The CPPA Letter Arrives About One Sentence on Your Site
Most CCPA writing is about the obligations. This is about the envelope: what a California privacy inquiry into an AI feature looks like when it lands, what it asks for, and why the thing that decides the outcome is usually a mechanism a stranger could have tested from a browser.
How these start
Not with a raid and not with a theory about your model. The three routes in are ordinary. A consumer files a complaint through the CPPA's own web form, usually because a deletion or opt-out request went unanswered. The agency or the Attorney General runs a sweep — a themed batch of letters to businesses in one sector, sent after somebody spent an afternoon in a browser checking the same three things on forty sites. Or a registration duty is missed, which is how data-broker enforcement under the Delete Act works and why it accrues per day.
The consequence of that origin story is that the first letter is about what is visible. Nobody has your architecture diagram. They have your privacy policy, your footer, your cookie banner, your "Do Not Sell or Share My Personal Information" link and whether clicking it does anything. An inquiry that begins with an AI feature almost always begins with the sentence in your notice that fails to mention it.
What the first request asks for
Your notice at collection, as it appeared on specified dates
Not the current one. A dated version, which means the reviewer already has the archived copy and is asking whether your account of it matches. Version-control your policy for the same reason you version-control code.
A description of the opt-out mechanism and its behaviour
Where the link is, what it does, how many steps it takes, whether it requires an account or extra identity verification, and whether the Global Privacy Control browser signal is honoured as an opt-out. Every one of those is testable without your help.
The third parties that receive personal information
For an AI feature this is the question with teeth: whether sending prompt content or customer records to a model provider is a service-provider arrangement under contract, or a sale or share that carries an opt-out.
Your written contract terms with those recipients
The CCPA requires specific terms for service providers, contractors and third parties. A vendor agreement that omits the required limitations does not merely breach a formality — it reclassifies the transfer.
Consumer-request metrics, where the threshold applies
A business that handles the personal information of 10 million or more California consumers in a calendar year must compile and publish request counts and median response times. Publishing a number you cannot reconcile is worse than the threshold itself.
Categories of sensitive personal information and inferences
Inferences are personal information, and some inferred categories are sensitive. An AI system that guesses health status, precise location or ethnicity from ordinary signals has created a category you probably do not list in your notice.
The published orders turned on mechanics
It is worth reading the resolved California matters as a set, because they rhyme. None of them punished a business for having an opinion about privacy. Each turned on whether a specific control worked:
Sephora (AG, 2022)
GPC NOT HONOURED$1.2 million. The business disclosed personal information to analytics and advertising partners, did not treat that as a sale, and did not process the Global Privacy Control signal.
The signal is a machine-readable request. Ignoring it is the easiest violation in the statute to prove and the easiest to test from the outside.
DoorDash (AG, 2024)
A CO-OP IS A SALE$375,000. Customer data went into a marketing co-operative in exchange for the ability to reach other members' customers. No money changed hands; the exchange of value was enough to make it a sale.
The AI analogue is direct: a model provider that may use your submissions to improve its own service is receiving something of value.
Honda and Todd Snyder (CPPA, 2025)
FRICTION AND OVER-VERIFICATIONAdministrative orders addressing opt-out flows that demanded more identification than the request required, asymmetric designs where opting out took more steps than opting in, and a consent tool that did not actually transmit the choice.
The through-line is that a control which exists but is harder to use than its opposite is treated as a defect in the control, not a design preference.
The first week, in order
The instinct on receipt is to fix the page. Do the other things first.
- Preserve. Suspend routine deletion of the request logs, consent records, vendor agreements and policy versions inside the stated period. This is the step that is irreversible if skipped.
- Snapshot your own surfaces. Capture the live pages as they are today, before anyone edits them, so your account of the timeline matches the archived copies the reviewer already has.
- Diary the date. These letters carry a response deadline and an extension is usually available on request. Missing it silently converts a document question into a cooperation question.
- Test the mechanism yourself. Open the opt-out in a clean browser with the Global Privacy Control enabled and count the steps. Whatever you find is what the reviewer found.
- Then remediate, and date it. Voluntary remediation is discretionary mitigation, and the discretion is exercised on a record. An undated fix earns nothing.
Can a reviewer reach your opt-out link at all?
A "Do Not Sell or Share" control that is a low-contrast footer link, a button with no accessible name, or a modal that traps keyboard focus is a control a consumer cannot reliably operate — and the published orders treat an unusable control as a missing one. Scan the page free and see what it exposes.
Scan Your Privacy Page for Free →Why the AI runway is not a reprieve
The CPPA's automated decision-making, risk-assessment and cybersecurity-audit regulations phase in with dates that sit in 2027 and 2028, and it is tempting to read that as a window in which AI features are unregulated in California. They are not. Every order described above was brought under duties that already applied to any business handling personal information, and an AI feature is a new processing purpose inside those duties rather than a separate regime. The practical reading of the phase-in is narrower and more useful: the artefacts those rules will eventually require — a written risk assessment, a pre-use notice, a documented logic description — are the same artefacts that make an inquiry short today.
This is general background on California privacy enforcement practice, not legal advice. A live inquiry should be answered through counsel.
Frequently Asked Questions
Is there still a 30-day right to cure under the CCPA?
No. The original 2018 statute gave businesses 30 days to cure before the Attorney General could act, and the California Privacy Rights Act removed that automatic right as of January 1, 2023. What survives is discretionary: the CPPA and the AG may consider a business's good-faith efforts and any voluntary remediation when deciding what to seek. A fix made after the letter arrives is a mitigating fact, not a defence.
Who can open an inquiry — the CPPA or the Attorney General?
Both, independently. The California Privacy Protection Agency has an Enforcement Division that brings administrative actions and issues orders with administrative fines. The Attorney General brings civil actions, and in practice also pleads the Unfair Competition Law alongside the CCPA, which carries its own penalties and a four-year limitations period. The two coordinate but neither is a prerequisite for the other.
What does the first request usually ask for?
It is narrower and more mechanical than most teams expect. Typically: the notice at collection as it appeared on specified dates, the privacy policy and its version history, a description of how your opt-out mechanism works and whether it honours the Global Privacy Control browser signal, the contracts with third parties that receive personal information, and — for businesses that process the personal information of 10 million or more California consumers in a year — the consumer-request metrics the regulations require you to publish.
What makes an AI feature the subject rather than the site as a whole?
Three characteristics draw attention, and all three are visible from outside. Personal information flowing to a third-party model provider in a way that meets the definition of a sale or a share, so an opt-out obligation attaches. Inferences drawn about a consumer that fall inside the sensitive personal information categories. And a notice at collection that does not name the AI use at all, which is the single most common gap in a product launched faster than its privacy documentation.
Do the new automated decision-making rules apply yet?
The CPPA finalised regulations covering automated decision-making technology, risk assessments and cybersecurity audits in 2025, and their substantive compliance dates phase in from 2027 with the first risk-assessment attestation due to the agency in April 2028. Do not read the runway as a pause. The duties that reach an AI feature today are the ordinary ones — notice at collection, purpose limitation, the sale-and-share opt-out, sensitive-information limits, service-provider contract terms — and every published enforcement order to date has turned on those.
What should we do in the first week?
Preserve before you tidy. Stop any routine deletion that touches the relevant logs, contracts or policy versions, and capture your own copy of how the pages looked — regulators and plaintiffs both read the Internet Archive, and a policy you quietly rewrote after the letter is a fact about you rather than a fix. Then answer what was asked, on the date asked, through counsel, without volunteering an inventory you have not verified.