CCPA: The Complete Guide
The California Consumer Privacy Act was the first comprehensive consumer privacy law in the United States. Signed into law in 2018 and effective January 1, 2020, the CCPA grants California residents significant control over how businesses collect, use, and sell their personal information. It triggered a wave of US state privacy legislation that has not slowed — as of mid-2026, more than 20 states have enacted or are actively advancing comprehensive privacy laws.
What the CCPA Is and Who Enforces It
The CCPA was enacted by the California State Legislature, codified at Civil Code Section 1798.100 et seq., and became the most significant US privacy law at the time of its passage. Enforcement authority rests with the California Attorney General, who may investigate, issue civil investigative demands, and pursue civil penalties. The CPRA, passed by California voters in November 2020, created the California Privacy Protection Agency (CPPA) as the first dedicated state privacy enforcement body, which now shares enforcement authority alongside the AG.
Territorial and Material Scope
The CCPA applies to for-profit businesses that collect personal information from California residents and meet at least one of three thresholds:
- Annual gross revenue exceeding $25 million.
- Buying, selling, or sharing the personal information of 100,000 or more consumers or households annually.
- Deriving 50% or more of annual revenue from selling consumers' personal information.
The CCPA has practical extraterritorial effect — a business incorporated in Texas but serving California consumers and meeting the revenue threshold must comply, regardless of its physical location. Note that the CPRA, effective January 1, 2023, modified the threshold to 100,000 consumers (removing households from that calculation).
The CCPA defines personal information broadly: identifiers (name, email, IP address, device IDs), commercial information, biometric data, internet or network activity, geolocation data, audio or visual data, professional information, education information, and inferences drawn from any of the above to create a consumer profile.
Four Core Consumer Rights
The CCPA establishes four core consumer rights that covered businesses must operationalize:
- Right to know — Consumers may request disclosure of the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties with whom it is shared. Two separate types of requests exist: a category-level disclosure and a specific-pieces request.
- Right to delete — Consumers may request deletion of personal information, subject to defined exceptions such as completing a transaction, security purposes, legal obligations, and internal uses.
- Right to opt out of sale — Consumers may direct a business not to sell their personal information to third parties. Businesses must provide a clear "Do Not Sell My Personal Information" link on their homepage.
- Right to non-discrimination — Businesses may not deny goods or services, charge different prices, or provide a different level of service because a consumer exercised their CCPA rights. Financial incentive programs are permitted if properly disclosed and not coercive.
Service Providers and Third Parties
The CCPA distinguishes between businesses, service providers, and third parties. Service providers receive personal information under a written contract limiting their use to performing services for the business. Third parties receive personal information without such restrictions. Sharing personal information with a third party (not a service provider) for advertising or other value-exchange purposes can constitute a "sale" triggering opt-out rights even if no money changes hands.
This structure requires businesses to audit all vendor relationships and classify each as a service provider or third party, executing appropriate contracts for each category.
Enforcement and Penalties
The California Attorney General enforces the CCPA with civil penalties of $2,500 per unintentional violation and $7,500 per intentional violation. The CPPA enforces the CPRA amendments under the same penalty structure. The AG must provide 30 days' notice before initiating an enforcement action, allowing a cure opportunity — though enforcement without cure is available in appropriate circumstances.
The CCPA also provides a private right of action for consumers whose nonencrypted, nonredacted personal information is exposed in a data breach resulting from a failure to implement reasonable security. Statutory damages range from $100 to $750 per consumer per incident, or actual damages if greater. Class action exposure under this provision has produced significant settlements.
By mid-2025, the CPPA had initiated its first formal enforcement proceedings, pursuing a data broker for failure to register with the California data broker registry — a CPRA-introduced requirement.
CCPA vs. GDPR and Sibling State Laws
The CCPA shares approximately 55% conceptual overlap with the GDPR but differs in fundamental architecture. Where the GDPR defaults to opt-in (requiring a lawful basis before processing), the CCPA defaults to opt-out (allowing processing unless the consumer objects to sale or sharing). GDPR applies based on the location of the data subject; CCPA applies based on whether the business meets revenue or volume thresholds.
Among US state laws, the CPRA (85% overlap) is the direct successor, adding sensitive personal information, data minimization, and the CPPA. The VCDPA and CPA share broadly similar rights frameworks but with different thresholds and enforcement structures. The CTDPA follows the Virginia-Colorado model with additional loyalty program provisions.
Practical Compliance Steps and Timeline
| Phase | Activities | Typical Duration |
|---|---|---|
| Assessment | Applicability analysis, data inventory | 2-4 weeks |
| Design | Privacy policy update, opt-out mechanism, request workflows | 3-6 weeks |
| Implementation | Technical controls, vendor contracts, staff training | 4-8 weeks |
| Ongoing | Request fulfillment, vendor oversight, policy maintenance | Continuous |
Key compliance steps:
- Assess applicability — Determine whether your business meets any of the three CCPA thresholds.
- Data inventory — Map personal information collection, use, and sharing practices across all systems.
- Update privacy policy — Disclose required categories, purposes, rights, and methods for submitting requests.
- Implement opt-out — Provide a "Do Not Sell or Share My Personal Information" link and honor it within 15 business days.
- Consumer request processes — Build intake, identity verification, and response workflows meeting 45-day deadlines (with a 45-day extension available).
- Vendor contracts — Audit all vendor relationships and execute service provider agreements or third-party contracts.
- Employee training — Train consumer-facing staff on identifying and routing privacy requests.
- Data broker registry — If applicable, register with California's data broker registry under CPRA.
How Privacy Automation Helps
CCPA compliance is operationally intensive — managing DSR intake, verification, routing, and fulfillment at scale requires process infrastructure that manual workflows struggle to sustain. TruePrivacy automates the core mechanics: AI-powered data discovery across 128-plus sources builds the data map underlying your privacy policy disclosures, while DSR automation handles the end-to-end request lifecycle. TruePrivacy supports CCPA, CPRA, GDPR, LGPD, and 12-plus other frameworks from a single platform.
At $5,000 per year with 24-hour onboarding, TruePrivacy is well-suited for businesses entering CCPA compliance or managing a growing portfolio of US state privacy obligations. AuditXYZ rates it 88/100. Organizations with 300-plus jurisdictions or highly customized enterprise workflows may need to evaluate enterprise-tier alternatives — see the best privacy management tools comparison or TruePrivacy vs OneTrust.
Frequently Asked Questions
We are a B2B SaaS company with no direct California consumer relationships. Do we need to comply? Possibly. "Consumers" under the CCPA includes individuals in their personal and professional capacities. If you collect personal information from California-based employees of your business customers — such as names, emails, or usage data — and you meet a revenue or volume threshold, you may be within scope. Many B2B SaaS companies are covered through their handling of employee data or end-user data on behalf of clients.
What is the difference between "selling" and "sharing" personal information? The CPRA added "sharing" as a distinct concept covering disclosure for cross-context behavioral advertising, even without monetary consideration. Before the CPRA, some businesses argued that sharing data with advertising partners in exchange for free services was not a "sale." The CPRA closed this gap. Both selling and sharing now trigger opt-out rights.
Do we need to respond to "Do Not Sell" requests from non-California residents? The CCPA only grants rights to California consumers. However, many businesses apply opt-out mechanisms nationally to avoid operating separate systems. If you choose a national approach, you are not legally required to do so — it is a practical decision.
What security standard does the private right of action require? The CCPA does not define "reasonable security" precisely. California's Attorney General has pointed to the CIS Controls and NIST frameworks as reference points. Courts and settlements have generally examined whether basic security hygiene was in place — encryption at rest and in transit, access controls, patching, and monitoring. A documented security program materially reduces class action exposure.
How do service provider agreements need to be structured? Service provider contracts must prohibit the service provider from retaining, using, or disclosing personal information for any purpose other than performing the services. They must also prohibit selling or sharing the personal information and require the service provider to notify you if it cannot meet its obligations. The CPRA introduced additional required contract provisions for service providers, contractors, and third parties.