Back to Blog
    Compliance

    CPRA Enforcement in 2026: Verified Fines, Audits and Priorities

    A source-checked review of California privacy enforcement in 2026, including the PlayOn Sports and Ford orders, the first sectoral audit, and practical compliance priorities.

    CPRA Enforcement in 2026: Verified Fines, Audits and Priorities
    PolicyForge Editorial Team
    May 12, 2026
    9 min read
    CPRA
    CCPA
    California privacy
    enforcement
    CPPA
    fines
    2026
    Share:

    California privacy enforcement in 2026: the verified record

    California privacy enforcement is active in 2026, but businesses should rely on published orders and agency announcements rather than unsupported aggregate numbers. The California Privacy Protection Agency now uses the public-facing name CalPrivacy. Its enforcement decisions generally concern the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and some 2026 actions also involve the Delete Act.

    For a concise explanation of the underlying consumer rights and business scope, start with PolicyForge's CCPA guide.

    As of September 24, 2026, CalPrivacy's official newsroom lists enforcement actions involving businesses and data brokers, along with the agency's first announced sectoral audit. The record supports a practical conclusion: opt-out design, tracking technologies, notices, children's data, data-broker obligations, and access-request operations are concrete enforcement priorities.

    Two published 2026 CCPA orders

    PlayOn Sports: $1.10 million

    On March 3, 2026, the agency announced an order requiring PlayOn Sports to pay a $1.10 million fine and change its practices. According to the agency, PlayOn used tracking technologies for targeted advertising, required users to agree to tracking before using tickets or websites, failed to provide an adequate first-party opt-out method, did not recognize opt-out preference signals, and did not provide sufficient notice of its privacy practices.

    The order also addressed consumers aged 13 through 15. CalPrivacy stated that PlayOn must comply with the requirement to obtain affirmative opt-in consent before selling or sharing personal information belonging to consumers in that age range. The remedial terms included risk assessments, clearer disclosures, and proper opt-out methods.

    Ford: $375,703

    On March 5, 2026, the agency announced an order requiring Ford Motor Company to pay $375,703 and change its opt-out process. CalPrivacy said Ford required consumers to verify an email address before it would process requests to opt out of sale or sharing. The agency characterized that extra verification as unnecessary friction.

    Ford was also required to audit tracking technologies on its website and ensure compliance with opt-out preference signals, including Global Privacy Control. The order is a useful design lesson: an opt-out flow should ask only for information reasonably necessary to process that request, and the business should test what happens when a browser sends a recognized opt-out preference signal.

    The first announced sectoral audit

    On July 21, 2026, CalPrivacy announced that its Audits Division had begun the agency's first formal sectoral privacy audit. The announced audit concerns gig-economy platforms operating in California, not mid-market businesses across every industry.

    The agency said the audit would examine whether workers and consumers can exercise access rights in practice. Its announcement specifically identified completeness of responses, the statutory 45-day response window, and the systems used to process access requests. It also noted the sensitivity and operational importance of data that gig platforms may hold, including precise geolocation, performance metrics, financial information, communications, and data used in algorithmic decisions.

    CalPrivacy described this as the first in a series of sectoral audits. That establishes an audit program, but it does not substantiate the former article's claims about random selection criteria, referrals, breach reports, or audits spanning all industries. Businesses should monitor future agency announcements before treating those items as formal audit triggers.

    Data-broker enforcement is a separate 2026 theme

    CalPrivacy's 2026 newsroom also records multiple actions involving data brokers, including actions under data-broker registration requirements and, later in the year, actions involving both the CCPA and Delete Act. A business that qualifies as a data broker should assess those obligations separately instead of assuming that a general CCPA privacy notice is sufficient.

    The agency's current announcements are the best source for the latest action-specific facts. This article does not combine CPPA orders, Attorney General settlements, and data-broker matters into a single headline fine total because they can arise under different authorities and involve different respondents and remedies.

    Penalty amounts and cure periods

    California adjusts certain CCPA monetary thresholds for inflation. The CPPA's published monetary-threshold table lists civil penalties of no more than $2,663 for each violation and $7,988 for each intentional violation or violation involving the personal information of consumers the business knows are under 16. Those are statutory maximums, not an automatic invoice calculated by multiplying every affected consumer by the higher figure.

    Businesses should also not plan around a guaranteed 30-day cure period. The CCPA statute effective January 1, 2026 allows the agency discretion in handling complaints and in deciding whether to provide time to cure an alleged violation. A company should remediate a discovered problem promptly and document the work rather than waiting for a cure notice.

    Practical compliance priorities

    1. Test opt-out flows end to end. Confirm that consumers can opt out of sale or sharing without unnecessary identity verification, account creation, or extra steps.
    2. Honor recognized preference signals. Test Global Privacy Control and document how the website, consent banner, analytics stack, and advertising vendors respond.
    3. Inventory tracking technologies. Identify tags, SDKs, pixels, cookies, and server-side data transfers, then compare the inventory with notices and opt-out behavior.
    4. Review age-related controls. If the service may process data belonging to consumers under 16, verify the applicable opt-in workflow and the evidence supporting it.
    5. Make notices match reality. Describe the categories of personal information collected, purposes, retention approach, disclosures, and consumer rights in language consistent with the implementation.
    6. Operationalize access requests. Build a process that can locate, review, and deliver a complete response within the applicable timeframe, including data held in connected systems.
    7. Keep an evidence file. Retain test results, request logs, vendor assessments, risk assessments where required, remediation decisions, and ownership records.
    8. Check data-broker status separately. Registration, DROP, deletion, and audit obligations may apply in addition to general CCPA duties.

    The CCPA policy generator can support this work, but generated text cannot make an inaccurate data inventory or broken opt-out flow compliant. The policy, website behavior, vendor configuration, and request-handling process must agree. For unresolved scope questions or higher-risk processing, consult qualified counsel.

    Primary sources

    PET

    PolicyForge Editorial Team

    PolicyForge publishes practical policy guidance based on primary regulatory and product sources. Editorial content is reviewed for source accuracy and is not legal advice.

    Policy Workflows
    Primary-source Research
    AI Governance
    Product Documentation

    Related Posts

    Compliance

    Indiana, Kentucky & Rhode Island Privacy Laws 2026: Complete Compliance Deep-Dive

    Three new state privacy laws took effect January 1, 2026. This deep-dive covers Indiana's INPA, Kentucky's KCDPA, and Rhode Island's RIDPA — including unique requirements, thresholds, and compliance strategies.

    4/21/202610 min read
    Compliance

    20 US States Now Have Privacy Laws in 2026: Complete Business Compliance Guide

    With 20 US states now enforcing comprehensive privacy laws in 2026, businesses face a complex patchwork of compliance requirements. This guide breaks down every state law, key deadlines, and actionable steps to achieve multi-state compliance.

    3/17/202612 min read
    Compliance

    Complete GDPR Compliance Guide 2025: Everything Your Business Needs to Know

    Comprehensive GDPR compliance guide covering requirements, penalties, and practical steps. Includes checklist, real case studies, and automation tips.

    12/17/20255 min read

    Ready to generate your legal policies?

    Create compliant privacy policies, terms of service, and more with AI assistance.