What CCPA/CPRA Covers
CCPA/CPRA governs the collection, use, disclosure, and sale of personal information (PI) of California consumers by covered businesses. "Personal information" is defined broadly — any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a California consumer or household. It explicitly includes IP addresses, browsing history, purchasing history, inferences drawn from PI to create a profile, and biometric data.
The CPRA introduced "sensitive personal information" (SPI) as a distinct category: social security numbers, driver's license numbers, account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health data, sexual orientation, and contents of communications. Consumers have the right to limit the use of SPI to what is necessary for the primary purpose of collection.
Who Must Comply
The following entities are subject to CCPA / CPRA Compliance Hub obligations:
- →For-profit businesses doing business in California with annual gross revenue exceeding $25 million
- →Businesses buying, selling, sharing, or receiving PI of 100,000+ California consumers or households annually
- →Businesses deriving 50% or more of annual revenue from selling or sharing California consumers' PI
- →Any entity that controls or is controlled by a covered business and shares common branding
- →Service providers processing PI on behalf of covered businesses under CPRA-compliant contracts
- →Contractors and third parties receiving PI for a business purpose under written contract
- →Any company — regardless of state of incorporation — that meets the above thresholds
Penalties and Enforcement History
The California Privacy Protection Agency (CPPA) enforces CCPA/CPRA through administrative action. The California Attorney General retains concurrent enforcement authority. Civil penalties: $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving PI of minors (consumers under 16). Each consumer whose rights are violated represents a separate violation — a single unauthorized disclosure of a 50,000-record dataset can theoretically produce $375,000,000 in maximum exposure. Private right of action applies only to data breaches involving certain categories of nonencrypted PI (Social Security numbers, financial account details, medical information, and others listed in Cal. Civ. Code § 1798.150).
Enforcement Timeline
Regulatory Comparison
| Dimension | CCPA/CPRA | GDPR | Virginia VCDPA |
|---|---|---|---|
| Scope Trigger | Revenue OR data volume threshold | Established in EU OR EU data subjects | Controller processing 100k+ VA consumers |
| Max Fine | $7,500 per intentional violation | €20M or 4% annual turnover | $7,500 per violation (AG enforcement) |
| Enforcement Body | CPPA + California AG | National DPAs | Virginia Attorney General |
| Private Right of Action | Data breach only (limited categories) | No (member state variation) | None |
| Employee Data | Covered (limited exemptions expired) | Covered | Excluded |
| Right to Correct | Yes (CPRA addition) | Yes (GDPR Art. 16) | Yes |
Mitigation Strategy
Map every category of personal information collected from California consumers: the specific data elements, source, business purpose, retention period, and all third parties to whom the PI is disclosed. Update the data map annually and whenever a new data collection process is introduced. The CCPA privacy policy must disclose all categories collected, purposes of use, categories of third parties to whom PI is disclosed, and the categories sold or shared.
CCPA requires businesses to respond to consumer requests within 45 days (extendable by 45 days with notice). Implement a verified consumer request intake process via at minimum two methods (webform + toll-free number if operating a physical location), identity verification proportionate to sensitivity, a response workflow that retrieves PI from all in-scope systems, and a request log with date tracking. For Sensitive PI requests to limit use, implement a separate "Limit the Use of My Sensitive Personal Information" link.
Every contract with a service provider receiving PI must include CPRA-required provisions: permitted business purposes, prohibitions on sale/sharing without consent, obligations to assist with consumer requests, deletion obligations, security standards, and audit cooperation rights. Simultaneously implement data minimization — the CPRA makes collecting only PI reasonably necessary for the disclosed purpose a substantive legal obligation.
Frequently Asked Questions
A: Yes, if you meet the threshold criteria. The CCPA applies to any for-profit business "doing business in California" — which includes selling products or services to California consumers online, taking orders from California residents, or targeting California residents in advertising. The thresholds ($25M revenue, 100k consumers, 50% revenue from selling PI) determine whether CCPA applies — not the business's state of incorporation or physical location.
A: The CCPA prohibited "selling" PI, defined as transferring PI to a third party for monetary or other valuable consideration. The CPRA added "sharing" to cover disclosure of PI for cross-context behavioral advertising, even if no monetary consideration is paid. This addition captures data disclosures to Google Analytics, Meta Pixel, and other advertising tracking tools. Businesses must honour opt-outs of both sale and sharing via the "Do Not Sell or Share My Personal Information" link and via Global Privacy Control (GPC) signals.
A: The CPPA's regulations require that if a consumer sends a GPC signal — a browser-level opt-out signal — the business must treat it as a valid opt-out without requiring a separate form submission. Your consent management platform (CMP) must: detect incoming GPC signals from browsers like Firefox, Brave, and DuckDuckGo; honour them by blocking associated data flows to third-party advertising platforms; and maintain records of GPC signals received. The Sephora enforcement action makes GPC compliance mandatory.
A: CPRA requires a functionally similar but differently named contract. A "service provider" is only exempt from the definition of a "third party" — and thus from sale/sharing restrictions — if it processes PI pursuant to a written contract that prohibits retaining, using, or disclosing the PI outside the direct business relationship, prohibits selling or sharing the PI, and obligates the service provider to notify the business if it cannot honour the terms. Without this contract, your service provider relationship may be recharacterised as a "sale" of PI.
A: From 1 January 2023, California employees, independent contractors, and job applicants are "consumers" under CCPA/CPRA with full rights. Businesses must provide Notice at Collection to employees and applicants, disclose all categories of PI collected and business purposes, and honour deletion and portability requests for non-retention-required PI. HR systems holding employee monitoring data, payroll information, performance records, and recruiting data are all in scope.
CCPA / CPRA Compliance Checklist → Applicability thresholds, 6 consumer rights (including CPRA right to correct + SPI limits), service provider DPA requirements, GPC signal implementation, and CPPA enforcement powers — with $7,500-per-violation fine context.
This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.