US State Law California, USA

CCPA Complete Guide: California Privacy Law After the CPRA

The CCPA as amended by the CPRA: who is covered, consumer rights, sale and sharing rules, CPPA enforcement, and the fines and settlements shaping compliance.

Regulation

California Consumer Privacy Act (Cal. Civ. Code 1798.100 et seq.), as amended by the CPRA (2020)

Max Penalty

$2,500 per violation; $7,500 per intentional violation or violation involving minors; statutory damages of $100-$750 per consumer per incident for breaches

Enforcing Authority

California Privacy Protection Agency (CPPA) and California Attorney General

Official Source

cppa.ca.gov

Executive Summary

  • The CCPA (2018), rewritten by the CPRA ballot initiative (fully operative January 2023), is the strictest US state privacy law and the template regulators elsewhere react to.
  • It covers for-profit businesses doing business in California that exceed any one threshold: roughly $25M+ annual revenue (inflation-adjusted), data on 100,000+ consumers or households, or 50%+ revenue from selling or sharing personal information.
  • Consumers hold rights to know, delete, correct, opt out of sale and sharing (including for cross-context behavioral advertising), limit sensitive-data use, and non-discrimination; businesses must honor Global Privacy Control signals.
  • Enforcement is two-headed: the CPPA (the first dedicated US privacy agency, with rulemaking and administrative fines) and the Attorney General, with no cure right since 2023.
  • The enforcement record is concrete: Sephora $1.2M (2022, GPC and sale disclosures), DoorDash $375K (2024, marketing co-op as sale), Honda $632,500 (2025, CPPA's first public order, dark-pattern opt-outs), and Healthline $1.55M (2025, the largest CCPA settlement, ad-tracker disclosures).

California built US privacy law’s reference implementation, then built the first agency dedicated to enforcing it. Since the CPRA’s rules became operative in 2023, the practical CCPA has been defined less by its text than by its enforcement pattern: regulators keep landing on the ad stack. Sephora, DoorDash, Honda, and Healthline were all, at core, cases about trackers, opt-outs, and the gap between what the privacy policy said and what the website actually transmitted.

RegulationCCPA, as amended by CPRA (Cal. Civ. Code 1798.100 et seq.)
Max penalty$2,500 / $7,500 per violation; $100-$750 per consumer for breaches
EnforcersCPPA + California AG
StatuteCiv. Code 1798.100 et seq.

The compliance core

Notices. A notice at collection (categories, purposes, retention, sale/sharing status) and a privacy policy updated at least annually with rights metrics disclosures for larger businesses. The Healthline settlement shows what fails: disclosing “advertising cookies” generically while shipping article titles implying health conditions to ad networks.

Rights plumbing. Know/access, delete (with a duty to push deletion to service providers and third parties), correct, opt out of sale/sharing via a “Do Not Sell or Share My Personal Information” link and GPC, and limit SPI. Verified requests get 45 days (extendable once). California adds household-level requests, unusual among the states, and 2026 brings the Delete Act’s DROP mechanism for data brokers.

Contracts. Every disclosure of personal information needs paper: service-provider/contractor agreements with purpose limitation, no-sale certification, and audit rights, or the recipient is a “third party” and the disclosure is a sale. The specifics are in the service-provider agreements guide.

Risk work. CPPA regulations finalized in 2025 phase in cybersecurity audits, risk assessments for high-risk processing (including behavioral advertising and ADMT), and automated decision-making rights, the closest US analog to GDPR accountability. See CPRA risk assessments.

Enforcement pattern, and what it predicts

Four public actions define the priority list: honor GPC (Sephora); recognize non-cash consideration as a sale (DoorDash); make opt-outs symmetrical and stop demanding excess verification data (Honda); and align tracker behavior with disclosures, especially for health-adjacent inference (Healthline, which also invoked the CCPA’s purpose-limitation principle for the first time). The CPPA has also swept data-broker registration and announced ADMT rulemaking, so agentic and AI processing is next. The CPPA enforcement priorities page tracks this in detail.

The fastest way to see your own Sephora exposure is to look at what your site transmits before consent: run a free scan and compare the tracker inventory against your notice at collection.

Frequently Asked Questions

Does the CCPA apply to my company if we have no California office?

Location is irrelevant; doing business in California and crossing a threshold is what matters. The thresholds are alternatives: annual gross revenue above the inflation-adjusted $25M mark, buying/selling/sharing personal information of 100,000 or more California consumers or households, or deriving 50% or more of revenue from selling or sharing. A media site running third-party ad trackers can cross the 100,000-consumer bar on traffic alone.

What counts as a 'sale' or 'sharing'?

Sale is disclosure of personal information for monetary or other valuable consideration; sharing is disclosure for cross-context behavioral advertising, with or without money changing hands. Regulators read both broadly: Sephora's use of third-party analytics/ad trackers was a sale, and DoorDash's participation in a marketing cooperative was a sale even though no cash moved. If ad pixels send identifiers to third parties, you almost certainly sell or share.

What does honoring GPC actually require?

Treat a Global Privacy Control browser signal as a valid opt-out of sale/sharing for that browser (and associated consumer if identifiable), automatically, without forcing an extra click. Sephora's failure to process GPC was central to the first AG settlement, and the CPPA's Honda order also targeted opt-out friction: opting out must take symmetrical effort to opting in.

What are the sensitive personal information rules?

SPI (SSNs, precise geolocation, race, religion, union membership, genetic/biometric data, health, sex life, message contents, financial credentials) triggers a 'Limit the Use of My Sensitive Personal Information' right where SPI is used beyond enumerated business purposes. Unlike GDPR, it is a limit-on-use right rather than a consent gate, except for minors, where sale/sharing needs opt-in.

Is there a private right of action?

Only for data breaches: consumers whose unencrypted, unredacted personal information is breached due to failure to maintain reasonable security can sue for $100-$750 statutory damages per consumer per incident, no actual-harm proof needed, which is why California breach class actions settle fast. All other violations are enforced by the CPPA and AG, and the 30-day cure period was abolished in 2023.

Regulatory Crosswalk

CPRAGDPRColorado CPAVirginia VCDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.