CCPA / CPRA

Cal. Civ. Code §§ 1798.100–1798.199.100

California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020

In force since January 1, 2020

Who it applies to

  • For-profit businesses that do business in California, determine the purposes and means of processing, and meet any one of the three thresholds below
  • Annual gross revenue above the statutory $25 million threshold (adjusted for inflation by the Agency)
  • Buys, sells or shares the personal information of 100,000 or more California consumers or households per year
  • Derives 50% or more of annual revenue from selling or sharing personal information
  • Also reaches entities that control or are controlled by a business and share common branding

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — grantedRequire inaccurate personal data to be fixed.
  • Deletion / erasure — grantedRequire deletion of personal data, subject to the statute's retention exceptions.
  • Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
  • Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
  • Opt out of targeted advertising — grantedStop your data being used to target advertising across sites or services.
  • Opt out of profiling — grantedStop automated profiling that produces legal or similarly significant effects.
  • Limit sensitive data use — grantedRestrict use of sensitive categories to what is necessary to deliver the service.
  • Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
  • Non-discrimination — grantedNot be charged more or given a worse service for exercising a privacy right.
  • Appeal a refusal — not granted
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-out
Universal opt-out signal
Must honour a browser-level opt-out such as Global Privacy Control
Risk assessments
Required for higher-risk processing
Data protection officer
Not required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Required
Minors
Opt-in consent required to sell or share the personal information of consumers under 16; for under-13s, consent must come from a parent or guardian.
Automated decisions
Under the 2026 regulations, businesses using automated decision-making technology for significant decisions must give pre-use notice, offer an opt-out and provide a route to human review.

Breach notification

To individuals
In the most expedient time possible and without unreasonable delay (Cal. Civ. Code § 1798.82)
To the regulator
Submit a sample notice to the Attorney General where more than 500 Californians are affected
What triggers it
Unauthorised acquisition of unencrypted, or encrypted-with-compromised-key, computerised personal information

Penalties

Headline
$2,500 per violation, or $7,500 per intentional violation or violation involving a minor
Private right of action
Yes — individuals can sue directly
Notes
The private right of action is narrow: it covers data breaches of certain unencrypted personal information only, at $100–$750 per consumer per incident or actual damages, whichever is greater (§ 1798.150). Everything else is enforced by the CPPA and the Attorney General.

Exemptions

Entities

  • Non-profit organisations
  • Government agencies
  • Businesses below all three thresholds

Data

  • Protected health information under HIPAA and the CMIA
  • Consumer reports governed by the FCRA
  • Personal information governed by the GLBA or the California Financial Information Privacy Act
  • Driver's licence data under the DPPA
  • Clinical trial data

Amendment history

  1. January 1, 2023

    California Privacy Rights Act (Proposition 24)

    Created the CPPA, added the rights to correct and to limit sensitive personal information, extended opt-out to 'sharing' for cross-context behavioural advertising, and removed the mandatory 30-day cure period.

  2. March 29, 2023

    First CPPA regulations effective

    Rulemaking authority transferred from the Attorney General to the Agency in 2022; the Agency's first formal rulemaking concluded and took effect in March 2023.

  3. January 1, 2025

    AB 1008 — personal information in AI systems

    Clarifies that personal information covers physical, digital and abstract digital formats, including generative AI systems capable of outputting personal information.

  4. January 1, 2025

    SB 1223 — neural data

    Adds neural data to the definition of sensitive personal information.

  5. January 1, 2025

    AB 1824 — opt-outs survive a merger

    A business to which personal information is transferred as an asset in a merger or acquisition must honour the consumers' existing opt-out preferences.

  6. January 1, 2026

    CCPA Updates, Cyber, Risk and ADMT Regulations

    Adds cybersecurity audit duties, risk assessments for higher-risk processing, and rules on automated decision-making technology, at CCR tit. 11, §§ 7001–7304.

Sources

Timeline

todayCCPA / CPRA in forceJanuary 1, 2020California Privacy Rights Act (Proposition 24)January 1, 2023First CPPA regulations effectiveMarch 29, 2023AB 1008 — personal information in AI systemsJanuary 1, 2025SB 1223 — neural dataJanuary 1, 2025AB 1824 — opt-outs survive a mergerJanuary 1, 2025CCPA Updates, Cyber, Risk and ADMT RegulationsJanuary 1, 2026