Skip to main content
Back to resources

Regulatory watch — CCPA Amendments and the 2026 privacy-regulatory calendar

The privacy-regulatory calendar a communications-platform operator tracks in 2026 — the CPRA-amended CCPA enforcement posture, the five new state privacy laws going live, and the FTC rulemaking cycle that touches A2P messaging — and which tenant-owned controls close each gap.

Orbit Editorial Team

Why a privacy-regulatory column, and why now

The communications-platform regulatory calendar turned over twice in the last eighteen months — and the next six months bring another five state privacy laws into effect, a CCPA enforcement cycle that no longer carries a cure-period safety net, and an FTC rulemaking track that extends to A2P messaging. This column tracks those developments as they land, one update at a time. Each entry names the rule or law, the date it takes effect, which tenant-owned control closes the compliance gap on a platform like Devotel Orbit, and where the operator should check their own posture before the effective date.

The column is a regulatory-news explainer, not a product announcement. Every control it names is shipped and documented; the value is the audit-readiness guide — which knob to check, and by when. The quarterly cadence keeps the operator's compliance desk current without chasing every amendment; entries group by regulatory season rather than by week.

The CPRA-amended CCPA: enforcement with no more cure period

The California Privacy Rights Act of 2020 amended the California Consumer Privacy Act of 2018 and took full effect on January 1, 2023. The key operational change for a communications-platform operator arrived later: the California Privacy Protection Agency began enforcing the amended CCPA in July 2023, and the statutory 30-day cure period — the window a business had to fix a violation before the agency could assess a penalty — sunset on January 1, 2025. As of 2026, a CCPA enforcement action can proceed straight to a penalty without a formal opportunity to cure.

Four provisions touch communications-platform operations directly:

Consumer access and deletion requests. A California consumer can request every piece of personal information a business holds about them and can demand its deletion. For a communications platform this means the operator must be able to locate — and delete or redact — message bodies, call recordings, transcriptions, contact profiles, and consent records tied to a single consumer identifier, across every channel and storage tier. On Devotel Orbit, the GDPR/DSAR self-service portal resolves the access and deletion workflow within the platform; the evidence pack the dashboard produces for a single consumer identifier is the operator's CCPA-proof response.

Opt-out of sale and sharing. The CPRA extended CCPA's opt-out right from the sale of personal information to the sharing of personal information for cross-context behavioral advertising. For an A2P messaging operator this matters because third-party analytics and attribution pixels embedded in web-hosted message content or landing pages can constitute "sharing" — and if the operator has not registered those integrations and scoped them per consumer opt-out choice, they carry enforcement exposure. The tenant-owned opt-out suppression list on Devotel Orbit covers the messaging-side opt-out by channel.

Sensitive personal information. The CPRA created a new category — sensitive personal information — that includes precise geolocation, race, religion, union membership, genetic data, and the contents of a consumer's mail, email, and text messages unless the business is the intended recipient. For a communications platform, the last clause is the one that matters: message body content can qualify as sensitive personal information when the consumer did not send it to the business operating the platform. On Devotel Orbit, the compliance posture controls per workspace let the operator declare which data classes they process and for what purpose.

Data minimization and retention. The CPRA requires that a business not retain consumer information longer than reasonably necessary for the disclosed purpose. For a communications platform this means: define a retention policy that maps each data class — messages, recordings, transcriptions, consent records, contact profiles — to a retention duration and a disposal schedule, and document it. A phone number and its opt-out record are retained indefinitely by regulation; a recording from a completed support call is retained for a set number of months.

Five new state privacy laws going live in 2026

Beyond California, five state comprehensive privacy laws have 2026 effective dates:

  • Delaware Personal Data Privacy Act — January 1, 2026. Applies to businesses controlling or processing the data of 35,000 or more Delaware consumers, or deriving more than 20% of revenue from selling personal data.
  • Iowa Consumer Data Protection Act — January 1, 2026. Industry-standard DSAR, deletion, and opt-out rights. No private right of action.
  • Nebraska Data Privacy Act — January 1, 2026. Industry-standard rights plus a 45-day DSAR response window (extendable to 90 with notice).
  • New Hampshire Privacy Act — January 1, 2026. Industry-standard rights; private right of action limited to data-breach claims.
  • New Jersey Data Protection Act — January 15, 2026. Industry-standard rights plus a universal opt-out mechanism requirement.

The same DSAR self-service portal, opt-out suppression list, deletion pipeline, and retention schedule that satisfy CCPA satisfy these five laws too. The operator's action is to verify that their posture declaration names the states whose consumers they serve.

The FTC rulemaking cycle and A2P messaging

Click-to-cancel. Effective May 14, 2025, the amended Telemarketing Sales Rule requires that a consumer be able to cancel a recurring subscription through the same medium they used to sign up. A consumer who opted in to SMS marketing by texting a keyword must be able to opt out by texting a keyword; a consumer who subscribed through a web form must be able to unsubscribe through a web form.

Negative-option marketing. The FTC's Negative Option Rule (effective April 2025) requires clear disclosure of the terms of any negative-option arrangement — a free trial that converts to a paid subscription, or a recurring message series the consumer did not explicitly authorize beyond the first message. The disclosure must appear immediately adjacent to the opt-in trigger.

What the operator checks before the next enforcement window

  1. Run one DSAR from start to finish on your own tenant. Verify that the evidence pack includes message bodies, recordings, transcriptions, contact fields, and consent records for a real consumer identifier.
  2. Match your retention schedule to your actual storage. Confirm that every data class has a retention duration, that the schedule is in writing, and that the durations match what your team has actually been doing.
  3. Map each opt-in channel to its matching opt-out. List every channel through which a consumer can opt in and verify each one has a matching, same-medium opt-out path.

The next entry in this column covers the EU Digital Services Act's messaging-platform obligations as they apply to A2P communications.

Ready to build?

Orbit puts voice, messaging, and AI agents on one platform with one pay-as-you-go bill. Start free — no credit card required.

Regulatory watch — CCPA Amendments and the 2026 privacy-regulatory calendar — Orbit by Devotel