California Consumer Privacy Act (CCPA/CPRA, Cal. Civ. Code 1798.100) state silhouette

California Consumer Privacy Act (CCPA/CPRA, Cal. Civ. Code 1798.100)

Effective Date: 2020-01-01

The California Consumer Privacy Act, as amended by the CPRA, applies to for-profit businesses that do business in California and meet one of three thresholds: over $25 million in annual revenue, buying, selling, or sharing personal information of 100,000 or more California consumers or households, or deriving half or more of revenue from selling or sharing personal information.

California Consumer Privacy Act Requirements

Covered businesses must post a detailed privacy policy, honor requests to know, delete, and correct personal information, provide a Do Not Sell or Share My Personal Information link or equivalent, honor the Global Privacy Control browser signal as a valid opt-out, and limit use of sensitive personal information on request.

Enforcement and Penalties

Enforcement is by the California Privacy Protection Agency and the Attorney General, with fines up to $2,500 per violation and $7,500 for intentional violations or violations involving minors. Consumers also get a private right of action for certain data breaches. This is the strictest and most actively enforced state privacy law, so most agencies treat it as the baseline for national clients.

Source: California Legislative Information: Cal. Civ. Code 1798.100 et seq.

Report a violation: If you believe a business is violating this law, you can file a complaint with the California Attorney General Consumer Protection.

More Rules & Regulations