The California Privacy Protection Agency ("CalPrivacy") Board met last Thursday and Friday to hear updates on various initiatives underway at the agency, including a financial overview, an update on the launch of the DROP system, the growth of the audit division, and more. These meetings are a good opportunity to get insight into the mind of the regulators and where enforcement and legislation is headed. Here's my key takeaways:
CalPrivacy's budget is growing

Year over year, the agency continues to grow. I don't see this slowing down and, in fact, expect this to increase in coming years as CalPrivacy uses its enforcement powers to self-fund. Growth here year-over-year is almost entirely funded by data broker registration fees. It's somewhat amazing what CalPrivacy has managed to accomplish with so little budget: They've staffed an agency, launched investigations, built an audit division, engaged in legislative policy support for California, other states, and the federal government, stood up the DROP platform (centralized data broker opt outs), and marketed that platform to Californians.
CalPrivacy is in the process of adding 9 positions to support its activities. Those include staff members in the Audit Division and support staff for the DROP platform.

Yet this remains a paltry budget for a state the size of California with the number of laws and tech companies under its remit. This budget, unless I miss my guess here, also vastly exceeds the budget of any other state agency or division of the attorneys general offices that are tasked with privacy enforcement. I've beat the table on this repeatedly with state legislators: If you don't budget for enforcement, you don't have a law. You have a nice piece of paper that's the legislative equivalent of a Privacy Policy's "We take your privacy and security seriously."
Audit Division launches and talks priorities

CalPrivacy hired its first auditor earlier this year and she's hit the ground running to stand up a staff. According to Chief Privacy Auditor Sabrina Boyson Ross, the goal of the Audit Division is proactive and voluntary compliance that will look at industries and sectors, not individual companies. Their output will be individual reports privately to participating companies where they find gaps and public reports about common issues across industries and sectors. Ross emphasized that they are not intending to replicate the Enforcement Division's investigations and fines and penalties and emphasized the value of voluntary cooperation. Reading between the lines, it sounds like if you cooperate, you'll get a private findings report and not be referred to the Enforcement Division but if you don't, you could find yourself in the crosshairs of an investigation.
Looking ahead, the Audit Division remains in build-up mode. They launched their first sectoral audit in July, focused on the gig economy after stakeholder feedback. They continue to focus on hiring and, as per the screenshot above, looking to build capacity to receive and review the new Automated Decision Making Technologies ("ADMT"), Cybersecurity, and Risk Assessment submissions that are coming due in April 2028 under the 2026 round of CCPA Regulations passed earlier this year.
Looking specifically at the ADMT requirements, the Audit Division is also looking at these key research questions, which tells us a lot about where the agency is potentially going to focus its efforts on both audit and enforcement.

The Audit Division will also be tasked with the tri-annual audit compliance process for data brokers under the Delete Act. There are currently no regulations on what that audit process will look like but Ross emphasized the work on the cybersecurity audits forthcoming in 2028 as a common baseline and a way to decrease duplicative reporting by companies. The audits will likely focus on these 9 elements:

The CalPrivacy Board voted 4-0 (with one absent abstention) to open the public rulemaking process for regulations related to the Delete Act compliance audits.
DROP launches and data broker fees increase
In 2023, California passed the Delete Act, which required CalPrivacy to build a centralized data broker delete request and opt-out platform ("DROP"). All data brokers are required to register with and integrate with the DROP Platform which launched earlier this year. As of August 1, 2026, data brokers are now required to process the DROP requests they have received from California residents.


Since launch, over 345,000 requests have been received. We're still in early days on whether there are significant technical challenges with DROP, so we can expect to see some future reporting on the volume of the requests and their technical integrations.

Staff noted that California residents have indicated strong approval for the DROP platform. Here's one quote from a number they shared in their presentation:

Finally, despite objections from two members of the public (one an attorney representing data brokers and another a small data broker operating out of New York), data broker registration fees were raised from $6,000 to $9,500 by a 4-0 vote (one absentee abstention). One use of the increased revenues will be supporting the ongoing growth and needs of the DROP platform.
Some questions raised by these registration fees: How many states will pass data broker registration fees and will the accumulated fees across jurisdictions stack to become cost prohibitive to small data brokers or will they simply retreat from those states and only operate in states without registration fees? Do we want small data brokers to be a going concern given the privacy and cybersecurity risks inherent in vast pools of data (particularly sensitive data) being accumulated by small firms without the staff or resources to adequately protect them and operate required compliance programs? There's a genuine question here of whether states are potentially regulating small data brokers out of business by increasing costs.
California remains a hotbed of legislative activity
Finally, CalPrivacy's policy counsel presented on a number of federal and state privacy bills. Given the presence of Silicon Valley, it's no surprise that California remains a hotbed of activity for privacy legislation and rulemaking.
Regarding federal laws, CalPrivacy has led a coalition of 18 states opposing the current proposed federal privacy bill, the SECURE Data Act, because it is weaker than the state laws, including CCPA, that it would preempt. This isn't a new position for CalPrivacy and preemption has remained the primary faultline in federal privacy legislation for a decade now.

CalPrivacy's policy team also coordinates with other states and reviews other state's bills to benchmark California law against new developments. A pattern developing across the states is that a new state will take something up in their new comprehensive privacy bill that will be an incremental improvement over those that came before and older states will come back and amend their existing comprehensive privacy bills to include new language, coming into parity or even leapfrogging subsequent bills. In Minnesota, we saw this with Rep. Elkins introducing a bill this year to include provisions of the Washington My Health My Data Act into the Minnesota Consumer Data Privacy Bill previously enacted.

On the state front, the policy team also reviews legislation to determine whether it implicates CalPrivacy and the laws it oversees (CCPA, Delete, etc.) and provides guidance for state legislators on the impact of various privacy laws.
I won't do a deep dive on any of these bills here, but you can see what CalPrivacy is monitoring in the California legislature.



Of the bills above, SB 690 is the one to keep an eye on as it would narrow California's Invasion of Privacy Act ("CIPA") claims. CIPA claims have exploded in the last few years and have become a major source of consternation and work for privacy teams. CIPA claims, which are based on a 1960s wiretapping law, claim pixels, cookies and chatbots violate consent requirements, and have resulted in hundreds of class actions being filed against companies in California by the plaintiff's bar, including certain serial litigators. I expect this to pass, but it would remove one of the few laws out there with a private right of action for individuals to bring claims that (under resourced) agencies and attorneys general cannot. This would only impact California-based claims of course and would not stop the federal claims brought under the Electronic Communications Privacy Act or similar state wiretapping laws.
If you need someone to help you with any of these privacy laws, please reach out to me at Brandi@BennettTechLaw.com for help.