Skip to Content

CCPA Compliance Services

CCPA Compliance for Your
Existing Website

On 1 January 2026, new California Consumer Privacy Act regulations took effect that changed what your website has to do — not what it has to say. Several requirements that were previously optional became mandatory, and they are all things a website either does or does not do.

Most websites do not do them. Many added a cookie banner years ago that displays a notice without blocking anything, treats clicking the X as consent, and never tells the visitor their choice was registered. Under the rules now in force, that banner is not doing the job it appears to be doing.

Webstix configures the consent and opt-out layer on websites that already exist. No rebuild, no migration, no change to how your site looks.

Gavel and California flag

Not sure whether your website meets the current requirements?

Our free CCPA audit reviews what tracking scripts your site loads, when they fire, whether your current cookie notice actually controls them, and whether it handles browser opt-out signals.

What Changed on 1 January 2026

The California Privacy Protection Agency’s updated regulations took effect at the start of 2026 with no enforcement grace period. Four of the changes are public-facing and affect your website directly.

Cookies settings interface

You must now show that an opt-out was honoured

Previously a business could choose whether to confirm it had processed an opt-out request. That is now mandatory. When a visitor arrives with a browser-level opt-out preference signal such as Global Privacy Control, your website must indicate that the signal was recognised — the Agency’s own example is displaying “Opt-Out Request Honored”, or reflecting the status in a toggle within the visitor’s privacy settings.

This is the single most common gap we see. Many sites process the signal silently, or do not process it at all.

Privacy consent interface

Closing a cookie banner is not consent

The rules now state directly that a consumer closing or navigating away from a consent pop-up, without affirmatively selecting the equivalent of “I accept”, does not constitute consent. Banners built to treat dismissal as agreement no longer achieve anything.

Cookie settings screen

Choices have to be symmetrical

A more prominent “accept” button than “decline” — bigger, brighter, or higher-contrast — is treated as a dark pattern. Opting out must also take the same number of steps as opting in, or fewer, measured from the “Do Not Sell or Share My Personal Information” link through to completion.

Gold shield and document

Privacy policy disclosures were widened

Privacy policies must now identify the categories of personal information disclosed to service providers and contractors for a business purpose, not only those disclosed to third parties. This is a wording change to a legal document, so it belongs with your attorney rather than with us — but it is worth knowing it happened.

Does CCPA Apply to Your Business?

Worth answering first, because for a good number of smaller businesses the answer is no.

CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds:

Annual gross revenue above $26,625,000. This figure is adjusted for inflation in January of every odd-numbered year — it rose from $25,000,000 on 1 January 2025, and is next due for adjustment on 1 January 2027.

Buying, selling, or sharing the personal information of 100,000 or more California residents or households in a year.

Deriving 50% or more of annual revenue from selling or sharing California residents’ personal information.

When Does the CCPA Apply to Your Business?

Two things regularly surprise people. First, you do not need to be located in California — the law follows the consumer, not the company, so a Wisconsin manufacturer with California customers can fall within scope. Second, “selling or sharing” is broader than most business owners expect and can cover ordinary advertising and analytics arrangements that pass data to a third party.

Note also that the thresholds are alternatives, not a checklist — meeting any one of the three is enough. CCPA generally does not apply to nonprofit organisations or government agencies.

Whether it applies to your business specifically is a legal question and your attorney is the right person to answer it. What we can tell you is what your website is currently doing with visitor data, which is usually the piece missing from that conversation.

Two women at monitors
Digital lock icon

What CCPA Asks of Your Website

CCPA is a broad law governing how a business handles personal information across its whole operation. Only part of it lives on your website. The website-facing pieces are:

The first five are technical. They are built, configured, and tested on the website itself — and they are the part we handle.

What Webstix Does

We install and configure cookie consent and opt-out tooling on your existing website:

Review of the tracking scripts your site currently loads — analytics, advertising pixels, embedded media, chat tools, heatmaps, and anything else collecting visitor data

Selection of a consent management platform appropriate to your site and budget

Installation and configuration of the consent banner and preference centre

Script blocking, so non-essential trackers genuinely do not fire until consent is given

Global Privacy Control and opt-out preference signal handling, checked on page load

Visible opt-out confirmation, so a visitor arriving with a signal is shown that it was honoured — the requirement that came into force on 1 January 2026

Correcting banners that treat dismissal as consent, and unequal accept/decline choices

Region-based rules, so California visitors see what the law requires without changing the experience for everyone else

Styling the banner to match your brand rather than looking like a bolt-on

Testing across devices and browsers to confirm the controls actually work

Handover, so your team can add new scripts without breaking the setup

This is web development work. It is exactly what we do, and it does not require rebuilding your site.

What This Does Not Cover

We would rather tell you this upfront than have you find out later.

Configuring consent tooling addresses the opt-out and tracking-control side of CCPA. It does not, on its own, make a business CCPA compliant. Compliance also involves how your organisation handles personal information internally, what your privacy policy says, how you respond to consumer requests, your vendor contracts, and your employee and job-applicant data — none of which live on your website.

Webstix is a web development company, not a law firm. We implement technical requirements. We do not give legal advice, we do not write privacy policies as legal documents, and we will not tell you a cookie banner makes you compliant. Any vendor who does is selling something they cannot deliver.

What we will do is make the part that lives on your website work properly, and tell you plainly what is still outstanding so you can take it to your attorney.

Business meeting around laptops

Already have a cookie banner?

It is worth checking whether it does anything. A large share of the banners we review display a notice while the tracking scripts load regardless — and very few show a visitor that their browser opt-out signal was honoured, which has been mandatory since January 2026.

How It Works

1

Free website audit

We review your site and report what tracking scripts load, when they fire, whether any existing consent tool controls them, whether Global Privacy Control signals are recognised and confirmed, and what a properly configured setup would involve. No cost and no obligation.

2

Scope and Quote

Based on what we find, we tell you what the work involves and what it costs. Sites with a handful of scripts are straightforward. Sites carrying years of accumulated marketing tags take longer, and we will say so before you commit.

3

Configuration and Testing

We install the consent platform, configure the rules, block the scripts that need blocking, set up signal handling and opt-out confirmation, style the banner to your brand, and test across devices and browsers.

4

Handover

We show your team how the setup works and how to add new scripts without breaking it. If you would rather we maintain it, that can run through a Website Care plan.

Cybersecurity warning icon

Why It Is Worth Addressing Now

The updated regulations arrived without an enforcement grace period. In September 2025 the California Privacy Protection Agency announced a joint investigative sweep with the Colorado and Connecticut attorneys general specifically examining how businesses handle Global Privacy Control opt-out requests — so this is an area regulators are actively looking at, across state lines.

Penalties are assessed per violation, and because a violation is generally counted per affected consumer, exposure scales with traffic. Current amounts, in force since 1 January 2025, are up to $2,663 for each violation and up to $7,988 for each intentional violation or violation involving the personal information of a consumer the business knows to be under 16.

Separately, California’s data-breach provisions allow consumers statutory damages of between $107 and $799 per consumer per incident, or actual damages, whichever is greater.

For most businesses the realistic risk is not a headline enforcement action. It is the ordinary version: a complaint, a demand letter, or a customer asking a question nobody can answer. The technical fix takes days. Explaining why it was never done is harder.

Find Out Where Your Website Stands

The fastest way to know whether this affects you is to look at what your website is already doing. Our free website audit reports the tracking scripts loading on your site, whether anything currently controls them, whether browser opt-out signals are recognised and confirmed, and what a properly configured setup would involve.

If your site is fine, we will tell you that too.

Website audit dashboard

Talk to the Webstix web development team

Free, no-obligation CCPA audit. We will review your tracking scripts, your current consent setup if you have one, and how your site handles browser opt-out signals — then tell you honestly what is worth doing.

Frequently Asked Questions

Got questions? We’ve got answers. If you don’t see yours here, reach out — we’re happy to help.

What changed in CCPA on 1 January 2026?

The California Privacy Protection Agency’s updated regulations took effect with no grace period. The website-facing changes: businesses must now visibly confirm that an opt-out request has been processed, including browser signals such as Global Privacy Control; closing or navigating away from a consent pop-up no longer counts as consent; accept and decline choices must be symmetrical, and opting out must take the same number of steps as opting in or fewer; and privacy policies must identify categories of personal information disclosed to service providers and contractors, not only third parties.

Does CCPA apply to businesses outside California?

It can. CCPA applies based on whether you do business with California consumers and meet one of its thresholds, not on where your company is located. A business anywhere in the United States with California customers may fall within scope. Whether yours does is a question for your attorney.

What are the current CCPA thresholds?

A for-profit business doing business in California is covered if it meets any one of three tests: annual gross revenue above $26,625,000; buying, selling, or sharing the personal information of 100,000 or more California residents or households in a year; or deriving 50% or more of annual revenue from selling or sharing personal information. The revenue figure is inflation-adjusted every odd-numbered January and is next due to change on 1 January 2027.

Is a cookie banner enough to be CCPA compliant?

No. A consent banner addresses the opt-out and tracking-control requirements that live on your website. CCPA also covers privacy policy disclosures, consumer request handling, vendor contracts, and internal data practices. A banner is a necessary component, not the whole obligation — and a banner that displays a notice without blocking scripts or confirming opt-outs does not even achieve that much.

We already have a cookie notice. Is that enough?

It depends entirely on whether it controls anything. Many banners were installed as a display element: they do not block scripts, do not recognise browser opt-out signals, do not show the visitor their choice was honoured, and treat closing the banner as consent. All four of those are now problems. Our free website audit will tell you which you have.

What is Global Privacy Control, and do I have to honour it?

Global Privacy Control is a browser-level signal that tells every website a visitor goes to not to sell or share their personal information. Businesses covered by CCPA are required to honour it as a valid opt-out request, and since January 2026 must also show the visitor that it was honoured. California’s Opt Me Out Act goes further: from 1 January 2027 all web browsers must offer an opt-out preference signal, so the number of visitors arriving with one will rise sharply.

How much does CCPA cookie consent setup cost?

It depends on how many tracking scripts your site runs and how they load. A site with a handful of tags is straightforward; one carrying years of accumulated marketing and advertising tags takes longer to inventory and configure. Consent platforms also carry their own subscription cost, which we will identify so you can see the total. We quote after the free audit, not before.

Do you write our privacy policy or give legal advice?

No to both. We can build and publish the privacy policy page and link it correctly, but the wording is a legal document and should come from your attorney. Determining which regulations apply to your business, and what they require of it, is legal work and not something we do.

What about other state privacy laws?

California was first, not last — a number of other states now have consumer privacy laws with similar consent and opt-out expectations, and the recent regulatory sweep on opt-out signals was run jointly by California, Colorado, and Connecticut. A properly configured consent platform can apply region-based rules covering multiple states at once, which is why it is worth setting up properly rather than doing the minimum for California alone.

Webstix implements the technical requirements of website privacy compliance. We are not a law firm and this page is not legal advice. We recommend your attorney reviews your privacy policy and confirms which regulations apply to your business.