EnglishEspañol
California flag

California

What Is CCPA? California Consumer Privacy Act Explained (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

What Is CCPA? California Consumer Privacy Act Explained (2026)

Frequently Asked Questions

What does the CCPA do?

The CCPA gives California residents the right to know what personal information businesses collect about them, request deletion of that data, opt out of its sale or sharing, correct inaccurate information, and limit the use of sensitive personal information. It also prohibits businesses from discriminating against consumers who exercise these rights.

Does the CCPA apply to small businesses?

The CCPA only applies to for-profit businesses that meet at least one threshold: gross annual revenue over $26.625 million, buying/selling/sharing data of 100,000 or more California residents, or deriving 50% or more of revenue from selling or sharing personal data. Many small businesses fall below these thresholds and are not subject to the CCPA.

What are the penalties for violating the CCPA?

As of the 2025 CPI adjustment, administrative penalties reach up to $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors. For data breaches caused by inadequate security, consumers can sue for statutory damages of $107 to $799 per person per incident (the 2025 CPI-adjusted figure) under Cal. Civ. Code 1798.150.

Can individuals sue under the CCPA?

Individuals can only sue under the CCPA's private right of action for data breaches resulting from a business's failure to maintain reasonable security procedures (Cal. Civ. Code 1798.150). A consumer seeking statutory damages must first give the business 30 days' written notice identifying the specific provisions allegedly violated, and no statutory damages action may proceed if the business cures the violation within that window and confirms the cure in writing; no notice is required to sue for actual damages. For other types of CCPA violations, only the Attorney General or the CPPA can bring enforcement actions.

What is the difference between CCPA and CPRA?

The CPRA (Proposition 24, approved by voters in November 2020) amended the existing CCPA rather than replacing it. The CPRA added new consumer rights (correction, limiting sensitive data use), created the California Privacy Protection Agency (CPPA), expanded opt-out rights to cover data sharing for behavioral advertising, and introduced requirements for risk assessments and cybersecurity audits.

Does the CCPA apply to businesses outside California?

Yes. The CCPA applies to any for-profit business that collects personal information from California residents and meets the applicability thresholds, regardless of where the business is headquartered. A company in any state or country can be subject to the CCPA if it does business in California.

How long does a business have to respond to a CCPA request?

Businesses must respond to verified consumer requests within 45 calendar days. They can extend this deadline by an additional 45 days (90 days total) if they notify the consumer of the extension and the reason for it.

What is the CPPA and what does it do?

The California Privacy Protection Agency (CPPA) is the first dedicated data privacy enforcement agency in the United States. Created by the CPRA in 2020, it began enforcement operations on July 1, 2023. The CPPA adopts CCPA regulations, investigates violations, issues fines, and operates the DROP platform for consumer data deletion requests.

Updates

Corrected the data-breach private right of action to match Civil Code 1798.150: the statute covers personal information that is nonencrypted and nonredacted, and a consumer seeking statutory damages must first give the business 30 days' written notice and an opportunity to cure.

Updated the CCPA private-lawsuit damages range to the current CPI-adjusted $107-$799 per consumer per incident (from a stale $100-$750 figure), corrected the Disney and DoorDash settlement years, and fixed a link that pointed to the wrong bill's text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. CCPA Full Text (Cal. Civ. Code 1798.100-1798.199.100)(leginfo.legislature.ca.gov).gov
  2. California Consumer Privacy Act (CCPA) Overview(oag.ca.gov).gov
  3. CPPA Official Website and FAQ(cppa.ca.gov).gov
  4. CCPA Statute Effective January 1, 2026(cppa.ca.gov).gov
  5. Updated Monetary Thresholds (CPI Adjustment)(cppa.ca.gov).gov
  6. Cal. Civ. Code 1798.150 (Private Right of Action)(leginfo.legislature.ca.gov).gov
  7. CPPA Enforcement: 2025 Penalty Increases(cppa.ca.gov).gov
  8. AG Settlement with Sephora ($1.2M)(oag.ca.gov).gov
  9. AG Settlement with Disney ($2.75M)(oag.ca.gov).gov
  10. AG Settlement with DoorDash ($375K)(oag.ca.gov).gov
  11. CPPA Settlement with Honda ($632,500)(cppa.ca.gov).gov
  12. CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT Regulations(cppa.ca.gov).gov
  13. Delete Request and Opt-Out Platform (DROP)(cppa.ca.gov).gov
  14. Global Privacy Control (GPC)(oag.ca.gov).gov
  15. SB 1223 (Neural Data as Sensitive PI)(leginfo.legislature.ca.gov).gov
Share: