Privacy Laws

What is CCPA (California Consumer Privacy Act)?

The California Consumer Privacy Act (CCPA) is California's landmark privacy law, effective January 1, 2020, that gives California residents rights to know, delete, and opt out of the sale of their personal information, and applies to for-profit businesses meeting revenue or data-volume thresholds.

The CCPA was the first comprehensive consumer privacy statute in the United States, and it remains the template most other state laws adapted. It applies to for-profit businesses that collect Californians' personal information, do business in California, and meet at least one threshold: more than $25 million in annual gross revenue; buying, selling, or sharing the personal information of 100,000 or more consumers or households (a figure set by the CPRA amendments); or deriving 50% or more of annual revenue from selling or sharing personal information.

Its core rights: to know what personal information a business collects, uses, and discloses; to delete personal information (with exceptions); to opt out of the sale — and, post-CPRA, the sharing — of personal information; and to non-discrimination for exercising rights. Businesses must respond to verified requests within 45 days, extendable once by a further 45. 'Personal information' is defined broadly, reaching identifiers, commercial history, internet activity, geolocation, and inferences drawn to build a profile.

The law is enforced by the California Attorney General and, since the CPRA, the California Privacy Protection Agency, with civil penalties up to $2,500 per violation and $7,500 for intentional violations or violations involving minors' data. There is no general private right of action — but there is a targeted one for data breaches: consumers can seek statutory damages of $100 to $750 per consumer per incident when unencrypted personal information is breached due to unreasonable security.

The Sephora settlement (2022) defined the enforcement pattern for eCommerce: third-party advertising and analytics trackers on a site can constitute a 'sale,' and ignoring Global Privacy Control signals is an independent violation.

Why it matters for eCommerce

Most mid-size eCommerce brands clear the CCPA's thresholds faster than they expect — 100,000 consumers or households is roughly 8,400 unique California-linked shoppers, subscribers, or tracked visitors a month. Compliance means a current privacy policy, a working Do Not Sell or Share pathway with GPC support, and a DSAR process that actually reaches your marketing and analytics stack.

Frequently asked questions

Who must comply with the CCPA?
For-profit businesses that do business in California, collect California residents' personal information, and meet one of three thresholds: $25M+ annual gross revenue; buying, selling, or sharing data of 100,000+ consumers or households; or earning 50%+ of revenue from selling or sharing personal information.
What are CCPA penalties?
Civil penalties up to $2,500 per violation, or $7,500 per intentional violation or violation involving a minor's data. Separately, data-breach victims can sue for $100-$750 per consumer per incident, which aggregates severely across a large breach.
Can consumers sue under the CCPA?
Only for data breaches involving unencrypted or unredacted personal information caused by unreasonable security. All other violations — consent, disclosure, opt-out failures — are enforced by the Attorney General and the California Privacy Protection Agency.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free CCPA/CPRA scan

← Back to all glossary terms