Jurisdiction
California, United States (extraterritorial applicability)
Authority
California Privacy Protection Agency (CPPA) + California Attorney General
Max Penalty
$2,500 per unintentional violation · $7,500 per intentional violation
Compliance Difficulty65/100
The California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.100 et seq., enacted in 2018 and effective from 1 January 2020, established the most comprehensive US state consumer privacy law to date. The California Privacy Rights Act (CPRA), passed via Proposition 24 in November 2020, materially amended the CCPA effective 1 January 2023, creating the California Privacy Protection Agency (CPPA) as a dedicated enforcement body, adding sensitive personal information as a distinct category, and introducing a right to correct inaccurate personal information. Together, CCPA/CPRA imposes significant obligations on any business — regardless of where it is incorporated — that processes California consumer personal information at scale.

What CCPA/CPRA Covers

CCPA/CPRA governs the collection, use, disclosure, and sale of personal information (PI) of California consumers by covered businesses. "Personal information" is defined broadly — any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a California consumer or household. It explicitly includes IP addresses, browsing history, purchasing history, inferences drawn from PI to create a profile, and biometric data.

The CPRA introduced "sensitive personal information" (SPI) as a distinct category: social security numbers, driver's license numbers, account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health data, sexual orientation, and contents of communications. Consumers have the right to limit the use of SPI to what is necessary for the primary purpose of collection.

Who Must Comply

The following entities are subject to CCPA / CPRA Compliance Hub obligations:

  • For-profit businesses doing business in California with annual gross revenue exceeding $25 million
  • Businesses buying, selling, sharing, or receiving PI of 100,000+ California consumers or households annually
  • Businesses deriving 50% or more of annual revenue from selling or sharing California consumers' PI
  • Any entity that controls or is controlled by a covered business and shares common branding
  • Service providers processing PI on behalf of covered businesses under CPRA-compliant contracts
  • Contractors and third parties receiving PI for a business purpose under written contract
  • Any company — regardless of state of incorporation — that meets the above thresholds

Penalties and Enforcement History

The California Privacy Protection Agency (CPPA) enforces CCPA/CPRA through administrative action. The California Attorney General retains concurrent enforcement authority. Civil penalties: $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving PI of minors (consumers under 16). Each consumer whose rights are violated represents a separate violation — a single unauthorized disclosure of a 50,000-record dataset can theoretically produce $375,000,000 in maximum exposure. Private right of action applies only to data breaches involving certain categories of nonencrypted PI (Social Security numbers, financial account details, medical information, and others listed in Cal. Civ. Code § 1798.150).

Enforcement Timeline

Jun 2018
CCPA Enacted
California Consumer Privacy Act signed into law, giving California consumers unprecedented rights over personal information. Gave businesses 18 months to comply.
Jan 2020
CCPA Effective
CCPA became operative. Businesses required to implement notice at collection, privacy policies, consumer request procedures, and opt-out of sale mechanisms.
Jul 2020
AG Enforcement Began
California Attorney General commenced enforcement. First wave of enforcement letters sent to companies with noncompliant privacy policies, cookie banners, and opt-out flows.
Nov 2020
CPRA Passed
Proposition 24 passed with 56% of votes. Created CPPA, added sensitive PI category, right to correct, expanded data minimization requirements.
Jan 2023
CPRA In Force + CPPA Active
CPRA amendments became operative. CPPA assumed full enforcement authority. First enforcement actions under CPPA jurisdiction commenced 2024.

Regulatory Comparison

DimensionCCPA/CPRAGDPRVirginia VCDPA
Scope TriggerRevenue OR data volume thresholdEstablished in EU OR EU data subjectsController processing 100k+ VA consumers
Max Fine$7,500 per intentional violation€20M or 4% annual turnover$7,500 per violation (AG enforcement)
Enforcement BodyCPPA + California AGNational DPAsVirginia Attorney General
Private Right of ActionData breach only (limited categories)No (member state variation)None
Employee DataCovered (limited exemptions expired)CoveredExcluded
Right to CorrectYes (CPRA addition)Yes (GDPR Art. 16)Yes

Mitigation Strategy

01
Conduct a California PI Data Map

Map every category of personal information collected from California consumers: the specific data elements, source, business purpose, retention period, and all third parties to whom the PI is disclosed. Update the data map annually and whenever a new data collection process is introduced. The CCPA privacy policy must disclose all categories collected, purposes of use, categories of third parties to whom PI is disclosed, and the categories sold or shared.

02
Build Consumer Request Procedures and Honour Within Deadlines

CCPA requires businesses to respond to consumer requests within 45 days (extendable by 45 days with notice). Implement a verified consumer request intake process via at minimum two methods (webform + toll-free number if operating a physical location), identity verification proportionate to sensitivity, a response workflow that retrieves PI from all in-scope systems, and a request log with date tracking. For Sensitive PI requests to limit use, implement a separate "Limit the Use of My Sensitive Personal Information" link.

03
Update Service Provider Contracts and Implement Data Minimization

Every contract with a service provider receiving PI must include CPRA-required provisions: permitted business purposes, prohibitions on sale/sharing without consent, obligations to assist with consumer requests, deletion obligations, security standards, and audit cooperation rights. Simultaneously implement data minimization — the CPRA makes collecting only PI reasonably necessary for the disclosed purpose a substantive legal obligation.

Sephora, Inc. — California AG Enforcement Action (2022): "Sephora agreed to pay $1.2 million in penalties and to implement corrective measures after the Attorney General found that Sephora had failed to disclose that it was selling personal information, failed to process opt-out requests via Global Privacy Control (GPC), and failed to cure these violations within the 30-day cure period. This marks the first CCPA enforcement judgment and establishes GPC signal compliance as a mandatory technical implementation requirement." — California AG Press Release, 24 August 2022.Enforcement Precedent

Frequently Asked Questions

Q: Does CCPA/CPRA apply to my company if I'm not based in California?

A: Yes, if you meet the threshold criteria. The CCPA applies to any for-profit business "doing business in California" — which includes selling products or services to California consumers online, taking orders from California residents, or targeting California residents in advertising. The thresholds ($25M revenue, 100k consumers, 50% revenue from selling PI) determine whether CCPA applies — not the business's state of incorporation or physical location.

Q: What is the difference between "selling" and "sharing" PI under CPRA?

A: The CCPA prohibited "selling" PI, defined as transferring PI to a third party for monetary or other valuable consideration. The CPRA added "sharing" to cover disclosure of PI for cross-context behavioral advertising, even if no monetary consideration is paid. This addition captures data disclosures to Google Analytics, Meta Pixel, and other advertising tracking tools. Businesses must honour opt-outs of both sale and sharing via the "Do Not Sell or Share My Personal Information" link and via Global Privacy Control (GPC) signals.

Q: How do we honour Global Privacy Control (GPC) signals?

A: The CPPA's regulations require that if a consumer sends a GPC signal — a browser-level opt-out signal — the business must treat it as a valid opt-out without requiring a separate form submission. Your consent management platform (CMP) must: detect incoming GPC signals from browsers like Firefox, Brave, and DuckDuckGo; honour them by blocking associated data flows to third-party advertising platforms; and maintain records of GPC signals received. The Sephora enforcement action makes GPC compliance mandatory.

Q: Do we need a Data Processing Agreement (DPA) like GDPR requires?

A: CPRA requires a functionally similar but differently named contract. A "service provider" is only exempt from the definition of a "third party" — and thus from sale/sharing restrictions — if it processes PI pursuant to a written contract that prohibits retaining, using, or disclosing the PI outside the direct business relationship, prohibits selling or sharing the PI, and obligates the service provider to notify the business if it cannot honour the terms. Without this contract, your service provider relationship may be recharacterised as a "sale" of PI.

Q: What are the CPRA employee and job applicant PI obligations?

A: From 1 January 2023, California employees, independent contractors, and job applicants are "consumers" under CCPA/CPRA with full rights. Businesses must provide Notice at Collection to employees and applicants, disclose all categories of PI collected and business purposes, and honour deletion and portability requests for non-retention-required PI. HR systems holding employee monitoring data, payroll information, performance records, and recruiting data are all in scope.

Deep Dive Guide

CCPA / CPRA Compliance Checklist → Applicability thresholds, 6 consumer rights (including CPRA right to correct + SPI limits), service provider DPA requirements, GPC signal implementation, and CPPA enforcement powers — with $7,500-per-violation fine context.

About the Author

This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.

LLB · LLM
International Commercial Law
20 Years
Active Legal Practice
Notary + Arbitrator
Commissioned & International
Jurisdictions
UAE · EU · US · UK · Singapore
Full credentials and methodology →