What is CCPA?
Understanding California's Consumer Privacy Act: rights, requirements, and compliance
Quick answer
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights over personal information and imposes notice, request-handling, opt-out, contracting, and security obligations on covered businesses.
- Current revenue threshold
- $26.625M
- Data-volume threshold
- 100,000 residents or households
- Request response
- Generally 45 days
Reviewed against official sources on August 11, 2026. This guide is general information, not legal advice.
CCPA Definition
The California Consumer Privacy Act (CCPA) is a state-level data privacy law that went into effect on January 1, 2020. It gives California residents new rights over their personal information and imposes obligations on businesses that collect consumer data.
California voters approved the California Privacy Rights Act (CPRA) in 2020. Its principal amendments became operative in 2023, adding rights and creating the California Privacy Protection Agency. CPRA amended the CCPA rather than creating a separate privacy law.
Key Fact:
CCPA is often called "GDPR for California" but has significant differences in scope, rights, and enforcement.
Who Must Comply with CCPA?
CCPA applies to for-profit businesses that do business in California, determine why and how covered personal information is processed, and meet at least one of these criteria:
Gross annual revenue of $26.625 million or more for the preceding calendar year
Buys, sells, or shares the personal information of 100,000 or more California residents or households
Derives 50% or more of annual revenue from selling or sharing California residents' personal information
Important: A business does not need to be headquartered in California to be covered. The full definition includes additional conditions, and some controlled entities, joint ventures, service providers, and contractors have related obligations.
Consumer Rights Under CCPA
The CPPA summarizes six major privacy rights for California residents:
Right to Know
Request disclosure of personal information collected, used, or sold
Right to Delete
Request deletion of personal information held by businesses
Right to Opt-Out
Opt-out of the sale or sharing of personal information
Right to Equal Treatment
Equal service and pricing regardless of exercising rights
Right to Correct
Request correction of inaccurate personal information
Right to Limit
Limit certain uses and disclosures of sensitive personal information
What is Personal Information Under CCPA?
CCPA defines personal information broadly as information that identifies, relates to, or could reasonably be linked to a California consumer or household. This includes:
- Identifiers (name, email, IP address)
- Commercial information (purchase history)
- Biometric data
- Internet activity (browsing history)
- Geolocation data
- Professional information
- Education information
- Inferences about preferences
- Sensitive personal information
- Audio, video, thermal data
CCPA Compliance Requirements
Businesses subject to CCPA must:
1. Provide Privacy Notice
Disclose what categories of personal information are collected, sources, purposes, and whether it's sold or shared.
- Must be posted at or before collection
- Privacy-policy disclosures must be reviewed and updated at least annually
- Notices should be easy to read and available through the required channels
2. Honor Consumer Requests
Respond to consumer requests for access, deletion, correction, and opt-out within specified timeframes.
- Verify consumer identity before responding
- Confirm receipt of requests to know, delete, or correct within 10 business days and generally respond within 45 calendar days
- Provide the required request methods; an exclusively online business has a narrower email-only rule
3. Provide "Do Not Sell or Share" Link
If you sell or share personal information, provide the required opt-out method and honor qualifying preference signals such as Global Privacy Control. A combined "Your Privacy Choices" link may be used when it meets the regulations.
4. Train Employees
Train employees who handle consumer inquiries about CCPA requirements and how to respond to requests.
5. Implement Reasonable Security
Maintain reasonable security procedures to protect consumer personal information from unauthorized access.
Put the requirements into practice
Draft disclosures around your California data practices
Answer guided questions about personal information, purposes, selling or sharing, sensitive data, vendors, retention, and consumer request methods. Review the draft against your actual operations before publishing.
- Guided questions
- Editable draft
- Free to start
CCPA Penalties and Enforcement
Civil Penalties
Up to $2,663 per violation
Current CPI-adjusted administrative or civil penalty ceiling for each violation
Intentional Violations
Up to $7,988 per violation
For intentional violations and qualifying violations involving consumers known to be under 16
Private Right of Action
$107-$799 per consumer per incident
Current CPI-adjusted statutory range, or actual damages if greater, for the CCPA's limited private action involving certain security breaches
CCPA vs GDPR: Key Differences
| Aspect | CCPA | GDPR |
|---|---|---|
| Scope | Covered personal information of California residents | Processing connected with an EU establishment or covered activities involving people in the EU |
| Consent | Notice plus opt-out for sale/sharing; consent applies in specific cases | A lawful basis is required; consent is one of six bases |
| Right to Delete | More exceptions allowed | Broader right to erasure |
| Max Penalty | Up to $7,988 for intentional violations | €20M or 4% of worldwide annual turnover |
| Enforcement | State attorney general + CPPA | Data protection authorities |
Steps to CCPA Compliance
- Assess applicability: Determine if your business meets CCPA thresholds
- Data inventory: Map what personal information you collect and where it flows
- Update privacy information: Add the notices and disclosures required for your practices
- Add privacy choices: Implement sale/sharing opt-out, qualifying preference signals, and sensitive-information limits where applicable
- Create request portal: Set up process for consumers to submit requests
- Implement verification: Establish procedures to verify consumer identity
- Train staff: Educate employees on CCPA requirements and procedures
- Review contracts: Update service provider and vendor agreements
- Monitor the program: Test request flows, review disclosures at least annually, and update processes as practices or rules change
Ready to document your practices
Create a privacy policy draft informed by your CCPA review
Use PolicyForge to organize the disclosures, then verify the draft against your data inventory, request flows, contracts, opt-out controls, and applicable legal requirements.
- Free to start
- Editable before publishing
- Not a substitute for legal advice
Related Articles
What is GDPR?
Learn about Europe's General Data Protection Regulation and requirements
What is EU AI Act?
Understand Europe's groundbreaking AI regulation
CCPA Compliance Generator
Review key CCPA considerations and identify policy disclosures to examine
GDPR vs CCPA Comparison
Side-by-side comparison of GDPR and CCPA requirements