CCPA and CPRA compliance

CCPA compliance,
including the 2026 rules.

CCPA compliance is the work of meeting California's privacy law, which reaches companies far outside California. This guide covers what the CPRA changed, who is in scope, a practical checklist, Do Not Sell or Share, and the new regulations on risk assessments, cybersecurity audits and automated decisions. It is a practitioner's summary, not legal advice.

Civil Code 1798.100 et seq.11 CCR 7000 et seq.Regulations effective 1 Jan 2026Opt-out signalsADMT from 1 Jan 2027

Last updated Published by TryTrustableNot legal advice

Short answer

CCPA compliance means meeting the California Consumer Privacy Act, as amended by the CPRA, if your business meets one of its thresholds: annual gross revenue above $26,625,000, buying, selling or sharing the personal information of 100,000 or more California consumers or households, or earning half its revenue from selling or sharing it. In practice that is a notice at collection and privacy policy, a working process for requests to know, delete and correct, a Do Not Sell or Share link that also honours Global Privacy Control, contracts with every vendor that receives the data, reasonable security, and, since 1 January 2026, risk assessments, cybersecurity audits and automated decision-making rules from the California Privacy Protection Agency.

01

What is the CCPA?

The California Consumer Privacy Act is California's general privacy law. It took effect on 1 January 2020 and gives California residents (consumers, employees, job applicants and business contacts) rights over the personal information businesses collect about them. It applies to for-profit businesses that do business in California and meet a size or data threshold, wherever they are based. A SaaS company in Texas, London or Bengaluru with California users can be in scope.

02

What is the CPRA?

The California Privacy Rights Act is a ballot measure, Proposition 24, that voters approved on 3 November 2020. It did not replace the CCPA; it amended it, and most of its changes became operative on 1 January 2023. When people say "CCPA" today they mean the law as amended by the CPRA. The CPRA created the California Privacy Protection Agency (CPPA, which now also calls itself CalPrivacy), the first US regulator dedicated to privacy, and gave it power to write regulations and fine businesses.

03

CCPA vs CPRA: what changed

TopicOriginal CCPA (2020)After the CPRA (from 2023)
RegulatorCalifornia Attorney General onlyA dedicated agency, the California Privacy Protection Agency, plus the Attorney General
Volume thresholdBuys, sells or receives data of 50,000 or more consumers, households or devicesBuys, sells or shares data of 100,000 or more consumers or households
AdvertisingOpt-out of sale onlyOpt-out of sale and of sharing for cross-context behavioural advertising, even with no money paid
Sensitive personal informationNot a separate categoryA defined category with a right to limit its use (1798.121)
Consumer rightsKnow, delete, opt out of saleAdds correction and the right to limit sensitive data
Business dutiesNotice and request handlingAdds purpose limitation, data minimisation, retention periods in the notice, contracts with contractors and third parties, risk assessments and cybersecurity audits by regulation
Cure period30 days to cure after noticeNo automatic right to cure; the regulator may take it into account
Employee and B2B dataMostly exemptFully covered since 1 January 2023

CPRA: Proposition 24, approved 3 November 2020. Most amendments operative 1 January 2023.

04

Who does the CCPA apply to?

A for-profit business that does business in California, collects California residents' personal information and meets at least one threshold (Civil Code 1798.140(d)):

  • Revenue: annual gross revenue above $26,625,000 in the previous calendar year, the inflation-adjusted figure in force since 1 January 2025. It is total revenue, not California revenue.
  • Volume: buys, sells or shares the personal information of 100,000 or more California consumers or households a year.
  • Data revenue: earns 50% or more of annual revenue from selling or sharing personal information.

Employee, job applicant and B2B contact data has been fully covered since 1 January 2023. Some data is exempt rather than whole companies: protected health information governed by HIPAA, data covered by the Gramm-Leach-Bliley Act and consumer reports under the Fair Credit Reporting Act, for example. A service provider processing data only on a customer's instructions has narrower duties, mainly set by contract. Our free Does CCPA apply? checker walks through the tests.

05

What rights does the CCPA give consumers?

  • Know what personal information is collected, used, disclosed, sold or shared, and get a copy.
  • Delete it, subject to exceptions.
  • Correct inaccurate information.
  • Opt out of sale and sharing, including by a browser signal such as Global Privacy Control.
  • Limit the use of sensitive personal information to what the service needs.
  • Not be retaliated against for using these rights.

Requests to know, delete and correct must be answered within 45 days, extendable once by another 45 days with notice (1798.130). Opt-out requests must be acted on as soon as feasible and no later than 15 business days (11 CCR 7026). Selling or sharing the data of a consumer under 16 needs opt-in: the consumer's own if aged 13 to 15, a parent's if under 13. Our data discovery and DSAR page covers how to find the data a request touches.

06

"Do Not Sell or Share My Personal Information"

"Sell" means disclosing personal information to a third party for money or other valuable consideration. "Share" means disclosing it for cross-context behavioural advertising, whether or not money changes hands. Third-party advertising pixels and retargeting cookies on a website are the most common way a business sells or shares without realising it.

If you sell or share, you need a clear "Do Not Sell or Share My Personal Information" link (or the alternative "Your Privacy Choices" link with the official icon, 11 CCR 7015), a notice of the right to opt out, and a process that stops the selling and sharing once a consumer opts out. You must also treat an opt-out preference signal, in practice Global Privacy Control, as a valid opt-out for that browser and any profile linked to it. Under the regulations in force since 1 January 2026, you must display on your website whether you have processed the signal, for example "Opt-Out Request Honored" (11 CCR 7025(c)(6)). From 1 January 2027, a new section of the statute (1798.136, added by AB 566) requires browser makers to offer such a signal, so expect far more consumers to send one.

07

CCPA compliance checklist

  1. Confirm scope. Test the three thresholds every January, against the previous year.
  2. Map the data. List what you collect about consumers, employees, applicants and business contacts, where it lives, and every vendor that receives it. A record of processing works as the map.
  3. Classify each disclosure as to a service provider, a contractor or a third party, and decide which are sales or shares.
  4. Publish the notices: a notice at collection and a privacy policy with categories, sources, purposes, retention periods, disclosures and rights. The privacy policy generator is a starting point.
  5. Build request handling for know, delete, correct and limit, with identity verification, two or more intake methods and the 45-day clock tracked.
  6. Add the opt-out: the Do Not Sell or Share link, Global Privacy Control honoured, and a visible status showing the signal was processed. Test it with the free cookie scanner.
  7. Paper the vendors. Service provider and contractor contracts need the terms in 1798.100(d) and 11 CCR 7051; without them a disclosure may count as a sale. See vendor risk management.
  8. Limit sensitive data to what the service needs, or offer the "Limit the Use of My Sensitive Personal Information" link.
  9. Keep reasonable security in place and documented: it is your defence against breach lawsuits.
  10. Run risk assessments for selling, sharing, sensitive data and ADMT, and plan for the cybersecurity audit if you meet its triggers.
  11. Train the people who handle requests, and keep records of requests for 24 months.
  12. Check the other states. Nineteen states now have comprehensive privacy laws in force; see US state privacy laws.
08

The CPPA regulations: risk assessments, cybersecurity audits and ADMT

The agency's second major rulemaking is complete. Its Board adopted the regulations on 24 July 2025, the Office of Administrative Law approved them on 22 September 2025, and they took effect on 1 January 2026, with phased compliance dates.

RequirementWho it applies toDate
Risk assessments (11 CCR 7150 to 7157)Businesses that sell or share personal information, process sensitive personal information, use automated decision-making technology (ADMT) for significant decisions, or use certain profiling and trainingNew processing from 1 January 2026; existing processing assessed by 31 December 2027; attestation and summary to the agency by 1 April 2028
Cybersecurity audits (11 CCR 7120 to 7124)Businesses that earn 50% or more of revenue from selling or sharing, or that meet the revenue threshold and processed the data of 250,000 or more consumers, or sensitive data of 50,000 or more, in the prior yearFirst certification by 1 April 2028 (revenue over $100M), 1 April 2029 ($50M to $100M) or 1 April 2030 (under $50M)
ADMT (11 CCR 7200 to 7222)Businesses using ADMT to make significant decisions about consumers (for example jobs, credit, housing, education, healthcare)Pre-use notice, opt-out and access rights from 1 January 2027
Updated general rulesAll businesses in scope, including the duty to show whether an opt-out signal was processed (7025(c)(6))1 January 2026

Regulations adopted 24 July 2025, approved by the Office of Administrative Law 22 September 2025.

A risk assessment weighs the privacy risks of a processing activity against its benefits and must be reviewed at least every three years, or sooner when the processing changes materially. The cybersecurity audit must be done by a qualified, objective and independent auditor, internal or external, and an executive certifies completion to the agency. If you already run a DPIA programme for GDPR or a SOC 2 audit, much of the evidence carries over, but the California formats and submissions are their own.

09

CCPA penalties and enforcement

ExposureAmountWho enforces
Administrative fine or civil penaltyUp to $2,663 per violationCalifornia Privacy Protection Agency (1798.155) or Attorney General (1798.199.90)
Intentional violations, or violations involving consumers under 16Up to $7,988 per violationSame
Data breach of unencrypted, unredacted data caused by unreasonable security$107 to $799 per consumer per incident, or actual damages if higherConsumers, by private action (1798.150)

Figures adjusted for inflation from 1 January 2025. The agency adjusts them every two years.

Penalties apply per violation, and regulators often count each affected consumer, so totals add up quickly. Since the CPRA there is no automatic right to cure before an enforcement action. Enforcement has focused on opt-out mechanics: on 9 September 2025 the California, Colorado and Connecticut Attorneys General announced a joint sweep of businesses that may not be honouring Global Privacy Control. Consumers can sue only after a data breach; every other provision is enforced by the agency or the Attorney General.

10

How TryTrustable supports CCPA compliance

The consent platform applies an opt-out regime to US visitors, reads the Global Privacy Control signal server side, records a GPC browser as an opt-out in a tamper-evident consent ledger with the reason attached, and puts a privacy-request link on the banner. Requests land in a queue with deadlines set by request type. CCPA and the other US state laws are modelled in the shared control library, so a vendor review, a risk assessment or a security control counts toward SOC 2, GDPR and California at once. See the consent product and framework coverage. No tool makes you compliant by itself: your notices, contracts and decisions still need an owner.

Questions

The things people ask us

What is the difference between the CCPA and the CPRA?

The CPRA is a 2020 ballot measure that amended the CCPA. It added sharing for behavioural advertising, sensitive personal information, the right to correct, data minimisation duties and a dedicated regulator. Most changes applied from 1 January 2023. Today they are one law, usually still called the CCPA.

What is the CCPA revenue threshold for 2026?

$26,625,000 in annual gross revenue for the previous calendar year. The agency set that figure from 1 January 2025 and adjusts it for inflation every two years, so check for a new figure in January 2027.

Does the CCPA apply to B2B companies and employee data?

Yes. The exemptions for employee and business-to-business data expired on 1 January 2023, so job applicants, staff and business contacts in California have the same rights as other consumers.

Do I need a Do Not Sell or Share link if I only use analytics?

Only if you sell or share. First-party analytics run by a service provider under a compliant contract is usually not a sale or share. Advertising pixels and retargeting cookies usually are. Check what actually fires on your site with a scan before deciding.

Is honouring Global Privacy Control required under the CCPA?

Yes, for businesses that sell or share personal information. The regulations require you to treat the signal as a valid opt-out of sale and sharing and, since 1 January 2026, to display whether you processed it.

Is there a private right of action under the CCPA?

Only for data breaches of unencrypted and unredacted personal information caused by a failure to keep reasonable security. Damages are $107 to $799 per consumer per incident, or actual damages if greater.

What is the difference between the CCPA and GDPR?

GDPR needs a lawful basis before you process personal data and generally opt-in consent for non-essential cookies. The CCPA lets you collect with notice and gives people the right to opt out of sale and sharing. GDPR applies to almost every organisation; the CCPA only to businesses over its thresholds. See our GDPR guide.

When do the CCPA ADMT rules apply?

A business using automated decision-making technology to make significant decisions about consumers must comply with the pre-use notice, opt-out and access rules from 1 January 2027.

Book a walkthrough

See your California opt-outs recorded, not assumed.

Thirty minutes: we scan your site with Global Privacy Control switched on, show what still fires, and walk through the ledger and request queue.