CCPA
CCPA
Definition: The California Consumer Privacy Act, a state-level data privacy law giving California residents rights over their personal data, similar in spirit to GDPR but narrower in scope and built around an opt-out model.
How It Works
- Business scope: applies to for-profit businesses doing business in California that meet at least one threshold: over $25 million in annual gross revenue, buying/selling/sharing personal data of 100,000+ consumers or households, or deriving 50%+ of annual revenue from selling or sharing personal information.
- Consumer rights: know what categories and specific pieces of personal data a business collects, request deletion, correct inaccurate data, opt out of the sale or sharing of data, and limit use of sensitive personal information (like precise location or health data).
- Opt-out, not opt-in: businesses may collect and process data by default; the burden is on the consumer to find and use the opt-out mechanism, unlike GDPR’s consent-first model.
- “Do Not Sell or Share” requirement: businesses that sell or share personal data must post a clear link or honor an opt-out preference signal, such as Global Privacy Control (GPC), sent automatically by the browser.
- “Sale” is defined broadly: it covers any exchange of personal data for money or other valuable consideration, which under CPRA’s added “sharing” category also captures cross-context behavioral advertising with no money changing hands.
- CPRA amendments: the California Privacy Rights Act (effective 2023) expanded CCPA, added the sensitive personal information category, added the right to correct data, and created the California Privacy Protection Agency (CPPA) as a dedicated enforcement body.
- Non-discrimination: businesses cannot charge a different price or provide a lower quality of service just because a consumer exercised a CCPA right, though financial incentive programs are allowed if disclosed.
- 12-month lookback: a “right to know” request covers the 12 months preceding the request by default, not a consumer’s entire history with the business.
- Cure period: businesses historically had 30 days to fix a violation after notice before facing enforcement action; CPRA removed this automatic cure right for most violations, raising the stakes of getting it right the first time.
Consumer Rights at a Glance
| Right | What it means in practice |
|---|---|
| Right to know | Disclose categories and specific data points collected, sources, and purposes |
| Right to delete | Erase personal data on verified request, with statutory exceptions |
| Right to correct | Fix inaccurate personal data (added by CPRA) |
| Right to opt out | Stop the sale or sharing of personal data |
| Right to limit | Restrict use of sensitive personal information to what’s necessary |
| Right to non-discrimination | No penalty or degraded service for exercising any of the above |
Business Threshold Detail
| Trigger | Threshold |
|---|---|
| Revenue | Over $25 million in annual gross revenue |
| Data volume | Buys, sells, or shares personal data of 100,000+ consumers or households per year |
| Data-driven revenue | Derives 50% or more of annual revenue from selling or sharing personal information |
| Applies to | Any one of the above trips CCPA coverage, not all three |
Verification Standard by Request Type
| Request | Required verification level |
|---|---|
| Right to know (categories only) | Reasonable degree of certainty |
| Right to know (specific pieces of data) | Reasonably high degree of certainty |
| Right to delete | Matches the sensitivity of the data being deleted |
| Opt-out of sale/sharing | No identity verification required by default |
Under the Hood
A consumer rights request under CCPA follows a fixed verification and response timeline, whether it’s a know, delete, or opt-out-of-sale request:
Given: A California resident submits a “right to know” request on day 0. Step: The business must confirm receipt within 10 business days, then verify identity and respond within 45 calendar days. If the request is unusually complex or the business is handling a high volume of requests, it may extend by another 45 days, but must notify the consumer of the extension and the reason before the first 45-day window closes. Answer: Standard deadline is day 45. If extended, the final deadline is day 90, with the extension notice required before day 45.
Given: A consumer sends a browser-based Global Privacy Control (GPC) signal while browsing a retailer’s site, without ever visiting a settings page. Step: CCPA (as clarified by CPRA regulations) requires businesses to treat a GPC signal as a valid opt-out-of-sale-and-sharing request, equivalent to clicking a “Do Not Sell or Share My Personal Information” link. Answer: The business must stop selling or sharing that browser’s associated data going forward, without requiring the consumer to fill out a separate form, and honor the opt-out within 15 business days.
Given: A data breach exposes unencrypted consumer records due to the business’s failure to maintain reasonable security procedures. Step: CCPA grants a limited private right of action specifically for this scenario, letting consumers sue directly without going through the Attorney General or CPPA. Answer: Affected consumers can seek statutory damages of 750 per consumer per incident, or actual damages if higher, without having to prove actual financial harm.
Given: A consumer emails support asking to delete their account, but the business can’t confirm the email address matches the account on file. Step: CCPA requires businesses to verify a requester’s identity to a level matching the sensitivity of the data before acting, so a mismatched or unconfirmed identity is grounds to deny the request rather than delete the wrong person’s data. Answer: The business asks for additional matching information (like the last order date or account ID) before proceeding, and denies the request with an explanation if verification still fails.
Why It Matters
- California’s market size makes it a de facto national standard: many US companies apply CCPA-style rights to all US users rather than building California-only logic.
- Engineering implications are concrete: a working “Do Not Sell My Personal Information” flow, GPC signal detection, a verified deletion pipeline, and a 12-month lookback for “right to know” disclosures all need real implementation, not just a policy page.
- Penalties scale with violation count: fines apply per violation, so a bug affecting thousands of consumer records multiplies quickly even at a few thousand dollars each.
- The private right of action for breaches is real leverage: unlike most of CCPA, consumers can sue directly over a security failure, which raises the stakes of basic security hygiene like encryption at rest.
- Vendor contracts need updating too: service providers and third parties that receive personal data need CCPA-compliant contract terms limiting what they can do with it.
- Influenced other US state laws (Virginia, Colorado, Connecticut, and more), each with its own variations on rights and thresholds.
Common Pitfalls
- Building only a GDPR-compliant flow and assuming it automatically satisfies CCPA; the specific rights, thresholds, and opt-out-first model differ enough that they need separate review.
- Ignoring the “opt out of sale” requirement for data-sharing arrangements that don’t look like a traditional sale, like sharing data with ad-tech partners for cross-context behavioral advertising, which CCPA/CPRA treats as “sharing” even without money changing hands.
- Not honoring Global Privacy Control signals, treating them as optional when CPPA regulations require businesses to process them as valid opt-out requests.
- Posting a “Do Not Sell My Personal Information” link that leads to a dead end, a broken form, or a flow that doesn’t actually stop the data sale on the backend.
- Assuming CCPA doesn’t apply because the company isn’t based in California; the thresholds are based on doing business with California residents, not company headquarters.
- Treating identity verification as optional for deletion requests, which creates a risk of an attacker deleting or exposing someone else’s data through social engineering.
- Miscounting the business thresholds, for example assuming a small startup is exempt without checking whether ad-tech data sharing alone crosses the 100,000-consumer trigger.
- Deleting a consumer’s record from the primary database but leaving copies in analytics exports, marketing platforms, or offline backups untouched.
- This section is informational only and is not legal advice; consult qualified counsel for compliance decisions.
Comparison
| GDPR | CCPA | |
|---|---|---|
| Jurisdiction | EU residents, worldwide reach (Art 3) | California residents, threshold-based business scope |
| Default | Opt-in: consent or another lawful basis required before processing | Opt-out: processing allowed by default, consumer can opt out of sale/sharing |
| Private right of action | Limited; mainly via DPA complaints and collective redress (Art 80) | Limited to data breaches, with statutory damages |
| Response deadline | 1 month, extendable by 2 more months | 45 days, extendable by another 45 days |
| Breach notification | Within 72 hours to the supervisory authority | “Without unreasonable delay” to affected consumers |
| Maximum penalties | Up to €20M or 4% of global annual revenue | Up to $7,500 per intentional violation |
| Enforcement | National DPAs plus the European Data Protection Board | California Privacy Protection Agency (CPPA) |
| Consent standard | Explicit opt-in, granular by purpose | Implied consent unless the consumer opts out |
| Minors’ data | Parental consent generally required under 16 | Opt-in (not opt-out) required for consumers under 16 |
Example
After CCPA took effect on January 1, 2020, businesses across the US, not just in California, widely added “Do Not Sell My Personal Information” links to their website footers, since compliance was cheaper to apply site-wide than to geofence California visitors. Retailers, media companies, and ad-tech platforms rebuilt cookie consent and data-sharing flows around this requirement. After the CPRA amendments took effect in 2023, many of these links were updated to “Do Not Sell or Share My Personal Information” to reflect the broader “sharing” category, and companies began adding automatic Global Privacy Control detection to honor opt-out signals without requiring a manual click.
Related Terms
Referenced by