Skip to main content

California Privacy in 2026: What Service Businesses Must Get Right (CCPA and CPRA)

A plain-English 2026 overview of CCPA and CPRA for California service businesses — who it applies to, consumer rights, and what a compliant website needs.

GILNEX Compliance Team
GILNEX Compliance Team - Compliance & Trust, GILNEX
California Privacy in 2026: What Service Businesses Must Get Right (CCPA and CPRA)

If you run a service business in California — a dental practice, a law firm, an HVAC company, a med spa, or a real estate brokerage — the personal information you collect now sits inside a clear legal framework. California privacy law, anchored by the CCPA and broadened by the CPRA, shapes how you disclose your data practices, honor customer choices, and protect the information you gather online and in person. This article is general educational information, not legal advice, and you should consult a qualified attorney before making compliance decisions for your specific business.

What the CCPA and CPRA Actually Are

The California Consumer Privacy Act, known as the CCPA, took effect in 2020 and gave California residents defined rights over the personal information businesses collect about them. The California Privacy Rights Act, or CPRA, amended and strengthened that law — adding new consumer rights, creating a dedicated enforcement agency, and expanding protections for a category called sensitive personal information. When people refer to California privacy law today, they generally mean the CCPA as amended by the CPRA, operating together as a single framework.

Personal information here is broad. It includes obvious identifiers like names, email addresses, and phone numbers, but also things such as IP addresses, device identifiers, browsing activity, and inferences drawn about a person. For a service business, that means the contact form on your website, your appointment scheduler, your call logs, and your marketing analytics can all fall within scope.

Does California Privacy Law Apply to Your Business?

Not every business is covered, and the thresholds matter. In general terms, California privacy law applies to for-profit businesses that operate in California and meet at least one of a few broad conditions:

  • You have large annual revenue above a defined threshold.
  • You buy, sell, or share the personal information of a high volume of consumers or households.
  • You derive a significant share of your revenue from selling or sharing consumers' personal information.

These are described here in general terms, not as precise legal cutoffs — the exact figures are set by statute and can be adjusted, which is one more reason to confirm your status with counsel. Many small single-location practices fall below every threshold. But a fast-growing multi-location dental group, a busy real estate brokerage running heavy digital advertising, or a med spa with a large email and SMS marketing list can cross a line more easily than the owners expect.

The Core Consumer Rights You Must Honor

Where the law applies, California residents have several rights you are expected to recognize and support:

  1. The right to know what personal information you collect, why, and with whom you share it.
  2. The right to delete the personal information you have collected, subject to certain exceptions.
  3. The right to correct inaccurate personal information.
  4. The right to opt out of the sale or sharing of personal information.
  5. The right to limit the use of sensitive personal information.
  6. The right to non-discrimination, meaning you cannot penalize someone for exercising these rights.

That last point matters for service businesses. You cannot deny service, charge more, or degrade quality simply because a patient or client asked you to delete their data or opted out of tracking.

What a Compliant Website Generally Needs

Your website is where most of these obligations become visible. At a general level, a compliant site tends to include the following:

  • A clear, current privacy policy that explains what you collect, why, how long you keep it, and the rights available to California residents.
  • A visible opt-out mechanism — often a "Do Not Sell or Share My Personal Information" link — when your activities involve selling or sharing personal information, including some common advertising and analytics setups.
  • The ability to honor opt-out preference signals that a visitor's browser sends automatically.
  • A practice of collecting only what you need, rather than gathering data by default.
  • Clear consent and notice on lead and contact forms, so a prospective client knows what happens to the information they submit.

Many owners are surprised that ordinary advertising pixels and analytics tools can qualify as sharing. If your HVAC company or law firm runs retargeting ads, that alone may trigger opt-out obligations.

Treat privacy less as a legal burden and more as a trust signal. Clients who see that you handle their information with care are more likely to believe you will handle their treatment, their case, or their home with the same diligence.

A Practical Compliance Checklist

Use this as a starting point for a conversation with your attorney, not as a finish line:

  • Confirm whether the CCPA and CPRA apply to your business based on current thresholds.
  • Publish and date a plain-language privacy policy.
  • Add an opt-out link if you sell or share personal information.
  • Configure your site to detect and honor browser opt-out signals.
  • Review every form and pixel to see what data actually flows out.
  • Document how you respond to know, delete, and correct requests, and set a response timeline.
  • Train front-desk and intake staff to route privacy requests correctly.

Enforcement in California Is Active

California privacy law is not dormant. A dedicated agency and the state's Attorney General both enforce it, and public actions have signaled that regulators expect genuine effort rather than boilerplate. Good-faith compliance — real disclosures, working opt-out tools, and prompt responses to consumer requests — is your strongest position. Perfection is not the standard, but visible neglect is a risk, especially for businesses handling health-adjacent or financial details, as many med spas, dental practices, and real estate offices do.

To be clear once more: this article is general information, not legal advice, and your specific obligations depend on facts that only a qualified California attorney can assess. If it would help to see where your website stands today, GILNEX offers a free website trust-and-compliance review that looks at your privacy policy placement, opt-out mechanics, form consent, and overall trust signals — a calm, practical starting point before you bring findings to your lawyer. There is no obligation, and it is not a substitute for legal counsel.

Predictable Growth Engine

Websites, SEO, CRM, AI automation, and growth systems designed to generate customers — not just traffic.