CCPA / CPRA
Cal. Civ. Code §§ 1798.100–1798.199.100California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020
In force since January 1, 2020
Who it applies to
- For-profit businesses that do business in California, determine the purposes and means of processing, and meet any one of the three thresholds below
- Annual gross revenue above the statutory $25 million threshold (adjusted for inflation by the Agency)
- Buys, sells or shares the personal information of 100,000 or more California consumers or households per year
- Derives 50% or more of annual revenue from selling or sharing personal information
- Also reaches entities that control or are controlled by a business and share common branding
Consumer rights
- Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
- Correction — grantedRequire inaccurate personal data to be fixed.
- Deletion / erasure — grantedRequire deletion of personal data, subject to the statute's retention exceptions.
- Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
- Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
- Opt out of targeted advertising — grantedStop your data being used to target advertising across sites or services.
- Opt out of profiling — grantedStop automated profiling that produces legal or similarly significant effects.
- Limit sensitive data use — grantedRestrict use of sensitive categories to what is necessary to deliver the service.
- Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
- Non-discrimination — grantedNot be charged more or given a worse service for exercising a privacy right.
- Appeal a refusal — not granted
- Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.
Obligations
- Consent model
- Opt-out
- Universal opt-out signal
- Must honour a browser-level opt-out such as Global Privacy Control
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Required
- Minors
- Opt-in consent required to sell or share the personal information of consumers under 16; for under-13s, consent must come from a parent or guardian.
- Automated decisions
- Under the 2026 regulations, businesses using automated decision-making technology for significant decisions must give pre-use notice, offer an opt-out and provide a route to human review.
Breach notification
- To individuals
- In the most expedient time possible and without unreasonable delay (Cal. Civ. Code § 1798.82)
- To the regulator
- Submit a sample notice to the Attorney General where more than 500 Californians are affected
- What triggers it
- Unauthorised acquisition of unencrypted, or encrypted-with-compromised-key, computerised personal information
Penalties
- Headline
- $2,500 per violation, or $7,500 per intentional violation or violation involving a minor
- Private right of action
- Yes — individuals can sue directly
- Notes
- The private right of action is narrow: it covers data breaches of certain unencrypted personal information only, at $100–$750 per consumer per incident or actual damages, whichever is greater (§ 1798.150). Everything else is enforced by the CPPA and the Attorney General.
Exemptions
Entities
- Non-profit organisations
- Government agencies
- Businesses below all three thresholds
Data
- Protected health information under HIPAA and the CMIA
- Consumer reports governed by the FCRA
- Personal information governed by the GLBA or the California Financial Information Privacy Act
- Driver's licence data under the DPPA
- Clinical trial data
Amendment history
January 1, 2023
California Privacy Rights Act (Proposition 24)
Created the CPPA, added the rights to correct and to limit sensitive personal information, extended opt-out to 'sharing' for cross-context behavioural advertising, and removed the mandatory 30-day cure period.
March 29, 2023
First CPPA regulations effective
Rulemaking authority transferred from the Attorney General to the Agency in 2022; the Agency's first formal rulemaking concluded and took effect in March 2023.
January 1, 2025
AB 1008 — personal information in AI systems
Clarifies that personal information covers physical, digital and abstract digital formats, including generative AI systems capable of outputting personal information.
January 1, 2025
SB 1223 — neural data
Adds neural data to the definition of sensitive personal information.
January 1, 2025
AB 1824 — opt-outs survive a merger
A business to which personal information is transferred as an asset in a merger or acquisition must honour the consumers' existing opt-out preferences.
January 1, 2026
CCPA Updates, Cyber, Risk and ADMT Regulations
Adds cybersecurity audit duties, risk assessments for higher-risk processing, and rules on automated decision-making technology, at CCR tit. 11, §§ 7001–7304.
Sources
- PrimaryStatuteCal. Civ. Code, Title 1.81.5 (CCPA) — full statutory text
- PrimaryRegulationCPPA — CCPA regulations and rulemaking
- OfficialRegulatorCalifornia Privacy Protection Agency
- OfficialRegulatorAttorney General — CCPA guidance and enforcement