TL;DR:
- The California Privacy Protection Agency is the first independent U.S. agency dedicated solely to consumer privacy enforcement. Its responsibilities include regulating privacy rights, operating the DROP platform, managing the Data Broker Registry, and conducting audits and investigations.
The California Privacy Protection Agency is the first independent state agency in the United States devoted entirely to consumer privacy enforcement. Established in 2020 by Proposition 24, the CPPA implements and enforces the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Its core responsibilities span rulemaking, public education, administrative enforcement, and direct consumer services. Here is what you need to know about how it works and what it means for you.
At a glance:
- Governed by a board
- Enforces the CCPA and CPRA across California
- Operates the Delete Request and Opt-out Platform (DROP), launched in early 2026
- Manages the Data Broker Registry since 2024
- Conducts audits, investigations, and administrative enforcement actions
- Provides public education and guidance on privacy rights
How the CPPA was created and how it’s governed
California voters approved Proposition 24 in November 2020, passing the California Privacy Rights Act. The CPRA did two things at once: it added new privacy protections on top of the existing CCPA, and it created the CPPA as a standalone agency separate from the California Attorney General’s office. Before that, the Attorney General handled CCPA enforcement. The CPRA amendments took effect in early 2023.
The agency is governed by a five-member board. One of its most notable members is Alastair Mactaggart, founder of Californians for Consumer Privacy, who authored both the CCPA and the CPRA ballot initiative. The board sets agency policy, oversees rulemaking priorities, and directs enforcement strategy. Day-to-day operations fall to an executive staff that reports to the board.
Key milestones in the agency’s development:
- 2020: Proposition 24 passes; CPPA established
- Early 2023: CPRA amendments to the CCPA take effect; CPPA begins enforcement
- 2024: CPPA assumes administration of the Data Broker Registry from the Attorney General
- Early 2026: DROP platform launches; new regulations on automated decision-making, privacy risk assessments, and cybersecurity audits take effect
What consumer privacy rights does the CPPA enforce?
The CCPA gives California residents six major privacy rights, and the CPPA is the agency responsible for making sure businesses honor them. These rights apply to any California resident, including those temporarily outside the state.
The core consumer rights include:
- Right to know: You can ask a business what personal information it has collected about you, where it came from, and how it’s used.
- Right to delete: You can request that a business delete your personal information, with some exceptions.
- Right to correct: You can ask a business to fix inaccurate personal information it holds about you.
- Right to opt out: You can tell a business not to sell or share your personal information.
- Right to limit use of sensitive information: You can restrict how a business uses certain sensitive categories of data.
- Right to non-discrimination: A business cannot penalize you for exercising any of these rights.
The CCPA applies to for-profit businesses that collect California consumers’ personal information, do business in California, and meet specific size or revenue thresholds. Data brokers, which are businesses that collect and sell personal information without a direct relationship with the consumer, face additional obligations. They must register with the Data Broker Registry and provide information to help consumers exercise their rights. The CPPA took over registry administration in 2024, giving the agency direct oversight of this transparency mechanism.
Pro Tip: If you’re a marketer or analytics professional, understanding CCPA cookie consent requirements is the fastest way to get your site into compliance before an audit.
Services the CPPA offers, including DROP
The most significant consumer tool the CPPA has launched is the Delete Request and Opt-out Platform, known as DROP. Before DROP existed, a consumer who wanted to remove their data from data brokers had to contact each broker individually, a process that could involve dozens of separate requests. DROP centralizes that process into a single submission through the agency.

DROP launched on January 1, 2026, fulfilling a mandate from Senate Bill 362, signed into law in October 2023. That law required the CPPA to build a deletion mechanism allowing consumers to request removal of all non-exempt personal information from every registered data broker through one request to the agency.
| Privacy action | Before DROP | After DROP |
|---|---|---|
| Data deletion from brokers | Contact each broker separately | One request through the CPPA portal |
| Opt-out from data sales | Manage per-broker opt-out forms | Centralized opt-out via DROP |
| Tracking compliance | No central verification | Agency monitors broker responses |
| Consumer effort required | High, time-consuming | Significantly reduced |

Beyond DROP, the CPPA maintains the Data Broker Registry, publishes public guidance on privacy rights, and offers educational resources for both consumers and businesses. For businesses working to align their consent management practices with California law, the agency’s published guidance is a primary reference point.
How to submit a privacy complaint to the CPPA
If you believe a business has violated your privacy rights under the CCPA, you can file a complaint directly with the CPPA using its online complaint form. The agency’s contact details are publicly listed: email info@cppa.ca.gov or call 916-572-2900.
One thing to understand before filing: the CPPA does not represent individual consumers and cannot act as your attorney. It enforces the law on behalf of all Californians, using complaints to monitor industry-wide compliance and identify patterns that may trigger broader enforcement actions.
What happens after you submit:
- Review: The agency reviews the complaint for CCPA relevance.
- Investigation: If warranted, the CPPA may open an investigation into the business.
- Audit: The agency can audit businesses to verify compliance.
- Enforcement action: If a violation is confirmed, the CPPA can bring an administrative enforcement action.
When filing, include as much supporting detail as possible: the name of the business, the specific right you believe was violated, dates of relevant interactions, and any written communications you have. If your complaint involves something outside consumer privacy, the California Department of Justice handles those separately.
How you can participate in CPPA rulemaking
The CPPA has broad rulemaking authority covering a wide range of privacy-related topics. Its most recent set of finalized regulations, effective in early 2026, addresses automated decision-making technology (ADMT), privacy risk assessments, and cybersecurity audits. Certain compliance deadlines under those rules are phased, beginning in 2027 and 2028.

Public participation shapes these rules. The CPPA runs formal comment periods, stakeholder workshops, and public board meetings where anyone can weigh in on proposed regulations. Draft rules and responses to public comments are published on the agency’s website, making the process transparent and accessible.
Ways to engage:
- Written comments: Submit formal comments during open rulemaking periods.
- Workshops: Attend or watch stakeholder workshops where the agency solicits input on specific issues.
- Board meetings: Public board meetings are open to observers and often include public comment periods.
- Agency website: Monitor the Law & Regulations page for new rulemaking notices and draft text.
For businesses building out their privacy compliance programs, tracking active rulemaking is worth the effort. Regulations on ADMT, for example, will affect how companies use algorithmic tools in decisions that impact consumers.
Why the CPPA is a trustworthy privacy regulator
The CPPA is the first U.S. agency solely dedicated to privacy enforcement, operating independently of the Attorney General with its own administrative enforcement powers. That independence matters. It means the agency’s priorities are not divided between privacy and other law enforcement responsibilities.
The board includes founding advocates with deep expertise in consumer privacy law. Alastair Mactaggart’s involvement alone signals that the agency’s leadership understands the practical and legal complexity of the rules it enforces. The board’s governing policies are documented in a publicly available Board Handbook.
Trust signals worth noting:
- Administrative enforcement: The CPPA can investigate, audit, and penalize businesses without going to court.
- Transparency: Draft regulations, board meeting minutes, and annual reports are publicly published.
- Public accountability: The agency publishes annual reports covering its operations and milestones.
- Proactive audits: Rather than waiting for complaints, the CPPA conducts proactive compliance audits across industries.
- Consumer tools: DROP and the Data Broker Registry give consumers direct, practical ways to exercise their rights.
The CPPA’s creation marks a genuine U.S. milestone: a state agency built from the ground up to focus exclusively on consumer privacy regulation, reflecting the growing demand for specialized oversight in an era of pervasive data collection.
For digital marketing teams and analytics professionals, the CPPA’s enforcement posture means that data privacy compliance is no longer a background concern. Audits are real, penalties are administrative, and the agency’s scope covers the full range of businesses operating in California.
Trackingplan helps marketing and analytics teams stay ahead of exactly this kind of regulatory scrutiny. Its automated auditing and privacy compliance checks flag tracking errors, consent misconfigurations, and data collection issues before they become enforcement problems. ![]()
If your team relies on accurate analytics data, Trackingplan’s privacy compliance tools give you continuous visibility into whether your implementation meets current California standards.
Key Takeaways
The CPPA is California’s independent privacy enforcement agency, and its authority over the CCPA, Data Broker Registry, and DROP platform makes it the most consequential privacy regulator in the United States.
| Point | Details |
|---|---|
| Agency origin | The CPPA was established by Proposition 24 in 2020 and began enforcement january 1, 2023. |
| Consumer rights | The CCPA gives California residents six major privacy rights, enforced by the CPPA. |
| DROP platform | Launched on January 1, 2026, DROP lets consumers delete data from all registered brokers in one request. |
| Data Broker Registry | The CPPA took over registry administration from the Attorney General on january 1, 2024. |
| Enforcement approach | The CPPA uses proactive audits and administrative actions, not individual legal representation. |
FAQ
What is the CPPA in California?
The California Privacy Protection Agency (CPPA) is the state’s independent regulatory agency for consumer privacy, established by Proposition 24 in 2020 to implement and enforce the California Consumer Privacy Act.
What does the CPPA actually do for consumers?
The CPPA enforces privacy rights under the CCPA, operates the DROP platform for data deletion requests, manages the Data Broker Registry, and accepts consumer privacy complaints, though it does not represent individual consumers as an attorney.
Is there a CPPA certification for privacy professionals?
The acronym CPPA also refers to the Certified Pharmacy Policy Analyst credential, a professional certification unrelated to the California agency. It covers pharmacy policy and legislation and is administered by a separate organization. Neither credential is a “Certified Privacy Professional” designation tied to the California Privacy Protection Agency.
How do I file a complaint with the CPPA?
Submit a complaint through the CPPA’s online complaint form at cppa.ca.gov, or contact the agency at info@cppa.ca.gov or 916-572-2900. Include the business name, the right you believe was violated, and any supporting documentation.
When did the CPPA’s newest regulations take effect?
Regulations addressing automated decision-making technology, privacy risk assessments, and cybersecurity audits became effective January 1, 2026, with phased compliance deadlines extending into 2027 and 2028.









