California Privacy Law

    What is CCPA?

    Understanding California's Consumer Privacy Act: rights, requirements, and compliance

    Reviewed: August 202610 min read
    Quick answer

    Quick answer

    The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights over personal information and imposes notice, request-handling, opt-out, contracting, and security obligations on covered businesses.

    Current revenue threshold
    $26.625M
    Data-volume threshold
    100,000 residents or households
    Request response
    Generally 45 days

    Reviewed against official sources on August 11, 2026. This guide is general information, not legal advice.

    CCPA Definition

    The California Consumer Privacy Act (CCPA) is a state-level data privacy law that went into effect on January 1, 2020. It gives California residents new rights over their personal information and imposes obligations on businesses that collect consumer data.

    California voters approved the California Privacy Rights Act (CPRA) in 2020. Its principal amendments became operative in 2023, adding rights and creating the California Privacy Protection Agency. CPRA amended the CCPA rather than creating a separate privacy law.

    Key Fact:

    CCPA is often called "GDPR for California" but has significant differences in scope, rights, and enforcement.

    Who Must Comply with CCPA?

    CCPA applies to for-profit businesses that do business in California, determine why and how covered personal information is processed, and meet at least one of these criteria:

    1

    Gross annual revenue of $26.625 million or more for the preceding calendar year

    2

    Buys, sells, or shares the personal information of 100,000 or more California residents or households

    3

    Derives 50% or more of annual revenue from selling or sharing California residents' personal information

    Important: A business does not need to be headquartered in California to be covered. The full definition includes additional conditions, and some controlled entities, joint ventures, service providers, and contractors have related obligations.

    Consumer Rights Under CCPA

    The CPPA summarizes six major privacy rights for California residents:

    Right to Know

    Request disclosure of personal information collected, used, or sold

    Right to Delete

    Request deletion of personal information held by businesses

    Right to Opt-Out

    Opt-out of the sale or sharing of personal information

    Right to Equal Treatment

    Equal service and pricing regardless of exercising rights

    Right to Correct

    Request correction of inaccurate personal information

    Right to Limit

    Limit certain uses and disclosures of sensitive personal information

    What is Personal Information Under CCPA?

    CCPA defines personal information broadly as information that identifies, relates to, or could reasonably be linked to a California consumer or household. This includes:

    • Identifiers (name, email, IP address)
    • Commercial information (purchase history)
    • Biometric data
    • Internet activity (browsing history)
    • Geolocation data
    • Professional information
    • Education information
    • Inferences about preferences
    • Sensitive personal information
    • Audio, video, thermal data

    CCPA Compliance Requirements

    Businesses subject to CCPA must:

    1. Provide Privacy Notice

    Disclose what categories of personal information are collected, sources, purposes, and whether it's sold or shared.

    • Must be posted at or before collection
    • Privacy-policy disclosures must be reviewed and updated at least annually
    • Notices should be easy to read and available through the required channels

    2. Honor Consumer Requests

    Respond to consumer requests for access, deletion, correction, and opt-out within specified timeframes.

    • Verify consumer identity before responding
    • Confirm receipt of requests to know, delete, or correct within 10 business days and generally respond within 45 calendar days
    • Provide the required request methods; an exclusively online business has a narrower email-only rule

    3. Provide "Do Not Sell or Share" Link

    If you sell or share personal information, provide the required opt-out method and honor qualifying preference signals such as Global Privacy Control. A combined "Your Privacy Choices" link may be used when it meets the regulations.

    4. Train Employees

    Train employees who handle consumer inquiries about CCPA requirements and how to respond to requests.

    5. Implement Reasonable Security

    Maintain reasonable security procedures to protect consumer personal information from unauthorized access.

    Put the requirements into practice

    Draft disclosures around your California data practices

    Answer guided questions about personal information, purposes, selling or sharing, sensitive data, vendors, retention, and consumer request methods. Review the draft against your actual operations before publishing.

    • Guided questions
    • Editable draft
    • Free to start

    CCPA Penalties and Enforcement

    Civil Penalties

    Up to $2,663 per violation

    Current CPI-adjusted administrative or civil penalty ceiling for each violation

    Intentional Violations

    Up to $7,988 per violation

    For intentional violations and qualifying violations involving consumers known to be under 16

    Private Right of Action

    $107-$799 per consumer per incident

    Current CPI-adjusted statutory range, or actual damages if greater, for the CCPA's limited private action involving certain security breaches

    CCPA vs GDPR: Key Differences

    AspectCCPAGDPR
    ScopeCovered personal information of California residentsProcessing connected with an EU establishment or covered activities involving people in the EU
    ConsentNotice plus opt-out for sale/sharing; consent applies in specific casesA lawful basis is required; consent is one of six bases
    Right to DeleteMore exceptions allowedBroader right to erasure
    Max PenaltyUp to $7,988 for intentional violations€20M or 4% of worldwide annual turnover
    EnforcementState attorney general + CPPAData protection authorities

    Steps to CCPA Compliance

    1. Assess applicability: Determine if your business meets CCPA thresholds
    2. Data inventory: Map what personal information you collect and where it flows
    3. Update privacy information: Add the notices and disclosures required for your practices
    4. Add privacy choices: Implement sale/sharing opt-out, qualifying preference signals, and sensitive-information limits where applicable
    5. Create request portal: Set up process for consumers to submit requests
    6. Implement verification: Establish procedures to verify consumer identity
    7. Train staff: Educate employees on CCPA requirements and procedures
    8. Review contracts: Update service provider and vendor agreements
    9. Monitor the program: Test request flows, review disclosures at least annually, and update processes as practices or rules change

    Ready to document your practices

    Create a privacy policy draft informed by your CCPA review

    Use PolicyForge to organize the disclosures, then verify the draft against your data inventory, request flows, contracts, opt-out controls, and applicable legal requirements.

    • Free to start
    • Editable before publishing
    • Not a substitute for legal advice

    Related Articles

    What is GDPR?

    Learn about Europe's General Data Protection Regulation and requirements

    What is EU AI Act?

    Understand Europe's groundbreaking AI regulation

    CCPA Compliance Generator

    Review key CCPA considerations and identify policy disclosures to examine

    Blog Post

    GDPR vs CCPA Comparison

    Side-by-side comparison of GDPR and CCPA requirements