Back to docs
Research Operations

CCPA/CPRA Compliance for Customer Research: The 2026 Practitioner Guide

Most US teams assume GDPR is the hard one and California takes care of itself. It does not. Here is what CCPA/CPRA actually requires for interviews, surveys, and voice research — the service provider contract that keeps your vendor out of "sale" territory, and the enforcement record that shows what regulators punish.

Answer first: If your research vendor contract lacks the specific CCPA service provider clauses, handing them your participant list is legally a "sale" or "sharing" of personal information — which triggers opt-out rights you almost certainly are not honouring. That contract language, not your consent form, is the single highest-risk gap in most US research programmes.

The second thing to know: California enforcement in 2025–26 has not targeted exotic edge cases. It has targeted broken opt-outs, excessive verification, and missing vendor contract terms — all three of which are routine failures in research operations.

If your research reaches European participants too, read this alongside our GDPR-compliant AI user research guide. The regimes overlap but their mechanics differ sharply, and California's are less forgiving in one specific place: the paperwork with your vendors.

Does CCPA even apply to you?

The CCPA applies to for-profit businesses doing business in California that meet at least one threshold. Adjusted for inflation, the revenue threshold now stands at $26.625 million in annual gross revenue. The alternatives: buying, selling, or sharing the personal information of 100,000+ California consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information.

Two traps worth naming:

  • "Consumer" includes B2B contacts and employees. California abandoned the B2B and HR exemptions in 2023. Your enterprise buyer interviews and your employee research are both in scope. This surprises people constantly.
  • You do not need a California entity. Doing business in California is the test, and serving California customers over the internet counts.

If you are under every threshold, CCPA does not bind you today — but write your research programme to comply anyway. Crossing $26.625M in revenue should not require rebuilding your consent architecture.

The vendor contract that decides everything

This is the part of CCPA that research teams get wrong most often, and it is worth understanding precisely because the consequence is severe and invisible.

When you disclose participant personal information to an outside company — a research platform, a recruiting panel, a transcription service, an incentive fulfilment vendor — California asks what that recipient is. There are three answers:

ClassificationWhat it meansOpt-out consequence
Service provider / contractorProcesses data only for your specified purposes, under a written contract with required termsNo opt-out right triggered
Third partyAnyone who does not meet the service provider criteriaDisclosure is a "sale" or "sharing" — consumers can opt out

Here is the mechanism that catches people: the classification is created by the contract, not by the relationship. To qualify as a service provider, the transfer must be pursuant to a written contract that prohibits the recipient from retaining, using, or disclosing the personal information for any purpose other than the specific purposes named in that contract.

Without those terms, the disclosure is a sale or sharing to a third party by default — even if your vendor never does anything commercially inappropriate with the data. Good behaviour does not cure a missing clause.

Your CCPA vendor contract must:

  1. Prohibit use of the personal information beyond the specified purposes
  2. Require the vendor to provide the same level of privacy protection the CPRA requires of you
  3. Grant you rights to take reasonable steps to verify appropriate use
  4. Require the vendor to notify you if it can no longer meet its obligations
  5. Grant you rights to stop and remediate unauthorised use
  6. Bind subcontractors to equivalent terms

Your action item: pull every research vendor contract you have and check for these six terms. Recruiting panels and transcription services are the usual offenders — research platforms tend to have their paper in order, incentive and panel vendors frequently do not. A vendor who cannot produce a compliant DPA is not a procurement inconvenience; they are converting your research operations into an unreported sale of personal information.

Voice recordings, biometrics, and where the line sits

Voice research raises a question worth answering carefully, because the common assumption — "audio is biometric, therefore sensitive" — is wrong in a way that leads to unnecessary compliance theatre.

Under California law, a voice recording can qualify as biometric information if an identifier template can be extracted from it. But it constitutes sensitive personal information only when the recording is actually used to identify a consumer. Recording an interview to understand what a customer thinks about your onboarding flow is not identification. Running voiceprint matching against that audio is.

So ordinary voice research does not automatically pull you into the sensitive-personal-information regime with its additional right to limit use. What does pull you in: collecting health information, precise geolocation, racial or ethnic origin, or — added by SB 1223 and effective January 2025 — neural data.

Note also that AB 1008, effective January 2025, clarified that personal information includes data embedded in AI models and other abstract digital systems. If participant data was used to fine-tune a model, that model may itself hold personal information. This is a strong argument for research tooling that does not train on your data, and for asking vendors the question explicitly.

Where research does commonly touch sensitive categories is in screeners. A health-condition screener or an ethnicity quota question collects sensitive personal information directly — see research screener questions for how to collect only what your quotas genuinely require.

What California actually enforces

The enforcement record is the most useful compliance document available, because it shows what regulators care about rather than what commentators speculate about. Recent actions:

  • Honda — $632,500. For requiring excessive personal information to verify privacy rights requests, presenting asymmetrical privacy choices, making authorised-agent requests unnecessarily difficult, and — directly relevant here — sharing personal information with vendors without the required contract terms.
  • Healthline — $1.55 million, the largest CCPA penalty to date and the first data-minimisation enforcement action. The consent banner logged rejections while tracking continued regardless.
  • A youth sports media platform — $1.10 million, for opt-out and consumer notice failures.

Statutory penalties in 2026 run to $2,663 per violation for unintentional violations and $7,988 for intentional violations or those involving minors. Per violation means per consumer — the arithmetic across a participant database escalates quickly.

The pattern is unmistakable: asymmetrical choices, excessive verification, broken opt-outs, missing vendor contract terms, and collecting more than you need. Four of those five are ordinary research-operations failure modes.

Your compliance checklist

  1. Notice at collection, before you collect. At or before the point of collection, tell participants what categories you collect, why, how long you keep it, and whether it is sold or shared. On the recruitment screen — not in a policy they reach afterwards.
  2. Fix the vendor contracts. All six terms, every vendor, including panels and transcription.
  3. Make opt-outs real. If any disclosure is a sale or sharing, honour Global Privacy Control signals and provide a working opt-out. Honda's fine says asymmetrical choices are independently punishable.
  4. Verify proportionately. Do not demand a government ID to process a deletion request. Excessive verification is itself a violation.
  5. Minimise deliberately. Collect what the research question requires. Do not retain a full participant profile because it might be useful later — that is precisely the Healthline theory.
  6. Build deletion you can execute. A deletion request must reach transcripts, recordings, analysis artefacts, and your repository. If deletion cannot reach your insight repository, you cannot comply. See research repository guide.
  7. Honour the 45-day clock. Respond to requests within 45 days, extendable to 90 with notice.
  8. Keep a data inventory. Categories collected, sources, purposes, disclosure recipients, retention. Everything above depends on it.

How Koji helps

Compliance gets dramatically easier when the platform is designed so the compliant path is the default one:

  • Service provider by contract. Koji operates as a service provider under CCPA, with the required terms in place — your disclosure to Koji does not become a sale.
  • No training on your research data. Which keeps AB 1008's model-embedded-personal-information problem from arising in the first place.
  • Consent and notice at the front door. Koji's intake forms and consent present notice at collection before the first question, which is exactly where California requires it.
  • Per-study retention with automatic purge. Set retention when you design the study and let raw conversations expire on schedule while aggregated themes survive. Retention becomes a property of the study rather than a quarterly cleanup project.
  • Deletion that reaches everything. Because transcripts, analysis, and reports live in one system, a deletion request is one operation — not a hunt across a transcription vendor, a spreadsheet, a Notion page, and three stakeholders' downloads. That fragmentation is the real reason deletion requests go unfulfilled, and consolidation is the fix.
  • Minimisation through better instrumentation. This is where methodology and compliance align. Koji's six structured question typesopen_ended, scale, single_choice, multiple_choice, ranking, and yes_no — let you capture exactly the data point you need rather than an open field you later mine. A scale question asking satisfaction directly collects one number. A free-text field that participants fill with health details, employer names, and family circumstances collects sensitive personal information you never intended to hold and now must protect, disclose, and delete. Precise instrumentation is data minimisation implemented in the study design.

The structural contrast: legacy survey tools optimise for collecting as much as possible and sorting it out later. That instinct was harmless in 2015 and is now a liability with a per-consumer price tag.

Related Resources

Regulatory information current as of July 2026. Practitioner orientation, not legal advice — confirm your obligations with qualified privacy counsel.

Related Articles

AI Interview Data Privacy & Security: A Buyer's Evaluation Guide

How to evaluate the privacy and security of an AI customer research platform — the questions to ask about data handling, PII, retention, sub-processors, and compliance — plus how Koji approaches each one.

DPIA for User Research: When You Need One and How to Write It (2026)

A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.

The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)

AI-moderated customer interviews sit in the EU AI Act's limited-risk transparency tier, not the high-risk tier. Here is exactly what Article 50 requires from 2 August 2026, the two things that escalate a study to high-risk, and a compliance checklist you can run this week.

GDPR-Compliant AI User Research: A Practical Guide

How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.

Intake Forms and Consent

Collect participant information and consent before interviews begin with customizable form fields.

Research Consent Form Templates: GDPR-Compliant Forms for Every Study

Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.

Research Screener Questions: How to Write Questions That Find the Right Participants

Learn how to write effective screener questions that filter the right participants for your user research studies. Includes 10 proven templates, best practices, and common mistakes to avoid.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.