Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

New California Bill Would Prohibit Apps From Changing User Privacy Settings Without Consent

By Odia Kagan on September 14, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

If a user sets a privacy preference, an operating system or app cannot change that setting without the user’s explicit consent, says new bill, AB 2561, that passed the California legislature. 

A “Privacy setting” means any user-configurable option within an application’s privacy, or similarly labeled, menu that governs the application’s collection, use, sharing, disclosure, retention, or processing of the user’s personal information. 

What does this change for processing personal information of Californians? 

Under longstanding FTC enforcement, retroactive changes to privacy practices have often required consent where they would result in a more permissive use or disclosure of previously collected personal information. 

Similarly, the CCPA and its implementing regulations restrict businesses from using personal information for materially different purposes than those disclosed at collection without first obtaining consent.

This law, if signed, would make this (1) expressly required by statute and (2) applicable regardless of whether the change would otherwise be considered material.

An exception to this would be if changing the setting is required by state or federal law, court order, or in response to a subpoena in an individual case or proceeding. 

Businesses are also allowed to discontinue services or applications, cease the collection, use, retention, or sharing of a user’s personal information, or cease to offer privacy options, provided that such changes are either compliant with the law (required by law or in response to a subpoena), or the changes result in either of the following:

(1) Maintaining the current protections related to the collection, use, sharing, or retention of personal information collected by the business before the change in its services or settings.

(2) An increase in privacy protection by reducing the collection, use, sharing, or retention of personal information.

  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy Compliance & Data Security
  • Organization:
    Fox Rothschild LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo