πŸ‡ΊπŸ‡Έ California State Law

CCPA / CPRA

California's privacy law gives consumers the right to know, delete, and opt out of the sale of their personal information. Even if you are not based in California, the law may apply to your business.

⚑ Quick Facts

What it is: California's comprehensive consumer privacy law
Enforced by: California AG + new California Privacy Protection Agency (CPPA)
Penalty: $2,500 per unintentional violation; $7,500 per intentional or minor-related violation
Key rights: Right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive data
Thresholds: $25M+ revenue OR 100K+ consumer records OR 50%+ revenue from data sales

Do CCPA and CPRA Apply to Your Business?

CCPA/CPRA applies to for-profit businesses that do business in California AND meet at least one of these thresholds:

  • Annual gross revenue over $25 million
  • Buy, sell, or share personal information of 100,000+ California consumers or households per year
  • Derive 50% or more of annual revenue from selling or sharing consumers' personal information

"Doing business in California" is broadly interpreted. If you have a website that California residents use, ship products to California, or have any California customers, you likely meet this prong. The 100,000 consumer threshold sounds high β€” but "consumer" includes website visitors, and personal information includes IP addresses, cookies, and device identifiers tracked through analytics. A moderately trafficked small business website can easily hit 100,000 unique visitors/year if it has strong SEO.

Privacy Policy Template for CCPA Compliance

Our compliance toolkit includes a customizable privacy policy with CCPA-required disclosures and a 'Do Not Sell My Info' page.

View Compliance Toolkit β†’

Consumer Rights Under CCPA/CPRA

The CPRA (effective January 2023) amended and expanded the original CCPA. Together, they give California consumers these rights:

πŸ“‹ Right to Know

Consumers can request disclosure of: what categories of personal information you collect, the sources, the business purpose, and the categories of third parties you share it with. They can also request the specific pieces of personal information you hold about them.

πŸ—‘οΈ Right to Delete

Consumers can request deletion of personal information you collected from them. There are exceptions (completing a transaction, legal obligations, security, free speech) but the default is: you must delete when asked.

✏️ Right to Correct

New under CPRA β€” consumers can request correction of inaccurate personal information you hold about them.

🚫 Right to Opt Out of Sale and Sharing

The most well-known CCPA right. You must provide a clear "Do Not Sell or Share My Personal Information" link on your website. "Sale" is broadly defined and includes sharing data with advertising networks and analytics providers in exchange for value β€” not just money.

πŸ”’ Right to Limit Use of Sensitive Personal Information

New under CPRA β€” for sensitive data (SSN, precise geolocation, race/ethnicity, biometric data, health information), consumers can limit your use to what is strictly necessary to provide your service.

Cookie Consent & CCPA Opt-Out Setup

How to implement a CCPA-compliant opt-out mechanism and cookie consent banner on your website.

View Setup Guide β†’

Practical CCPA Compliance Steps

  1. 1
    Update your privacy policy.

    Disclose: categories of personal information collected, sources, business/commercial purposes, categories of third parties receiving the data, and specific CCPA rights. Update at least every 12 months.

  2. 2
    Add a "Do Not Sell or Share My Personal Information" link.

    This must be visible on your homepage and in your privacy policy. It must link to an opt-out mechanism that is easy to use and does not require account creation.

  3. 3
    Set up processes for consumer requests.

    Provide at least two methods for submitting requests (e.g., toll-free number + web form). You have 45 days to respond (with a possible 45-day extension). Verify the identity of the requestor before disclosing or deleting data.

  4. 4
    Review your data-sharing relationships.

    If you use Google Analytics, Facebook Pixel, or any ad network, you are likely "selling" or "sharing" data under CCPA definitions. Configure consent management correctly and honor opt-out requests across all platforms.

  5. 5
    Train your team.

    Anyone handling consumer inquiries must understand CCPA rights and your response procedures. Document your training. The CPPA can request training records during an investigation.

CCPA vs GDPR: Key Differences for Small Business

Thresholds: CCPA has revenue/data thresholds; GDPR has none. A very small business might be exempt from CCPA but still covered by GDPR if it has EU customers.

Opt-out vs Opt-in: CCPA is largely opt-out (consumers must request to stop sales). GDPR requires opt-in consent before data collection in many cases.

Private right of action: CCPA has a limited private right of action only for data breaches caused by failure to implement reasonable security. GDPR allows private claims more broadly.

Fines: CCPA penalties are per-violation ($2,500/$7,500). GDPR penalties are capped at a percentage of global revenue. For larger companies, GDPR fines are much bigger; for small companies, CCPA per-violation penalties can add up quickly.