Regulations › US states › California

CCPA/CPRA

California Consumer Privacy Act, as amended by the California Privacy Rights Act

In force privacy consumer rights
WhenIn effect since 1 January 2020
Who enforces itCalifornia Privacy Protection Agency and Attorney General
Who it applies toFor-profit businesses doing business in California that meet one threshold: annual gross revenue above $26,625,000 (inflation-adjusted), buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half or more of revenue from selling or sharing personal information.

The most detailed US state privacy law and the only one with a dedicated privacy regulator. It covers employee and business-to-business data, requires opt-outs from selling and sharing, and has its own regulations on automated decision-making.

The law in brief

The CCPA, as amended by the CPRA, is California's comprehensive privacy law and the most developed in the United States. It gives California residents rights over their personal information, including employees and business contacts, and puts duties on the businesses that collect it.

It is enforced by a dedicated regulator, the California Privacy Protection Agency, alongside the Attorney General, and its detailed regulations matter as much as the statute.

Who it applies to

  • For-profit businesses that do business in California and meet one of three tests: annual gross revenue above a threshold adjusted for inflation (originally $25 million), buying, selling or sharing the personal information of 100,000 or more California consumers or households, or earning half or more of annual revenue from selling or sharing personal information (Civil Code 1798.140(d)).
  • Service providers and contractors that process personal information for such a business, under contract.
  • All California residents count as consumers, including employees, job applicants and business contacts.

What it requires

Notice at collection

At or before collection, tell consumers what categories of personal information you collect, why, whether you sell or share it, and how long you keep it.

Purpose limitation and minimization

Collect, use and keep personal information only as reasonably necessary and proportionate to the disclosed purposes.

Opt-out of sale and sharing

Stop selling or sharing a consumer's personal information when they opt out, including through a recognized opt-out preference signal, and do not ask again for at least 12 months.

Contracts with every recipient

Bind service providers, contractors and third parties by contract to specific purposes and to CCPA-level protection.

Reasonable security

Implement reasonable security procedures and practices appropriate to the nature of the personal information.

People's rights

California residents can:

  • know what personal information is collected, used, shared or sold, and get a copy (1798.100, 1798.110);
  • delete it, with exceptions (1798.105);
  • correct inaccurate information (1798.106);
  • opt out of the sale or sharing of their information, including through an opt-out preference signal such as Global Privacy Control (1798.120, 1798.135);
  • limit the use of sensitive personal information (1798.121);
  • not be retaliated against for using these rights (1798.125).

Businesses must respond to requests within 45 days, extendable once by another 45 days with notice.

Enforcement and penalties

Administrative fines per violation, higher for intentional violations and for violations involving minors under 16, with amounts adjusted for inflation; enforced by the California Privacy Protection Agency and the Attorney General (1798.155, 1798.199.90). Consumers can sue directly only over certain data breaches caused by a failure to maintain reasonable security, for statutory damages per consumer per incident or actual damages (1798.150).

What's changing

Adopted rules with phased dates. Regulations on cybersecurity audits, risk assessments and automated decision-making technology took effect on January 1, 2026, with compliance dates phased over the following years. Check the regulations for the dates that apply to your business; Regulatory Watch reports new rules and enforcement.

What to do first

  1. Confirm the thresholds and whether you sell or share personal information, including through advertising cookies and pixels.
  2. Map personal and sensitive personal information, including employee and business-contact data.
  3. Update your notice at collection and privacy policy, and review it at least every 12 months.
  4. Honor opt-out preference signals and add "Do Not Sell or Share" and "Limit" links where required.
  5. Put CCPA terms in contracts with service providers, contractors and third parties.
  6. Build a request process that verifies identity and answers within 45 days.
  7. Check the 2026 regulations for risk assessments, audits and automated decision-making.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Sources