All posts
Guides·12 min read

CCPA, CPRA & the US State-Privacy Patchwork: What AI Customer Service Means for Your Data in 2026

King Mak·Founder & CEO, Omago·
Map of US state privacy laws affecting AI customer service chat data compliance

There is no single US federal privacy law — instead there are 20 active state laws, with Indiana, Kentucky, and Rhode Island all going live on January 1, 2026 (IAPP, 2026). If you run an AI agent that handles customer conversations, the short answer is this: you must comply with the strictest state where your customers live, and your chat logs count as personal information. This guide walks through what CCPA and CPRA actually require of a small business, what counts as a violation, and the handful of operational things that get companies fined.


How many state privacy laws are there in 2026, and which ones matter?

As of May 2026, 20 US states have an active comprehensive consumer privacy law, with one more enacted but not yet effective and 30 states plus D.C. with none (PrivacyLawMap, 2026). The three newest — Indiana, Kentucky, and Rhode Island — all took effect on January 1, 2026 (IAPP, 2026). That patchwork is the whole story: there is no overarching federal law to fall back on, so your obligations depend on where your customers are.

California started this in 2018 with the CCPA. Virginia and Colorado followed in 2021, Utah and Connecticut in 2022, seven states in 2023, and seven more in 2024. No brand-new comprehensive laws were enacted in 2025, but nine states amended their existing ones that year — California, Colorado, Connecticut, Kentucky, Montana, Oregon, Texas, Utah, and Virginia (Future of Privacy Forum, October 2025). The rules are not just spreading; the established ones are tightening.

For most small businesses, the practical move is to comply with the strictest standard you're exposed to — usually California's — and apply it everywhere. Trying to maintain a different data policy for each state is a losing game when you have a handful of staff and a chat widget. The authoritative scorecard to bookmark is the IAPP US State Privacy Legislation Tracker, which counts only laws meant as comprehensive frameworks, so it's the cleanest reference when you need to check who's covered.

Does CCPA apply to my small business?

The CCPA applies to a for-profit business doing business in California that meets at least one of three thresholds. Those are: gross annual revenue over $26.625 million (effective January 1, 2025), processing the personal data of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information (Jackson Lewis, 2026). If none of those describe you, the CCPA itself may not bind you yet.

But don't exhale too fast. The 100,000-consumer threshold is easier to cross than owners assume once you count website visitors, email subscribers, and chat sessions over a year — "consumers" is broad, and a household counts too. And several other states set their own thresholds, some lower, so a business below California's bar can still land inside Colorado's or Connecticut's reach.

The honest takeaway for a time-poor owner: if you serve US customers across state lines and run any kind of data-collecting tool, assume you'll cross at least one threshold and build clean habits now. Retrofitting consent and deletion logic after you've grown is far more painful than starting tidy. None of this is legal advice — for your exact numbers, a short conversation with counsel beats guessing.

What do CCPA and CPRA require when an AI agent handles customer data?

CCPA and CPRA give California residents five core rights: to know, to delete, to correct, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information (California Attorney General, 2026). When an AI agent sits between you and your customers, every one of those rights touches the data it collects. Chat transcripts, the inferences drawn from them, and any AI-generated customer profiles all qualify as personal information.

That last point trips people up. Owners think "personal information" means a credit card number or a Social Security number. Under CCPA it's much wider — a conversation where someone gives their name, describes their problem, and shares an address is personal information, and so is the profile your system builds from it. If an AI agent is logging and learning from those chats, that data is squarely in scope.

So the operational requirements are concrete. You need to be able to tell a customer what you've collected (the right to know), delete it on request (the right to delete, with a 45-day window to respond), correct it, and honor opt-out requests for any sale or sharing. The tools you choose should make those actions possible, not impossible. This is also why an AI agent like Omago, an AI agent platform that helps SMEs automate customer conversations across WhatsApp, Telegram, and web chat, is worth evaluating partly on its data controls — not just its conversational quality.

How long can I keep customer chat logs, and what do I have to disclose?

You must disclose, at or before the point of collection, how long you retain each category of personal information — or the criteria you use to decide — and you cannot keep data longer than reasonably necessary for the disclosed purpose (Clym, 2026). CCPA and CPRA do not set a fixed number of days; they require that you state your retention rule and then live by it.

In plain terms, that means two things for a small business running a chatbot. First, your privacy notice needs a line about how long chat conversations are stored — even "we retain customer chat logs for 24 months, then delete" is enough, as long as it's true and you follow it. Second, you need the operational ability to actually delete that data when someone asks, within the 45-day response window the CCPA allows.

The failure mode is common and avoidable: an AI tool stores every conversation indefinitely, nobody wrote a retention period into the privacy policy, and there's no button to delete a customer's history. That's a compliance gap sitting in plain sight. Here's a short checklist to close it:

  1. Write a retention period (or the criteria for one) into your privacy notice, covering chat logs specifically.
  2. Confirm your AI tool can export and delete an individual customer's conversation data on request.
  3. Set an automatic purge so old logs don't pile up past your stated period.
  4. Keep a simple record of deletion requests and when you honored them.
  5. Disclose, before or at collection, that the chat is recorded and how long it's kept.

A related rule worth flagging: the California Privacy Protection Agency (CPPA) adopted automated decision-making technology (ADMT) regulations in 2025, with key provisions becoming applicable January 1, 2026 (IAPP, 2026). ADMT is defined broadly enough that AI agents processing personal information to make or facilitate decisions could fall inside it. The exact scope and enforcement are still developing through 2026, so treat this as an evolving area to watch rather than a settled rulebook.

What happens if I get it wrong? CCPA penalties and real 2025 fines

CCPA penalties run from $2,500 per unintentional violation to $7,500 per intentional violation — and each affected consumer can count as a separate violation (Jackson Lewis, 2026). That per-consumer multiplier is what turns a paperwork slip into a real number: a broken opt-out affecting a few thousand people scales fast.

This stopped being theoretical in 2025. California's CPPA fined American Honda $632,500 in March 2025 and clothing retailer Todd Snyder $345,178 in May 2025, primarily for misconfigured opt-out mechanisms and for over-collecting identity verification on privacy requests (Cooley, 2025). Notice what got them: not some exotic data breach, but the plumbing — the opt-out buttons and the request-handling process. That's exactly the layer an AI customer-service tool touches.

The lesson for a small business is reassuring in one way and sobering in another. Reassuring, because you don't need a six-figure compliance program to stay clean — you need working opt-outs, a stated retention period, and the ability to honor deletion and access requests. Sobering, because those are operational details that quietly break, and an AI agent that mishandles them can manufacture the exact failure that draws a fine. Choose tools that make the right thing the default.

Do I have to tell customers they're talking to a bot? (And what about SB 243?)

In California, SB 1001 (effective 2019) requires disclosure when a bot is used to knowingly deceive a person in order to incentivize a sale or influence a vote — so undisclosed bots used to manipulate a transaction are off-limits. The newer SB 243 (effective January 1, 2026) regulates "companion chatbots" but explicitly exempts bots used only for customer service and business operations (Perkins Coie, 2026). A customer-service AI agent is not a companion chatbot, and that distinction matters.

That exemption is genuinely good news for small businesses, and it's worth stating plainly because a lot of online commentary blurs it: SB 243's companion-chatbot rules — built for emotional-relationship bots — do not apply to an AI agent that answers questions, captures leads, and books appointments. You are not suddenly subject to companion-bot obligations because you added a support chatbot.

That said, transparency is still the right default. Several state bills introduced in 2025 point toward simply telling users they're interacting with AI, and customers generally appreciate the honesty. A one-line "You're chatting with our AI agent — a human can step in anytime" costs you nothing and builds trust. For more on where AI should hand off to a person, the trade-offs in AI agent versus live chat versus chatbot are worth a read.

State privacy-law matrix: the numbers at a glance

Here's the landscape in one table, with every figure tied to a named source so you can verify it.

Metric Value Source / Year
Active comprehensive state laws 20 (+1 enacted, not yet effective) PrivacyLawMap, May 2026
New laws effective Jan 1, 2026 Indiana, Kentucky, Rhode Island IAPP, 2026
First comprehensive law California CCPA (enacted 2018) IAPP, 2026
States that amended laws in 2025 9 (CA, CO, CT, KY, MT, OR, TX, UT, VA) Future of Privacy Forum, Oct 2025
Core consumer rights Know, delete, correct, opt out of sale/share, limit sensitive PI use CA Attorney General, 2026
CCPA penalty range $2,500 (unintentional) – $7,500 (intentional) per violation Jackson Lewis, 2026
Largest 2025 CPPA fines Honda $632,500; Todd Snyder $345,178 Cooley / CPPA, 2025

A few things to read off this table. The count of active laws — 20 — is the figure that keeps moving, so always check the "as of" date; some trackers say 19 versus 20 depending on whether they count narrower laws, which is why the IAPP tracker is the citation of record. The amendment activity in 2025 is the quiet story: even where no new law passed, nine states sharpened the ones they had, so "we checked the rules last year" is not a safe position.

And the penalty math is the part to internalize. Per violation, per consumer. A misconfigured opt-out isn't one fine — it's potentially one fine per person it affected. That structure is precisely why the operational details, not the grand strategy, are where small businesses get burned.

What can AI actually do here — and what it can't?

An AI agent can help you comply, but it cannot make you compliant on its own. What it can genuinely do: log conversations consistently so you can honor access and deletion requests, apply a retention rule automatically so old chats get purged on schedule, surface a clear "you're talking to AI" disclosure, and route opt-out or data requests to the right place instead of letting them vanish in an inbox. Done well, automation makes the boring compliance plumbing reliable — which, as the 2025 fines showed, is exactly where things break.

What AI cannot do is decide your policy, write your privacy notice, or absolve you of responsibility. The retention period is your business decision. The privacy notice is your legal document. If your AI tool stores data in a way you haven't disclosed, that's on you, not the vendor. And no chatbot can interpret which state laws apply to your customer base — that's a judgment call, and for anything ambiguous, counsel is cheaper than a CPPA enforcement action.

Be skeptical of any vendor that markets a tool as "CCPA compliant" out of the box. Compliance is a property of how you operate, not a feature you switch on. The right question to ask a provider isn't "are you compliant?" — it's "can your tool delete a specific customer's data on request, enforce a retention period, and show me a record of opt-outs?" If the honest answer to those is yes, the tool is helping. If it's vague, keep looking. For a structured way to vet vendors on exactly these points, see the SME buyer's checklist for AI customer service.

A practical compliance starting point for SMEs

If you take nothing else from this, take the operational shortlist. These are the moves that map directly to the failures regulators actually fined in 2025, and they're achievable for a small team:

  • Default to the strictest standard. Treat California's CCPA/CPRA as your baseline and apply it to all US customers rather than slicing policy by state.
  • State your retention period. Add a plain line to your privacy notice about how long you keep chat logs, and make sure your AI tool can enforce it.
  • Make opt-outs and deletion actually work. Test the buttons. A broken opt-out is the single most-fined failure — Honda and Todd Snyder both got caught on request-handling, not data theft.
  • Don't over-collect on verification. Asking for too much ID to process a privacy request was part of why Todd Snyder was fined; collect only what you reasonably need.
  • Disclose the AI. SB 243's companion-bot rules don't cover customer service, but telling people they're chatting with an AI agent is good practice and cheap insurance.
  • Watch the moving pieces. ADMT rules and amended state laws are evolving through 2026 — recheck the IAPP tracker periodically rather than assuming last year's setup still holds.

This is the unglamorous work, and it's also where the real risk lives. The companies that get fined aren't usually the reckless ones — they're the ones whose opt-out quietly stopped working and nobody noticed. An AI agent that handles your customer conversations should make that plumbing more reliable, not less. Evaluate accordingly, and you'll be ahead of most of your competitors who haven't read past the headlines.

Frequently Asked Questions

Do chat logs count as personal information under CCPA?

Yes. Chat transcripts, the inferences drawn from them, and any AI-generated customer profiles all qualify as personal information under the CCPA. If your AI agent records and learns from customer conversations that include names, contact details, or descriptions of someone's situation, that data is in scope and subject to access, deletion, and retention rules.

How long can I keep customer chat logs?

There's no fixed legal limit. CCPA and CPRA require you to disclose your retention period (or the criteria you use to set it) at or before collection, and to not keep data longer than reasonably necessary for that disclosed purpose (Clym, 2026). Practically, write a retention period into your privacy notice — and make sure your AI tool can actually delete data when that period ends or when a customer asks.

Does the SB 243 companion-chatbot law cover my customer-service bot?

No. SB 243 (effective January 1, 2026) regulates companion chatbots but explicitly exempts bots used only for customer service and business operations (Perkins Coie, 2026). A customer-service AI agent is not a companion chatbot, so those specific obligations don't apply. Telling customers they're talking to AI is still good practice, though.

What are the CCPA fines for a small business?

Penalties run from $2,500 per unintentional violation to $7,500 per intentional violation, and each affected consumer can count as a separate violation (Jackson Lewis, 2026). In 2025 the CPPA fined Honda $632,500 and Todd Snyder $345,178 — mostly for broken opt-out mechanisms and over-collecting verification data, not for data breaches (Cooley, 2025).

Do I have to comply if I'm not based in California?

Possibly. The CCPA applies to businesses doing business in California that meet a revenue, volume, or data-sale threshold (Jackson Lewis, 2026), and 20 states now have their own comprehensive laws (PrivacyLawMap, 2026). If you serve customers across state lines, the safest approach is to comply with the strictest law that reaches your customer base — often California's — and apply it everywhere. This isn't legal advice; check your specific situation with counsel.

Sources: PrivacyLawMap (2026), IAPP US State Privacy Legislation Tracker (2026), Future of Privacy Forum (October 2025), California Attorney General (2026), Jackson Lewis (2026), Cooley/CPPA (2025), Clym (2026), Perkins Coie (2026).

Ready to try Omago?

Set up your AI agent in minutes. Free to start, no credit card required.