The Challenge
In 2018, a real estate developer named Alastair Mactaggart, with no legislative background, managed to push the California Consumer Privacy Act through a ballot initiative. Two years later, he returned with Proposition 24, aiming to expand those protections through the California Privacy Rights Act. This posed a unique problem for compliance teams: how do you prepare for regulations driven by a single advocate rather than legislative committees or industry coalitions?
Mactaggart's approach bypassed the usual negotiation process where industry stakeholders help shape implementation details. Compliance teams faced a binary outcome: either the California Privacy Rights Act would pass as written, or it wouldn't pass at all. You couldn't lobby for amendments or push for extended timelines. The usual tools of regulatory engagement didn't apply.
This created a planning vacuum. Your legal team couldn't draft implementation roadmaps based on draft language that might change. Your engineering team couldn't start building systems around requirements that might be negotiated down. And your budget holders couldn't model costs against a range of possible outcomes.
The Environment and Constraints
The vote on Proposition 24 occurred in a divided advocacy landscape. Traditional consumer groups didn't uniformly support the measure. Some argued it didn't go far enough; others worried it locked in protections that could have been stronger through legislative amendment. Industry groups were also split, with some preferring the certainty of a ballot measure over the unpredictability of ongoing legislative battles.
For compliance teams, this created an information problem. You couldn't rely on industry associations for unified guidance because they hadn't reached consensus. You couldn't assume consumer advocates would signal what regulators might prioritize because they were divided on whether the law should exist at all.
Timing added to the challenge. The California Consumer Privacy Act had only been in effect since January 2020. Your team was still working through first-generation compliance builds: consent management platforms, data mapping exercises, DSAR workflows. Now you faced the possibility of a second wave of requirements before you'd finished implementing the first.
Unlike GDPR, where you had two years between passage and enforcement, ballot initiatives work differently. If Proposition 24 passed, the California Privacy Rights Act would become law immediately, with most provisions taking effect January 1, 2023. That's a compressed timeline when you're building cross-functional programs that touch every system handling California resident data.
The Approach Compliance Teams Took
Smart compliance teams didn't wait for the vote. They ran dual-track planning: one roadmap assuming Proposition 24 would pass, another assuming it wouldn't. This meant identifying which California Consumer Privacy Act improvements would be valuable regardless of the outcome and which were specific bets on the California Privacy Rights Act.
For example, improving your data inventory was a safe investment either way. If Proposition 24 failed, you'd still need comprehensive data mapping for California Consumer Privacy Act compliance. If it passed, you'd need that same inventory to support new rights like correction and limitation of use. So you accelerated that work.
But building new technical infrastructure for sensitive personal information categories was a riskier bet. The California Privacy Rights Act would create new obligations around this data, but if Proposition 24 failed, you'd have built systems for requirements that didn't exist. Some teams made that bet anyway, reasoning that the direction of travel was clear even if this particular measure didn't pass.
The smartest teams also started stakeholder education early. They didn't wait for the vote to explain what the California Privacy Rights Act would require. Instead, they used the uncertainty productively: "Here's what might be coming, and here's what we should do now to be ready either way." That framing made it easier to secure budget and engineering time without triggering panic about another compliance overhaul.
Results and Metrics
Proposition 24 passed in November 2020, enacting the California Privacy Rights Act. For teams that had prepared, this meant they could move directly into detailed implementation planning. They'd already secured stakeholder buy-in, started foundational work like data inventory improvements, and educated their organizations about what was coming.
For teams that had waited, the compressed timeline became painful. You now had roughly two years to build systems supporting new rights, establish a California Privacy Protection Agency relationship framework, and train staff on expanded obligations, all while maintaining California Consumer Privacy Act compliance.
The lesson wasn't that you should build speculatively for every possible regulation. It's that when you see an advocate with Mactaggart's track record pushing a measure, you should treat it as a high-probability scenario worth planning for, not a distant possibility you can ignore until it becomes law.
What Teams Would Do Differently
In retrospect, compliance teams underestimated how ballot initiatives change the regulatory game. When privacy laws come through legislatures, you get advance signals: committee hearings, draft language, industry comment periods. You can plan incrementally as the bill moves through the process.
Ballot initiatives compress all that into a single vote. You don't get iterative signals. You get a binary outcome on a fixed date. That requires a different planning approach: scenario modeling rather than incremental response.
Teams also underestimated the importance of tracking individual advocates. Mactaggart wasn't a one-time actor. He'd already succeeded with the California Consumer Privacy Act. When he returned with Proposition 24, that track record should have been a strong signal. Yet many compliance teams treated it as just another ballot measure rather than a high-probability regulatory change.
The other mistake was waiting for industry guidance. When advocacy groups are divided and industry associations haven't reached consensus, you can't outsource your analysis. You need to read the actual text of the proposition, model its impact on your systems, and make your own risk assessment.
Takeaways for Your Team
First, track individuals, not just institutions. Privacy regulation increasingly comes from persistent advocates operating outside traditional policy channels. When someone like Mactaggart demonstrates they can force regulatory change through ballot initiatives, treat their next effort as a serious probability, not a speculative risk.
Second, build dual-track plans when facing binary regulatory outcomes. Identify which improvements are valuable regardless of the outcome and accelerate those. Then make explicit bets on higher-risk investments, but frame them as bets so stakeholders understand the uncertainty.
Third, don't wait for industry consensus before planning. When advocacy groups are divided and trade associations haven't aligned, that's a signal to do your own analysis, not to wait for someone else to tell you what to think.
Finally, recognize that ballot initiatives require different planning than legislative processes. You can't rely on iterative signals or assume you'll have time to respond once draft language emerges. You need to plan earlier, with less information, and accept more uncertainty in your roadmap.
The California Privacy Rights Act wasn't the last time privacy regulation will come through unconventional channels. Your ability to spot these patterns early and plan accordingly will determine whether you're ready when the vote happens or scrambling to catch up after.



