Back to the hub

California AB 566: what does the browser opt-out signal law require?

California Civil Code 1798.136, added by AB 566, bars a business from developing or maintaining a browser that lacks consumer-configurable functionality to send an opt-out preference signal. The control must be easy to locate and configure. The section became effective January 1, 2026 and becomes operative January 1, 2027.

Applies to: A business, as the CCPA defines that term, that develops or maintains a browser used by consumers to locate, access and navigate websites. It does not create new duties for businesses that merely receive the signal.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Every universal opt-out rule written so far has pointed at the business receiving the signal. AB 566 points the other way. It puts a duty on whoever makes the browser to ship the switch in the first place, which closes the gap where a consumer has an opt-out right but no practical way to exercise it.

What the statute actually says

Civil Code 1798.136 is short. The operative rule is in subdivision (a)(1): a business shall not develop or maintain a browser that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal to businesses with which the consumer interacts through the browser.

Subdivision (a)(2) adds a usability standard. That functionality shall be easy for a reasonable person to locate and configure. This is the part most likely to matter in practice, because a setting buried six screens deep would satisfy the first sentence and fail the second.

Subdivision (b) is a separate disclosure duty. A business that develops or maintains a browser shall make clear to a consumer in its public disclosures how the opt-out preference signal works and the intended effect of the signal.

Subdivision (c) gives the California Privacy Protection Agency authority to adopt regulations as necessary to implement and administer the section, so the detail may well grow before the operative date.

The two definitions that decide scope

Subdivision (e) supplies both terms, and they are narrower than they first look.

A browser means an interactive software application that is used by consumers to locate, access, and navigate internet websites. An opt-out preference signal means a signal that complies with this title and that communicates the consumer's choice to opt out of the sale and sharing of the consumer's personal information.

The other scoping word is the one the statute inherits rather than defines. The duty falls on "a business," which is the CCPA's own defined term. So the ordinary CCPA thresholds gate who is covered, and the section reaches businesses in their capacity as browser developers rather than creating a standalone category of regulated browser vendors.

The dates, which are not the same date

This trips people up because the section carries two.

The section became effective January 1, 2026, as part of the ordinary operation of the 2025 legislative session. The obligation becomes operative January 1, 2027. Subdivision (f) says so directly, and the codified version line repeats it: added by Stats. 2025, Ch. 465, Sec. 2 (AB 566), effective January 1, 2026, operative January 1, 2027, by its own provisions.

The practical reading is that the law is on the books now and enforceable against browser conduct from the start of 2027.

The safe harbor

Subdivision (d) is the provision browser developers will care about most. A business that develops or maintains a browser that includes the signal functionality shall not be liable for a violation of this title by a business that receives the opt-out preference signal.

In other words, shipping the switch does not make you responsible for the websites that ignore it. That allocation is deliberate and it keeps the enforcement target where it already sits, on the receiving business.

What this changes for everyone else

If you run a website rather than a browser, AB 566 imposes nothing new on you. Your obligation to honor an opt-out preference signal already exists and already applies, and it is unaffected by the 2027 date. That duty is set out in the CCPA regulations and is covered in does the CCPA require honoring Global Privacy Control.

What does change is volume. Today the signal reaches a business only when a consumer has gone looking for a browser or extension that sends one. From 2027, browsers covered by the section have to offer it as a built-in, easy-to-find setting. Any business that has been quietly under-investing in signal handling because the traffic was small should plan for that number to rise.

The wider picture of which states impose a duty to honor these signals, and from when, is in universal opt-out signals by state.

Compliance checklist

  • Determine whether you meet the CCPA definition of a business, because Section 1798.136 uses that term and it gates who is covered.
  • If you ship anything that lets consumers locate, access and navigate websites, test it against the statutory definition of browser in subdivision (e)(1).
  • Build the opt-out preference signal control so a reasonable person can locate and configure it, which is the standard subdivision (a)(2) sets.
  • Publish a plain description of how the signal works and its intended effect, which is the separate public disclosure duty in subdivision (b).
  • Keep honoring inbound opt-out preference signals under the existing CCPA regulations, since AB 566 does not change or delay that duty.

Sources

Last verified: 2026-09-10

Informational, not legal advice.