Legacy Core Trust Brief
California Privacy Expectations Keep Climbing for Small Businesses
California continues to raise the bar on how businesses handle and disclose personal information. This month’s Trust Signal is to confirm your privacy notice reflects what data you actually collect and how you honor customer requests.
- Regulation
- Data Privacy
Most relevant to: Professional Services, Retail, Real Estate, Healthcare, Nonprofits
What Changed
California adopted final CCPA cybersecurity audit regulations effective January 1, 2026. They apply only to businesses that meet specific revenue and data-volume thresholds — not most small CPA firms, solo attorneys, or medical practices. For covered businesses, auditors may evaluate up to 18 enumerated security controls using a risk-based scope.
Why It Matters for Small Businesses
Even when a small business is below the audit threshold today, California has articulated the control set it expects at scale. Privacy notices, consumer data requests, and vendor data mapping remain baseline expectations for businesses serving California customers.
What To Do This Month
- Confirm your privacy notice matches the data you actually collect and share.
- Make it easy for customers to ask what data you hold and to request deletion.
- Map which vendors and tools receive customer personal information.
- Limit access to personal data to staff who genuinely need it.
- Keep a short, written record of how you handle customer data requests.
Legacy Core Trust Tip
Demonstrating responsible data practices is a trust signal customers increasingly look for. Legacy Core helps small businesses document and communicate those practices in plain English.