If your game collects data from players in California, California’s privacy laws probably apply to you. Even if your studio has never set foot in the state.
That trips up a lot of developers. You do not have to be a California company to fall under California’s privacy rules. You just have to collect data from California players and hit one of the coverage thresholds. For a free-to-play game with an ad SDK and a decent user base, that is not a high bar.
And the rules changed in a big way at the start of 2026. New regulations took effect, enforcement got serious, and the fines went from hypothetical to seven figures. So if your privacy policy and your data practices have not been looked at since 2023, this is worth your time.
Here is the whole landscape for game companies: the CCPA, the CPRA, and CalOPPA, what is new for 2026, and what you actually have to do.

Does California privacy law apply to your game?
The main law is the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). It applies to a for-profit business that collects California residents’ personal information and meets at least one of three thresholds:
- Revenue. Annual gross revenue over $26,625,000 (the CPPA-adjusted figure for 2026; it is re-adjusted for inflation every two years). Note this is total revenue, not just California or game revenue.
- Volume. You buy, sell, or share the personal information of 100,000 or more California residents in a year.
- Data as the business. You make 50% or more of your revenue from selling or sharing personal information.
The volume threshold is the one that catches studios by surprise. If you have an ad-supported game and you pass data to ad networks, you are likely “sharing” personal information, and 100,000 California users is not a lot for a game with any traction.
CCPA basics: the rights you have to give players
At its core, the CCPA gives California consumers a set of rights, and your job is to honor them. Players can ask you to:
- Know what personal information you collect about them and how you use it.
- Delete the personal information you have collected.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of their personal information.
- Limit the use of sensitive personal information (things like precise geolocation or account credentials).
You also have to tell players about all of this up front, in your privacy policy, and give them clear ways to exercise these rights.
CCPA vs CPRA: what actually changed
People search “CCPA vs CPRA” like they are two separate compliance projects. They are not. The CCPA is the original 2018 law. The CPRA is a 2020 ballot measure that amended and expanded it, and it has been fully in effect since 2023.
What the CPRA added:
- The right to correct and the right to limit use of sensitive personal information.
- The concept of “sharing” data, which is what pulls cross-context behavioral advertising (the ad SDK situation) into the opt-out rules.
- The California Privacy Protection Agency (CPPA), a dedicated regulator that can write rules and levy fines, working alongside the California Attorney General.
So when you read “CCPA” today, assume it means the CCPA as amended by the CPRA. One framework, not two.

What is new for 2026
This is the part older privacy posts don’t cover, and they can really matter in some cases.
New CPPA regulations took effect January 1, 2026. They were finalized in 2025 and add real operational requirements for covered businesses. The rules are in force now, but the actual compliance deadlines are staggered and mostly land in 2027 and 2028:
- Risk assessments for processing that poses significant risk to consumers. Assessments covering 2026 and 2027 must be submitted to the CPPA by April 1, 2028.
- Annual cybersecurity audits for businesses whose processing presents significant risk. The earliest audit reports are due April 1, 2028, phased in by business size.
- Automated decision-making technology (ADMT) rules, giving consumers rights to access and opt out of certain significant automated decisions, with compliance required by January 1, 2027.
The exact date you are on the hook depends on which requirement you are looking at and how your business is sized. The CPPA’s regulations page has the current text and timelines.
Global Privacy Control is mandatory, and you now have to confirm you honored it. California requires businesses to treat a GPC browser signal as a valid opt-out of selling and sharing. New for 2026: you also have to give a consumer a way to confirm their opt-out was actually processed, for example by showing an “Opt-Out Request Honored” status. What used to be optional is now required.
The Delete Act’s DROP platform is live. California’s Deletion Request and Opt-Out Platform went live for consumers on January 1, 2026, letting residents send one deletion request to every registered data broker. If your studio qualifies as a data broker, you have to register and start processing DROP deletion requests by August 1, 2026. Most studios are not data brokers, but if a meaningful chunk of your revenue comes from passing player data to third parties, get that checked.

The 2026 compliance checklist for game companies
Here is what to actually do.
1. Get your privacy policy right (this is where CalOPPA comes in). Separate from the CCPA, the California Online Privacy Protection Act (CalOPPA) has required since 2004 that any commercial site, app, or online service collecting California residents’ personal information post a conspicuous privacy policy. That policy has to include specific contents, an effective date, and a statement of how you respond to “Do Not Track” signals. Your CCPA disclosures and your CalOPPA privacy policy live in the same document, but the CalOPPA pieces are their own requirement. Do not assume a generic template covers it.
2. Build working opt-out and “Do Not Sell or Share” mechanics. This is the number one enforcement target. Your “Do Not Sell or Share My Personal Information” link has to actually stop the data flow, and your site has to detect and honor GPC signals. A link that looks right but does nothing is exactly what California has been fining.
3. Handle consumer requests. You need real processes to respond to know, delete, correct, opt-out, and limit requests within the required timelines.
4. Do your risk assessments and cybersecurity audits. If you are a larger studio whose data processing presents significant risk, the 2026 regulations put these on your calendar. Figure out whether you are in scope and when.
5. Sort out ADMT before 2027. If you use automated systems to make significant decisions about players, the ADMT rules are coming. Map where you use automated decision-making now so the 2027 deadline is not a fire drill.
A note on kids’ games
If your game is directed to or used by children, you have an extra layer. Federal COPPA still governs collecting data from kids under 13, and that has not gone away.
California also passed the Age-Appropriate Design Code (AADC), which would impose design and data obligations on services likely to be accessed by minors. That law is tied up in court. In NetChoice v. Bonta, the Ninth Circuit narrowed the injunction on March 12, 2026 but left several of the most significant provisions (the data-use restrictions and the dark-patterns ban) blocked as likely unconstitutional, and sent the age-estimation piece back to the district court. So the AADC is partly on hold and still moving. If you make games for younger players, this is a “watch closely and get advice” situation rather than a settled checklist.

Why this matters now: the enforcement is real
For years, CCPA enforcement was mostly a warning. Not anymore.
California has two privacy enforcers, and both are active. The California Attorney General brings CCPA cases in court, and the California Privacy Protection Agency (CPPA), also called CalPrivacy, issues administrative fines directly. Recent actions from each:
- Disney settled with the Attorney General for $2.75 million in February 2026, the largest CCPA settlement to date, over failures to honor opt-out requests and opt-out preference signals across its streaming services.
- Healthline settled with the Attorney General for $1.55 million in July 2025, over opt-out and Global Privacy Control failures on a health-information site.
- Tractor Supply drew a $1.35 million fine from the CPPA, the agency’s largest to date, after its “Do Not Sell” link did not stop the data flow and the company did not honor GPC signals.
- PlayOn Sports settled with the CPPA for $1.1 million in March 2026, over opt-out failures on a youth-sports platform.
- Ford settled with the CPPA for about $376,000 in March 2026, for only processing opt-out requests from consumers who first completed an email-verification step.
The CPPA has reported more than 100 active investigations running at once, and California, Colorado, and Connecticut announced a coordinated sweep specifically targeting companies that ignore opt-out preference signals. The pattern is unmistakable: regulators are going after broken opt-out mechanics and ignored GPC signals, which is precisely the thing ad-monetized games tend to get wrong.
Where game companies usually slip
Three recurring problems, all fixable:
- The “Do Not Sell or Share” link is decorative. It is on the page, but the underlying data still flows to ad partners. Regulators check this directly now.
- GPC gets ignored. The site never detects the browser signal, so every privacy-conscious California player is being processed against their stated preference.
- The privacy policy is a generic template. It misses the CalOPPA specifics and the CCPA disclosures, or it describes data practices the studio does not actually follow.
Get this handled
California privacy law is not the kind of thing you want to discover you got wrong from a regulator’s letter. If you are running a game that collects player data and you are not sure where you stand, that is worth a conversation.
I work with game studios and publishers on exactly this: figuring out whether you are covered, getting your privacy policy and opt-out mechanics right, and building a compliance posture that holds up. If that is on your plate, let’s talk.
