What Is the CCPA? The California Consumer Privacy Act (2026)
Table of Contents
The California Consumer Privacy Act (CCPA) is California's consumer privacy law. It took effect on January 1, 2020, and a ballot measure called the CPRA expanded it in 2023. You'll see both names; it's one law, and most people call it the CCPA.
It gives California residents the right to know what a business collects about them, to delete it, to correct it, to opt out of its sale or sharing, and to limit how their sensitive data is used. It applies to for-profit businesses that meet any one of three thresholds: about $26.6 million in annual revenue, data on 100,000+ California residents or households, or half their revenue from selling or sharing data.
Fines run up to $2,500 per violation, or $7,500 for intentional violations or ones involving the data of consumers under 16. New rules finalized in 2025 add deadlines that reach beyond the website, starting with risk assessments in 2026.
If your business has had a "Do Not Sell My Info" link since 2020 and left it there, you're behind the current law. The CCPA gained a sharing opt-out, a sensitive-data category, a dedicated regulator, and, most recently, a set of 2025 rules with compliance dates running through 2030.
This guide covers the law as it stands now: what it is, who it covers, the rights it grants, and what it requires from your business. For a side-by-side of what the 2023 amendment changed, see CPRA vs CCPA. For where California sits among all 20 state laws, see our state privacy law tracker.

What is the CCPA?
The California Consumer Privacy Act is the law that gives California residents control over the personal information businesses collect about them. California's governor signed it on June 28, 2018, and it took effect on January 1, 2020, making California the first state with a comprehensive consumer privacy law. It lives in the California Civil Code at § 1798.100 and following.
In 2020, voters passed the California Privacy Rights Act (CPRA), which amended and expanded the CCPA effective January 1, 2023. The state Attorney General is explicit that this did not create a second law:
"The CPRA amends the CCPA; it does not create a separate, new law." — California Attorney General
The official name is still "the CCPA, as amended." When you see "CCPA," "CPRA," or "CCPA/CPRA," they refer to the same statute.
What does CCPA stand for?
CCPA stands for the California Consumer Privacy Act. It was enacted as Assembly Bill 375 in 2018.
What is personal information under the CCPA?
Personal information under the CCPA is any data that identifies, relates to, or could reasonably be linked to a California resident or their household. The definition is deliberately wide: it catches data that points to someone directly and data that points to them by inference.
It includes:
- Direct identifiers: name, email, postal address, account login
- Online identifiers: cookie IDs, IP addresses, device IDs
- Internet activity: browsing and search history, and how someone interacts with a site or an ad
- Precise geolocation, meaning data that can pinpoint someone within about 1,850 feet
- Biometric data: face, fingerprint, or voice records
- Sensitive personal information: Social Security number, precise location, race or ethnicity, religion, health, and genetic data
- Inferences drawn from any of the above to build a profile
Truly aggregated or anonymized data sits outside the definition, but only while it cannot be traced back to a person. Combine two harmless-looking fields and the data can land right back inside it.
What does the CCPA say about cookies?
The CCPA treats cookies as personal information whenever they act as unique identifiers, which most advertising and analytics cookies do. The law never names cookies outright; they fall in through the "unique identifier" part of the personal-information definition.
First-party cookies, set by the site someone is visiting, usually run core functions like keeping a user logged in. Third-party cookies, set by ad networks and social platforms, are the ones that follow people across sites and build advertising profiles. Those are the cookies that count as sharing under the law.
For a business, that means the cookies sending data to ad platforms are exactly what a California resident can opt out of. Enzuzo's consent management platform classifies each cookie, holds the sharing-classified ones until the consent state allows them, and records the choice.

Who must comply with the CCPA?
The CCPA applies to a for-profit business that does business in California and meets at least one of these three thresholds:
- Over $26.6 million in gross annual revenue in the prior year. (The CCPA's original $25 million line is adjusted for inflation every two years; the state set it at $26,625,000 as of 2025.)
- Personal information of 100,000 or more California residents or households, bought, sold, or shared in a year.
- Half or more of annual revenue from selling or sharing California residents' personal information.
Most small businesses clear none of these lines and aren't covered; the thresholds are built to catch data-heavy operations, not the corner store.
A "resident" is a California consumer, and the count is people, not visits: one person who visits your site fifty times is still one resident.
The law reaches businesses anywhere, not just those based in California, if they do business with California residents and cross a threshold. Nonprofits and government agencies are not covered. Certain data is carved out at the data level, including health information under HIPAA, some financial data under the GLBA, and credit data under the FCRA.
One change that catches teams that set up compliance early: since January 1, 2023, the CCPA also covers data about employees and business contacts, which were previously exempt. If your only California "consumers" are your own staff and B2B contacts, you may still be in scope.
Rights under the CCPA
California residents hold the following rights, and each one puts a specific job on the businesses that hold their data:
- Know what personal information a business collects, and how it's used and shared.
- Access a copy of that information.
- Delete personal information the business collected from them.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of their personal information.
- Limit the use of sensitive personal information (things like Social Security numbers, precise location, health, race, or religion) to what's needed to provide the service.
- Non-discrimination: businesses can't penalize them for exercising any of these rights.
A business has 45 days to respond to a request, with one 45-day extension allowed for complex cases. Rights 4, 5, and 6 arrived with the 2023 amendment; the rest have been in force since 2020.
"Do not sell or share my personal information"
The opt-out is the CCPA right most visible on your website, and its wording changed with the amendment. The original CCPA covered the sale of personal information. The amended law added sharing, meaning disclosure for cross-context behavioral advertising (tracking someone across different sites to target ads), even when no money changes hands.
Under the law, a "sale" is broader than a cash transaction: it means disclosing or making personal information available to a third party for money or for anything else of value. A data exchange with no invoice attached can still count as a sale.
That addition is what pulls in ordinary ad tech. If your site sends visitor data to an advertising platform to target ads, that is "sharing" under the law, and California residents can opt out of it. You provide the opt-out through a "Do Not Sell or Share My Personal Information" link, an opt-out preference signal, or both.
What the CCPA requires from your website
Under this law your website needs a privacy notice, working opt-out mechanics, and records that prove requests were honored. These are the pieces that show up in enforcement.
Notice at collection. At or before the point you collect data, tell people what you collect, why, whether you sell or share it, and how long you keep it.
A privacy policy that matches practice. List the categories of personal information you collect, where it comes from, why you use it, what you sell or share, and who receives it. Refresh that list at least once a year so it tracks what the site actually does.
The opt-out, and Global Privacy Control. Give California residents a way to opt out of sale and sharing. The state also requires you to honor Global Privacy Control (GPC), a setting built into browsers like Firefox, Brave, and DuckDuckGo that sends the opt-out for the visitor automatically. The Attorney General says it "must be honored by covered businesses as a valid consumer request," so a banner that ignores GPC is out of step with the law. Once someone opts out, stop selling or sharing their data within 15 business days.
A right-to-limit path for sensitive data. If you use sensitive personal information beyond the exempt purposes, give residents a way to limit that use.
Data minimization. Collect and keep only the personal information you need for the purpose you named. The same limit applies to tracking technologies, so drop cookies you cannot justify.
Rights-request intake with records. Handle know, access, delete, correct, and opt-out requests within 45 days, verify identity in proportion to the request, and keep logs that show what happened.
Doing this on one page is manageable by hand. Doing it across a whole site, and keeping the records to prove each request was honored, is what a consent management platform automates.
CCPA compliance checklist
CCPA compliance is mostly a set of website mechanics enforcement actually tests, plus a few dated obligations that phase in through 2030. The CPRA compliance checklist lays out the full step-by-step, with every deadline and who each one applies to.
CCPA penalties and enforcement
A CCPA violation costs up to $2,500, or up to $7,500 for intentional violations or ones involving the data of consumers under 16, and each affected resident can count as a separate violation.
Two bodies enforce the law: the California Privacy Protection Agency (CPPA), the dedicated regulator the amendment created, and the Attorney General. Consumers can't sue over most violations, but a data breach carries a private right of action worth $100 to $750 per resident per incident.
Enforcement is active. In 2025 the CPPA fined American Honda $632,500 over ad-tech contracts and opt-out flows, and fined the retailer Todd Snyder $345,178 after its privacy portal failed to process opt-out requests for 40 days.
The Attorney General settled with Healthline for $1.55 million, its largest CCPA penalty so far, for sharing data that revealed users' health interests, using it beyond what was disclosed, and missing required vendor-contract terms. The through-line across all three is operational: the fine follows the gap between what a site promises and what it actually does with data.
How the CCPA changed: CPRA and the 2025 rules
The law has kept moving since 2020. The 2023 amendment reshaped it, and a set of rules the CPPA adopted in September 2025 added new obligations with staggered deadlines:
Deadlines confirmed against CPPA rulemaking records, August 2026. For the full comparison of what the amendment changed and what to do about each change, see CPRA vs CCPA.
| Date | What changed | What it means |
|---|---|---|
| Jan 1, 2020 | CCPA takes effect | The original rights and opt-out |
| Jan 1, 2023 | CPRA amendments take effect | Sharing opt-out, sensitive-data category, correction right, CPPA created, employee/B2B data covered |
| Jan 1, 2025 | Neural data added to sensitive personal information | Update your data inventory |
| Sep 2025 | ADMT, risk-assessment, and cybersecurity-audit rules adopted | The three rows below are the schedule |
| Jan 1, 2026 | Risk-assessment obligations apply | Assess and document high-risk processing |
| Jan 1, 2027 | Automated decision-making (ADMT) compliance | Notices and opt-outs for significant automated decisions |
| Apr 2028–2030 | Cybersecurity audit certifications, staged by revenue | Larger businesses certify first |
FAQs
What does CCPA stand for?
CCPA stands for the California Consumer Privacy Act, enacted in 2018 (Assembly Bill 375) and in effect since January 1, 2020. It gives California residents rights over the personal information businesses collect about them, and it was the first comprehensive consumer privacy law in the United States.
Who has to comply with the CCPA?
For-profit businesses that do business in California and meet one of three thresholds: over $26.6 million in annual revenue, personal information of 100,000+ California residents or households, or half or more of revenue from selling or sharing personal information. Businesses based outside California are covered if they meet a threshold.
What rights does the CCPA give consumers?
California residents can know what's collected about them, access it, delete it, correct it, opt out of its sale or sharing, and limit the use of sensitive personal information. They also have a right not to be penalized for exercising these rights. Businesses must respond within 45 days.
Is the CCPA the same as the California Privacy Rights Act (CPRA)?
Effectively, yes. The CPRA is a 2020 ballot measure that amended the CCPA effective January 1, 2023; it did not create a separate law. The Attorney General refers to the result as "the CCPA, as amended." The CPRA added the sharing opt-out, a sensitive-data category, and the CPPA regulator.
Does the CCPA require honoring Global Privacy Control?
Yes. The Attorney General states that GPC, a browser signal that automatically sends a consumer's opt-out, must be honored by covered businesses as a valid request. Your consent tooling needs to read the signal and stop selling or sharing that visitor's data.
What are the penalties for a CCPA violation?
Up to $2,500 per violation, or up to $7,500 if the violation is intentional or involves a child's personal information, with each affected resident counting separately. The CPPA and the Attorney General enforce it. Data breaches also allow consumers to sue directly, at $100 to $750 per resident per incident.
What changed under the CCPA in 2025 and 2026?
Neural data became sensitive personal information in January 2025. The CPPA adopted rules on risk assessments, automated decision-making, and cybersecurity audits in September 2025, with compliance deadlines starting January 1, 2026 (risk assessments) and January 1, 2027 (automated decision-making).
How Enzuzo handles CCPA on your site
Enzuzo's consent management platform serves California visitors the required opt-out, honors GPC signals automatically, blocks sale- and sharing-classified tags until the consent state allows them, and keeps the timestamped records that enforcement asks for. Teams typically go live in one to three days, and the same setup covers the other 19 state laws. See our CCPA compliance software for the details.
One consent setup for California and the other 19 state privacy laws → Book a demo
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.

