy. Unlike the cybersecurity-audit rules, internal auditors are not permitted and there is no threshold for triggering the audit requirement. A business that becomes a data broker under the Delete Act by knowingly collecting and selling to a third party the personal information of a single consumer with whom the business does not have a “direct relationship” (as defined in the regulations) would still have to undergo a third-party audit (in addition to paying $19,000 in annual fees). Under the proposed rulemaking, the first audit reports would be due November 1, 2028, and cover an audit period beginning August 1, 2026. Data brokers would need to undergo new audits every three years thereafter. Second, the package amends the existing DROP regulations. For instance, it would tighten registration accuracy requirements and add a 10-business-day window to update registration information.
The Audit Program: Gig-Economy, ADMT, and Cybersecurity Audits
The Audits Division delivered its first annual update. Its first sectoral audit targets the gig economy. Because CalPrivacy has confirmed that gig platforms are only the first in a planned series of sectoral audits, businesses across all industries should treat audit-readiness as a present priority, particularly as the following audit and assessment obligations phase in. Automated Decision-Making Technology (ADMT) obligations take effect January 1, 2027, followed by cybersecurity and risk-assessment audits. The first cybersecurity-audit certifications are due April 1, 2028, for businesses with over $100 million in annual gross revenue and phase in by revenue for smaller organizations after that. Businesses with $50 – $100 million in annual gross revenue must certify by April 1, 2029, and all other businesses engaged in processing activities that pose a “significant risk” to consumers’ security by April 1, 2030. Risk-assessment submissions are first due April 1, 2028, and annually after that.
Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex privacy and data security issues pertaining to CalPrivacy rulemaking, guidance, and enforcement. For more information or advice concerning your CCPA, data broker, or ADMT compliance efforts, please contact Tracy Shapiro, Eddie Holman, Ekaterina Moiseeva, or Malcolm Yeary, or any member of the firm’s Data, Privacy, and Cybersecurity practice.