California Cybersecurity Laws You Should Know (2026)

Last Updated: August 27, 2026

California has the most comprehensive cybersecurity and consumer privacy framework in the United States. Businesses operating in California or collecting personal information from California residents must comply with multiple state laws governing consumer privacy, data security, breach notification, data brokers, connected devices, and industry-specific cybersecurity requirements.

Unlike many other states that focus primarily on breach notification, California requires covered businesses to manage personal information throughout its entire lifecycle. Organizations must provide consumers with significant control over their personal data while implementing reasonable security measures designed to protect that information from unauthorized access, disclosure, alteration, or destruction.

Whether your organization is headquartered in California or simply serves California residents, understanding these laws is essential for reducing regulatory risk, maintaining customer trust, and developing a mature cybersecurity program.

This guide explains the major California cybersecurity laws businesses should understand in 2026 and outlines practical steps organizations can take to improve compliance.

California Cybersecurity Laws at a Glance

Requirement Summary
Primary Privacy Law California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
Primary Breach Law California Civil Code §§1798.29 & 1798.82
Primary Privacy Regulator California Privacy Protection Agency (CPPA)
Consumer Privacy Rights Access, correction, deletion, portability, opt-out, limit use of sensitive personal information
Data Broker Law California Delete Act & Data Broker Registry
IoT Security Law Security requirements for connected devices
Consumer Notification In the most expedient time possible and without unreasonable delay
Attorney General / Agency Enforcement California Privacy Protection Agency and California Attorney General

California Cybersecurity Law Timeline

Year Legislative Update
2003 California became the first state to enact a statewide data breach notification law.
2018 California Consumer Privacy Act (CCPA) signed into law.
2020 California voters approved the California Privacy Rights Act (CPRA).
2023 California Delete Act signed into law.
2024 California Privacy Protection Agency assumed responsibility for the Data Broker Registry.
2026 New CPRA regulations addressing automated decision-making, cybersecurity audits, and risk assessments took effect, and the Delete Act’s one-stop deletion mechanism became operational.

Who Should Read This Guide?

This guide is especially valuable for:

  • Technology companies
  • Healthcare organizations
  • Financial institutions
  • Retail businesses
  • Manufacturers
  • Construction companies
  • SaaS providers
  • Professional service firms
  • E-commerce companies
  • Any organization collecting personal information from California residents

Why California Cybersecurity Laws Matter

California has influenced privacy legislation throughout the United States.

Many states have modeled portions of their consumer privacy laws after California’s framework. Businesses that successfully comply with California law often find it easier to prepare for compliance in other jurisdictions as additional states adopt comprehensive privacy legislation.

Unlike states that primarily regulate organizations after a data breach occurs, California regulates nearly every stage of the information lifecycle, including:

  • Data collection
  • Consumer notice
  • Data sharing
  • Targeted advertising
  • Data retention
  • Consumer rights requests
  • Vendor management
  • Data broker activities
  • Cybersecurity practices

Because California has the largest state economy in the United States, many organizations outside California also fall within the scope of these laws simply because they collect information from California residents.

California Consumer Privacy Act (CCPA)

The foundation of California privacy law is the California Consumer Privacy Act (CCPA).

The CCPA became effective on January 1, 2020 and established broad privacy rights for California consumers while creating significant compliance obligations for covered businesses.

The law generally applies to for-profit businesses doing business in California that collect consumers’ personal information and meet specified statutory thresholds related to revenue or data processing. The California Privacy Rights Act later expanded these protections and created additional compliance obligations.

California Privacy Rights Act (CPRA)

The California Privacy Rights Act (CPRA) significantly expanded the CCPA and created one of the most comprehensive privacy frameworks in the United States.

The CPRA became fully effective in 2023 and established the California Privacy Protection Agency (CPPA) as the nation’s first dedicated state privacy regulator. It also introduced additional consumer rights, expanded protections for sensitive personal information, and strengthened enforcement authority.

Since then, California has continued refining its privacy regulations. Additional regulations addressing automated decision-making technology, cybersecurity audits, and risk assessments took effect in 2026, further expanding compliance obligations for covered businesses.

Consumer Rights Under California Law

California consumers receive some of the strongest privacy protections in the country.

Covered consumers generally have the right to:

  • Know what personal information businesses collect
  • Access personal information
  • Correct inaccurate information
  • Delete personal information
  • Obtain a portable copy of personal data
  • Opt out of the sale of personal information
  • Opt out of the sharing of personal information used for cross-context behavioral advertising
  • Limit the use and disclosure of sensitive personal information
  • Exercise privacy rights without discrimination

Businesses subject to the CCPA and CPRA must establish procedures allowing consumers to exercise these rights within statutory response periods.

What Is Sensitive Personal Information?

The CPRA introduced a new category known as Sensitive Personal Information (SPI).

Examples include:

  • Social Security numbers
  • Driver’s license numbers
  • Passport numbers
  • Financial account credentials
  • Precise geolocation
  • Racial or ethnic origin
  • Religious beliefs
  • Union membership
  • Genetic information
  • Biometric information
  • Health information
  • Sexual orientation
  • Contents of private communications

Consumers may direct covered businesses to limit the use or disclosure of sensitive personal information under certain circumstances.

California Privacy Protection Agency (CPPA)

One of California’s most significant innovations was creating the California Privacy Protection Agency (CPPA).

The CPPA is the first standalone privacy regulator in the United States. It is responsible for:

  • Enforcing the CCPA and CPRA
  • Issuing regulations
  • Investigating violations
  • Maintaining the California Data Broker Registry
  • Administering the Delete Act’s data broker deletion platform (DROP)

The agency’s creation significantly expanded California’s privacy enforcement capabilities beyond those of the Attorney General alone.

California Data Breach Notification Law

California was the first state in the country to enact a statewide data breach notification law, and it continues to maintain detailed notification requirements under California Civil Code §§1798.29 and 1798.82.

Organizations experiencing a qualifying breach generally must notify affected California residents in the most expedient time possible and without unreasonable delay, subject to legitimate law enforcement delays and the time reasonably necessary to determine the scope of the breach and restore system integrity.

Organizations should quickly determine:

  • What systems were affected
  • What personal information was involved
  • Which California residents were impacted
  • Whether third-party vendors were involved
  • Whether additional state or federal notification obligations apply

California’s breach notification law continues to serve as a model for many other states.

What Information Is Protected?

California defines personal information broadly.

Depending on the applicable statute, protected information may include:

  • Names
  • Addresses
  • Email addresses
  • Social Security numbers
  • Driver’s license numbers
  • Passport numbers
  • Financial account information
  • Credit card information
  • Biometric information
  • Geolocation data
  • Internet activity
  • Device identifiers
  • Browsing history
  • Online identifiers
  • Commercial information
  • Employment information
  • Education information
  • Health information
  • Inferences created from personal information

The broad definition of personal information is one reason California privacy compliance can be significantly more complex than compliance in many other states.

California Delete Act

One of California’s newest privacy laws is the California Delete Act (SB 362).

The Delete Act expands California’s regulation of data brokers by creating a centralized process that allows consumers to request deletion of their personal information from every registered data broker through a single request.

Beginning in 2026, eligible consumers can use the California Privacy Protection Agency’s Delete Request and Opt-out Platform (DROP) to submit one deletion request that participating data brokers must honor, subject to applicable legal exceptions. This significantly simplifies the process compared to contacting each broker individually. (cppa.ca.gov)

Businesses that qualify as data brokers should understand both their registration requirements and their obligations under the Delete Act.

California Data Broker Registry

California requires qualifying data brokers to register annually with the California Privacy Protection Agency.

The registry increases transparency by allowing consumers to identify organizations that collect and sell personal information without having a direct relationship with the consumer.

Businesses that qualify as data brokers should review the registration requirements carefully to avoid potential enforcement actions.

California Internet of Things (IoT) Security Law

California was also one of the first states to establish cybersecurity requirements for connected devices.

The Information Privacy: Connected Devices Law (SB 327) requires manufacturers of internet-connected devices to equip those devices with reasonable security features appropriate to the:

  • Nature of the device
  • Information collected
  • Function of the device
  • Foreseeable cybersecurity risks

Examples of reasonable security features may include:

  • Unique preprogrammed passwords
  • Required password changes during setup
  • Secure authentication mechanisms
  • Protection against unauthorized access

Organizations developing smart devices, industrial IoT equipment, medical devices, or connected consumer products should evaluate whether this law applies to their products.

California Student Privacy Laws

Educational institutions and education technology providers may also be subject to California’s Student Online Personal Information Protection Act (SOPIPA).

SOPIPA places restrictions on how operators of websites, applications, and online services designed for K-12 school purposes may collect, use, or disclose student information.

Organizations serving schools should review both SOPIPA and FERPA requirements when developing cybersecurity and privacy programs.

California Insurance Data Security Law

Insurance companies and certain licensed insurance professionals operating in California must comply with the California Insurance Information and Privacy Protection Act as well as applicable regulations issued by the California Department of Insurance.

In addition, insurers should monitor evolving cybersecurity expectations from the Department of Insurance and applicable NAIC guidance.

AI, Automated Decision-Making, and Cybersecurity

California continues to lead the nation in regulating emerging technologies.

The California Privacy Protection Agency has adopted regulations addressing automated decision-making technology, cybersecurity audits, and risk assessments for covered businesses under the CPRA. Organizations that use AI systems for significant decisions involving consumers should review these regulations carefully to determine whether additional notice, opt-out, or assessment obligations apply.

Businesses implementing artificial intelligence should also evaluate:

  • AI governance policies
  • Model security
  • Data quality controls
  • Third-party AI vendor management
  • Privacy impact assessments
  • Employee AI usage policies

Federal Cybersecurity Laws That Also Apply

California organizations frequently must comply with federal cybersecurity regulations in addition to state law.

Health Insurance Portability and Accountability Act (HIPAA)

Healthcare providers, health plans, healthcare clearinghouses, and business associates handling protected health information must comply with HIPAA.

HIPAA generally requires:

  • Administrative safeguards
  • Physical safeguards
  • Technical safeguards
  • Security risk assessments
  • Workforce cybersecurity training
  • Access controls
  • Audit logging
  • Incident response procedures
  • Business associate agreements

Healthcare organizations experiencing a breach may have notification obligations under both HIPAA and California law.

Gramm-Leach-Bliley Act (GLBA)

Banks, credit unions, mortgage companies, investment firms, and other financial institutions may also be subject to GLBA.

GLBA generally requires:

  • Written information security programs
  • Risk assessments
  • Vendor oversight
  • Employee training
  • Administrative safeguards
  • Technical safeguards
  • Physical safeguards

Federal Trade Commission Act

The Federal Trade Commission may investigate organizations that engage in unfair or deceptive cybersecurity or privacy practices.

Organizations should ensure their privacy policies, marketing materials, and public statements accurately reflect their cybersecurity practices.

Family Educational Rights and Privacy Act (FERPA)

Educational institutions maintaining student education records may also be subject to FERPA.

FERPA establishes protections governing student records while limiting unauthorized disclosure.

Defense Federal Acquisition Regulation Supplement (DFARS)

California has one of the nation’s largest aerospace and defense industries.

Organizations handling Controlled Unclassified Information (CUI) frequently must comply with DFARS and NIST SP 800-171.

These standards establish cybersecurity controls involving:

  • Access controls
  • Multi-factor authentication
  • Logging
  • Configuration management
  • Incident reporting
  • Continuous monitoring

NIST Cybersecurity Framework

Many California organizations align their cybersecurity program with the NIST Cybersecurity Framework (CSF 2.0).

The Framework organizes cybersecurity activities into six core functions:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Although California law does not require every business to implement NIST, the Framework provides an excellent foundation for cybersecurity governance and often supports compliance with multiple regulations simultaneously.

California Cybersecurity Compliance Checklist

Organizations collecting personal information from California residents should regularly evaluate their cybersecurity and privacy program.

Best practices include:

  • Maintain an up-to-date privacy policy
  • Map personal data throughout the organization
  • Classify sensitive personal information
  • Develop procedures for responding to consumer rights requests
  • Maintain contracts with service providers and contractors
  • Conduct cybersecurity risk assessments
  • Implement multi-factor authentication
  • Encrypt sensitive information whenever appropriate
  • Maintain endpoint detection and response
  • Monitor third-party vendors
  • Conduct employee cybersecurity awareness training
  • Test incident response procedures
  • Review AI governance practices
  • Evaluate compliance with CCPA, CPRA, and the Delete Act
  • Monitor changes to California privacy regulations

Privacy compliance should be viewed as an ongoing governance process rather than a one-time project.

Example: A California SaaS Company Experiences a Data Breach

A software company headquartered in San Jose discovers attackers exploited a cloud application vulnerability.

The investigation determines:

  • Customer account information was accessed.
  • Authentication credentials may have been exposed.
  • Personal information belonging to California residents was affected.
  • Several third-party vendors processed portions of the compromised data.

The company immediately begins its incident response plan.

Its response includes:

  • Determining which California residents were affected
  • Preparing legally compliant breach notifications
  • Reviewing contractual notification obligations
  • Evaluating whether consumer rights requests may increase following the incident
  • Coordinating with outside legal counsel and forensic investigators

Because the organization already maintained mature privacy governance under the CCPA and CPRA, it was able to identify affected systems, preserve evidence, and communicate with customers more efficiently.

Frequently Asked Questions About California Cybersecurity Laws

What is California’s primary privacy law?

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), establishes California’s primary consumer privacy framework.

Does California have one of the strongest privacy laws in the United States?

Yes.

California is widely recognized as having the nation’s most comprehensive state privacy framework and has influenced many other state privacy laws.

What is the California Privacy Protection Agency?

The CPPA is the nation’s first standalone state privacy regulator. It is responsible for enforcing California’s privacy laws, issuing regulations, maintaining the Data Broker Registry, and administering the Delete Act’s deletion platform.

What rights do California consumers have?

Consumers generally have rights to:

  • Know what information is collected
  • Access personal information
  • Correct inaccurate information
  • Delete personal information
  • Obtain a copy of personal data
  • Opt out of the sale and sharing of personal information
  • Limit the use of sensitive personal information

What is Sensitive Personal Information?

The CPRA created a separate category of information that includes items such as Social Security numbers, precise geolocation, health information, biometric information, and other particularly sensitive data.

What is the California Delete Act?

The Delete Act allows eligible consumers to submit a single request requiring registered data brokers to delete personal information, subject to applicable legal exceptions.

Does California have an IoT security law?

Yes.

California requires manufacturers of connected devices to equip those devices with reasonable security features appropriate to the nature and function of the device.

How quickly must businesses notify consumers following a breach?

California generally requires notification in the most expedient time possible and without unreasonable delay after discovering a qualifying breach.

Does California require cybersecurity audits?

Certain businesses subject to CPRA regulations may have cybersecurity audit and risk assessment obligations depending on their data processing activities and applicable regulations.

Does complying with California law satisfy federal cybersecurity requirements?

No.

Organizations may also need to comply with HIPAA, GLBA, FTC requirements, FERPA, DFARS, PCI DSS, contractual obligations, and other industry-specific cybersecurity regulations.

Related Cybersecurity Guides

Continue learning about cybersecurity compliance by exploring:

Conclusion

California continues to set the national standard for cybersecurity and consumer privacy regulation. Through the CCPA, CPRA, Delete Act, data broker requirements, breach notification laws, and sector-specific cybersecurity regulations, the state has created one of the most comprehensive privacy frameworks in the world.

Organizations collecting personal information from California residents should view compliance as an ongoing governance initiative rather than a one-time legal requirement. A mature cybersecurity and privacy program that includes data mapping, consumer rights management, vendor oversight, employee training, incident response planning, AI governance, and continuous monitoring can help reduce regulatory risk while strengthening customer trust.

As additional states continue adopting privacy laws modeled after California, businesses that invest in California compliance today will be better positioned to adapt to future privacy regulations across the United States.

Disclaimer: This article is provided for informational purposes only and should not be considered legal advice. Businesses should consult qualified legal counsel regarding the application of California cybersecurity and privacy laws to their specific circumstances.

Mitch Wolverton

Mitch, Marketing Manager at PivIT Strategy, brings over many years of marketing and content creation experience to the company. He began his career as a content writer and strategist, honing his skills on some of the industry’s largest websites, before advancing to specialize in SEO and digital marketing at PivIT Strategy.