Data Protection Matters
← All privacy laws

California, USA

CCPA / CPRA

California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code ยง 1798.100 et seq.)

Keywords

CCPACPRACaliforniaCalifornia Consumer Privacy ActCalifornia Privacy Rights ActCPPACivil Code 1798.100consumer rightsright to knowright to deleteopt-out of saleopt-out of sharingsensitive personal informationGlobal Privacy Control
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The California Consumer Privacy Act (CCPA) was enacted in 2018 and took effect on 1 January 2020, giving California residents rights over the personal information that businesses collect about them. The California Privacy Rights Act (CPRA), approved by voters in November 2020, amended and expanded it, with most changes operative from 1 January 2023. The law is codified in the Civil Code starting at section 1798.100, and detailed regulations are in Title 11 of the California Code of Regulations.

Who it applies to

It protects "consumers", meaning California residents. It applies to for-profit businesses that do business in California and meet at least one threshold: annual gross revenue above a set dollar amount (originally 25 million dollars, adjusted for inflation), buying, selling or sharing the personal information of 100,000 or more consumers or households, or earning 50% or more of annual revenue from selling or sharing personal information. Exemptions exist for certain data already regulated by laws such as HIPAA and the Gramm-Leach-Bliley Act. The earlier exemptions for employee and business-to-business data expired on 1 January 2023.

Core principles

Businesses must tell consumers at or before collection what categories of personal information they collect, why, and whether it is sold or shared. Collection and use must be reasonably necessary and proportionate to the disclosed purposes, and data may not be kept longer than reasonably necessary. The law also sets a heightened category of "sensitive personal information", which includes precise geolocation, government identifiers, health data and racial or ethnic origin.

Individual rights

Consumers have the right to know what personal information is collected, used, sold or shared; to delete it; to correct inaccurate information; to opt out of the sale or sharing of their personal information; to limit the use of sensitive personal information; and to be free from retaliation for exercising these rights. Consumers can also receive their data in a portable format. Businesses generally have 45 days to respond to a verified request, extendable once.

Key obligations

Businesses must post a privacy policy, provide clear methods to submit requests, and show "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" links where relevant. They must honour opt-out preference signals such as the Global Privacy Control. Contracts with service providers, contractors and third parties must include the terms the law requires, and businesses must maintain reasonable security. The regulations also set out requirements for risk assessments, cybersecurity audits and automated decision-making technology for covered businesses.

Data breaches

The CCPA does not itself set a notification deadline, which is governed by California's separate breach notification statute. What the CCPA adds is a private right of action: consumers whose unencrypted or unredacted personal information is exposed because a business failed to maintain reasonable security can sue for statutory damages per consumer per incident, or for actual damages if greater. This is the only part of the law that individuals can enforce directly, and it generally requires prior written notice and an opportunity to cure.

Enforcement and penalties

Enforcement is shared between the California Privacy Protection Agency (CPPA), created by the CPRA, and the California Attorney General. Administrative fines and civil penalties are set per violation, with a higher amount for intentional violations and violations involving consumers under 16, and the dollar figures are adjusted periodically for inflation. The CPRA removed the automatic 30-day cure period that businesses previously had, so cure is now at the regulator's discretion.

The official text

The authoritative version is the California Consumer Privacy Act of 2018 as codified in Title 1.81.5 of Part 4, Division 3 of the California Civil Code, published by the California Legislative Information service, together with the CPPA's regulations. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →