CCPA Compliance for Your
Existing Website
On 1 January 2026, new California Consumer Privacy Act regulations took effect that changed what your website has to do — not what it has to say. Several requirements that were previously optional became mandatory, and they are all things a website either does or does not do.
Most websites do not do them. Many added a cookie banner years ago that displays a notice without blocking anything, treats clicking the X as consent, and never tells the visitor their choice was registered. Under the rules now in force, that banner is not doing the job it appears to be doing.
Webstix configures the consent and opt-out layer on websites that already exist. No rebuild, no migration, no change to how your site looks.
Not sure whether your website meets the current requirements?
Our free CCPA audit reviews what tracking scripts your site loads, when they fire, whether your current cookie notice actually controls them, and whether it handles browser opt-out signals.
What Changed on 1 January 2026
The California Privacy Protection Agency’s updated regulations took effect at the start of 2026 with no enforcement grace period. Four of the changes are public-facing and affect your website directly.
You must now show that an opt-out was honoured
Previously a business could choose whether to confirm it had processed an opt-out request. That is now mandatory. When a visitor arrives with a browser-level opt-out preference signal such as Global Privacy Control, your website must indicate that the signal was recognised — the Agency’s own example is displaying “Opt-Out Request Honored”, or reflecting the status in a toggle within the visitor’s privacy settings.
This is the single most common gap we see. Many sites process the signal silently, or do not process it at all.
Closing a cookie banner is not consent
The rules now state directly that a consumer closing or navigating away from a consent pop-up, without affirmatively selecting the equivalent of “I accept”, does not constitute consent. Banners built to treat dismissal as agreement no longer achieve anything.
Choices have to be symmetrical
A more prominent “accept” button than “decline” — bigger, brighter, or higher-contrast — is treated as a dark pattern. Opting out must also take the same number of steps as opting in, or fewer, measured from the “Do Not Sell or Share My Personal Information” link through to completion.
Privacy policy disclosures were widened
Privacy policies must now identify the categories of personal information disclosed to service providers and contractors for a business purpose, not only those disclosed to third parties. This is a wording change to a legal document, so it belongs with your attorney rather than with us — but it is worth knowing it happened.
Does CCPA Apply to Your Business?
CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds:
Annual gross revenue above $26,625,000. This figure is adjusted for inflation in January of every odd-numbered year — it rose from $25,000,000 on 1 January 2025, and is next due for adjustment on 1 January 2027.
Buying, selling, or sharing the personal information of 100,000 or more California residents or households in a year.
Deriving 50% or more of annual revenue from selling or sharing California residents’ personal information.
When Does the CCPA Apply to Your Business?
Two things regularly surprise people. First, you do not need to be located in California — the law follows the consumer, not the company, so a Wisconsin manufacturer with California customers can fall within scope. Second, “selling or sharing” is broader than most business owners expect and can cover ordinary advertising and analytics arrangements that pass data to a third party.
Note also that the thresholds are alternatives, not a checklist — meeting any one of the three is enough. CCPA generally does not apply to nonprofit organisations or government agencies.
Whether it applies to your business specifically is a legal question and your attorney is the right person to answer it. What we can tell you is what your website is currently doing with visitor data, which is usually the piece missing from that conversation.
What CCPA Asks of Your Website
CCPA is a broad law governing how a business handles personal information across its whole operation. Only part of it lives on your website. The website-facing pieces are:
- A clear and conspicuous “Do Not Sell or Share My Personal Information” link that lets a visitor submit an opt-out request
- Recognition of browser-level opt-out preference signals such as Global Privacy Control
- Visible confirmation that an opt-out request has been processed — mandatory since 1 January 2026
- Consent and tracking controls that take effect before third-party scripts collect anything
- Symmetrical, non-deceptive consent choices
- A privacy policy disclosing what you collect and how it is used
- A route for consumers to submit access and deletion requests
The first five are technical. They are built, configured, and tested on the website itself — and they are the part we handle.
What Webstix Does
We install and configure cookie consent and opt-out tooling on your existing website:
Review of the tracking scripts your site currently loads — analytics, advertising pixels, embedded media, chat tools, heatmaps, and anything else collecting visitor data
Selection of a consent management platform appropriate to your site and budget
Installation and configuration of the consent banner and preference centre
Script blocking, so non-essential trackers genuinely do not fire until consent is given
Global Privacy Control and opt-out preference signal handling, checked on page load
Visible opt-out confirmation, so a visitor arriving with a signal is shown that it was honoured — the requirement that came into force on 1 January 2026
Correcting banners that treat dismissal as consent, and unequal accept/decline choices
Region-based rules, so California visitors see what the law requires without changing the experience for everyone else
Styling the banner to match your brand rather than looking like a bolt-on
Testing across devices and browsers to confirm the controls actually work
Handover, so your team can add new scripts without breaking the setup
This is web development work. It is exactly what we do, and it does not require rebuilding your site.
What This Does Not Cover
We would rather tell you this upfront than have you find out later.
Configuring consent tooling addresses the opt-out and tracking-control side of CCPA. It does not, on its own, make a business CCPA compliant. Compliance also involves how your organisation handles personal information internally, what your privacy policy says, how you respond to consumer requests, your vendor contracts, and your employee and job-applicant data — none of which live on your website.
Webstix is a web development company, not a law firm. We implement technical requirements. We do not give legal advice, we do not write privacy policies as legal documents, and we will not tell you a cookie banner makes you compliant. Any vendor who does is selling something they cannot deliver.
What we will do is make the part that lives on your website work properly, and tell you plainly what is still outstanding so you can take it to your attorney.
Already have a cookie banner?
It is worth checking whether it does anything. A large share of the banners we review display a notice while the tracking scripts load regardless — and very few show a visitor that their browser opt-out signal was honoured, which has been mandatory since January 2026.
How It Works
1
Free website audit
We review your site and report what tracking scripts load, when they fire, whether any existing consent tool controls them, whether Global Privacy Control signals are recognised and confirmed, and what a properly configured setup would involve. No cost and no obligation.
2
Scope and Quote
Based on what we find, we tell you what the work involves and what it costs. Sites with a handful of scripts are straightforward. Sites carrying years of accumulated marketing tags take longer, and we will say so before you commit.
3
Configuration and Testing
We install the consent platform, configure the rules, block the scripts that need blocking, set up signal handling and opt-out confirmation, style the banner to your brand, and test across devices and browsers.
4
Handover
We show your team how the setup works and how to add new scripts without breaking it. If you would rather we maintain it, that can run through a Website Care plan.
Why It Is Worth Addressing Now
The updated regulations arrived without an enforcement grace period. In September 2025 the California Privacy Protection Agency announced a joint investigative sweep with the Colorado and Connecticut attorneys general specifically examining how businesses handle Global Privacy Control opt-out requests — so this is an area regulators are actively looking at, across state lines.
Penalties are assessed per violation, and because a violation is generally counted per affected consumer, exposure scales with traffic. Current amounts, in force since 1 January 2025, are up to $2,663 for each violation and up to $7,988 for each intentional violation or violation involving the personal information of a consumer the business knows to be under 16.
Separately, California’s data-breach provisions allow consumers statutory damages of between $107 and $799 per consumer per incident, or actual damages, whichever is greater.
Find Out Where Your Website Stands
The fastest way to know whether this affects you is to look at what your website is already doing. Our free website audit reports the tracking scripts loading on your site, whether anything currently controls them, whether browser opt-out signals are recognised and confirmed, and what a properly configured setup would involve.
If your site is fine, we will tell you that too.
Talk to the Webstix web development team
Free, no-obligation CCPA audit. We will review your tracking scripts, your current consent setup if you have one, and how your site handles browser opt-out signals — then tell you honestly what is worth doing.
Frequently Asked Questions
Got questions? We’ve got answers. If you don’t see yours here, reach out — we’re happy to help.
What changed in CCPA on 1 January 2026?
The California Privacy Protection Agency’s updated regulations took effect with no grace period. The website-facing changes: businesses must now visibly confirm that an opt-out request has been processed, including browser signals such as Global Privacy Control; closing or navigating away from a consent pop-up no longer counts as consent; accept and decline choices must be symmetrical, and opting out must take the same number of steps as opting in or fewer; and privacy policies must identify categories of personal information disclosed to service providers and contractors, not only third parties.
Does CCPA apply to businesses outside California?
It can. CCPA applies based on whether you do business with California consumers and meet one of its thresholds, not on where your company is located. A business anywhere in the United States with California customers may fall within scope. Whether yours does is a question for your attorney.
What are the current CCPA thresholds?
A for-profit business doing business in California is covered if it meets any one of three tests: annual gross revenue above $26,625,000; buying, selling, or sharing the personal information of 100,000 or more California residents or households in a year; or deriving 50% or more of annual revenue from selling or sharing personal information. The revenue figure is inflation-adjusted every odd-numbered January and is next due to change on 1 January 2027.
Is a cookie banner enough to be CCPA compliant?
We already have a cookie notice. Is that enough?
What is Global Privacy Control, and do I have to honour it?
How much does CCPA cookie consent setup cost?
Do you write our privacy policy or give legal advice?
What about other state privacy laws?
Webstix implements the technical requirements of website privacy compliance. We are not a law firm and this page is not legal advice. We recommend your attorney reviews your privacy policy and confirms which regulations apply to your business.







