The California Consumer Privacy Act (CCPA), effective January 1, 2020, was enacted to provide California residents with essential privacy rights, including the rights to know, delete, and opt out of the sale of their personal information. In 2023, the California Privacy Rights Act (CPRA) further expanded these protections by introducing new rights. Together, as pillars of California privacy law, the CCPA and CPRA set a robust benchmark for data privacy in the United States.
The California Consumer Privacy Act (CCPA) is a state law granting California residents rights over their personal data. It allows them to know, access, delete, and opt-out of the sale of their data, while requiring businesses to disclose data practices and ensure privacy protections.
The CCPA, also known as Proposition 24, was signed into law on June 28, 2018 by Governor Jerry Brown, and took effect on January 1, 2020.
The CCPA was passed to address growing concerns about data privacy and empower California residents with greater control over their personal information. It aims to increase transparency in how businesses collect, use, and share data while holding companies accountable for protecting consumer rights.
The first law of its kind in the United States, the CCPA was initiated in the wake of Europe’s even more comprehensive General Data Protection Regulation (GDPR) to improve data transparency in the most populous U.S. state.
Read more: CCPA vs GDPR
The CCPA stands out as the first comprehensive privacy law in the U.S., granting Californians groundbreaking rights over their personal data. It ensures access, deletion, and opt-out rights for data sales, uniquely defining "sale" to include sharing information for any valuable consideration, not just monetary exchanges, offering unprecedented control to consumers.
The key definitions of the California Consumer Privacy Act (CCPA), including consumer, personal information, and business, are found in Section 1798.140 of the California Civil Code.
The California privacy law introduces several critical terms that businesses and consumers need to understand:
The California Privacy Rights Act (CPRA) expanded on the CCPA by:
While that may seem clear in theory, many businesses are still not entirely certain if they need to comply. First, it’s important to understand that your business does not need to be physically located in California, or even in the U.S. for that matter. Regardless of whether the processing of information takes place in California or not, you need to comply if you’re handling personal data of California residents and meet any of the thresholds.
CCPA and CPRA are applicable to any for-profit entity doing business in California that meet any one of the following thresholds:
Additionally, service providers and third parties handling consumer data on behalf of these businesses may also need to adhere to specific CCPA requirements.
The CPRA lowered the threshold for compliance by:
“We are at the beginning of a journey that will profoundly shape the fabric of our society by redefining who is in control of our most personal information and putting consumers back in charge of their own data.”
- Alastair Mactaggart, Chair of Californians for Consumer Privacy and Proposition 24 sponsor
The CCPA includes specific exemptions where its provisions do not apply. Key exemptions include:
These criteria and exemptions ensure that the CCPA and CPRA focus on businesses handling significant amounts of personal data, while avoiding undue burdens on smaller enterprises and organizations already governed by other privacy regulations.
Read further: Who does CCPA apply to?
Under the CCPA, California residents have the following privacy rights regarding their personal information, as stated :
Read more: Understanding the CCPA right to deletion
Let’s take a look at the main CCPA and CPRA differences.
The California Privacy Rights Act (CPRA) expands the CCPA, enhancing data privacy rights for California residents. It adds rights like data correction, limits on sensitive data use, and stricter business compliance. It also creates the California Privacy Protection Agency (CPPA) for enforcement.
Coined CCPA 2.0, the California Privacy Rights Act (CPRA) was approved by voters on November 4, 2020, as a means to improve upon the existing CCPA. The new rights and requirements outlined in the CPRA went into effect and superseded CCPA on January 2, 2023, resulting in a law more in line with the EU’s GDPR and providing greater protection for consumers and additional compliance regulations for businesses.
One of the key provisions introduced in the CPRA is the establishment of the California Privacy Protection Agency (CPPA) that will be responsible for auditing and enforcing CCPA. Unlike GDPR that included a governing authority, the original CCPA lacked a dedicated “watchdog” to enforce the law and an advocate to provide businesses and consumers with an educational venue for public awareness and understanding of rights and obligations. The establishment of the CPPA fills this previous gap.
“The CPPA Board will help California residents understand and control their data privacy while holding online businesses accountable.”
- California Governor Gavin Newsom
Read more: CCPA vs CPRA
The CPRA also expanded on the following CCPA privacy rights:
Read more: What are the CCPA categories of personal information?
CPRA also doubles CCPA’s 50,000 threshold to companies that buy, receive or sell personal information of more than 100,000 consumers or households. Additional modifications that help eliminate ambiguity, better define who must comply and provide greater protection, include:
Read more: CPRA consumer rights: a trendsetter in data privacy
California's CCPA is primarily an opt-out privacy law, meaning businesses can collect and use personal data by default, but consumers have the right to opt-out of specific data practices, such as the sale of their personal information.
Read more: What Does CCPA Mean for Advertisers? [CCPA-Compliant Advertising]
Opt-in consent is required for consumers under 16 years old:
To comply with the CCPA, businesses must follow these CCPA legal obligations:
The CPRA:
Read further: What are the requirements for CCPA?
Like GDPR, businesses required to be CPRA/CCPA-compliant must provide notice to consumers at the time they collect personal data, allow them to opt out and disclose the reason for retaining, sharing or selling personal information.
They also must allow consumers to access and delete their personal information, respond to consumer requests within specific timeframes, and maintain all records of requests for a minimum of two years.
The California Attorney General enforces the CCPA and can impose penalties for non-compliance:
Businesses have 30 days to address alleged violations after being notified by the Attorney General. Failing to cure within this period may lead to enforcement actions.
“Beginning in 2025, monetary damages, administrative fines, and civil penalties are being increased for violations of the CCPA.”
- The California Consumer Privacy Act (CCPA)
Penalties violating CCPA can cost businesses $2500 for each individual violation (i.e., per consumer), with higher fees for intentional violations. While you can avoid liability if you cure the noncompliance within 30 days, there are some types of non-compliance that may not be capable of a cure. For example, if a data breach has already occurred, there’s little you can do to fix it.
With the passing of the CPRA, the price of non-compliance has increased and the establishment of the CCPA is expected to result in greater enforcement. Most notably, CPRA triples the maximum penalty for an individual violation to $7500 for violations concerning minors.
While these fees seem minor, a business faced with one individual violation may likely have hundreds, thousands or even millions of violations—and all it takes is for one individual to determine and publicize the violation for the fees to stack up.
And CPRA/CCPA has NO ceiling on the number of violations. An online retailer doing business with a million Californians could quickly find themselves faced with $2.5 billion in fines.
Just six months into 2020, more than 50 lawsuits invoked the CCPA—everything from a student data management software company that failed to safeguard student data, to a class-action lawsuit against Zoom for sharing millions of users’ personal information through third-party Facebook.
“My office is watching, and we will hold you accountable. Today’s settlement with Sephora makes clear that businesses must heed the California Consumer Privacy Act.”
- California Attorney General Rob Bonta in August 2022
The CPRA removed the mandatory 30-day cure period for certain violations and increased penalties for violations involving minors' data.
The CCPA has reshaped how businesses handle consumer data, driving operational changes, increasing compliance costs, and offering opportunities for competitive advantage. The CPRA builds on this by adding stricter accountability and privacy requirements, further solidifying California's leadership in data privacy.
Businesses must overhaul their data collection, storage, and sharing practices to align with CCPA. This involves conducting data mapping exercises, implementing consent management solutions, and establishing workflows to manage consumer rights requests.
Compliance with the CCPA often requires significant financial investments in:
Compliance demonstrates a commitment to consumer privacy, fostering trust and loyalty. Businesses that implement robust privacy policies may gain a competitive edge, particularly as consumers grow more privacy-conscious.
Read more: Turn CCPA regulations into your competitive edge in 2025
Read further: What is the impact of CCPA on businesses?
The CCPA marked a significant shift in data privacy rights across the United States, setting a precedent for other states to follow. As the first comprehensive consumer privacy law of its kind in the U.S., it introduced European-style protections previously unseen at this scale.
The law paved the way for greater transparency and accountability, prompting businesses nationwide to rethink their data handling practices. It also inspired a wave of state-level privacy legislation, highlighting the growing demand for stronger consumer protections in the digital age.
The CCPA empowers consumers by granting them more control over their personal data:
The CPRA enhances consumer rights by expanding control and increasing transparency in data practices.
With these updates, the CPRA strengthens privacy protections, giving consumers greater oversight and trust in how their data is handled.
While CCPA is California-specific, it shares similarities with and differences from other U.S. data privacy laws:
The CCPA is broader and more consumer-focused than most U.S. data privacy laws, granting Californians rights to access, delete, and opt out of data sales. Unlike sector-specific laws like HIPAA or GLBA, the CCPA applies to a wide range of businesses. It has inspired similar state laws, such as Virginia's and Colorado's, though with varying scopes and enforcement mechanisms.
Not taking the appropriate steps to ensure compliance is a significant risk that can ultimately mean the difference between business success or business failure. Now is the time to become CCPA/CPRA compliant—and it all starts by following these simple steps.
CCPA compliance means adhering to the California Consumer Privacy Act, which grants California residents rights over their personal data. Businesses must provide transparency, allow data access or deletion requests, and avoid selling data without consent. Compliance involves updating privacy policies, handling consumer requests, and ensuring data security.
To comply with CCPA/CPRA, you must:
Read further: Your CCPA compliance checklist
Complying with CCPA and other state privacy laws can be simpler than you think. The Ketch data permissioning platform helps businesses stay compliant by:
Read more: Top Tips for CCPA Compliance Software in 2025
Francesca’s successfully achieved CCPA compliance by partnering with Ketch to implement automated privacy solutions. Their strategy focused on quick consent banner deployment, using legal policy templates, and streamlining data subject requests.
This enabled them to meet compliance deadlines efficiently while maintaining their focus on growth. The collaboration resulted in an agile, scalable approach to privacy compliance across multiple states.
“The privacy of our customers' data is very important to us, and we want to make sure we are acting in accordance with their wishes as well as complying with all state laws. Ketch helps us do this without a lot of overhead so we can focus our internal resources on growing our technology capabilities and supporting our aggressive omni-channel growth plans.”
– Mike Early, Chief Technology Officer, Francesca's
Good Smile Company achieved CCPA/CPRA compliance by transitioning from a manual, homegrown solution to an automated privacy management system with Ketch. The company implemented consent management, data discovery, and classification tools to handle consumer data requests efficiently and ensure compliance across their operations. This approach allowed them to scale their privacy practices while minimizing manual effort.
“We needed to move from homegrown compliance to scalable, futureproof privacy tech. Ketch is a great solution for us. Today we’re complying with privacy regulations and respecting people’s privacy choices in every data system.”
- Taylor Locke, Director of IT, Good Smile Company
Compliance with the CCPA is essential for businesses operating in California. To ensure readiness:
Taking proactive steps today can minimize risks, build consumer trust, and position your business as a privacy leader.
Contact Ketch today to streamline your compliance and future-proof your privacy strategy.
Read further: 2025 U.S. State Privacy Laws: what you need to know