What Is CCPA?
The California Consumer Privacy Act (CCPA) is a comprehensive privacy law that went into effect on January 1, 2020, giving California residents rights over their personal information and imposing obligations on businesses that collect, use, sell, or share it. As amended by the California Privacy Rights Act (CPRA) — approved by voters in November 2020 and operative since January 1, 2023 — it is the most significant and most enforced state privacy law in the US. When practitioners say "CCPA" today, they almost always mean the amended statute plus the regulations issued by the California Privacy Protection Agency (CPPA).
For founders and compliance leads, CCPA matters for three reasons. First, California is roughly the world's fifth-largest economy; if you sell to US consumers or businesses at any scale, you likely touch California residents. Second, enforcement is real and growing: the Attorney General and the CPPA have both brought actions, with settlements against major companies for opt-out failures and dark patterns. Third, CCPA anchors the US state-law patchwork — twenty-plus states have passed similar laws, and a CCPA-grade program covers most of what they require.
This lesson gives you the foundation: applicability, definitions, the enforcement landscape, and how CCPA compares to GDPR.
Who Must Comply
CCPA applies to a for-profit entity that does business in California, collects California consumers' personal information (or has it collected on its behalf), determines the purposes and means of processing it, and meets at least one of three thresholds:
- Annual gross revenue above $25 million (adjusted periodically for inflation) — measured globally, not just California revenue;
- Annually buys, sells, or shares the personal information of 100,000 or more California consumers or households; or
- Derives 50 percent or more of annual revenue from selling or sharing consumers' personal information.
Notes that matter in practice:
- "Does business in California" does not require an office there — serving California customers is enough.
- Threshold 2 was raised from 50,000 to 100,000 by CPRA, and "sharing" (for behavioral advertising) counts toward it. A media site with modest revenue but ad trackers firing on 100,000+ California visitors is in scope through this door.
- Nonprofits and government entities are out of scope, but entities that control or are controlled by a covered business and share branding can be swept in.
- Even if you fall below the thresholds, your enterprise customers may be covered businesses — meaning you will face CCPA service provider contract terms regardless. Most B2B SaaS companies encounter CCPA first through customer DPAs, not their own thresholds.
- Some data is exempt from most provisions because other laws govern it: HIPAA-covered health information, GLBA financial data, FCRA credit data, and driver information under the DPPA. The CPRA also ended the temporary exemptions for employee/HR data and B2B contact data on January 1, 2023 — covered businesses now owe full CCPA rights to their California employees, job applicants, and business contacts, which surprises many companies.
Key Definitions
Consumer — a California resident, in any capacity: customer, website visitor, employee, job applicant, or business contact.
Personal information (PI) — information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The statute's categories include identifiers, commercial information (purchase history), internet activity (browsing history, interactions with a site or ad), geolocation, biometrics, employment and education information, and inferences drawn to build a profile. Publicly available government-record information and properly de-identified or aggregated data are excluded.
Sensitive personal information (SPI) — a CPRA-added subcategory: Social Security and other government ID numbers, financial account credentials, precise geolocation, race or ethnicity, religious or philosophical beliefs, union membership, contents of mail/email/texts (where the business is not the intended recipient), genetic data, biometrics processed for identification, health data, and sex life or sexual orientation. SPI carries its own notice and "limit use" obligations, covered in CPRA amendments.
Sale — disclosing PI to a third party for monetary or other valuable consideration. "Other valuable consideration" makes this far broader than cash-for-data brokering; regulators have treated exchanges of data for analytics benefits or ad services as sales.
Sharing — disclosing PI to a third party for cross-context behavioral advertising, whether or not money changes hands. CPRA added this term specifically to end the argument that ad-tech disclosures were not "sales." If you run third-party ad pixels or retargeting, you are almost certainly "sharing."
Service provider / contractor — entities that process PI on a business's behalf under a contract with mandatory restrictions (no selling/sharing, no use beyond the contracted business purposes). Disclosures to a proper service provider are not sales. Third party is everyone else — and disclosures to third parties trigger the opt-out machinery.
Enforcement and Penalties
| Enforcer | Scope | Penalties |
|---|---|---|
| California Privacy Protection Agency (CPPA) | Full administrative enforcement of CCPA/CPRA and its regulations; audits; rulemaking | Up to $2,500 per violation; $7,500 per intentional violation or violations involving minors' PI |
| California Attorney General | Parallel civil enforcement | Same per-violation amounts, civil actions |
| Consumers (private right of action) | Data breaches only — where unredacted/unencrypted PI is breached due to failure to maintain reasonable security | Statutory damages of $100–$750 per consumer per incident, or actual damages |
Three points to internalize. Per violation can mean per consumer per incident, so numbers scale brutally. The CPRA removed the automatic 30-day cure period — regulators now have discretion whether to allow cure. And the private right of action turns any sizable breach into class-action exposure with statutory damages requiring no proof of harm — the strongest argument for treating "reasonable security" as a board-level issue. Enforcement to date has targeted missing or broken opt-outs, ignoring Global Privacy Control signals, dark patterns in consent flows, and defective service-provider contracts.
CCPA vs GDPR
| Dimension | CCPA (as amended) | GDPR |
|---|---|---|
| Model | Opt-out for sale/sharing; transparency-first | Opt-in lawful basis required before processing |
| Applies based on | Business thresholds (revenue/volume) | Any processing of personal data in scope — no size threshold |
| Protected population | California residents (including households) | People in the EU/EEA |
| Lawful basis requirement | None generally — but purpose limitation and minimization now apply | One of six Article 6 bases mandatory |
| Sensitive data | SPI category with limit-use right | Special category data — processing prohibited absent Article 9 condition |
| Fines | $2,500–$7,500 per violation | Up to 20M euros or 4% of global revenue |
| Individual lawsuits | Breach cases only | Broad rights to compensation |
| DPO/representative | Not required | Sometimes required |
The practical takeaway: GDPR compliance gives you a strong head start on CCPA, but not full coverage — the "Do Not Sell or Share" link, GPC honoring, SPI limit-use mechanics, and California-specific notice content are CCPA-specific work.
What Compliance Actually Involves
If the thresholds catch you, the work breaks into a recognizable stack — each layer covered in depth later in this track:
- Data inventory. Map the PI you collect, in the statute's categories, across customers, visitors, employees, and business contacts, flagging sensitive PI and every disclosure to vendors and ad partners.
- The sell/share determination. Audit the tags, SDKs, and data deals. This single analysis drives whether you need opt-out links, GPC handling, and downstream signal propagation — the most enforcement-tested machinery in the law.
- Notices. A CCPA-compliant privacy policy (updated annually), notices at collection at every intake point, and the required footer links.
- Rights operations. Intake channels, verification tiers, and workflows to fulfill know, delete, correct, opt-out, and limit requests inside the statutory clocks — see consumer rights.
- Contracts. Service-provider and contractor terms with every vendor receiving PI, third-party terms where applicable — see business obligations.
- Substantive hygiene. Purpose limitation, minimization, retention schedules, and reasonable security — the CPRA-added duties detailed in CPRA amendments.
- Governance. Training, request logs, and a maintenance cadence — assembled end to end in building a compliance program.
For a company starting from partial compliance, this is typically a three-to-six-month build; for one with a GDPR program already, closer to a third of that.
CCPA Applicability Checklist
- Are you a for-profit entity doing business with California residents?
- Is global annual gross revenue above $25 million?
- Do you buy, sell, or share PI of 100,000+ California consumers or households annually (count ad-tech traffic)?
- Does 50 percent or more of revenue come from selling or sharing PI?
- Do you share common branding with a covered affiliate?
- Even if not covered: do your customers' DPAs impose CCPA service-provider terms on you?
- Have you inventoried California employee, applicant, and B2B contact data (exemptions expired)?
- Do third-party pixels, SDKs, or ad partners receive data from your properties (likely "sharing")?
- Have you identified any SPI categories in your data?
If you checked any of the first four items, you need a compliance program; if you checked the DPA item, you need at least service-provider-grade contracts and processes.
Frequently Asked Questions
We are a B2B SaaS company — does CCPA really affect us?
Almost certainly, through one of two doors. If you meet a threshold (the $25 million revenue test catches many scale-ups), you owe full CCPA compliance — including to California employees and business contacts, since those exemptions ended in 2023. If you do not, your covered customers will still require CCPA service-provider terms in your DPA, restricting how you use their data. Either way, plan for it.
Is using Google Analytics or Meta pixels a "sale" or "share"?
Very likely yes, absent specific configurations. Sending identifiers and browsing behavior to ad-tech partners for cross-context behavioral advertising is the definition of "sharing," and regulators' first major CCPA settlement involved exactly this pattern. If those tags fire on your site for California visitors, you need the opt-out link, GPC support, and contractual coverage.
Do we have to comply for all US users or just Californians?
Legally, only California residents. Operationally, many companies extend CCPA rights nationally because state-by-state gating is complex, other states' laws overlap heavily, and offering rights broadly is good positioning. Geolocation-gating rights is legal but adds engineering and risk if it misfires.
What is the difference between CCPA and CPRA — are they two laws?
One law. The CPRA is a ballot initiative that amended the CCPA — adding sensitive PI, the sharing definition, new rights, data minimization, and the CPPA. There is no separate "CPRA compliance"; there is compliance with the CCPA as amended. The changes are detailed in the CPRA amendments lesson.
Can consumers sue us for any CCPA violation?
No — the private right of action is limited to data breaches involving certain unencrypted, unredacted PI caused by failure to maintain reasonable security. All other violations are enforced by the CPPA and Attorney General. But that breach exposure alone, at $100–$750 statutory damages per consumer, dwarfs regulatory fines for most companies.
How does CCPA fit with other state privacy laws?
CCPA is the strictest baseline in most respects: lowest effective thresholds via the sharing definition, the only dedicated privacy agency, and the only private right of action. Virginia, Colorado, Connecticut, Texas, and the rest mostly follow a similar rights-plus-opt-out model. Build to CCPA plus Colorado's universal opt-out rules and you cover the bulk of the patchwork.
In the next lesson, we will cover consumer rights under CCPA — the requests you must honor and the timelines that govern them.
Standing up CCPA compliance means choosing consent, DSAR, and GRC tooling. AuditXYZ helps you compare compliance automation platforms and find auditors — coverage and pricing in one place.