Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

CCPA / CPRA compliance in United States: who is in scope and what is owed

How CCPA / CPRA applies to companies operating in or serving the United States — scope tests, the obligations that follow, and the primary sources to verify each one against.

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), regulates how businesses handle the personal information of California residents. Enforced by the California Privacy Protection Agency and the California Attorney General, the statute applies to for-profit entities meeting specific statutory thresholds, regardless of their physical location. Organizations subject to the framework must provide clear privacy disclosures, honor consumer rights requests, and maintain appropriate data governance controls.

Extraterritorial Scope and Threshold Criteria Under CCPA and CPRA

The applicability of the California Consumer Privacy Act reaches far beyond the physical borders of California, capturing any for-profit entity that does business in the state and determines the purposes and means of processing consumers' personal information. To fall within the statutory scope, an entity must satisfy one or more quantitative criteria outlined in the governing text. Check the cited source for the current figure regarding annual gross revenues, threshold counts for buying, receiving, selling, or sharing personal information, and the percentage of revenue derived from sharing consumer data. Organizations that meet these thresholds must evaluate their data processing activities to determine whether they qualify as a business under the statute. Entities operating outside California that collect data from website visitors residing in the state must assess their traffic patterns and revenue sources against these criteria. Compliance software and regulatory tools such as tools/website-compliance assist legal-operations teams in auditing digital touchpoints. Entities that process consumer data on behalf of other businesses must evaluate their status under specific provisions, distinguishing direct controllers from organizations operating under service provider agreements. Organizations should review their operational models against statutory definitions found in California Civil Code §1798.100 et seq. (CCPA/CPRA text) at https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5. Proper scoping prevents misplaced compliance efforts and ensures that resources target the correct operational workflows within the enterprise.

Core Consumer Rights Mandated by the California Privacy Framework

Regulated entities must operationalize a comprehensive suite of consumer rights that empower California residents to control their personal information. These rights include the right to know what personal information is collected, disclosed, or sold, the right to delete personal information, and the right to correct inaccurate personal information held by the business. Consumers hold the right to limit the use and disclosure of sensitive personal information. Businesses must establish robust operational channels for receiving and fulfilling these requests within statutory timeframes. Implementing structured workflows for data subject requests is essential for meeting regulatory expectations. Organizations can reference operational frameworks such as guides/ccpa-cpra-data-subject-request-operations-guide to design efficient intake and verification procedures. When handling requests related to sensitive data categories, teams must apply specific handling rules consistent with statutory definitions. The framework also grants consumers the right to opt out of the sale or sharing of their personal information and cross-context behavioral advertising. Compliance teams must integrate mechanisms that honor consumer preferences across all digital interfaces, including automated signals like the glossary/global-privacy-control. Failure to provide accessible request mechanisms or ignoring verified consumer demands exposes the organization to administrative enforcement actions and potential statutory liabilities.

Managing Opt-Out Rights for Sales, Sharing, and Targeted Advertising

The statute imposes strict requirements on businesses that engage in the sale or sharing of personal information, as well as those utilizing consumer data for cross-context behavioral advertising. When a consumer exercises the glossary/right-to-opt-out, the business must immediately cease disclosing the consumer's personal information to third parties for monetary or other valuable consideration. This obligation extends to data transfers used in targeted advertising campaigns across multiple websites and applications. Businesses must place clear and conspicuous notices on their internet homepages, typically utilizing a link titled Do Not Sell or Share My Personal Information or Limit the Use of My Sensitive Personal Information. Operational teams must audit all third-party tags, pixels, and software development kits embedded in their digital properties to identify data flows that constitute a sale or share. Contractual arrangements with third-party recipients must be reviewed to verify compliance with statutory exceptions. Organizations should consult resources like guides/ccpa-cpra-compliance-checklist to verify that all required opt-out mechanisms function correctly across web and mobile platforms. Businesses must recognize opt-out preference signals sent by consumer platforms or browsers, ensuring technical alignment with state regulatory expectations. Documenting these technical workflows provides an audit trail demonstrating adherence to statutory opt-out mandates.

Classifying Data Recipients: Service Providers, Contractors, and Third Parties

A critical component of regulatory compliance involves correctly classifying every entity that receives personal information from the business. The framework establishes distinct legal categories, each carrying specific contractual and operational requirements. A glossary/service-provider-ccpa processes personal information on behalf of a business pursuant to a written contract that prohibits retention, use, or disclosure of the data for any purpose other than the business purposes specified in the contract. Similarly, a glossary/contractor-ccpa receives personal information under a similar written agreement containing specific certification language and audit rights. In contrast, transfers to entities that do not qualify as service providers or contractors are typically classified as sales or shares of personal information, triggering consumer opt-out obligations. Legal and procurement teams must review all vendor agreements to ensure they incorporate the mandatory contractual terms prescribed by the California Privacy Protection Agency — regulations at https://cppa.ca.gov/regulations/. Misclassifying a data recipient can lead to unauthorized data disclosures and regulatory penalties. Maintaining a comprehensive inventory of data sharing relationships and associated contract types is essential for demonstrating regulatory alignment during audits or investigations conducted by the California Attorney General — CCPA at https://oag.ca.gov/privacy/ccpa.

Handling Sensitive Personal Information and Data Retention Governance

The framework establishes heightened protections for specific categories of data classified under the statute. Organizations that collect glossary/sensitive-personal-information—such as precise geolocation, social security numbers, financial account credentials, and health data—must provide consumers with the right to limit its use to only those purposes necessary to perform services or provide goods reasonably expected by an average consumer. Businesses cannot retain personal information or sensitive personal information for longer than is reasonably necessary for the disclosed purpose for which the information was collected. Establishing defensible data retention schedules is therefore a legal necessity rather than a mere IT best practice. Compliance teams can utilize structured methodologies found in guides/data-retention-deletion-policy-guide to align retention periods with operational needs and statutory limits. Every data category must have a defined lifecycle, from initial collection to secure deletion or anonymization. Regular audits of stored data repositories ensure that stale or unneeded consumer records are purged in a timely manner. Documenting these retention practices provides verifiable evidence to regulatory bodies that the organization respects data minimization principles.

Evidencing Compliance and Preparing for Regulatory Oversight

Demonstrating adherence to the California privacy framework requires a systematic approach to documentation, technical auditing, and employee training. Organizations must maintain comprehensive records of all consumer privacy requests received, the actions taken in response, and any communications with consumers. These records must be retained for a statutory period and made available for regulatory review upon request. Legal-operations teams should implement compliance management platforms that track request metrics, error rates, and fulfillment timelines. Periodic risk assessments and cybersecurity audits must be conducted, particularly when processing sensitive personal information or engaging in high-risk data processing activities. The California Privacy Protection Agency at https://cppa.ca.gov/ provides ongoing regulatory updates and guidance that organizations must monitor to remain aligned with evolving enforcement priorities. Training programs must be deployed for all personnel handling consumer inquiries or managing personal information databases. By maintaining rigorous internal controls, updating privacy notices promptly, and securing verifiable audit trails, organizations can effectively manage regulatory exposure and demonstrate accountability under the statute.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does the California privacy framework apply to companies with no physical office in the state?

Yes, statutory applicability is determined by revenue thresholds, data processing volumes, and commercial activity involving California residents, rather than physical presence. Out-of-state entities that collect personal information from individuals located in California must evaluate their business activities against the statutory criteria to determine if they fall within scope.

What distinguishes a service provider from a third party under the regulatory text?

A service provider processes personal information pursuant to a strict written contract that restricts its use of the data solely to specific business purposes defined by the instructing entity. Any recipient that does not operate under such restrictive contractual terms is generally classified as a third party, which may trigger consumer opt-out obligations.

How must businesses handle automated opt-out preference signals from web browsers?

Regulated entities must configure their digital properties to recognize and process consumer opt-out preference signals, such as the global privacy control, without requiring the consumer to manually click a separate opt-out link. This technical requirement ensures seamless enforcement of consumer privacy preferences across online channels.

Are non-profit organizations subject to the California privacy framework?

The statute primarily targets for-profit entities that collect consumers' personal information and meet specific revenue or data volume thresholds. Non-profit organizations and government agencies are generally excluded from the definition of a business under the core provisions of the framework.

What records should compliance teams retain to demonstrate regulatory accountability?

Teams should maintain detailed logs of all consumer privacy requests received, verification procedures applied, fulfillment timelines, and copies of responses sent. Additionally, organizations must retain records of employee privacy training, vendor contracts, data inventory mappings, and periodic risk assessment reports.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact