What is the California Consumer Privacy Act (CCPA)?
Also known as: CCPA, California Consumer Privacy Act, CCPA/CPRA, California Privacy Law
The CCPA was originally enacted in 2018 and was significantly amended by the California Privacy Rights Act (CPRA), approved by California voters in 2020. The CPRA amendments took effect on January 1, 2023. The CPRA did not create a separate privacy law; it amended the CCPA.
The CCPA gives consumers rights including the right to know, delete, correct, opt out of the sale or sharing of personal information, limit certain uses of sensitive personal information, and receive equal treatment when exercising their privacy rights.
For websites, CCPA compliance commonly involves Do Not Sell or Share My Personal Information, Global Privacy Control (GPC), privacy notices, cookie and tracking disclosures, and mechanisms for consumers to exercise their rights.
What does CCPA mean?
CCPA stands for California Consumer Privacy Act.
The law regulates how covered businesses collect, use, disclose, sell and share consumers' personal information.
The CCPA is particularly notable because it gives consumers meaningful control over how businesses use their information, including the ability to opt out of certain sales and sharing.
Unlike a traditional consent-based privacy framework, the CCPA generally focuses heavily on consumer rights and opt-out mechanisms.
This distinction is important when comparing CCPA with regulations such as the GDPR.
What is CPRA?
CPRA stands for the California Privacy Rights Act.
The CPRA was approved by California voters through Proposition 24 in 2020. Rather than replacing the CCPA with a completely separate law, the CPRA amended the existing CCPA and introduced additional consumer rights and business obligations.
The CPRA amendments became effective on January 1, 2023.
Who does the CCPA protect?
The CCPA provides privacy rights to California residents.
The California Privacy Protection Agency explains that a California resident is an individual who resides in California, including certain employees, job applicants, students, independent contractors and business contacts.
The law is therefore focused on the privacy rights of people rather than corporations or other business entities.
Which businesses must comply with the CCPA?
The CCPA applies to certain for-profit businesses that do business in California, collect consumers' personal information, determine the purposes and means of processing that information, and satisfy applicable statutory thresholds.
The exact applicability thresholds and exemptions should be assessed against the current CCPA and regulations rather than relying on a generic "does business in California" test.
The CCPA can therefore apply to businesses located outside California.
A company does not necessarily need a physical office in California for the law to become relevant.
What is personal information under the CCPA?
The CCPA defines personal information broadly.
It generally includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household.
Examples can include:
- Name
- Email address
- Telephone number
- Postal address
- IP address
- Browsing history
- Search history
- Purchase history
- Geolocation information
- Online identifiers
- Device information
- Inferences about preferences
- Account information
- Advertising identifiers
The CCPA also distinguishes sensitive personal information, which receives additional protections. Examples include precise geolocation, certain financial information, account credentials, health information, genetic information and certain biometric information.
What is sensitive personal information under CCPA?
Sensitive personal information (SPI) is a category of personal information that receives additional protection under the CCPA.
Depending on the circumstances, sensitive personal information can include:
- Social Security numbers
- Driver's license information
- Financial account credentials
- Precise geolocation
- Contents of communications
- Genetic information
- Certain biometric information
- Health information
- Information about sex life or sexual orientation
- Racial or ethnic origin
- Religious or philosophical beliefs
- Union membership
Consumers have a right to limit the use and disclosure of sensitive personal information in circumstances covered by the law.
What are the main CCPA consumer rights?
The CCPA provides California residents with several important privacy rights.
Right to Know
Consumers can request information about:
- The categories of personal information collected
- The sources from which information was collected
- The purposes for collecting, selling or sharing information
- Categories of third parties receiving information
- Certain specific pieces of personal information
Right to Delete
Consumers can request deletion of personal information collected about them, subject to statutory exceptions.
Businesses may be required to direct applicable service providers or contractors to delete information as well.
Right to Correct
Consumers can request correction of inaccurate personal information maintained by a business.
Right to Opt Out of Sale or Sharing
Consumers can opt out of the sale or sharing of their personal information in circumstances covered by the CCPA.
The right to opt out of sharing is particularly relevant to cross-context behavioral advertising.
Right to Limit
Consumers can limit certain uses and disclosures of their sensitive personal information.
Right to Equal Treatment
Businesses generally cannot discriminate against consumers for exercising their CCPA rights.
Rights relating to Automated Decisionmaking Technology
California's updated framework also includes rights and obligations relating to certain uses of Automated Decisionmaking Technology (ADMT).
Applicable businesses using ADMT for significant decisions may have additional notice, opt-out and access-related obligations. The relevant ADMT requirements have their own implementation timelines.
What is CCPA opt-out?
One of the defining features of the CCPA is the consumer's right to opt out of the sale or sharing of personal information where applicable.
A business that sells or shares personal information may need to provide consumers with an appropriate mechanism to exercise this right.
For websites, this commonly appears as:
“Do Not Sell or Share My Personal Information”
or an equivalent privacy-choice mechanism.
The opt-out mechanism should be easy to find and use.
What is Do Not Sell or Share My Personal Information?
Do Not Sell or Share My Personal Information is a CCPA privacy-choice mechanism that allows consumers to exercise their right to opt out of certain sales or sharing of personal information.
The concept is especially relevant to:
- Advertising technology
- Retargeting
- Cross-context behavioral advertising
- Data sharing
- Third-party marketing platforms
- Data monetisation
A website should connect the consumer's privacy choice to the technical systems that process or share the relevant information.
Simply displaying a link without enforcing the resulting preference can create a gap between the website's stated privacy controls and its actual behaviour.
What is Global Privacy Control (GPC)?
Global Privacy Control (GPC) is a browser or user-agent signal that communicates a consumer's privacy preference to websites.
Under the CCPA framework, covered businesses must honour qualifying opt-out preference signals in the circumstances required by law.
The California Privacy Protection Agency specifically identifies opt-out preference signals as a mechanism through which consumers can exercise their opt-out rights.
For a website, this means privacy compliance cannot necessarily depend only on a visitor manually clicking a "Do Not Sell or Share" link.
A compliant implementation should be capable of detecting and appropriately responding to applicable privacy signals.
CCPA and cookies
The CCPA does not simply regulate "cookies" as a standalone category.
The relevant question is what information a cookie, pixel, SDK or similar technology collects or enables a business or third party to process.
Website technologies that may be relevant include:
- Advertising cookies
- Retargeting pixels
- Analytics technologies
- Social-media pixels
- Device identifiers
- Advertising IDs
- Cross-site tracking technologies
- Third-party scripts
Businesses should therefore evaluate their tracking technologies against their CCPA obligations rather than assuming that a particular cookie category is automatically compliant or non-compliant.
Does CCPA require cookie consent?
Not in the same way as the GDPR.
The CCPA generally centres on transparency and consumer rights, particularly the right to opt out of the sale or sharing of personal information.
This is different from the GDPR's approach to consent as one of several lawful bases for processing.
However, businesses may still need privacy choices, disclosures and technical controls for cookies and tracking technologies depending on what those technologies do and whether the associated processing falls within CCPA requirements.
This distinction is why a CCPA privacy preference centre should not simply be copied from a GDPR consent banner without considering the applicable legal framework.
CCPA opt-in vs opt-out
A useful way to understand the difference is:
| GDPR | CCPA |
|---|---|
| Often requires prior consent where consent is the applicable basis | Generally emphasises consumer opt-out rights |
| Consent can be required before certain processing | Opt-out is particularly important for sale/sharing |
| Prior blocking may be required where consent is necessary | Technical enforcement should respect opt-out preferences |
| Consent must meet specific validity requirements | Businesses must provide mechanisms for exercising CCPA rights |
| Consent withdrawal is important | Opt-out preference must be honoured |
These frameworks can overlap, but they should not be treated as identical.
A business operating globally may need a consent model capable of adapting to the user's jurisdiction.
CCPA vs GDPR
The CCPA and GDPR are both major privacy laws, but they use different regulatory approaches.
GDPR
The GDPR is a comprehensive European data-protection regulation focused on lawful processing, data-subject rights, accountability, security and other privacy principles.
Consent is one of several lawful bases for processing.
CCPA
The CCPA focuses heavily on consumer transparency and rights, including the right to know, delete, correct, opt out of sale or sharing, and limit certain uses of sensitive personal information.
The two frameworks therefore overlap but are not interchangeable.
A website attempting to meet both requirements may need:
- Consent controls
- Opt-out controls
- GPC handling
- Prior blocking
- Privacy notices
- Consent or preference records
- Data-subject/consumer request workflows
CCPA vs CPRA
CCPA and CPRA are often used together because the CPRA amended the CCPA.
The CPRA introduced additional privacy protections and created the California Privacy Protection Agency.
Important changes included enhanced rights relating to sensitive personal information, correction, data minimisation, consumer privacy choices and other areas.
For current compliance purposes, businesses should generally evaluate the CCPA as amended by the CPRA, together with the applicable regulations.
What is CCPA compliance?
CCPA compliance means implementing the legal, organisational and technical measures necessary to meet applicable CCPA requirements.
A compliance programme may include:
- Privacy notices
- Personal-information inventories
- Data mapping
- Consumer request processes
- Opt-out mechanisms
- GPC handling
- Sensitive personal information controls
- Vendor and service-provider management
- Data retention controls
- Security safeguards
- Privacy preference management
- Recordkeeping
- Risk assessments where applicable
- Cybersecurity audits where applicable
- ADMT compliance where applicable
The CCPA regulations effective January 1, 2026 expanded the operational compliance landscape, including requirements related to risk assessments, cybersecurity audits and automated decisionmaking technology.
What is a CCPA privacy policy?
A CCPA privacy policy is a privacy notice that provides consumers with information required by applicable California privacy law.
Depending on the business and processing activities, it may explain:
- Categories of personal information collected
- Sources of personal information
- Business or commercial purposes
- Categories of third parties
- Sale or sharing practices
- Consumer privacy rights
- How consumers can exercise their rights
- How consumers can submit requests
- Information about opt-out mechanisms
The California Privacy Protection Agency states that covered businesses must provide consumers with disclosures about their privacy practices, including a privacy policy.
How do consumers exercise CCPA rights?
Businesses subject to the CCPA must provide appropriate methods for consumers to exercise their rights.
Depending on the right and business, mechanisms can include:
- Online forms
- Privacy request portals
- Toll-free telephone numbers
- Privacy preference centres
The applicable requirements differ depending on the request and business circumstances.
For example, the CPPA explains that businesses generally must provide at least two methods for certain requests to know, delete or correct, subject to specific exceptions.
What is a CCPA DSAR?
A Data Subject Access Request (DSAR) is a general privacy-industry term for an individual's request to exercise certain data rights.
Under the CCPA, businesses more commonly refer to these as consumer requests rather than using GDPR terminology.
Depending on the situation, a consumer may request to:
- Know information held about them
- Delete information
- Correct inaccurate information
- Opt out of sale or sharing
- Limit certain sensitive personal information uses
A privacy-management system can help organisations receive, verify, route and document these requests.
CCPA and data minimisation
The modern CCPA framework also includes requirements around purpose limitation and data minimisation.
The California Privacy Protection Agency explains that businesses must limit the collection, use and retention of personal information to purposes that meet the applicable statutory standards and are reasonably necessary and proportionate.
This means CCPA compliance is not only about providing a privacy link.
Businesses should also examine whether they collect and retain more personal information than is reasonably necessary for their disclosed purposes.
CCPA enforcement
The California Privacy Protection Agency (CalPrivacy) is responsible for implementing and enforcing the CCPA, alongside its other statutory responsibilities.
The Agency can investigate potential violations, conduct audits and bring administrative enforcement actions.
This makes demonstrable privacy compliance increasingly important for organisations within the CCPA's scope.
CCPA penalties
CCPA violations can result in significant financial consequences, depending on the violation and applicable statutory provisions.
Businesses should not approach compliance by simply calculating a potential fine.
A stronger approach is to establish repeatable controls that can demonstrate:
- What personal information is collected
- Why it is collected
- Where it goes
- Which privacy choices were available
- What choice the consumer made
- Whether an opt-out signal was received
- Whether the preference was technically enforced
- How consumer requests were handled
CCPA compliance checklist
A practical CCPA website compliance checklist includes:
- Determine whether the business falls within the CCPA.
- Identify personal information collected from consumers.
- Identify sensitive personal information.
- Map third-party scripts, cookies and tracking technologies.
- Review whether personal information is sold or shared.
- Provide an appropriate privacy policy.
- Provide required opt-out mechanisms.
- Support applicable Global Privacy Control signals.
- Provide mechanisms for consumer privacy requests.
- Maintain processes for deletion and correction requests.
- Review sensitive personal information controls.
- Review service providers and contractors.
- Implement applicable data minimisation and retention controls.
- Evaluate risk-assessment requirements where applicable.
- Evaluate cybersecurity-audit requirements where applicable.
- Evaluate ADMT requirements where applicable.
- Regularly test whether privacy preferences are technically enforced.
How ConsentX helps with CCPA compliance
ConsentX helps businesses operationalise privacy preferences across websites and digital properties.
For CCPA/CPRA use cases, relevant capabilities can include:
Global Privacy Control handling
Opt-out preference management
Consent and preference records
Prior-script blocking
Cookie and tracker scanning
Privacy preference centres
Audit evidence
DSAR and grievance workflows
Region-based privacy rules
The goal is to connect a consumer's privacy decision with the technical behaviour of the website.
For example, if a visitor opts out of the sale or sharing of personal information, the organisation needs an implementation that can carry that preference into the relevant processing and advertising technologies.
ConsentX provides tooling for CCPA/CPRA privacy preferences, GPC handling and consent records.
CCPA and Global Privacy Control with ConsentX
GPC is particularly important for automated privacy preference management.
Instead of requiring every consumer to manually locate an opt-out link on every website, a browser or user agent can communicate a qualifying privacy preference.
A privacy platform can then:
Detect
Detect the GPC signal.
Associate
Associate it with the applicable privacy preference.
Apply
Apply the relevant opt-out state.
Restrict
Prevent or restrict applicable processing.
Evidence
Maintain evidence of the preference where appropriate.
This turns privacy choice into an enforceable technical control rather than a purely informational disclosure.
CCPA: Key takeaways
The California Consumer Privacy Act (CCPA) is California's comprehensive consumer privacy law, as amended by the CPRA.
The key points are:
- The CCPA protects privacy rights of California residents.
- CPRA amended the CCPA rather than creating a separate law.
- The framework provides rights to know, delete and correct personal information.
- Consumers can opt out of applicable sales and sharing.
- Consumers can limit certain uses of sensitive personal information.
- Businesses must provide mechanisms for exercising applicable privacy rights.
- Global Privacy Control is an important opt-out preference mechanism.
- CCPA is not identical to GDPR.
- CCPA compliance involves both legal processes and technical enforcement.
- The 2026 regulatory framework introduces additional compliance considerations around risk assessments, cybersecurity audits and ADMT.
- A privacy banner alone is not a complete CCPA compliance strategy.
Make CCPA privacy preferences enforceable
CCPA compliance is not just about publishing a privacy policy or adding a “Do Not Sell or Share” link. Privacy choices need to be captured, respected and technically enforced across the systems that process personal information. ConsentX helps organisations manage CCPA/CPRA privacy preferences, respond to GPC signals, control trackers and maintain audit-ready evidence. Build a privacy preference system that turns consumer choices into enforceable controls with ConsentX.
Related Terms
A browser or user-agent signal that communicates a consumer's privacy preference, including applicable CCPA opt-out requests.
A CCPA privacy choice allowing consumers to opt out of applicable sale or sharing of personal information.
The European Union's comprehensive data-protection regulation.
The California Privacy Rights Act, which amended and expanded the CCPA.
A category of information receiving additional protection under the CCPA.
A general privacy-industry term for requests to exercise applicable data rights.
Technology used to manage consent and privacy preferences across websites and digital properties.
A technical and legal concept generally associated with obtaining required consent before applicable non-essential processing occurs.
An interface where users can review and change their privacy choices.