In late July we spent an hour with Tom Kemp, Executive Director of CalPrivacy. The agency, formerly the California Privacy Protection Agency, is the only regulator in the country dedicated solely to enforcing privacy law.
Kemp came to the role from the other side of the table. He was the founder and CEO of the identity security company Centrify. He then ran the marketing campaign for Prop 24, the ballot measure that created the agency he now leads, co-drafted the California Delete Act and the AI Transparency Act, and wrote Containing Big Tech.
One idea ran through the full hour. CalPrivacy is fairly open about what it cares about, publishing advisories, announcing sweeps, and writing its settlement agreements in enough detail that they read as guidance. The expectation running the other direction is that a business can demonstrate its systems actually behave the way they were designed to, and that is where most of the exposure tends to sit.
Here are four areas where the agency's expectations came through most clearly, and what each one suggests you should be looking at.
Key takeaways
The short version
A vendor tool does not transfer responsibility for meeting the statute. Configuration validation is where the risk lives.
CalPrivacy telegraphs its priorities through advisories, sweeps, and settlements. The opt-out preference signal is at the top of the list right now.
Opt-out obligations are delivery agnostic. A choice made on the web has to hold on mobile and connected TV.
Settlement agreements and published audit reports are written to be read as guidance, so read them as a rubric.
Global Privacy Control moves into the browser itself in January 2027, and signal volume will rise sharply with it.
Takeaway 01
A vendor tool does not make you compliant out of the box
Purchasing privacy software does not transfer responsibility for meeting the statute. A product may make compliance considerably easier, and most organizations of any size will need one, though the agency does not treat a vendor relationship as evidence that requirements have been met.
Kemp was specific about where the assumption should sit:
"The assumption should be that having a vendor tool doesn't necessarily make you compliant out of the box, but these third-party tools actually may require significant configuration validation to meet California requirements."Tom Kemp, Executive Director, CalPrivacy
The risk tends to live in configuration. Consent platforms, preference centers, and data subject request portals all sit between the consumer and the business, and each one can be installed correctly, tagged incorrectly, and still return a green status in an admin console.
His recommendation applies whether or not a vendor is involved, which is that businesses should walk a mile in the shoes of the consumer and confirm the system behaves the way they believe it does.
Pick the three consumer-facing flows you rely on a vendor to handle, and complete each one end to end as an outside consumer would, not as an authenticated admin. Confirm the request registers, the confirmation reaches the consumer, and the downstream signal actually fires to the systems that need it.
Takeaway 02
CalPrivacy telegraphs its enforcement priorities, and the opt-out preference signal is at the top of the list
CalPrivacy communicates its areas of interest deliberately, through three mechanisms.
The first is enforcement advisories. Three have been issued, covering data minimization, dark patterns, and registration obligations for businesses operating multiple entities. Each has already shown up in enforcement. The General Motors settlement, reached alongside the Attorney General and four district attorneys, was a data minimization case, and other resolved matters involved dark patterns and interfaces that made it harder for consumers to exercise their rights.
The second is enforcement sweeps. The agency announced a data broker strike force, and it is running a joint sweep on Global Privacy Control with the Attorneys General of California, Colorado, and Connecticut. A tri-state coordinated sweep is an unusually loud signal about how much weight opt-out preference signals carry.
The third is the settlement agreements themselves, which spell out in detail where businesses added friction.
Opt-out preference signal support is easy for a regulator to test from the outside. A browser sends the signal, an observer watches what the site does with it, and no access to internal systems is required. This is one of the few obligations where a third party can reach a conclusion about your compliance posture before you know they were looking.
Send a Global Privacy Control signal to your own properties and confirm it is received, honored, and reflected in downstream tag behavior rather than only acknowledged in a banner. Then read the three enforcement advisories against your own collection practices and consent interfaces, since they describe the specific patterns the agency has already acted on.
Takeaway 03
Opt-out obligations do not change based on the device
Cross-device opt-out is a genuinely difficult engineering problem, and whether a choice made on the web carries to a mobile app or a connected TV property involves real identity resolution work. The regulatory answer sets that complexity aside and goes to the underlying obligation, which Kemp illustrated with an analogy:
"If I tell my kid to take out the trash, and I communicate via text, a phone call, or a note on the refrigerator, I'm still expressing what I want to have happen."Tom Kemp, Executive Director, CalPrivacy
The instruction stays the same no matter how it reaches you, and a business does not get to honor the version that arrives one way while ignoring the version that arrives another.
The obligations are technology and delivery agnostic. The rights and the corresponding business obligations hold regardless of platform, and the Attorney General's Disney settlement did useful work setting expectations here. In practice this is a problem most organizations have solved on the web and left open on mobile, because web and app properties are frequently owned by different teams running different tooling against different tag inventories.
Opt out on your web property, then look at whether that choice is reflected in your mobile app and any connected TV surface you operate. Where it is not, document the reason and the remediation path rather than leaving the gap undescribed.
Takeaway 04
Settlement agreements and audit reports are written to be read as guidance
California has a chief privacy auditor and a dedicated audits division, which is unusual in the United States. The division looks at compliance broadly instead of hunting for specific violations, though violations may surface along the way, and unlike an investigation that quietly closes when nothing turns up, an audit ends in a report that gets published.
The first sectoral audit sweep targets gig economy companies, chosen partly because California is unique among state privacy laws in extending rights to employees, contractors, and consultants. It is a starting point rather than a one-off, and other sectors will follow.
For everyone outside that sector, the published output is the useful part. The agency publishes because it wants other businesses to read the findings and adjust, which is the same reasoning behind writing settlement agreements in detail. Together they are the closest thing available to a public rubric for how a regulator evaluates a privacy program.
Read the published settlement agreements as a rubric rather than as news. Take the specific friction patterns they describe, put your own consent interfaces and opt-out paths next to them, and note where the description fits.
What comes next
The SECURE Data Act and the case for a floor
CalPrivacy's position on federal preemption is that any national framework must set a floor rather than a ceiling, leaving states free to go above it. The SECURE Data Act, the proposal currently in play, does the opposite.
There is a practical reason for businesses to follow this. The proposal would have converted federal support for the opt-out preference signal into a three-year study, and it makes no mention of a deletion mechanism comparable to the one California already operates and several other states are building. A ceiling set below current state practice would unsettle obligations that are already live instead of simplifying them.
Global Privacy Control moves into the browser
Asked for a headline a year out that will surprise people but should not, Kemp pointed to Global Privacy Control. AB 566, the California Opt Me Out Act, requires browser vendors to build the opt-out preference signal directly into the browser beginning in January 2027.
Support is already required in 12 states covering roughly 100 million residents, which is enough of a footprint that treating it as a national requirement is the simpler operating assumption.
The volume of opt-out signals arriving at your properties should rise sharply next year. The share of them that get honored correctly is the number that will matter.
Frequently asked questions
Does buying a consent management platform make my business compliant with California law?
No. A vendor tool can make compliance considerably easier, and most organizations of any size will need one, though responsibility for meeting the statute stays with the business. CalPrivacy's position is that third-party tools may require significant configuration validation to meet California requirements.
How can a regulator tell whether we honor Global Privacy Control?
By sending the signal and watching what your site does with it. Opt-out preference signal support is testable from the outside with no access to internal systems, which is part of why it draws attention and why CalPrivacy is sweeping on it alongside the Attorneys General of Colorado and Connecticut.
Does a web opt-out have to carry over to our mobile app and CTV properties?
The obligations are technology and delivery agnostic. The consumer is expressing the same instruction regardless of how it reaches you, and the rights hold across platforms. Cross-device identity resolution is genuinely hard, which is a reason to document your gap and remediation path, not a reason the obligation changes.
What is AB 566 and when does it take effect?
AB 566, the California Opt Me Out Act, requires browser vendors to build the opt-out preference signal directly into the browser beginning in January 2027. Expect signal volume at your properties to rise sharply from that point.
Why should we read settlement agreements if we were not party to them?
CalPrivacy writes them in detail on purpose, so other businesses can read the findings and adjust. Together with published audit reports, they are the closest thing available to a public rubric for how the agency evaluates a privacy program.