WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • Healthcare and FDA Regulatory
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • FDA Regulatory and Compliance

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
CalPrivacy Authorizes Rulemaking on Opt-Out Signals, Raises Data Broker Fees, and Starts the Clock on DROP Amendment Comment Period
Alerts
August 18, 2026

At its August 6–7, 2026, board meetings, the California Privacy Protection Agency (CalPrivacy) Board directed staff to prepare formal rulemaking to name Global Privacy Control (GPC) in the California Consumer Privacy Act (CCPA) regulations and tighten how opt-out preference signals must be honored. It also advanced separate rulemaking on data broker deletion audits and Delete Request and Opt-out Platform (DROP) rule amendments. Finally, the Board raised annual data broker registration and DROP access fees from $6,000 to $9,500 for 2027 and previewed its audit program.

Formal Rulemaking on Opt-Out Preference Signals (OOPS)

The Board voted 4–0 to direct staff to prepare formal rulemaking, including draft text, on four OOPS recommendations.

  • Name GPC as a valid OOPS. The anticipated regulations would identify GPC by name, codifying the agency’s standing position and easing recognition across the 13 other states with universal opt-out requirements. These updates are occurring in the context of looming AB 566 (the “California Opt Me Out Act”), which will require browser developers to build a universal opt-out signal into their browsers starting January 1, 2027.
  • Clarify OOPS for pseudonymous, cross-device profiles. CalPrivacy staff proposed to add an example to the CCPA regulations to clarify how OOPS obligations apply to pseudonymous profiles. The California Attorney General enforced this standard in the February 2026 Disney settlement: where a business links consumer personal information across devices and identifiers for advertising, it must honor opt-out rights at the same scope.
  • New OOPS/GPC reporting threshold and new metrics. Under the anticipated regulations, businesses would have to report how many opt-outs came via OOPS/GPC, and the current 10-million-consumer threshold for annual metrics reporting would be replaced by the “significant risk to consumer security or privacy” standard used for cybersecurity audits and risk assessments.
  • Detect and honor GPC before firing trackers. Staff also proposed to add another example to illustrate that businesses must honor GPC before deploying cookies or trackers that sell or share personal information. This example would reinforce the existing requirement in Section 7026(f)(1) to stop selling or sharing “as soon as feasibly possible.” CalPrivacy takes the position that ignoring the GPC, allowing the sale or share, and then chasing it down within the required 15-business-day period is not complying with the “as soon as feasibly possible” language of the regulations.

DROP Is Live and the Delete Act’s Penalties Carry No Cure Period

As of August 7, DROP has received roughly 450,000 deletion requests covering more than 200 million identifiers. Nearly 30 percent of registered brokers are already processing DROP requests, and registration has climbed to roughly 600 brokers. Registered brokers have 45 days to download deletion lists and 45 days from download to report back. The Delete Act’s $200-per-request-per-day penalty currently carries no cure period. So, failure to process requests within the 45-day period can carry fines in the tens of millions of dollars per day.

Data Broker Registration and Access Fees Rise to $9,500

The Board amended Sections 7600 and 7611 to raise the data broker registration and access fees each by 58 percent to $9,500, up from $6,000. The access fee is set at $9,500 in January and is prorated by $792 each month thereafter. Because the Delete Act funds the platform through fees, CalPrivacy raised them to cover the higher cost of running a now-live DROP. The fee increase is final starting in 2027, and the Board approved it over broker objections that a flat fee disadvantages small data brokers.

New Rulemaking Would Require Independent Data Broker Deletion Audits and Amend the DROP Rules

The Board advanced draft regulations to formal rulemaking and authorized a 45-day comment period. The proposed rules would amend Sections 7601–7622 and adopt new Sections 7630–7633. The package does two things. First, registered data brokers would have to retain an independent, qualified third party to audit whether they processed DROP deletion requests correctly and on time. Findings must be evidence-based, with system logs, hashing evidence, deletion commands, status reports, and personnel interviews, and may not rest primarily on management attestations or the mere existence of a policy. Unlike the cybersecurity-audit rules, internal auditors are not permitted and there is no threshold for triggering the audit requirement. A business that becomes a data broker under the Delete Act by knowingly collecting and selling to a third party the personal information of a single consumer with whom the business does not have a “direct relationship” (as defined in the regulations) would still have to undergo a third-party audit (in addition to paying $19,000 in annual fees). Under the proposed rulemaking, the first audit reports would be due November 1, 2028, and cover an audit period beginning August 1, 2026. Data brokers would need to undergo new audits every three years thereafter. Second, the package amends the existing DROP regulations. For instance, it would tighten registration accuracy requirements and add a 10-business-day window to update registration information.

The Audit Program: Gig-Economy, ADMT, and Cybersecurity Audits

The Audits Division delivered its first annual update. Its first sectoral audit targets the gig economy. Because CalPrivacy has confirmed that gig platforms are only the first in a planned series of sectoral audits, businesses across all industries should treat audit-readiness as a present priority, particularly as the following audit and assessment obligations phase in. Automated Decision-Making Technology (ADMT) obligations take effect January 1, 2027, followed by cybersecurity and risk-assessment audits. The first cybersecurity-audit certifications are due April 1, 2028, for businesses with over $100 million in annual gross revenue and phase in by revenue for smaller organizations after that. Businesses with $50 - $100 million in annual gross revenue must certify by April 1, 2029, and all other businesses engaged in processing activities that pose a “significant risk” to consumers’ security by April 1, 2030. Risk-assessment submissions are first due April 1, 2028, and annually after that.

Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex privacy and data security issues pertaining to CalPrivacy rulemaking, guidance, and enforcement. For more information or advice concerning your CCPA, data broker, or ADMT compliance efforts, please contact Tracy Shapiro, Eddie Holman, Ekaterina Moiseeva, or Malcolm Yeary, or any member of the firm’s Data, Privacy, and Cybersecurity practice.

Contributors

  • Tracy Shapiro
  • Eddie Holman
  • Ekaterina Moiseeva
  • Malcolm Yeary
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.