IN EFFECT since January 1, 2020
Last verified against primary sources:
CCPA / CPRA (California)
US-State · Effective January 1, 2020
California privacy law: notice, opt-out of sale/sharing, deletion, and Global Privacy Control honoring. Applies at $25M+ revenue, 100K+ CA consumers, or 50%+ revenue from data sales.
Overview
New CPPA regulations took effect January 1, 2026 (automated decision-making/ADMT, risk assessments, cybersecurity audits), but their compliance deadlines phase in 2027-2030 and bite only at $25M+ revenue or large user counts - not immediate for $0-5K MRR founders. The applicability revenue threshold is CPI-adjusted (~$25M; confirm the current figure). Businesses must honor the Global Privacy Control browser signal.
Official text: https://cppa.ca.gov/regulations/
See where your app stands
SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.
Scan Your App