CCPA/CPRA Compliance and Managed Security: What California Businesses Must Do Differently
California's privacy law has quietly become a security law. When the CCPA arrived in 2018 it read like a data-rights statute — the right to know, to delete, to opt out. The CPRA amendments (Prop 24, effective January 1, 2023) created the California Privacy Protection Agency, the nation's first dedicated state privacy regulator, and handed it rulemaking and enforcement power alongside the Attorney General. On July 24, 2025, the CPPA Board adopted final regulations on cybersecurity audits, risk assessments, and automated decision-making technology — filed with the Secretary of State on September 22, 2025 and effective January 1, 2026. 2026 is shaping up to be the most consequential enforcement year California privacy law has seen, and much of what regulators now expect is, functionally, a managed security program.
Start with who is actually covered, because the threshold most businesses remember is already out of date. A for-profit business doing business in California is a covered entity under CPRA if it meets any one of three tests: annual gross global revenue exceeding $26,625,000 for the 2026 compliance year (this figure is inflation-adjusted annually from the original $25 million — a change many older articles and even some competitors still get wrong); buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually; or deriving 50% or more of annual revenue from selling or sharing personal information. That 100,000-record threshold is easier to cross than it sounds — website visitors, loyalty program members, tenant and resident records, and even camera footage of the public can all count. Property managers, multi-location retailers, and healthcare groups frequently cross it without realizing they've become a 'covered business.'
The most consequential change for 2026 is procedural, not aspirational: California now has a hard deadline for telling people they've been breached. SB 446 amended Civil Code Section 1798.82, and effective January 1, 2026, businesses must notify affected California residents within 30 calendar days of discovering a breach — replacing the old, vague 'most expedient time possible and without unreasonable delay' standard. Limited extensions still exist for legitimate law enforcement needs or to determine the scope of a breach and restore system integrity, but the open-ended language is gone. For breaches affecting 500 or more California residents, the Attorney General must also be notified within 15 calendar days of when consumer notices go out. A 30-day clock means a business needs to detect, scope, and confirm a breach fast enough to still have weeks left to draft compliant notices — not months.
The CPPA's new cybersecurity audit regulations are the clearest sign yet that 'reasonable security' now has a specific shape. The requirement phases in by revenue: businesses over $100 million in 2026 revenue file their first audit report by April 1, 2028 (covering January 2027 through January 2028); businesses between $50–100 million in 2027 revenue follow by April 1, 2029; and businesses under $50 million that still meet CPRA thresholds and engage in 'high-risk' processing face an April 1, 2030 deadline. Audits must be performed by a qualified, independent professional following AICPA or ISO-recognized standards — not a self-assessment. Critically, the CPPA has named 18 specific audit components, including multifactor authentication, encryption of personal information, access controls, network monitoring, incident response planning, employee security training, and data disposal practices. That list reads like a managed security services statement of work.
Even businesses years away from an actual audit obligation should treat that 18-point list as the working definition of 'reasonable security' that regulators and plaintiffs' attorneys will point to going forward. Civil Code Section 1798.81.5 has long required businesses to 'implement and maintain reasonable security procedures and practices appropriate to the nature of the information' they hold — without ever defining the term numerically. The CPPA's audit framework now fills that gap in practice. A business that can't demonstrate MFA, encryption at rest and in transit, documented access controls, active network monitoring, a tested incident response plan, and ongoing staff training is going to have a hard time arguing its security was 'reasonable' if something goes wrong — regardless of whether it was technically subject to a mandatory audit.

Enforcement in 2025 and 2026 has been aggressive, fast, and not limited to hacking incidents. Healthline paid $1.55 million in July 2025 for failing to include CCPA-compliant language in service provider contracts. Tractor Supply Co. paid a then-record $1.35 million CPPA fine in September 2025 — triggered by a single consumer complaint — for inadequate opt-out mechanisms and failure to honor Global Privacy Control signals, plus weak vendor contracts; the company must now certify compliance annually for four years. Ford Motor Company paid $375,703 in March 2026 for forcing consumers through an email-verification step before processing opt-outs, silently discarding unverified requests. Disney's $2.75 million settlement in February 2026 — the largest CCPA settlement to date — cited 'significant functional gaps' in opt-out tools across its streaming platforms. Notice the pattern: none of these were breach cases. They were operational and contractual failures. CPPA staff have said hundreds of investigations are already underway.
Statutory penalties make even modest violations expensive at scale. Civil Code Section 1798.155 sets base fines at $2,500 per violation (unintentional) and $7,500 per violation that is intentional or involves a minor under 16, regardless of intent — figures that are inflation-adjusted annually. Violations are generally counted per consumer, per incident, so exposure compounds quickly: a violation touching 10,000 California residents at the base rate alone theoretically reaches $25 million. Separately, Civil Code Section 1798.150 gives consumers a private right of action specifically for data breaches involving unencrypted personal information tied to a failure of reasonable security, with statutory damages of $100–$750 per consumer per incident — recoverable without proving actual harm. Recent federal court decisions in the Northern District of California have allowed such claims to proceed even without a classic hacking event, including a 2025 case involving website tracking pixels sharing user data with third parties without consent. Privacy exposure now extends to marketing tags, not just firewalls.
Vendor and service provider contracts are no longer boilerplate — CPRA specifies what they must contain. Any business sharing personal information with a service provider or contractor must have a written agreement obligating the vendor to provide the same level of privacy protection the business itself owes; granting the business the right to monitor compliance, including audits at least once every 12 months; requiring the vendor to notify the business if it can no longer meet its obligations; and prohibiting the vendor from selling, retaining, or combining the data outside the agreed purpose. This flows down to sub-processors as well. Verizon's 2025 Data Breach Investigations Report found third-party and vendor involvement in breaches doubled year over year, from 15% to 30% — which is exactly why the CPRA puts contractual teeth into the vendor relationship. Any California business using an IT or security vendor should have a current, CPRA-compliant data processing agreement on file, not a legacy template.
This matters directly for multifamily and affordable housing operators, a client segment with unusually concentrated exposure. Property management increasingly runs on cloud platforms, digital rent payment portals, keyless access systems, and networked building controls — a wide attack surface typically managed without dedicated in-house security staff. Resident PII, financial data, and rental history are high-value targets, and a breach can trigger obligations under CCPA/CPRA alongside other frameworks tied to subsidized or affordable housing compliance reporting. It also connects directly to the physical security systems installed on these properties: CCTV footage and access-control badge logs are personal information under CCPA, and biometric data — facial images, fingerprints, hand geometry, voiceprints — is classified as 'sensitive personal information' under CPRA once processed to uniquely identify someone, triggering heightened consumer rights even for general camera systems that were never intended to do facial recognition.
The device layer matters too. California's SB-327, in effect since January 1, 2020 (Civil Code Sections 1798.91.04–1798.91.06), requires manufacturers of internet-connected devices sold in California — cameras, access panels, WiFi access points — to ship either a unique preprogrammed password per device or force the user to set new credentials before first use. It's aimed at manufacturers, not installers, but the practical effect lands on whoever specs the hardware: installing legacy or non-compliant IoT devices with shared default passwords undermines the client's overall 'reasonable security' posture under Section 1798.81.5, no matter how good everything else looks. Also worth flagging for 2026: employee and job-applicant data lost its CCPA exemption back on January 1, 2023, and the Attorney General has since specifically targeted employment data in enforcement sweeps — HR records are no longer a lower-priority category.
The financial stakes behind all of this keep climbing. IBM's 2025 Cost of a Data Breach Report put the U.S. average breach cost at a record $10.22 million, up 9% year over year and driven partly by regulatory penalties and slower detection. Verizon's 2025 DBIR found ransomware present in 44% of all breaches overall — but in 88% of breaches at small and midsize businesses specifically, compared to 39% at larger organizations. System intrusions involving multiple attack stages rose from 36% to 53% of breaches year over year, now the leading pattern. California SMBs are not exempt from these national trends, and the CPPA's new audit framework, the 30-day breach clock, and the string of eight-figure enforcement actions all point the same direction: 'reasonable security' is being defined in increasingly specific, checkable terms, and businesses that can't produce evidence of MFA, encryption, monitoring, and incident response will carry that risk personally.
Mytek Pros helps California businesses close this gap before it becomes a regulatory or litigation problem. As a licensed low-voltage contractor (License #1116987) with DIR public-works registration (PW-LR-1001158430) and BICSI-certified, DBE/DVBE/MBE-certified managed service provider based in Carlsbad, we build the exact control set the CPPA's audit framework names: managed security with MFA enforcement, encryption, access control, and network monitoring; managed IT and vCIO consulting to keep vendor contracts and data-handling practices audit-ready; backup and disaster recovery and incident response planning built for a 30-day notification clock; and the structured cabling, CCTV, and access-control installations that determine whether the physical systems on a property are collecting biometric or sensitive personal information responsibly from day one. Managed IT and security services typically run $125–$250 per user per month, a predictable cost against penalties that scale into the millions. If your business, multifamily property, or affordable housing development hasn't reviewed its CCPA/CPRA exposure against the CPPA's 2026 requirements, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com.
Questions about it services? Get in touch or explore our IT Services.
