Last updated: 2026-10-03
On September 27, 2026, Governor Newsom approved California AB 2561 (Valencia). It was chaptered the same day as Chapter 478, Statutes of 2026 and adds §§ 22710 and 22711 to the Business and Professions Code. From January 1, 2027, an operating system or an app may not undo a privacy setting a user chose, unless the user consents or a law, court order or subpoena requires it. The bill passed the Assembly 77 to 0 on May 14, 2026 and the Senate 40 to 0 on August 26, 2026, with Assembly concurrence 79 to 0 the same day.
What does AB 2561 require?
Section 22711(a) is the rule. From the chaptered text:
An operating system or an application shall not undo a user's affirmative configuration of a privacy setting without the user's consent except as required by state or federal law, court order, or in response to a subpoena in an individual case or proceeding.
"Consent" has the CCPA meaning in Civil Code § 1798.140(h): a "freely given, specific, informed, and unambiguous indication of the consumer's wishes". Under the same subdivision, acceptance of "a general or broad terms of use, or similar document" that mixes processing descriptions with unrelated information "does not constitute consent", and "agreement obtained through use of dark patterns does not constitute consent."
Section 22711(b) "does not prohibit" a business from discontinuing a service, ceasing data collection or sharing, or ceasing to offer privacy options, where the change complies with § 22711, keeps "the current protections" or produces "an increase in privacy protection".
Which apps and settings does AB 2561 cover?
An "application" under § 22710(a) is "a software program, mobile app, or desktop app" that handles personal information of a user in California "and that provides privacy settings allowing the user to control" it. A "privacy setting" under § 22710(d) is "any user-configurable option within an application's privacy, or similarly labeled, menu" that governs how personal information is collected, used, shared, disclosed, kept or processed. The chapter leaves "operating system" undefined.
The Senate Privacy, Digital Technologies, and Consumer Protection Committee analysis for the June 8, 2026 hearing says the protection "only applies to settings that a user affirmatively configures, rather than those privacy settings that may be the default."
The Assembly Privacy and Consumer Protection Committee analysis gives one example: after the iOS 17 update in 2023, "a few privacy-savvy users noticed" that "Significant Locations" and "iPhone Analytics", which they had toggled off, "were turned back on." The analysis cites a Bitdefender blog post for that account; supporter Oakland Privacy called the practice "privacy-slamming".
When does AB 2561 take effect?
AB 2561 takes effect on January 1, 2027. The text has no operative-date clause, and the bill status page lists it as non-urgency. California Constitution article IV, § 8(c)(1) puts such a statute into effect "on January 1 next following a 90-day period from the date of enactment of the statute." For AB 2561, enacted September 27, 2026, that period ends December 26, 2026.
What was cut from AB 2561 before it passed?
The introduced bill required "the most privacy protective setting" as the default. The Assembly committee's amendments for the April 21, 2026 hearing, in print on April 23, 2026, removed it "to address opposition's concerns about the feasibility and operational impacts". TechNet, one of four registered opponents of that version (page 6), supported the August 20, 2026 version, per the Assembly concurrence analysis.
| Provision | Introduced, February 20, 2026 | Chaptered, September 27, 2026 |
|---|---|---|
| Default settings | Must be "the most privacy protective setting offered" | Removed by Assembly amendments of April 23, 2026 |
| Core rule | May not "change a user's privacy setting without the user's explicit consent" | May not "undo a user's affirmative configuration of a privacy setting without the user's consent" |
| Consent | Undefined | CCPA, Civil Code § 1798.140(h) |
| Privacy setting | Any option "within an application" | An option "within an application's privacy, or similarly labeled, menu" |
| Exceptions | None | Law, court order, subpoena (Senate floor amendments, August 20, 2026) |
| Service changes | Not addressed | § 22711(b) "does not prohibit" changes that keep or increase protection (Senate floor amendments, August 20, 2026) |
Sources: introduced, amended and chaptered texts on the compare versions page, retrieved October 3, 2026; Assembly and Senate committee analyses; Assembly concurrence analysis.
Who enforces AB 2561, and what is the penalty?
Chapter 23.1 (§§ 22710 and 22711) names no penalty, no enforcing agency and no private right of action, and the six committee and floor analyses of both houses discuss no enforcement route. The Unfair Competition Law (UCL) in the same code covers "any unlawful, unfair or fraudulent business act or practice". Section 17206 sets a civil penalty "not to exceed two thousand five hundred dollars ($2,500) for each violation" in public actions, and § 17204 limits private plaintiffs to a person who "has suffered injury in fact and has lost money or property" as a result. No court has ruled on whether a § 22711 violation supports a claim under the UCL's "unlawful" prong; § 22711 becomes operative on January 1, 2027.
Related: SB 690, operative the same day, makes California Invasion of Privacy Act pen register claims over websites and apps an Attorney General action; data brokers must process deletion requests from the Delete Act's Delete Request and Opt-out Platform.
What a CanITrustThat scan and capture show for AB 2561
AB 2561 turns on what a setting was before an update and what it is after. A rescan starts when the store listing shows a new version, and the report keeps the previous scan as a dated entry under "Changes since the previous scan", which lists new findings and findings no longer present. For an Android build, the findings include consent management SDKs present in the binary, such as Google UMP, OneTrust and Didomi, and manifest flags that set Firebase Analytics collection, ad personalization signals and Meta automatic event logging (what a scan checks). Each finding cites its file and line. A flag set differently in the new build appears in the changes list. These flags are build defaults; a value the app sets after the user's choice is outside a static scan.
To test behavior, I opt out on a test device, record the traffic, install the update and record again. If ad or analytics requests that stopped after the opt-out are sent again after the update, the captures show the hosts, payloads and timestamps. A capture records the requests the app sends; the stored value of the setting is outside it (see the limits of a scan).
I run these scans and captures for lawyers and researchers working with lawyers. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.