Field Guide

CCPA / CPRA Compliance: A Practitioner's Guide

The short version

California's privacy law runs on a single statute. The CCPA created it in 2018 and the CPRA amended it in 2020, so the live rules today are the CCPA as amended by the CPRA, enforced by the California Privacy Protection Agency. It applies to a for-profit business that handles California consumers' personal information and clears one of three thresholds (over 25 million dollars in revenue, the data of 100,000 or more consumers or households, or 50 percent or more of revenue from selling or sharing personal information). It gives consumers the right to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. Its mechanics differ from those of the GDPR, and the two regimes are not interchangeable.

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is California's comprehensive consumer privacy statute. It was the first comprehensive consumer privacy regime enacted in the United States, it is administered by a dedicated state enforcement agency, and it grants rights that reach nearly every customer-facing system a covered business operates.

This article covers who the law reaches, the rights it grants, the sale-versus-share distinction, how service providers differ from contractors and third parties, what the notice at collection has to say, who enforces the law, and where California diverges from the GDPR. Privacy law changes and the regulations are amended; the current statutory and regulatory text should be verified at the source before any specific figure is relied on.

One law, two names

The California Consumer Privacy Act (CCPA) took effect in 2020. In 2020 voters passed Proposition 24, the California Privacy Rights Act (CPRA), which did not replace the CCPA. It amended and expanded it, with most provisions operative from January 2023. A present-day reference to the CCPA almost always means the CCPA as amended by the CPRA. The CPRA added the right to correct, the sensitive-personal-information category, the share concept for cross-context behavioral advertising, and a dedicated regulator.

Who has to comply

The law reaches a business: a for-profit entity that does business in California, determines the purposes and means of processing consumers' personal information, and meets at least one of three thresholds. Nonprofits and government agencies generally fall outside the definition. Clearing any one threshold is enough.

ThresholdWhat it means
RevenueAnnual gross revenue over 25 million dollars in the prior calendar year. Size alone can pull a business in, regardless of how much data it handles.
VolumeBuys, sells, or shares the personal information of 100,000 or more California consumers or households in a year. Note that the threshold counts consumers and households, not just paying customers.
Data revenueDerives 50 percent or more of annual revenue from selling or sharing consumers' personal information. A data-driven business can fall under the law well below the revenue and volume marks.

A consumer is a natural person who is a California resident. The law also reaches the employees and job applicants of covered businesses and the personnel of business-to-business contacts, an expansion the CPRA made permanent after an early exemption sunset. A business with a national customer base should assume that some of those consumers are California residents and that the law applies to that portion.

The consumer rights

The statute grants six consumer rights. These are the provisions a regulator tests against a business's actual systems.

RightWhat the consumer can do
KnowRequest the categories and specific pieces of personal information a business has collected, the sources, the purposes, and the categories of parties it was disclosed to.
DeleteRequest deletion of personal information the business collected from them, subject to statutory exceptions such as completing a transaction or complying with a legal obligation.
CorrectRequest correction of inaccurate personal information. Added by the CPRA.
Opt out of sale or sharingDirect a business to stop selling or sharing their personal information. This is the right behind the Do Not Sell or Share My Personal Information link.
Limit use of sensitive personal informationDirect a business to limit its use and disclosure of sensitive personal information to what is necessary to provide the requested service. Added by the CPRA.
No retaliationThe right not to face discrimination or be denied service, charged a different price, or given a lower quality of service for exercising any privacy right.

The deadlines matter as much as the rights. A business generally has to confirm receipt of a request within 10 business days and respond within 45 calendar days, with one 45-day extension available when reasonably necessary. Most requests require verifying the consumer's identity. The opt-out of sale or sharing and the limit-sensitive-information requests do not require verification, because the law does not want a verification step to become a barrier to opting out.

Sale versus share

Sale and share are separate defined terms and are frequently conflated. The CCPA defined a sale broadly: disclosing personal information to a third party for monetary or other valuable consideration. The phrase "other valuable consideration" is what broadens the definition, because a disclosure can be a sale even when no money moves, if the business receives something of value in return. The CPRA then added share: disclosing personal information to a third party for cross-context behavioral advertising, whether or not consideration changes hands.

Share exists because of advertising technology. A business that drops a third-party advertising pixel and lets a partner use the data to target ads across other sites may not be selling in the old monetary sense, but it is sharing. Both sale and share trigger the consumer's opt-out right, which is why the required link reads Do Not Sell or Share My Personal Information. A business that handles either has to provide that link, honor opt-out requests, and recognize the Global Privacy Control, an opt-out preference signal a browser sends on the consumer's behalf.

Service providers, contractors, and third parties

The classification of a party that receives personal information determines whether a disclosure counts as a sale or a share. The law draws three roles, and the contract terms are what separate them.

RoleWhat it isWhy it matters
Service providerA party that processes personal information on the business's behalf under a written contract that restricts use to the specified business purpose.A transfer to a properly contracted service provider is generally not a sale or a share.
ContractorA party the business makes personal information available to for a business purpose, also bound by the required contract terms and certifications.Functionally close to a service provider for compliance purposes. The contract carries the same restrictions.
Third partyA party that is neither the business nor a service provider or contractor bound by the required terms.Disclosure to a third party for value or for cross-context advertising is a sale or a share, with all the opt-out obligations that follow.

The contract determines the classification. The same vendor can be a service provider or a third party depending on the terms executed. A disclosure that operates as a routine processing handoff is a regulated sale where the contract does not contain the required restrictions on the vendor's use of the data. Reviewing the data terms is what establishes whether a vendor is a service provider.

Notice at collection

The law requires transparency at the moment of collection rather than only in a general privacy policy. At or before the point a business collects personal information, it has to give a notice at collection that states the categories of personal information collected, the purposes for which they will be used, whether the information is sold or shared, and how long each category is retained. If the business collects sensitive personal information, the notice covers that category and its purposes too.

The notice at collection works alongside a fuller privacy policy that describes the consumer rights and how to exercise them. A business that sells or shares personal information, or collects sensitive personal information for non-exempt uses, also has to post the opt-out and limit links so a consumer can act without hunting for them.

The CPPA and enforcement

The CPRA created the California Privacy Protection Agency (CPPA), the first standalone privacy regulator in the United States. It holds rulemaking authority over California privacy regulations and the power to investigate and bring administrative enforcement actions. The California Attorney General keeps concurrent enforcement authority, so a business answers to two enforcers, not one.

The CPRA also removed the automatic 30-day right to cure that the original CCPA gave businesses before an enforcement action. A business can no longer assume a grace period to fix a violation once it is found. The law carries civil penalties per violation, with a higher tier for violations involving the personal information of minors. Separately, the CCPA gives consumers a private right of action for certain data breaches that result from a failure to maintain reasonable security, which is a distinct exposure from the regulators' general enforcement authority.

Automated decision-making, risk assessments, and cybersecurity audits

In 2025 the CPPA finalized a package of regulations the CCPA's earlier text had authorized. The Agency's board adopted them on July 24, 2025; the Office of Administrative Law approved them and filed them with the Secretary of State on September 22, 2025; they took effect on January 1, 2026. The package covers automated decision-making technology (ADMT), risk assessments, and annual cybersecurity audits.

The obligations phase in rather than landing at once. A business that uses ADMT to make a significant decision about a consumer has to meet the ADMT requirements, which include a pre-use notice, the right to opt out, and the right to access information about the decision, by January 1, 2027. Risk assessments conducted in 2026 and 2027 are due to the Agency by April 1, 2028. The final ADMT scope is narrower than the early drafts: it reaches technology that replaces or substantially replaces human decision-making, and it dropped the broad references to artificial intelligence the proposed version carried.

A CCPA program that treats automated decisioning as out of scope does not yet account for the ADMT requirements, whose compliance date has not passed.

How California differs from the GDPR

A GDPR program does not map onto California one to one. The two regimes share a general objective and differ in mechanics.

DimensionCCPA / CPRA (California)GDPR (EU)
Who it coversFor-profit businesses meeting one of three thresholds.Any controller or processor handling EU residents' data, with no revenue or volume threshold.
Default postureOpt-out. A business can process and sell or share until the consumer says stop.Often opt-in. Many activities need a lawful basis, and consent must be affirmative.
Lawful basisNo general lawful-basis requirement to process. Transparency and the opt-out carry the load.Processing requires one of six lawful bases under Article 6.
Sensitive dataConsumer can direct a business to limit use of sensitive personal information.Special-category data is generally prohibited unless a specific Article 9 condition applies.
Data portabilityDelivered through the right to know in a portable format.A standalone right to receive data in a structured, machine-readable form.
RegulatorThe CPPA plus the California Attorney General.National supervisory authorities, coordinated under the EDPB.

The structural difference is the order of justification. The GDPR requires a controller to establish, in advance, why it is permitted to process at all. California presumes processing is permitted and gives the consumer mechanisms to stop sale, stop sharing, limit sensitive use, and demand, delete, or correct the information a business holds. A GDPR program supplies a foundation, and California-specific work remains.

A readiness checklist

The following items are confirmed before a business represents to a customer or a regulator that it is compliant.

California privacy law is its own regime, with its own enforcer, its own thresholds, and a sale-and-share concept that reaches activity a business may not treat as selling data. Compliance work generally begins with mapping the personal information the business holds and reviewing the contracts that move it. For the working definitions behind every term here, see the CCPA / CPRA glossary.

Common questions

Who has to comply with the CCPA and CPRA?
A for-profit business that does business in California, decides the purposes and means of processing California consumers' personal information, and meets at least one of three thresholds: annual gross revenue over 25 million dollars; buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information. Meeting one threshold is enough.
What is the difference between a sale and a share under the CCPA?
A sale is disclosing personal information to a third party for monetary or other valuable consideration. A share, added by the CPRA, is disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. Both trigger the consumer's right to opt out, which is why the required link reads Do Not Sell or Share My Personal Information.
What rights does the CCPA give California consumers?
California consumers have the right to know what personal information a business collects and how it is used and disclosed, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, the right to limit the use and disclosure of sensitive personal information, and the right not to be retaliated against for exercising any of these rights.
What is sensitive personal information under the CPRA?
Sensitive personal information is a defined subset that includes Social Security and government ID numbers, financial account and login credentials, precise geolocation, race or ethnic origin, religious beliefs, union membership, the contents of mail, email, and texts, genetic data, biometric data used to identify a person, and data about health, sex life, or sexual orientation. Consumers can direct a business to limit its use and disclosure of this category to what is necessary to provide the service.
Who enforces the CCPA and CPRA?
The CPRA created the California Privacy Protection Agency (CPPA), a dedicated state agency with rulemaking, investigation, and administrative enforcement authority over California privacy law. The California Attorney General also retains enforcement authority. The CPRA removed the prior 30-day right to cure as an automatic entitlement, so a business cannot assume it will get a window to fix a violation before enforcement.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.