If your game collects data from players in California, California’s privacy laws probably apply to you. Even if your studio has never set foot in the state.
That trips up a lot of developers. You do not have to be a California company to fall under California’s privacy rules. You just have to collect data from California players and hit one of the coverage thresholds. For a free-to-play game with an ad SDK and a decent user base, that is not a high bar.
And the rules changed in a big way at the start of 2026. New regulations took effect, enforcement got serious, and the fines went from hypothetical to seven figures. So if your privacy policy and your data practices have not been looked at since 2023, this is worth your time.
Here is the whole landscape for game companies: the CCPA, the CPRA, and CalOPPA, what is new for 2026, and what you actually have to do.

Does California privacy law apply to your game?
The main law is the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). It applies to a for-profit business that collects California residents’ personal information and meets at least one of three thresholds:
- Revenue. Annual gross revenue over $26,625,000 in the preceding calendar year (the CPPA’s inflation-adjusted figure, effective January 1, 2025 and re-adjusted every two years, so the next change lands January 1, 2027). Note this is total revenue, not just California or game revenue.
- Volume. You buy, sell, or share the personal information of 100,000 or more California consumers or households in a year. Note this counts data you buy, sell, or share, not everyone you collect from.
- Data as the business. You make 50% or more of your revenue from selling or sharing personal information.
The volume threshold is the one that catches studios by surprise. If you have an ad-supported game and you pass data to ad networks, you are likely “sharing” personal information, and 100,000 California users is not a lot for a game with any traction.
CCPA basics: the rights you have to give players
At its core, the CCPA gives California consumers a set of rights, and your job is to honor them. Players can ask you to:
- Know what personal information you collect about them and how you use it.
- Delete the personal information you have collected.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of their personal information.
- Limit the use of sensitive personal information (things like precise geolocation, or account login combined with a password) to what the law permits. This one is not absolute: it applies to uses beyond a set of permitted purposes, not to every use.
You also have to tell players about all of this up front, in your privacy policy, and give them clear ways to exercise these rights.
CCPA vs CPRA: what actually changed
People search “CCPA vs CPRA” like they are two separate compliance projects. They are not. The CCPA is the original 2018 law. The CPRA is a 2020 ballot measure that amended and expanded it, and it has been fully in effect since 2023.
What the CPRA added:
- The right to correct and the right to limit use of sensitive personal information.
- The concept of “sharing” data, which is what pulls cross-context behavioral advertising (the ad SDK situation) into the opt-out rules.
- The California Privacy Protection Agency (CPPA), a dedicated regulator that can write rules and levy fines, working alongside the California Attorney General.
So when you read “CCPA” today, assume it means the CCPA as amended by the CPRA. One framework, not two.

What is new for 2026
This is the part older privacy posts don’t cover, and they can really matter in some cases.
New CPPA regulations took effect January 1, 2026. They were finalized in 2025 and add real operational requirements. Some of the reporting deadlines are years out, but do not read that as “nothing to do until 2028” — one of these obligations is already running:
- Risk assessments are the one to watch. Since January 1, 2026, a business has to conduct a risk assessment before it starts certain activities, including selling or sharing personal information, processing sensitive personal information, and using or training certain automated technologies. If your game shares player data with ad networks, that is you, and the obligation is live now. The separate deadline to submit assessments covering 2026 and 2027 to the CPPA is April 1, 2028. Conducting and filing are two different dates, and only the filing one is far away.
- Annual cybersecurity audits for businesses whose processing presents significant risk. The earliest audit reports are due April 1, 2028, phased in by business size.
- Automated decision-making technology (ADMT) rules, giving consumers rights to access and opt out of certain significant automated decisions, with compliance required by January 1, 2027.
The 2026 rules also made the personal information of consumers under 16 sensitive personal information, which can pull it into the right to limit. For a game with any teenage audience, that is a meaningful change.
The exact date you are on the hook depends on which requirement you are looking at and how your business is sized. The CPPA’s regulations page has the current text and timelines.
Global Privacy Control is mandatory, and you now have to confirm you honored it. California requires businesses to treat a GPC browser signal as a valid opt-out of selling and sharing. New for 2026: you also have to give a consumer a way to confirm their opt-out was actually processed, for example by showing an “Opt-Out Request Honored” status. What used to be optional is now required.
The Delete Act’s DROP platform is live. California’s Deletion Request and Opt-Out Platform went live for consumers on January 1, 2026, letting residents send one deletion request to every registered data broker. If your studio qualifies as a data broker, you have to register and start processing DROP deletion requests by August 1, 2026. Most studios are not data brokers. The test is not how much money you make from data; it turns on whether you knowingly collect and sell personal information about consumers you have no direct relationship with. A studio selling data about its own players is generally not a broker on that basis alone, but if any part of your business handles data on people who never touched your game, get that checked.

The 2026 compliance checklist for game companies
Here is what to actually do.
1. Get your privacy policy right (this is where CalOPPA comes in). Separate from the CCPA, the California Online Privacy Protection Act (CalOPPA) has required since 2004 that any commercial site, app, or online service collecting California residents’ personal information post a conspicuous privacy policy. That policy has to include specific contents, an effective date, and a statement of how you respond to “Do Not Track” signals. Your CCPA disclosures and your CalOPPA privacy policy live in the same document, but the CalOPPA pieces are their own requirement. Do not assume a generic template covers it.
2. Build working opt-out and “Do Not Sell or Share” mechanics, in the game as well as on the site. This is the most common enforcement target by a wide margin. Your “Do Not Sell or Share My Personal Information” link has to actually stop the sale or sharing, and your site has to detect and honor GPC signals. If you ship mobile apps, you need an opt-out inside each app too. Jam City’s $1.4 million settlement was 21 apps without one. A link that looks right but does nothing is exactly what California has been fining.
3. Paper your vendor relationships. Every ad network, analytics provider, cloud host, attribution tool, and support platform that touches player data needs a contract with the specific privacy terms the CCPA requires. Without them, handing data to a vendor can count as a sale or share, with all the opt-out obligations that brings. Missing contract terms were a finding in both the Tractor Supply and Healthline actions, and it is the requirement studios most often have no paperwork for.
4. Handle consumer requests. You need real processes to respond to know, delete, correct, opt-out, and limit requests within the required timelines. Note that you generally may not require identity verification for a sale/share opt-out, which is what caught Ford.
5. Do not forget your own team. The CCPA’s exemptions for employee and business-contact data expired in 2023. If you are a covered business, your California employees, contractors, and job applicants have privacy rights too, and you owe them notice. Tractor Supply was fined in part for missing exactly this. Most studios build for players and never think about the hiring pipeline.
6. Get your security and breach exposure in order. Regulators are not your only risk. The CCPA gives consumers a private right of action for certain data breaches caused by a failure to maintain reasonable security, with statutory damages of $100 to $750 per consumer per incident, or actual damages if higher. For a studio holding account credentials for a large player base, that math is the biggest number on this page.
7. Do your risk assessments and cybersecurity audits. The obligation to conduct a risk assessment before selling or sharing data is already running. If you are a larger studio whose processing presents significant risk, the audit requirements are on your calendar too. Figure out whether you are in scope and when.
8. Sort out ADMT before 2027. If you use automated systems to make significant decisions about players, the ADMT rules are coming. Map where you use automated decision-making now so the 2027 deadline is not a fire drill.
A note on kids’ games
If your game is directed to or used by children, you have an extra layer. Federal COPPA still governs collecting data from kids under 13, and that has not gone away.
The CCPA has its own under-16 rule, and it is the one game companies miss. Selling or sharing the personal information of a player you know is under 16 requires opt-in consent, not just an opt-out. For players 13 to 15, that means their own affirmative consent. For players under 13, it means a parent’s. Default ad-SDK behavior does not satisfy either. This is a separate obligation from COPPA and it applies whether or not your game is “directed to children.”
California also passed the Age-Appropriate Design Code (AADC), which would impose design and data obligations on services likely to be accessed by minors. That law is still in litigation. In NetChoice v. Bonta (9th Cir., No. 25-2366), decided March 12, 2026, the Ninth Circuit affirmed the injunction against the AADC’s data-use and dark-patterns provisions, holding those likely unconstitutionally vague, but vacated the injunction as to the statute as a whole and as to the age-estimation requirement, sending those back to the district court. Practically: less of the AADC is blocked than was blocked a year ago, and the pieces that came back are live questions. Keep in mind these are preliminary rulings about likelihood of success, not final judgments on the law’s validity. If you make games for younger players, this is a “watch closely and get advice” situation rather than a settled checklist.

Why this matters now: the enforcement is real
For years, CCPA enforcement was mostly a warning. Not anymore.
California has two privacy enforcers, and both are active. The California Attorney General brings CCPA cases in court, and the California Privacy Protection Agency (CPPA), also called CalPrivacy, issues administrative fines directly. Recent actions from each:
- Jam City, a mobile game developer, settled with the Attorney General for $1.4 million in November 2025. Two problems: none of its 21 mobile apps offered a compliant in-app opt-out, and some of its games shared or sold the data of players aged 13 to 16 without the affirmative consent the CCPA requires. This is the one to read twice, because it is your industry and your business model.
- Disney settled with the Attorney General for $2.75 million in February 2026, the largest CCPA settlement to date, for applying opt-out requests only to the specific service or device a consumer happened to be using.
- Healthline settled with the Attorney General for $1.55 million in July 2025, over opt-out failures and sharing data with third parties without the privacy terms the CCPA requires in vendor contracts.
- Tractor Supply drew a $1.35 million fine from the CPPA, the agency’s largest to date. Worth noting how broad the findings were: a privacy policy that did not tell consumers their rights, no notice to California job applicants about their rights, no working opt-out mechanism including for GPC signals, and disclosing personal information to other companies without contracts containing the required privacy protections.
- PlayOn Sports settled with the CPPA for $1.1 million in March 2026, over opt-out failures on a youth-sports platform, the agency’s first action involving students’ data.
- Ford settled with the CPPA for about $376,000 in March 2026, for only processing opt-out requests from consumers who first completed an email-verification step. You generally cannot make someone verify their identity to opt out of sale or sharing.
California, Colorado, and Connecticut also announced a coordinated investigative sweep in September 2025 aimed squarely at businesses that ignore opt-out preference signals, sending letters demanding immediate compliance. The pattern is unmistakable: regulators are going after broken opt-out mechanics, ignored GPC signals, and missing vendor contracts, which is precisely the set of things ad-monetized games tend to get wrong.
Where game companies usually slip
Four recurring problems, all fixable:
- The “Do Not Sell or Share” link is decorative. It is on the page, but the underlying data still flows to ad partners. And on mobile, there is often no in-app equivalent at all.
- GPC gets ignored. The site never detects the browser signal, so California players who have opted out of the sale and sharing of their data are having it sold and shared anyway.
- Nobody papered the ad and analytics vendors. The data flows out under a standard commercial agreement with none of the CCPA’s required privacy terms in it.
- The privacy policy is a generic template. It misses the CalOPPA specifics and the CCPA disclosures, or it describes data practices the studio does not actually follow.
Get this handled
California privacy law is not the kind of thing you want to discover you got wrong from a regulator’s letter. If you are running a game that collects player data and you are not sure where you stand, that is worth a conversation.
I work with game studios and publishers on exactly this: figuring out whether you are covered, getting your privacy policy and opt-out mechanics right, papering your vendor relationships, and putting a real compliance posture in place. If that is on your plate, let’s talk.
