What is the CCPA? Overview and Compliance Requirements for the California Consumer Privacy Act

Close
Read time
14 mins
Published
Aug 25, 2026
Share
  • The CCPA gives California consumers the right to know, delete, and correct their personal information, and to opt out of its sale or sharing.
  • It applies to for-profit businesses that meet a revenue, data-volume, or data-sale threshold, regardless of where the business is based.
  • The CPRA expanded the CCPA and created the California Privacy Protection Agency (CPPA) to enforce it alongside the Attorney General.
  • New ADMT regulations, effective January 1, 2026, add a consumer right to opt out of automated decision-making used in significant decisions.
  • Non-compliance penalties currently run up to $7,988 per intentional violation, plus statutory damages for data breaches.

California was one of the first states in the United States to enshrine privacy as an “inalienable right” of all people when it amended its constitution in 1972.

On January 1, 2020, California became the first state to enact a data privacy law to empower its residents with ownership over their personal information and change the way businesses handle this personal information.

We look at the California privacy law, what it means for your business and website, and steps you can take to support ongoing compliance.

What Is the CCPA?

The California Consumer Privacy Act (CCPA) is the first comprehensive modern data privacy law in the United States, and came into effect January 1, 2020. It grants California residents specific rights over their personal information and requires covered businesses to provide transparency and control over how that information is collected, used, and shared.

What Is the CPRA?

The California Privacy Rights Act (CPRA) amended and expanded the CCPA, enhancing consumer privacy rights for the state's residents, tightening requirements for businesses that collect and share personal information, and creating a new government agency to enforce California's privacy laws.

The CPRA took effect on January 1, 2023, and enforcement began in February 2024 after a legal challenge delayed the original enforcement date of July 2023.

Who Does the CCPA Protect?

The CCPA, as amended by the CPRA, protects the state’s nearly 40 million residents, known as consumers under the law.

A consumer is a natural person who is either:

  • In the state for other than a temporary or transitory purpose, or
  • Domiciled in the state, but temporarily outside of the state, such as on a vacation or business trip

It is not enough to simply be located in the state when having one’s data collected — individuals must meet the definition of California resident under the law. Those who are simply passing through, visiting on vacation, or in the state to complete a particular transaction or perform a particular contract are considered to be in the state for temporary or transitory purposes and are not protected by the CCPA/CPRA. This definition is likely to evolve over time, particularly based on case law resulting from lawsuits relating to alleged violations.

The CCPA/CPRA protects the personal information of California residents even when they are temporarily outside the state.

Who Does the CCPA Apply To?

The CCPA/CPRA applies to for-profit businesses that operate in California and collect the personal information of its residents, if they meet at least one of the following thresholds:

  • Earn gross annual revenue exceeding USD 26,625,000
  • Buy, sell, or share the personal information of more than 100,000 consumers or households annually
  • Derive 50 percent or more of their annual revenue from selling consumers’ personal information

The CCPA/CPRA has extraterritorial application, meaning that a business located in another US state, or even outside the US, must comply with the law if it meets one of these conditions.

Additionally, if your business shares common brandingwith a company that meets one of the above mentioned thresholds, your business will be subject to CCPA compliance. Common branding means that a business shares a name, service mark, or trademark with another business.

Interestingly, a number of more recently passed state-level privacy laws in the US do not include the revenue-only threshold.

What Is Personal Information Under the CCPA?

The CCPA/CPRA law defines personal information (known as personal data under some laws) as “information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”

Personal information under the CCPA/CPRA includes:

  • Direct identifiers, such as real name, alias, postal address, email address
  • Unique identifiers, such as cookies, IP addresses, beacons, pixel tags
  • Biometric data, such as face, retina, fingerprints, and voice recordings
  • Precise geolocation data used to accurately identify a person within a radius of 1850 feet (563 meters)
  • Internet activity, such as browsing history, search history, data on interaction with a web page or app
  • Sensitive personal information, such as Social Security number, racial or ethnic origin, citizenship or immigration status, genetic data, financial information

Personal information also includes data that by inference can lead to the identification of an individual or a household.

Aggregate and anonymous data is exempt from the CCPA/CPRA, unless it is in any way re-identifiable. 

What Does the CCPA Say About Cookies?

Cookies and other website tracking technologies are classified as unique identifiers that form part of the CCPA's definition of personal information. Cookies are one of the most commonly used technologies for websites to collect personal information on visitors.

First-party cookies, set by the website itself, often collect anonymous data for core website functions. They are deleted once a user closes the browser. Third-party cookies, like those set by tech companies, ad networks, and social media platforms, often collect a lot of personal information on consumers, which is sometimes sensitive.

Data collected on your website through cookies can ultimately be considered personal information under the CCPA/CPRA. This information might not in itself constitute personal information, e.g. anonymized analytics data, but it can become personally identifying by inference or in combination with other data, for the purpose of identifying and connecting devices, creating profiles, or serving personalized ads.

What Are the CCPA’s Consumer Rights?

The CCPA/CPRA sets up a legal framework whereby California residents can claim ownership of their data. It also requires organizations that do business in California to provide consumers with easy ways of exercising their CCPA rights.

The CCPA/CPRA empowers consumers with the following rights:

  • Right to opt out of having their data sold to or shared with third parties
  • Right to limit the use and disclosure of their sensitive personal information
  • Right to know and access personal informationcollected about them, including that collected through cookies, purposes of processing, and to whom the personal information is disclosed
  • Right to correct inaccurate or incomplete personal information
  • Right to request deletion of personal information collected from them, with exceptions
  • Right to know what personal information is sold or shared, and to whom
  • Right not to be discriminated against if they choose to exercise their rights under the law
  • Right to opt out of automated decision-making technology (ADMT) used to make significant decisions about them, subject to certain exceptions

Organizations that meet any of the CCPA/CPRA compliance thresholds are liable for personal information collected on California residents via their website's cookies, if the information is sold or shared. With the CPRA, consumers are now also able to opt out of collection and use of their data for targeted advertising or profiling purposes.

What Are the Obligations for Businesses Under the CCPA?

If your business meets any of the three CCPA/CPRA thresholds, you are required to comply with the obligations under the law.

The CCPA/CPRA operates under an opt-out consent model, meaning that in most cases, you don’t need to obtain prior consent from visitors before collecting their personal data through cookies or other tracking technologies. However, there is an exception for personal data belonging to minors under age 13.

If your website has visitors or customers who are minors under the age of 16, you are required to obtain their opt-in (consent) before you can sell or disclose their personal information to third parties. If the minor is under the age of 13, a parent or legal guardian must consent for them.

The California privacy law grants consumers the right to opt out of the sale or sharing of their personal information, and to limit the use or disclosure of sensitive personal information.

CCPA Compliance with the Rights to Opt Out and Limit

If your business sells or shares consumers’ personal information, your website must feature a link titled “Do Not Sell Or Share My Personal Information,” which consumers can use to make an opt-out request. (“Or Share” was added when the CPRA came into effect.) If such a request is received, you are prohibited from selling or sharing the consumer’s personal information, and must cease those activities if they are already in progress.

Similarly introduced with the CPRA, if your business uses or discloses consumers’ sensitive personal information, your website must feature a link titled “Limit The Use Of My Sensitive Personal Information,” which consumers can use to limit its use or disclosure.

You may use a single link for both purposes if consumers can exercise their right to both — to opt out of sale/sharing/targeted advertising/profiling and limit the use/disclosure of sensitive information — effectively from one link.

The law defines sale as “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party for monetary or other valuable consideration.”

Your business must respect universal opt-out mechanisms, such as Global Privacy Control (GPC) signals, that consumers may use to set their consent preferences once, typically via their browser settings or a browser plugin, which are then communicated automatically across various websites and online services.

CCPA Notice at Collection

Your website must inform visitors at or before the point of data collection about the categories of personal information that it collects, including any sensitive personal information, for what purposes, and whether you sell or share consumers’ personal information.

If you sell or share personal information, you must include a “Do Not Sell Or Share My Personal Information” link in the notice at collection.

The notice at collection must also link to your business’s privacy policy.

CCPA Privacy Policy

Your business must publish a privacy policy that includes: 

  • Description of consumers' rights and how to exercise them
  • Annually updated list of the categories of personal information that your business collects, sells, and/or discloses
  • Categories of sources from which your business collects personal information
  • Business or commercial purpose for collecting, selling, or sharing personal information
  • Categories of third parties to whom your business discloses personal information

Your privacy policy may contain a section detailing your website’s use of cookies and other trackers, or you can create a separate cookie policy with this information.

Businesses usually link to their privacy policy where consumers can easily find it on their website, often in the footer at the bottom of the page, or from a consent banner.

CCPA Compliance with Consumer Requests for Rights to Know, Correct, and Delete

Consumer rights requests under the California privacy law must be verifiable before your business has to provide the information. Your business must make available two or more methods for consumers to submit requests and must disclose the required information, correct inaccurate personal information, or delete consumers' personal information within 45 days of receiving the verifiable request. An extension of 45 days may be taken when reasonably necessary and you must inform the consumer of the extension within the first 45-day period.

You may not require Californian consumers to create a new account to make a request, but they can be required to use an existing account to verify their identity.

The CCPA/CPRA prohibits discrimination against consumers based on their choice to exercise their rights. This means that if a consumer chooses to opt out of the selling of their data to third parties, or if they request their data deleted, you cannot charge different prices for services, provide different levels or quality of services, or deny service.

However, the CCPA does authorize businesses to offer financial incentives, e.g. different prices and quality of service, for the collection, sale, or deletion of personal information, if the differences are reasonably related to the value provided to the business by the consumer’s data.

CCPA Obligation of Data Minimization

Under the CCPA/CPRA, businesses must collect, use, store, and share consumers’ personal information only to the extent necessary to fulfill the original purpose for which the information was collected, or for another compatible purpose. You may not process consumers’ personal information in ways that conflict with these original purposes.

This principle of data minimization also applies when collecting data through cookies and other tracking technologies. You may only use tracking cookies to collect data that is necessary for the specified purposes and must make sure that consumers are informed about the use of such technologies in your cookie policy.

CCPA Enforcement and Penalties

The enforcement of the CCPA/CPRA lies with two entities: the California Attorney General and the California Privacy Protection Agency (CPPA), the government agency established under the CPRA. This is unique to California, as most other states’ data privacy laws empower the Attorney General of the state with full enforcement authority.

Importantly, while the CPPA has enforcement authority, it cannot limit the Attorney General's authority and must stay any actions or investigations if the Attorney General requests it. Businesses cannot be penalized by both the CPPA and the Attorney General for the same violation.

The penalties for non-compliance with the CCPA/CPRA can be substantial: 

  • Up to USD 2,663 for each unintentional violation
  • Up to USD 7,988 for intentional violations 

Those amounts are periodically adjusted for the Consumer Price Index, with the next adjustment due in 2027. If a business commits multiple CCPA/CPRA violations, the fines can accumulate quickly, leading to significant financial repercussions.

The California privacy law also grants consumers the right to to take legal action against businesses in the event of a data breach. Consumers can seek statutory damages ranging from USD 107 to USD 799 per incident or the actual damages incurred, whichever amount is greater, or injunctive relief. California is the only state that grants consumers this private right of action.

Consumers must give businesses 30 days to cure any violations stemming from a data breach before they can take legal action. When the CCPA first went into effect, the 30-day cure period also applied to actions brought by the Attorney General/CPPA. This has now sunset.

How Does the CCPA Relate to CIPA?

The California Invasion of Privacy Act (CIPA) is a separate, older California statute that's not part of the CCPA/CPRA framework. But it's increasingly relevant to the same website operators. Originally a wiretapping law, CIPA has been used in a wave of lawsuits arguing that common website tracking technologies, such as session replay tools, live chat widgets, and analytics pixels, amount to unlawful wiretapping or the unauthorized use of a "pen register" or "trap and trace" device.

Unlike the CCPA/CPRA, CIPA carries statutory damages of USD 5,000 per violation and allows private lawsuits, which has made it attractive to plaintiffs' firms sending demand letters.

CCPA Checklist to Support Compliance Requirements

Here is a checklist that covers the main CCPA requirements for businesses and websites.

  • Accessibly display the “Do Not Sell Or Share My Personal Information” link (and “Limit The Use Of My Sensitive Personal Information" link if required) on your website so that consumers can use to opt out of third-party data sales/sharing and use/disclosure of sensitive personal information.
  • Provide a notice at or before the point of collection informing consumers of the categories of personal information (including sensitive personal information) your business collects, for what purposes, and whether it shares or sells the personal information. Also outline their rights under the CCPA and how to exercise them.
  • Respond to opt-out requests within 15 days of receipt, including stopping further sale/sharing of data and notifying all parties to whom you have sold the personal information in the previous 90 days.
  • Obtain opt-in consent from minors age 13 to 16 and from parents or legal guardians of minors under the age of 13 before selling or sharing their personal information.
  • Provide consumers with records of the personal information collected in the past 12 months free of charge, including sources, commercial purposes, and categories of third parties with whom it has been shared, if a consumer requests disclosure or deletion. This is for a reasonable number of requests by a consumer annually, and excessive requests can be denied.
  • Respond within 45 days of receiving a verifiable request for disclosure or deletion with information on how the request will be processed.
  • Establish at least two methods for consumers to exercise their rights, such as a toll-free phone number, email address, or web form.
  • Only offer financial incentives (e.g., different prices, rates, and quality) for goods and services if the differences are reasonably related to the value that the consumer’s data brings to the business.
  • Refrain from discriminating against consumers who choose to exercise their rights under the law, particularly opting out of data collection and processing.

How Cookiebot CMP Supports CCPA Compliance

Cookiebot™ automatically scans your website, finds all cookies and similar tracking technologies in use, and can automatically block them if visitors opt out. This enables compliance with both the CCPA and the European Union’s General Data Protection Regulation (GDPR).

Cookies, especially those from third parties embedded through plugins, can harvest personal information such as names, physical addresses, IP addresses, and location data, but also sensitive personal data such as religious convictions, political opinions, and/or sexual orientation.

The CCPA requires that businesses enable California residents to opt out of having their personal information sold to third parties, as well as disclosing what data has already been collected and deleting it, if consumers request it.

Cookiebot CMP enables compliance with the CCPA with a specific configuration that detects whether a user is from California, and then displays the required “Do Not Sell Or Share My Personal Information” link on the website’s cookie banner.

You can also fulfill the CCPA/CPRA requirement to inform visitors about personal information processing at or before the point of data collection by using a cookie banner or cookie notice to display your notice at collection.

Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.