Taking Privacy Seriously in the New CCPA Era – IA Magazine

California privacy compliance has moved far beyond adding a policy link to the footer and hoping nobody clicks it. For insurance agencies, carriers, technology vendors, and other businesses that handle customer information, the new CCPA era demands practical data governance, honest notices, usable consumer controls, and security that works outside a PowerPoint presentation. The good news is that privacy can be more than a legal chore. Done well, it becomes a trust-building service feature.

Privacy Is No Longer a Fine-Print Issue

An insurance agency may collect names, addresses, driver information, property details, payment data, claims histories, website identifiers, call recordings, email engagement data, and sometimes highly sensitive health or financial information. That is not a customer file. It is a small digital biography wearing a business-casual outfit.

The California Consumer Privacy Act took effect on January 1, 2020, and the California Privacy Rights Act later amended it with additional rights and obligations beginning in 2023. Since then, California has created a dedicated privacy regulator, expanded enforcement, updated regulations, and made it increasingly clear that privacy controls must work in practice, not merely appear in a policy.

Research: California Attorney General and CalPrivacy explain the CCPA, CPRA amendments, consumer rights, and enforcement structure.

The original IA Magazine discussion made a business point that remains powerful: customers reward organizations they trust and avoid organizations that treat personal information carelessly. Today, that principle has sharper legal teeth. Privacy is now part customer experience, part operational discipline, and part regulatory risk management.

Research basis: IA Magazine’s original article linked strong privacy practices with customer trust and loyalty.

What the CCPA Gives California Consumers

California residents have meaningful control over personal information linked or reasonably linkable to them or their households. Depending on the circumstances, those rights include the ability to know what a business collects, request access, ask for deletion, correct inaccurate data, opt out of the sale or sharing of personal information, limit certain uses of sensitive personal information, and receive equal treatment after exercising privacy rights.

The phrase sale or sharing is broader than a traditional cash transaction. Advertising technology, analytics arrangements, marketing cooperatives, audience matching, and cross-context behavioral advertising may involve regulated disclosures. California also recognizes browser-based signals such as Global Privacy Control. An opt-out that requires seven clicks and a scavenger hunt through cookie settings is not a charming user journey; it is a potential enforcement exhibit.

Research: California recognizes opt-outs including Global Privacy Control; enforcement has focused on ineffective opt-out mechanisms.

Does the CCPA Apply to Your Organization?

The CCPA generally applies to a for-profit business that does business in California, determines the purposes and means of processing personal information, and meets at least one statutory threshold. Current thresholds include gross annual revenue of at least $26.625 million for the preceding calendar year, buying, selling, or sharing the personal information of 100,000 or more California residents or households, or deriving at least 50% of annual revenue from selling or sharing California residents’ personal information.

Research: CalPrivacy publishes the current applicability thresholds and inflation-adjusted revenue figure.

Service providers, contractors, affiliates, and third parties may have separate duties. Smaller agencies can also inherit requirements through carrier agreements, vendor contracts, insurance rules, breach laws, or another state’s privacy statute. “We are too small” is not a data strategy; document the analysis and revisit it as revenue, data volume, and business relationships change.

The Insurance Exemption Is Not a Magic Invisibility Cloak

Insurance organizations have long operated under sector-specific privacy rules, including the Gramm-Leach-Bliley Act and state insurance privacy laws. That has led some teams to repeat a dangerously oversimplified sentence: “Insurance is exempt from the CCPA.” The accurate answer is more complicated.

California’s regulations effective January 1, 2026 clarify that insurance companies meeting the CCPA definition of a business must comply with the CCPA for personal information that is not subject to the California Insurance Code and its regulations. The regulation expressly includes insurance institutions, agents, and insurance-support organizations within its description of insurance companies.

Information used in a regulated personal insurance transaction may fall under insurance-specific law, while unrelated data may remain within the CCPA. Examples include website visitor information from people not applying for coverage, advertising profiles, employee records, and job-applicant data. The exemption follows the information and its purpose; it does not place the entire company inside a privacy-proof bubble.

Research: The 2026 CCPA regulations clarify application to insurance companies and give examples involving website visitors, employees, and applicants.

A single customer journey may cross several categories: a quote form can begin as website analytics, become an application, pass through a comparative rater, enter an agency management system, and later feed marketing. Agencies should map those transitions with qualified counsel and carrier partners.

A Practical CCPA Compliance Plan for Insurance Agencies

1. Build a Real Data Inventory

Start by mapping what personal information enters the organization, why it is collected, where it is stored, who can access it, which vendors receive it, how long it is retained, and how it is deleted. Include websites, mobile apps, call-tracking systems, email tools, comparative raters, agency management platforms, customer relationship systems, document storage, payroll software, and “temporary” spreadsheets that somehow celebrate their eighth birthday.

Connect each data category to a purpose, legal exception, retention period, security owner, and disposal method. The resulting map supports notices, requests, contracts, incident response, and data minimization.

2. Write Notices for Humans

A privacy policy should accurately describe online and offline practices. A notice at collection should appear at or before the point where information is gathered and explain the categories collected and purposes of use. Do not describe every possible use in the known universe merely to preserve flexibility. California’s purpose-limitation approach expects collection, use, retention, and sharing to be reasonably necessary and proportionate to disclosed purposes and consumer expectations.

Keep language specific. “We may use information to improve services” is broad enough to cover teaching a toaster to sell umbrella policies. Explain what actually happens.

3. Make Consumer Requests Easy to Complete

Create an intake process for requests to know, access, delete, and correct. Covered businesses that are not exclusively online generally need at least two designated methods, including a toll-free number, and a website method when they maintain a website. Establish procedures for identity verification, authorized agents, exceptions, response deadlines, and documentation.

Verification should be proportionate. Consumers should not have to surrender substantially more sensitive data merely to request less data.

Research: The 2026 regulations address request methods, minimal steps, verification, training, and recordkeeping.

4. Test Opt-Outs Across Every Channel

Do not assume the cookie banner completes the CCPA job. Test websites while logged in and logged out, on multiple browsers, with Global Privacy Control enabled, and after clearing cookies. Test mobile apps, connected devices, account settings, advertising identifiers, and vendor handoffs. Confirm that an opt-out changes downstream behavior rather than merely changing the color of a button.

Recent enforcement has targeted confusing flows, incomplete account-wide choices, improper tracking disclosures, and sharing that continued after an opt-out. A nice-looking banner will not rescue broken back-end logic.

Research: Official enforcement actions involving DoorDash, Healthline, Sling TV, Disney, Honda, and Todd Snyder emphasize functional opt-outs and accurate data practices.

5. Control Vendors Before Vendors Control the Risk

Review contracts with analytics providers, lead generators, marketing firms, cloud services, call centers, artificial intelligence tools, and insurance technology vendors. Contracts should identify roles, permitted purposes, confidentiality duties, security safeguards, deletion and return requirements, audit or assessment rights, incident notification duties, and restrictions on secondary use.

Then verify reality. A contract label does not automatically make the data flow compliant. Inventory software kits, pixels, tags, APIs, and integrations, including tools forgotten by everyone except the tool itself.

6. Minimize and Secure the Data

Collect only what is reasonably necessary, restrict access by role, use multifactor authentication, encrypt sensitive information, patch systems, monitor privileged accounts, maintain tested backups, and dispose of records according to a defensible schedule. Insurance organizations hold information attractive to criminals because underwriting and claims can combine identity, financial, property, vehicle, and health details in one convenient package.

The NAIC emphasizes safeguards, incident response, and third-party oversight for insurers and producers. CCPA compliance belongs inside the broader security program, not in a lonely binder labeled “LEGAL.”

Research: NAIC materials emphasize protection of sensitive insurance data and model privacy and data-security requirements.

7. Prepare for Risk Assessments, Audits, and Automated Decisions

The regulations effective in 2026 add detailed requirements for certain businesses engaging in processing that presents significant privacy or security risk. Covered activities may require risk assessments, while qualifying businesses will phase into cybersecurity-audit obligations. The rules also address automated decision-making technology, including notices and consumer rights in specified uses.

Identify where automated tools influence marketing, lead scoring, fraud detection, recruiting, service, or eligibility workflows. Peripheral uses may require separate analysis even when core underwriting falls under another framework. “The algorithm did it” is not a persuasive compliance officer.

Research: CalPrivacy’s completed 2026 regulations cover risk assessments, cybersecurity audits, ADMT, and phased implementation.

8. Train People and Keep Evidence

Employees who handle consumer inquiries or CCPA compliance need appropriate training. Front-desk staff, producers, claims personnel, recruiters, marketers, and IT teams should know how to recognize a privacy request and route it promptly. Training must reflect actual workflows, including requests arriving through email, social media, phone calls, or handwritten letters.

Preserve request records, policy versions, inventories, contract reviews, and testing results. Regulators do not grade compliance by telepathy; the organization must show what it did, when, and why.

Enforcement Has Become Larger, Faster, and More Technical

California enforcement is no longer limited to symbolic cases. The Attorney General and CalPrivacy have pursued retailers, automakers, publishers, streaming services, mobile applications, and data brokers. Allegations have included failure to honor opt-outs, excessive verification, inaccurate privacy notices, dark patterns, unprotected third-party disclosures, and unlawful sale of location and driving information.

In 2025, CalPrivacy announced a $1.35 million action against Tractor Supply involving privacy notices and job-applicant rights. In February 2026, California announced a $2.75 million settlement with Disney over incomplete opt-outs across services and devices. In May 2026, the state announced a $12.75 million General Motors privacy settlement involving the sale of location and driving data, described as the largest CCPA penalty at that time.

Research: Official California announcements document the Tractor Supply, Disney, and General Motors enforcement actions and penalties.

These cases offer a blunt lesson: regulators look beyond policy language to actual interfaces, vendor relationships, technical signals, data flows, and consumer outcomes. A compliance program must be testable.

The Delete Act Raises the Stakes for Data Ecosystems

California’s Delete Request and Opt-Out Platform, known as DROP, opened to consumers in 2026. It allows a California resident to submit one deletion request directed to registered data brokers. Beginning August 1, 2026, covered data brokers must regularly retrieve and process matching requests, subject to limited exceptions.

Research: CalPrivacy explains DROP, its January 2026 availability, and the August 1, 2026 processing start for data brokers.

Most independent agencies are not data brokers, but DROP increases scrutiny of purchased leads, enrichment services, audience lists, and third-party sources. Ask vendors where data originated, whether registration is required, and how deletion signals flow downstream.

Privacy Can Be a Competitive Advantage

Privacy can improve performance: clear notices reduce confusion, preference centers lower complaints, minimization reduces exposure, inventories speed incident response, and retention rules prevent seventeen competing files named “FINAL_v9_REALFINAL.”

For insurance professionals, trust is the product wrapped around the product. Customers disclose intimate details because they expect help managing risk. An agency that explains its data practices plainly, honors choices promptly, and secures information responsibly demonstrates the same qualities customers seek in insurance advice: competence, transparency, and reliability.

Experience-Based Lessons from Privacy Program Rollouts

The following composite experiences reflect common patterns seen when organizations turn privacy requirements into daily operations. They are not claims about one named agency; they illustrate what teams frequently discover once they stop treating privacy as a footer-link project.

The Data Map That Found a Forgotten Marketing Pipeline

One common experience begins with a simple question: “Which vendors receive website leads?” The marketing team names the agency management system and the email platform. IT adds the hosting provider. Then someone notices a tag-management container containing an old advertising pixel, a session-replay tool, a call-tracking script, and a lead-routing service installed during a campaign two years earlier. Nobody intended to conceal the tools. The organization had simply accumulated technology faster than it accumulated governance.

Questionnaires alone are not enough. Teams need technical scans, browser testing, contract review, payment records, and conversations with campaign owners. The most important vendor may be the one nobody remembers owning.

The Request Form That Worked Only in the Demo

Another familiar experience involves a beautiful privacy portal. During the vendor demonstration, a test request glides from submission to completion. In production, however, requests from logged-in users create duplicate identities, the verification email lands in spam, and deletion fails in a downstream CRM. The dashboard still displays a reassuring green checkmark because the portal completed its own step.

A mature team tests end to end, follows records through connected systems, checks exceptions, and verifies vendor completion. Privacy operations resemble a fire-alarm test: sound at the front desk does not prove every room is protected.

The Opt-Out That Marketing Accidentally Reversed

A third experience occurs when a customer opts out, but a later data import overwrites the suppression flag. The marketing system sees a “new” lead and resumes targeted outreach. Nobody deliberately ignored the consumer. The failure came from weak data lineage and conflicting systems of record.

The fix is persistent preference architecture, suppression testing, vendor coordination, and controls for imports. Consumer choices must travel with the record and survive routine operations.

The Training Session That Changed the Program

Privacy training becomes useful when employees can connect it to real work. A producer may receive a deletion request during a renewal call. A recruiter may collect applicant data through a third-party platform. A service representative may receive an authorized-agent request from an adult child helping a parent. A marketing manager may activate a new analytics feature without realizing it changes data sharing.

Scenario-based training reveals broken processes and turns privacy from legal trivia into customer service. Escalating a question is not failure; it is the control working as designed.

The Business Result Nobody Put in the Compliance Budget

Organizations often discover that privacy cleanup produces operational benefits. Removing unnecessary fields shortens forms. Consolidating systems reduces licensing costs. Retention schedules shrink storage. Better vendor ownership speeds procurement. Clear preferences improve marketing quality because teams stop contacting people who do not want to hear from them.

Privacy maturity feels like good housekeeping: the organization knows what it has, why it has it, who uses it, and when it should disappear. That clarity matters during an inquiry, incident, audit, merger, or ordinary Monday.

Conclusion: Take Privacy Seriously Before Someone Else Does

The new CCPA era rewards organizations that treat privacy as an operating capability. Insurance agencies should map data, separate insurance-regulated information from other business data, update notices, honor consumer signals, test request workflows, govern vendors, minimize collection, strengthen cybersecurity, and document decisions.

The goal is not to turn every producer into a privacy attorney, but to make responsible handling routine across sales, service, recruiting, marketing, and technology. That is better than discovering your data practices for the first time in a regulator’s complaint.

Research synthesis reviewed 14 reputable U.S. sources/outlets: IA Magazine, California Privacy Protection Agency, California Attorney General, NAIC, Reuters Legal, Associated Press, The Washington Post, Jackson Lewis, Skadden, Greenberg Traurig, Ogletree Deakins, Coblentz Patch Duffy & Bass, IBM, and Proofpoint. Supporting materials included official statutes, regulations, enforcement releases, insurance privacy guidance, and compliance analyses.

This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.