Most privacy laws get ignored until the first fine lands. The California Consumer Privacy Act (CCPA) is the first broad, cross-industry consumer privacy law in the US that makes ignoring it costly. It gives California residents the right to know what personal data businesses collect, request deletion, and opt out of the sale or sharing of that data.
Businesses are surprised by how far these rules extend. Every ad pixel, analytics tool, vendor, and even their vendors can bring a company under the law.
This guide explains what the law is, who must follow it, what it requires, the rights and responsibilities it creates, and what happens if you do not comply.
Key takeaways
- You do not need to be in California. One threshold is enough: $26.625M in revenue, data on 100,000 or more consumers, or half your revenue from selling or sharing data.
- Your ad pixels can count as “selling” data. No money needs to change hands.
- 2026 changed what regulators ask for. Audits, attestations, and documented risk assessments now matter more than what your policy says.
- Penalties run up to $7,988 per intentional violation.
- Consent banners now have hard rules. Closing a pop-up is not consent, and opting out cannot take more steps than opting in.
- Every big fine traces to the same blind spot. Trackers, vendors, and AI tools that were never mapped, classified, or contracted.
What is CCPA?
The California Consumer Privacy Act of 2018 is the first major state privacy law in the US. It gives California residents clear rights over their personal information. They can learn what businesses collect, delete or correct their data, opt out of its sale or sharing, limit how sensitive data is used, and avoid discrimination for using these rights.
This law was created because data collection grew faster than the rules to control it. Californians were being profiled, tracked, and their information was sold to unknown parties, so the state gave them tools to see and limit this activity.
The CPRA updated and strengthened the CCPA in 2023. Now, both laws work together as a single set of rules, managed by the California Privacy Protection Agency (CPPA).
A brief history of CCPA
| Date | Milestone |
| June 28, 2018 | CCPA (AB-375) signed into law |
| January 1, 2020 | CCPA takes effect |
| July 1, 2020 | Enforcement begins |
| November 2020 | Voters pass the CPRA (Proposition 24), amending the CCPA |
| January 1, 2023 | CPRA takes effect; CPPA assumes enforcement; employee and B2B exemptions expire |
| January 1, 2026 | New regulations on ADMT, risk assessments, and cybersecurity audits begin to take effect. |
Does the CCPA apply to you?
The first thing to check with the CCPA is the numbers, not the legal details. A for-profit business operating in California that collects consumers’ personal information is covered if it meets any of three thresholds (Cal. Civ. Code § 1798.140(d)(1)):
The three thresholds
| Threshold | You are covered if your business… |
| Revenue | Gross annual revenue above $26,625,000. The figure is adjusted for inflation each year (The next adjustment is due January 2027). |
| Data volume | Buys, shares, or sells personal information of 100,000 or more California consumers or households a year |
| Data-driven revenue | Earns 50% or more of its annual revenue from selling or sharing personal information |
Nonprofits and government agencies are usually not included. “Doing business in California” does not depend on where your company is based. Out-of-state companies that collect data from Californians can also be covered.
These thresholds are broad, so many mid-sized companies qualify without realizing it, especially those relying heavily on data.
Who counts as a “Consumer”
The CCPA protects California residents, defining them by where they live, not just where they are physically located.
“A consumer is someone who lives in California for a non-temporary purpose, or who is domiciled in California but temporarily outside the state, such as on a business trip.”
Someone just passing through California is not automatically covered. Many businesses get this wrong.
What counts as a “Business”
The law targets the for-profit entity that decides why and how personal information is processed. Non-profits and government agencies are generally excluded.
Affiliates that share a common brand, such as a name or trademark, can be treated as part of the same covered business. This means the law can apply to related companies as well.
What are common CCPA exemptions?
Some data is exempt rather than the whole company, and one major exemption has narrowed. Information governed by HIPAA (health data), the Gramm-Leach-Bliley Act (financial data), or the Fair Credit Reporting Act (credit data) is generally exempt.
The temporary exemptions for HR and B2B contacts ended December 31, 2022. Since January 1, 2023, this information is covered by the law.
What personal information does the CCPA protect?
The CCPA has a broad definition of personal information, so a lot of everyday business data falls under its rules.
Personal information is any data that identifies, relates to, describes, or could reasonably be linked to a particular consumer or household. This covers obvious identifiers and less obvious ones like device IDs, cookies, and inferences about a person. Publicly available information is not treated as personal information.
The CPRA introduced a new category called sensitive personal information, which comes with extra requirements.
What counts as sensitive personal information?
Sensitive personal information is a specific list set by law. It includes government identifiers, account numbers with credentials, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, contents of mail, email and texts, genetic data, biometric identification, health data, and sex life or sexual orientation.
Since January 1, 2025, the list has included neural data. This is information generated by measuring the activity of a consumer’s central or peripheral nervous system, not inferred from nonneural information – added by SB 1223.
Categories of personal information
| Category | Examples |
| Identifiers | Name, alias, postal address, email, phone, IP address, account name, device IDs |
| Personal records (§ 1798.80) | SSN, driver’s license number, passport number, financial account numbers, signature |
| Protected classifications | Race, sex, age, medical information, health insurance information, military status |
| Commercial information | Products or services purchased, obtained, or considered; purchasing histories and tendencies |
| Biometric information | Fingerprints, face and voice prints, keystroke patterns, gait |
| Internet and electronic activity | Browsing and search history, site and app interactions, cookies, ad IDs |
| Geolocation | Precise physical location and movement |
| Audio, visual, and sensory | Call recordings, CCTV footage, photos, thermal imagery |
| Professional and employment | Job history, employer details, performance evaluations |
| Education | Records under FERPA: transcripts, grades, student records, etc. |
| Inferences | Profiles drawn from any of the above to predict preferences or behavior |
What are your rights under the CCPA?
California residents have six main rights under the law, and every covered business must honor them. The rights below come from the California Attorney General’s guidance.
| Right | What it lets a consumer do |
| Right to know & access | Ask what personal information a business collects, uses, shares, or sells, and get a copy |
| Right to delete | Ask a business to delete personal information it collected, with some exceptions |
| Right to correct | Ask a business to fix inaccurate personal information |
| Right to opt out of sale or sharing | Tell a business to stop selling or sharing personal information |
| Right to limit sensitive personal information collected | Restrict how a business uses and discloses sensitive data |
| Right to non-discrimination | Receive equal service and pricing after exercising a right |
Under the 2026 rules, consumers also gain rights to access and opt out of certain automated decisions.
Two of these rights depend on an important distinction. Under the CCPA, “selling” means exchanging personal information for money or something else of value. “Sharing” refers to giving data for cross-context behavioral advertising. The CPRA added “sharing,” so one opt-out now stops both the sale of your data and its use for ad targeting.
What does the Consumer Privacy Act CCPA require businesses to do?
Rights on the consumer side create duties on the business side. These operational requirements are where compliance succeeds or fails. A covered business must do more than just post a policy. It needs to set up real processes to handle requests.
- Notice at collection: tell consumers what you collect and why, at or before the point of collection (A notice at collection must list the categories of personal information businesses collect).
- “Do Not Sell or Share My Personal Information” link: place a clear opt-out link on your site, and honor the Global Privacy Control (GPC), a browser signal that automatically communicates a consumer’s opt-out.
- Request channels and timelines: offer at least two ways to submit requests, respond to access and deletion requests within 45 days (extendable once), and act on opt-out requests within 15 business days.
- Respect the opt-out: do not ask a consumer to opt back in for at least 12 months after they opt out.
- Minors’ data: you need opt-in consent to sell or share the data of consumers under 16, parental consent for those under 13, and the minor’s own affirmative consent for ages 13 to 16.
- Vendor contracts: put required terms in place with service providers and third-party companies that receive personal information.
The definitions that decide your liability
Most CCPA risk does not start with a data breach, but with three definitions that can turn normal vendor relationships into regulated or even unlawful transactions.
“Sale” needs no money:
Selling means “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating” a consumer’s personal information to a third party “for monetary or other valuable consideration” (Cal. Civ. Code § 1798.140).
No cash has to change hands. A vendor providing analytics or advertising services in exchange for access to visitor data can fall under the CCPA sale of personal information definition.
The CPRA added a second concept: disclosing personal information to a third party “for cross-context behavioral advertising, whether or not for monetary or other valuable consideration,” including transactions “in which no money is exchanged” (Cal. Civ. Code § 1798.140).
The plain example: an analytics or advertising pixel on your site that sends visitor data to a vendor in exchange for ad or measurement services. That was the Attorney General’s enforcement position in the August 24, 2022 Sephora settlement: third-party trackers on Sephora’s site and app “constituted a sale of consumer information under the CCPA” (California AG press release, August 24, 2022).
This interpretation was agreed upon but never decided in court. Treat it as the regulator’s official view, not as settled law. Regulators have used this approach since then.
Classification is the hinge:
Every recipient of your data is one of three things, and the label controls your liability:
| Recipient | What it is | What the contract must do |
| Service provider | Processes personal information on your behalf for a business purpose, under a written contract | Must prohibit the vendor from selling or sharing the data, using or disclosing it for any purpose beyond the specified business purposes or outside your direct business relationship, and combining it with data from other sources (Cal. Civ. Code § 1798.140 (ag)) |
| Contractor | Receives data for a business purpose, distinct CPRA category | Same four prohibitions, plus a written certification of compliance and your right to monitor, including testing at least once every 12 months (Cal. Civ. Code § 1798.140 (j)) |
| Third party | Anyone who is neither of the above | No contract shields you; disclosure counts as a sale or share if consideration or cross-context behavioral advertising is involved (Cal. Civ. Code § 1798.140 (ai)) |
The CCPA service provider vs third party question is not semantic: a misclassified or uncontracted vendor converts an ordinary transfer into an unlawful sale or share, and the missing contract is itself a violation.
In the CPPA’s first enforcement decision, American Honda was fined $632,500 partly for sharing data with ad-tech companies without the required contract terms (CPPA, March 12, 2025). Tractor Supply’s $1.35 million order, the CPPA’s largest fine as of September 30, 2025, included the same defect (CPPA, September 30, 2025).
What about AI vendors?
The same analysis applies to your AI stack. Since January 1, 2025, the statute confirms that personal information can exist in “artificial intelligence systems that are capable of outputting personal information” (Cal. Civ. Code § 1798.140(v)(4)(C)).
The Attorney General’s January 13, 2025 advisories confirm existing California privacy law applies to entities that develop, sell, or use AI: “the fifth largest economy in the world is not the wild west” (California AG).
The key point for CCPA and AI is that personal information sent to AI tools in prompts, uploads, or integrations needs the same service-provider or third-party classification and a matching contract. An AI vendor without CCPA-compliant terms creates the same risk that led Sephora to pay a $1.2 million penalty.
What are the CCPA updates for 2026?
The CPPA’s 2025 regulations package – Board-adopted July 24, 2025, OAL-approved September 22, 2025, and effective January 1, 2026 – is a big expansion of CCPA obligations. It adds a new sensitive-PI category, tightens consent and opt-out rules, and introduces risk assessments, ADMT rules, and annual cybersecurity audits on phased deadlines through 2030 (CPPA announcement).
| Requirement | What it means | Deadline |
| Regulations effective | Updates to existing CCPA rules | January 1, 2026 |
| Under-16 PI as sensitive PI | Actual knowledge or willful disregard of age (11 CCR § 7001(bbb)(4)) | January 1, 2026 |
| GPC visible confirmation | Display that the opt-out signal was processed, e.g., “Opt-Out Request Honored” (11 CCR § 7025(c)(6)) | January 1, 2026 |
| Risk assessments | Compliance from January 1, 2026; attestation and summary due to the CPPA | April 1, 2028 |
| ADMT notice, opt-out, access | Rights for significant decisions only | January 1, 2027 |
| Cybersecurity audits | Annual independent audits, phased by revenue tier | April 1, 2028 / 2029 / 2030 |
Sources: CPPA regulations package.
Two of these deserve a closer look:
- A new sensitive-PI category: The personal information of consumers under 16 is treated as sensitive personal information when a business actually knows or willfully disregards their age. (11 CCR § 7001(bbb)(4).
- A stricter definition of consent: Closing or navigating away from a consent pop-up without affirmatively accepting is now expressly not consent (11 CCR § 7004(a)(3)(D)), and opting out must take the same number of steps as opting in or fewer (§ 7004(a)(2)(A)). The principle underneath isn’t new: since January 1, 2023, agreement obtained through dark patterns has not counted as consent (Cal. Civ. Code § 1798.140(h)).
What this means for you
2026 is the year CCPA compliance shifts from policies to evidence. Audits, attestations, and documented assessments mean regulators will ask what you did, and when, not just what your policy says.
All of these requirements depend on one thing: knowing which systems, vendors, and trackers actually handle regulated data. A risk assessment is only as good as this understanding, and most teams find this is where they have the biggest gap.
CCPA vs CPRA
The CCPA and the CPRA are not separate laws. The CPRA is an amendment that made the CCPA stronger. Passed by voters in 2020 and effective January 1, 2023, it expanded consumer rights, increased business responsibilities, and created the CPPA. Today, when people say “CCPA,” they usually mean the law as amended by the CPRA.
| Feature | CCPA (2020) | CPRA (from 2023) |
| Enforcer | Attorney General only | Attorney General + CPPA |
| New rights | Know, delete, opt out of sale | Adds correct and limit sensitive PI |
| Sensitive PI | Not a separate category | Distinct category with extra protections |
| “Sharing” data | Not covered | Covered (cross-context behavioral advertising) |
| Employee / B2B data | Temporarily exempt | Exemptions expired; now covered |
| Cure period | 30-day cure to fix violations | No guaranteed cure period |
For a full side-by-side, see our guide on CCPA vs CPRA.
CCPA vs GDPR
The CCPA and Europe’s GDPR (General Data Protection Regulation) have similar goals but different structures, and confusing them can cause compliance problems. The main difference is that the GDPR usually requires a lawful reason before you process consumer data, while the CCPA allows data processing until a consumer opts out.
| Dimension | CCPA | GDPR |
| Applies to | For-profit businesses meeting thresholds that handle California residents’ data | Any organization processing EU residents’ data, regardless of location |
| Protected people | California residents (consumers) | Everyone in the EU (data subjects) |
| Legal basis to process | None required; relies on notice and opt-out | Requires a lawful basis (consent, contract, etc.) |
| Consent model | Mainly opt-out | Mainly opt-in |
| Enforcer | CA Attorney General + CPPA | National data protection authorities |
| Maximum penalty | $7,988 per intentional violation (2026) | Up to €20 million or 4% of global revenue |
For the details, see our CCPA vs GDPR comparison.
What are the penalties for violating the CCPA?
Ignoring the CCPA and failure to maintain reasonable security procedures required by CCPA guidelines can result in serious financial penalties, and enforcement has become stricter since the CPPA was created. Penalties apply to each violation, so cases involving many consumers can add up quickly.
| Type | Amount (2026, inflation-adjusted) |
| Unintentional violation | Up to $2,663 per violation |
| Intentional violation, or one involving a consumer under 16 | Up to $7,988 per violation |
| Consumer lawsuit for certain data breaches | $107–$799 per consumer per incident, or actual damages |

CCPA enforcement trends: what attorney general & CCPA actually punished
In less than four years, CCPA enforcement has moved from warnings to multi-million dollar penalties. The main regulator documents each action below. The table and chart show how fines have grown since 2022.
| Date | Company | Amount | Enforcer | Core violation |
| Aug 24, 2022 | Sephora | $1.2M | AG | Trackers “constituted a sale” (the AG’s enforcement position; settled, never adjudicated); ignored Global Privacy Control (release) |
| Feb 21, 2024 | DoorDash | $375,000 | AG | Customer data traded to a marketing cooperative “was a sale” (release) |
| Mar 12, 2025 | American Honda | $632,500 | CPPA | Excessive info for rights requests; asymmetrical consent tool; ad-tech data without required contracts (decision) |
| May 6, 2025 | Todd Snyder | $345,178 | CPPA | Misconfigured portal failed opt-outs for 40 days; ID verification for opt-outs (decision) |
| Jul 1, 2025 | Healthline Media | $1.55M | AG | Health-site trackers shared data suggesting serious conditions; the largest CCPA settlement at that date (release) |
| Sep 30, 2025 | Tractor Supply | $1.35M | CPPA | Job-applicant notice gaps; broken opt-out and GPC handling; missing contracts; the CPPA’s largest fine to date (decision) |
| November 2025 | Sling TV | $530,000 | AG | Confusing opt-outs, no in-app opt-out; first streaming-sweep action (release) |
| Nov 21, 2025 | Jam City | $1.4M | AG | No compliant opt-out in any of 21 apps; teens’ data shared without opt-in (release) |
| Feb 11, 2026 | Disney | $2.75M | AG | Opt-out toggles applied only per device or service, so opting out never fully took effect; then the largest settlement (release) |
| Mar 3, 2026 | PlayOn Sports | $1.1M | CPPA | Forced “Agree” banner; first student-privacy decision (decision) |
| Mar 5, 2026 | Ford | $375,703 | CPPA | Opt-out friction; unverified opt-outs treated as “expired” (decision) |
| May 8, 2026 | General Motors | $12.75M | AG with county DA partners and CPPA support | OnStar location and driving data sold to Verisk and LexisNexis Risk Solutions; largest CCPA penalty to date; subject to court approval, not final (release) |

Three main trends stand out in CCPA enforcement:
- Enforcement runs in sector sweeps: Connected vehicles, streaming apps and devices, location data, and a multi-state Global Privacy Control sweep with Colorado and Connecticut.
- Fines are calculated per violation: $382,500 of the Honda penalty mapped to just 153 consumers at $2,500 each, and caps now stand at $2,663 and $7,988 after inflation adjustment.
- Advisories signal what’s next: The CPPA’s data minimization and dark patterns advisories telegraph future targets; as enforcement head Michael Macko put it, “Dark patterns aren’t about intent, they’re about effect.”
The blind spot enforcement keeps finding
If you look at the violations column again, Sephora and Healthline were fined for advertising trackers, DoorDash for a marketing cooperative, GM for selling connected-vehicle data, and Honda, Tractor Supply, and Todd Snyder for opt-out systems that did not work. Most of these data flows were not hidden; they just were not mapped, classified, or properly contracted.
Most compliance programs depend on self-reported vendor inventories, such as questionnaires, procurement lists, and policies about declared tools. However, enforcement often uncovers data flows that were never declared, like a pixel added by a marketing agency or a data feed in a vehicle platform that does not appear on any questionnaire.
How to comply with the CCPA
CCPA compliance is an ongoing process, not a one-time task, and it starts with understanding your own data. The steps below outline the main work involved. You can find more details in our full CCPA compliance guide and checklist.
- Map every tracker and third-party flow on your sites and apps, including AI tools that receive sensitive personal information, and verify by observation rather than questionnaire.
- Fix service-provider contracts. Every recipient must be classified as service provider, contractor, or third party with the required terms.
- Honor Global Privacy Control as a binding opt-out and display confirmation to the consumer.
- Audit your choice UX for symmetry: opting out must be as easy as opting in; agreement obtained through dark patterns is not consent.
- Businesses must update their privacy policy annually.
- Test opt-outs end-to-end across devices, services, and logged-in state.
- Calendar what is next: ADMT rules require compliance from January 1, 2027, and data brokers face DROP deletion duties from August 1, 2026, at $200 per request per day for non-compliance.
How does MELURNA help?
Almost every CCPA requirement – notice at collection, opt-outs, and service provider contracts – comes down to one question: Where does your regulated data actually go?
MELURNA answers it from the outside-in. It is an agentless privacy and AI risk intelligence platform that maps how sensitive data moves across first-, third-, fourth-, and nth-party ecosystems, including the pixels, trackers, and AI vendors that never show up on a security questionnaire.
It traces real data journeys across the web, scores privacy risk at each step, and maps every finding to frameworks like CCPA, GDPR, HIPAA, and SOC 2. MELURNA helps privacy, security, and compliance teams with continuous, evidence-based monitoring instead of point-in-time self-assessments.
Next Steps
If you think the CCPA might apply to you, it is time to take action. Start with the applicability checker above, then read the CCPA compliance guide to build your program, and compare the CCPA and CPRA frameworks.
To find out where your regulated data actually lives before your first risk assessment, request a demo.
FAQs
Does the CCPA apply to small businesses?
Usually not. Coverage depends on meeting one of three thresholds, and most small businesses fall below all of them. However, small businesses that rely on ads or sell data can still be affected by the volume and revenue-share tests.
What is the difference between the CCPA and the CPRA?
The CPRA is a 2023 amendment that expanded the CCPA. It is not a separate law. It added rights to correct and limit sensitive data, created the CPPA regulator, and included coverage of “sharing.”
See our CCPA vs CPRA guide.
Is website tracking a sale under the CCPA?
The AG’s enforcement position is yes: Sephora and DoorDash treated ad trackers and data co-ops as sales. That theory was settled, never adjudicated. Since 2023, “sharing” covers cross-context behavioral advertising regardless of consideration.
What are the CCPA penalties per violation?
Civil penalties can be up to $2,663 per violation and $7,988 for intentional violations or those involving minors. Consumers can also sue for certain breaches, with damages ranging from $107 to $799 per person.
Does the CCPA apply outside California?
In practice, yes. The law covers for-profit businesses doing business in California, no matter where they are based, and “consumer” means a California resident.
What is a CCPA consumer request?
A CCPA request (also called a data subject request, or DSAR) is how a consumer uses their rights, such as asking to know, delete, or correct their data. Covered businesses must provide at least two ways to submit a request and usually have 45 days to respond.
Does the CCPA apply to healthcare?
Data already covered by HIPAA is usually exempt, but other sensitive information that a healthcare company holds, like marketing or website data, can still be subject to the CCPA.
What is ADMT under the CCPA, and when does it apply?
ADMT is any technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. The rules cover only five significant-decision domains: financial or lending services, housing, education, employment or compensation, and healthcare – insurance and advertising are excluded. Pre-use notice, opt-out, and access rights apply from January 1, 2027 (CPPA announcement, September 23, 2025).
What does it mean to be CCPA compliant?
Being CCPA compliant means a covered business meets the law’s ongoing obligations: giving consumers notice at or before data collection, maintaining an accurate privacy policy, honoring consumer requests to know, delete, or correct their data within 45 days, providing “Do Not Sell or Share” and “Limit the Use of My Sensitive Personal Information” opt-outs, honoring Global Privacy Control signals, and holding service providers and contractors to written contracts. Since 2026, it can also mean completing risk assessments and cybersecurity audits, depending on business size.
Does the CCPA only apply to California residents?
It protects only California residents, but it applies to businesses anywhere. Any for-profit business that collects those residents’ data and meets a revenue, volume, or revenue-share threshold must comply, regardless of where it is headquartered or incorporated. California’s CCPA influence has prompted other states to enact similar privacy legislation.
DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.
