{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-07-29T16:01:47.045Z"},"content":[{"type":"documentation","id":"203dbc40-d0f1-4b51-925c-8e619d75efaa","slug":"ccpa-user-research-compliance","title":"CCPA/CPRA Compliance for Customer Research: The 2026 Practitioner Guide","url":"https://www.koji.so/docs/ccpa-user-research-compliance","summary":"CCPA/CPRA applies to for-profit businesses doing business in California meeting one threshold: $26.625M annual revenue, 100,000+ California consumers, or 50%+ revenue from selling/sharing personal information. B2B contacts and employees are in scope since the 2023 exemption sunset. The highest-risk research gap is vendor contracts: without six specific service provider terms, disclosing participant data to a research platform, panel, or transcription vendor is legally a sale or sharing that triggers opt-out rights. Voice recordings are biometric information only if an identifier template can be extracted, and sensitive personal information only when actually used to identify a consumer, so ordinary voice research is not automatically sensitive. Enforcement in 2025-26 targeted broken opt-outs, excessive verification, asymmetrical choices, missing vendor terms, and over-collection: Honda $632,500, Healthline $1.55M, a youth sports platform $1.10M. Statutory penalties are $2,663 per unintentional and $7,988 per intentional violation.","content":"**Answer first:** If your research vendor contract lacks the specific CCPA service provider clauses, handing them your participant list is legally a **\"sale\" or \"sharing\"** of personal information — which triggers opt-out rights you almost certainly are not honouring. That contract language, not your consent form, is the single highest-risk gap in most US research programmes.\n\nThe second thing to know: California enforcement in 2025–26 has not targeted exotic edge cases. It has targeted **broken opt-outs, excessive verification, and missing vendor contract terms** — all three of which are routine failures in research operations.\n\nIf your research reaches European participants too, read this alongside our [GDPR-compliant AI user research guide](/docs/gdpr-compliant-ai-user-research). The regimes overlap but their mechanics differ sharply, and California's are less forgiving in one specific place: the paperwork with your vendors.\n\n## Does CCPA even apply to you?\n\nThe CCPA applies to for-profit businesses doing business in California that meet at least one threshold. Adjusted for inflation, the revenue threshold now stands at **$26.625 million** in annual gross revenue. The alternatives: buying, selling, or sharing the personal information of **100,000+** California consumers or households annually, or deriving **50% or more** of annual revenue from selling or sharing personal information.\n\nTwo traps worth naming:\n\n- **\"Consumer\" includes B2B contacts and employees.** California abandoned the B2B and HR exemptions in 2023. Your enterprise buyer interviews and your employee research are both in scope. This surprises people constantly.\n- **You do not need a California entity.** Doing business in California is the test, and serving California customers over the internet counts.\n\nIf you are under every threshold, CCPA does not bind you today — but write your research programme to comply anyway. Crossing $26.625M in revenue should not require rebuilding your consent architecture.\n\n## The vendor contract that decides everything\n\nThis is the part of CCPA that research teams get wrong most often, and it is worth understanding precisely because the consequence is severe and invisible.\n\nWhen you disclose participant personal information to an outside company — a research platform, a recruiting panel, a transcription service, an incentive fulfilment vendor — California asks what that recipient is. There are three answers:\n\n| Classification | What it means | Opt-out consequence |\n| --- | --- | --- |\n| **Service provider / contractor** | Processes data only for your specified purposes, under a written contract with required terms | No opt-out right triggered |\n| **Third party** | Anyone who does not meet the service provider criteria | Disclosure is a \"sale\" or \"sharing\" — consumers can opt out |\n\nHere is the mechanism that catches people: **the classification is created by the contract, not by the relationship.** To qualify as a service provider, the transfer must be pursuant to a written contract that prohibits the recipient from retaining, using, or disclosing the personal information for any purpose other than the specific purposes named in that contract.\n\nWithout those terms, the disclosure is a sale or sharing to a third party by default — even if your vendor never does anything commercially inappropriate with the data. Good behaviour does not cure a missing clause.\n\nYour CCPA vendor contract must:\n\n1. Prohibit use of the personal information beyond the specified purposes\n2. Require the vendor to provide **the same level of privacy protection** the CPRA requires of you\n3. Grant you rights to take reasonable steps to verify appropriate use\n4. Require the vendor to **notify you** if it can no longer meet its obligations\n5. Grant you rights to stop and remediate unauthorised use\n6. Bind subcontractors to equivalent terms\n\n**Your action item:** pull every research vendor contract you have and check for these six terms. Recruiting panels and transcription services are the usual offenders — research platforms tend to have their paper in order, incentive and panel vendors frequently do not. A vendor who cannot produce a compliant DPA is not a procurement inconvenience; they are converting your research operations into an unreported sale of personal information.\n\n## Voice recordings, biometrics, and where the line sits\n\nVoice research raises a question worth answering carefully, because the common assumption — \"audio is biometric, therefore sensitive\" — is wrong in a way that leads to unnecessary compliance theatre.\n\nUnder California law, a voice recording can qualify as biometric information **if an identifier template can be extracted from it**. But it constitutes *sensitive* personal information only when the recording is actually **used to identify a consumer**. Recording an interview to understand what a customer thinks about your onboarding flow is not identification. Running voiceprint matching against that audio is.\n\nSo ordinary voice research does not automatically pull you into the sensitive-personal-information regime with its additional right to limit use. What does pull you in: collecting health information, precise geolocation, racial or ethnic origin, or — added by SB 1223 and effective January 2025 — **neural data**.\n\nNote also that AB 1008, effective January 2025, clarified that personal information includes data **embedded in AI models and other abstract digital systems**. If participant data was used to fine-tune a model, that model may itself hold personal information. This is a strong argument for research tooling that does not train on your data, and for asking vendors the question explicitly.\n\nWhere research *does* commonly touch sensitive categories is in screeners. A health-condition screener or an ethnicity quota question collects sensitive personal information directly — see [research screener questions](/docs/research-screener-questions) for how to collect only what your quotas genuinely require.\n\n## What California actually enforces\n\nThe enforcement record is the most useful compliance document available, because it shows what regulators care about rather than what commentators speculate about. Recent actions:\n\n- **Honda — $632,500.** For requiring excessive personal information to verify privacy rights requests, presenting asymmetrical privacy choices, making authorised-agent requests unnecessarily difficult, and — directly relevant here — **sharing personal information with vendors without the required contract terms.**\n- **Healthline — $1.55 million**, the largest CCPA penalty to date and the first data-minimisation enforcement action. The consent banner logged rejections while tracking continued regardless.\n- **A youth sports media platform — $1.10 million**, for opt-out and consumer notice failures.\n\nStatutory penalties in 2026 run to **$2,663 per violation** for unintentional violations and **$7,988** for intentional violations or those involving minors. Per violation means per consumer — the arithmetic across a participant database escalates quickly.\n\nThe pattern is unmistakable: **asymmetrical choices, excessive verification, broken opt-outs, missing vendor contract terms, and collecting more than you need.** Four of those five are ordinary research-operations failure modes.\n\n## Your compliance checklist\n\n1. **Notice at collection, before you collect.** At or before the point of collection, tell participants what categories you collect, why, how long you keep it, and whether it is sold or shared. On the recruitment screen — not in a policy they reach afterwards.\n2. **Fix the vendor contracts.** All six terms, every vendor, including panels and transcription.\n3. **Make opt-outs real.** If any disclosure is a sale or sharing, honour Global Privacy Control signals and provide a working opt-out. Honda's fine says asymmetrical choices are independently punishable.\n4. **Verify proportionately.** Do not demand a government ID to process a deletion request. Excessive verification is itself a violation.\n5. **Minimise deliberately.** Collect what the research question requires. Do not retain a full participant profile because it might be useful later — that is precisely the Healthline theory.\n6. **Build deletion you can execute.** A deletion request must reach transcripts, recordings, analysis artefacts, and your repository. If deletion cannot reach your insight repository, you cannot comply. See [research repository guide](/docs/research-repository-guide).\n7. **Honour the 45-day clock.** Respond to requests within 45 days, extendable to 90 with notice.\n8. **Keep a data inventory.** Categories collected, sources, purposes, disclosure recipients, retention. Everything above depends on it.\n\n## How Koji helps\n\nCompliance gets dramatically easier when the platform is designed so the compliant path is the default one:\n\n- **Service provider by contract.** Koji operates as a service provider under CCPA, with the required terms in place — your disclosure to Koji does not become a sale.\n- **No training on your research data.** Which keeps AB 1008's model-embedded-personal-information problem from arising in the first place.\n- **Consent and notice at the front door.** Koji's [intake forms and consent](/docs/intake-forms-and-consent) present notice at collection before the first question, which is exactly where California requires it.\n- **Per-study retention with automatic purge.** Set retention when you design the study and let raw conversations expire on schedule while aggregated themes survive. Retention becomes a property of the study rather than a quarterly cleanup project.\n- **Deletion that reaches everything.** Because transcripts, analysis, and reports live in one system, a deletion request is one operation — not a hunt across a transcription vendor, a spreadsheet, a Notion page, and three stakeholders' downloads. That fragmentation is the real reason deletion requests go unfulfilled, and consolidation is the fix.\n- **Minimisation through better instrumentation.** This is where methodology and compliance align. Koji's six [structured question types](/docs/structured-questions-guide) — `open_ended`, `scale`, `single_choice`, `multiple_choice`, `ranking`, and `yes_no` — let you capture exactly the data point you need rather than an open field you later mine. A `scale` question asking satisfaction directly collects one number. A free-text field that participants fill with health details, employer names, and family circumstances collects sensitive personal information you never intended to hold and now must protect, disclose, and delete. Precise instrumentation is data minimisation implemented in the study design.\n\nThe structural contrast: legacy survey tools optimise for collecting as much as possible and sorting it out later. That instinct was harmless in 2015 and is now a liability with a per-consumer price tag.\n\n## Related Resources\n\n- [GDPR-Compliant AI User Research](/docs/gdpr-compliant-ai-user-research) — the European regime, and where it diverges from California's\n- [The EU AI Act and User Research](/docs/eu-ai-act-user-research-compliance) — AI-specific obligations layered on top of privacy law\n- [Structured Questions Guide](/docs/structured-questions-guide) — the six question types, and why precise instrumentation is data minimisation\n- [AI Interview Data Privacy & Security](/docs/ai-interview-data-privacy-security) — storage, encryption, and retention mechanics\n- [Intake Forms and Consent](/docs/intake-forms-and-consent) — presenting notice at collection correctly\n- [Research Consent Form Templates](/docs/research-consent-form-templates) — copy-ready participant notices\n- [Research Screener Questions](/docs/research-screener-questions) — qualifying participants without over-collecting\n\n*Regulatory information current as of July 2026. Practitioner orientation, not legal advice — confirm your obligations with qualified privacy counsel.*\n","category":"Research Operations","lastModified":"2026-07-29T03:21:12.817673+00:00","metaTitle":"CCPA/CPRA Compliance for Customer Research (2026 Guide)","metaDescription":"What CCPA/CPRA actually requires for interviews, surveys, and voice research: the six service provider contract terms that keep vendor disclosures from becoming a \"sale\", when voice recordings count as biometric data, and the 2026 enforcement record.","keywords":["ccpa user research","cpra customer research","ccpa compliance interviews","california privacy research","ccpa service provider contract","ccpa voice recording biometric","ccpa research participants","cpra sensitive personal information","ccpa penalties 2026","ccpa data minimization research"],"aiSummary":"CCPA/CPRA applies to for-profit businesses doing business in California meeting one threshold: $26.625M annual revenue, 100,000+ California consumers, or 50%+ revenue from selling/sharing personal information. B2B contacts and employees are in scope since the 2023 exemption sunset. The highest-risk research gap is vendor contracts: without six specific service provider terms, disclosing participant data to a research platform, panel, or transcription vendor is legally a sale or sharing that triggers opt-out rights. Voice recordings are biometric information only if an identifier template can be extracted, and sensitive personal information only when actually used to identify a consumer, so ordinary voice research is not automatically sensitive. Enforcement in 2025-26 targeted broken opt-outs, excessive verification, asymmetrical choices, missing vendor terms, and over-collection: Honda $632,500, Healthline $1.55M, a youth sports platform $1.10M. Statutory penalties are $2,663 per unintentional and $7,988 per intentional violation.","aiPrerequisites":["Basic understanding of user research operations","Familiarity with research participant recruitment"],"aiLearningOutcomes":["Determine whether CCPA/CPRA applies to your research programme","Audit vendor contracts for the six required service provider terms","Distinguish ordinary voice research from regulated biometric processing","Present a compliant notice at collection during recruitment","Build deletion workflows that reach transcripts, analysis, and repositories","Apply data minimisation through study design rather than post-hoc cleanup"],"aiDifficulty":"intermediate","aiEstimatedTime":"13 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}