California Consumer Privacy Act (CCPA/CPRA)

CCPA and CPRA: California's privacy rulebook

California was the first US state to give consumers broad control over the personal information businesses collect about them — and its rules have become the template much of the country now follows. If your website reaches visitors in California, the CCPA applies to you regardless of where your company is based. This page explains what the law requires, what changed under the CPRA, what it means for your website in practice, and how to comply.

What is the CCPA, and what did the CPRA change?

The California Consumer Privacy Act (CCPA) took effect on 1 January 2020, granting California residents rights over the personal information businesses collect, use, disclose and sell.

The California Privacy Rights Act (CPRA), approved by voters in November 2020 and effective from 1 January 2023, did not replace the CCPA — it amended and expanded it. Three changes matter most:

  • It added a right to correct inaccurate personal information.  
  • It created a category of sensitive personal information with its own right to limit use.  
  • It extended the concept of "selling" to sharing for cross-context behavioural advertising — which brought most advertising pixels and tracking tags squarely into scope.

The CPRA also established the California Privacy Protection Agency (CPPA), the first dedicated privacy regulator in the United States, and removed the automatic 30-day window businesses previously had to fix a violation before enforcement.

Who has to comply

The law applies to for-profit businesses that do business in California and meet at least one of these thresholds:

  • annual gross revenue above roughly $25 million (adjusted periodically for inflation);  
  • buying, selling or sharing the personal information of 100,000 or more California consumers or households per year; or  
  • deriving 50% or more of annual revenue from selling or sharing personal information.

Two points are commonly missed. First, there is no California office requirement — a company anywhere in the world can be caught if it does business with California consumers. Second, service providers and contractors have their own obligations flowing down through contracts.

Consumer rights under the CCPA/CPRA

                          

RightWhat it means in practice
Know / accessConsumers can ask what personal information you collected, from where, why, and with whom you shared it.
DeleteConsumers can ask you to delete personal information, subject to exceptions.
CorrectConsumers can ask you to fix inaccurate personal information.
Opt out of sale or sharingConsumers can tell you to stop selling or sharing their data for cross-context behavioural advertising.
Limit sensitive informationConsumers can restrict use of sensitive data to what is necessary to provide the service.
PortabilityConsumers can receive their data in a usable format.
Non-discriminationYou cannot penalise a consumer for exercising these rights.

Minors are treated differently: consumers aged 13–16 must opt in before their data is sold or shared, and for children under 13 a parent or guardian must consent.

What this means for your website

Unlike the GDPR, California operates on an opt-out model: you generally do not need consent before advertising tags load, but you must give the consumer a genuine and easy way to say no. In practice, your website needs:

  1. A "Your Privacy Choices" or "Do Not Sell or Share My Personal Information" link that is clearly visible — commonly in the footer and on any page where data is collected. California also specifies an official opt-out icon that may accompany it.  
  2. A "Limit the Use of My Sensitive Personal Information" mechanism, where sensitive data is used beyond permitted purposes.  
  3. Recognition of opt-out preference signals — including Global Privacy Control (GPC). This is not optional. If a browser sends a GPC signal, you must treat it as a valid opt-out request for that consumer, without asking them to click anything.  
  4. Notice at collection — telling consumers, at or before the point of collection, what categories you collect and for what purposes, with a link to your privacy policy.  
  5. A privacy policy reviewed and updated at least every 12 months, describing the rights above and how to exercise them.  
  6. A verifiable process for handling requests, generally answered within 45 days (extendable by a further 45 days where necessary).

Penalties and enforcement

Enforcement sits with the CPPA and the California Attorney General. Civil penalties reach up to $2,500 per violation and $7,500 per intentional violation or violations involving minors — amounts that are adjusted for inflation. Because penalties are assessed per violation and a single misconfigured tag can affect every visitor, exposure scales with traffic rather than with intent.

There is also a private right of action for consumers whose non-encrypted personal information is exposed in a data breach caused by inadequate security.

Beyond California

California is no longer alone. More than a dozen other US states now have comprehensive privacy laws in force, and while the details differ, the mechanics repeat: notice at collection, an opt-out route for targeted advertising, recognition of universal opt-out signals, and rights to access and delete. A website built to satisfy California typically satisfies most of them — provided the experience adapts to where each visitor actually is.

How to comply

  1. Find out what is actually running on your site. You cannot disclose or control tags you have not inventoried.  
  2. Classify what counts as selling or sharing. Most advertising and analytics pixels do.  
  3. Publish the opt-out route and make it work — the link must lead to a functioning mechanism, not a static page.  
  4. Honour GPC signals automatically, before the consumer asks.  
  5. Adapt by region, so California visitors get an opt-out experience while EU visitors get an opt-in one.  
  6. Keep records of requests and preferences, so you can demonstrate compliance if asked.

How Corpowid helps

Corpowid detects where each visitor is and applies the framework that governs them — an opt-out experience for California, an opt-in banner for Europe, and the correct notice elsewhere — from a single installation. Our scanner inventories every cookie, tag, pixel and browser-storage write on your site so nothing runs undisclosed; GPC signals are recognised and applied automatically; and every preference is written to a searchable, exportable record you can produce on request. Because Corpowid also carries your accessibility layer and your legal pages in the same interface, the privacy choices you offer are usable by every visitor — including those using a keyboard or a screen reader.

 

Frequently asked questions

 

Does the CCPA apply to companies outside the United States?

  

Yes. The law applies based on doing business with California residents and meeting one of the thresholds, not on where your company is located. A European or Turkish company with California customers can be in scope.

 

Do I need a cookie banner for California?

  

Not in the European sense. California uses an opt-out model, so you generally do not need prior consent before tags load — but you do need a clear, working way for consumers to opt out of the sale or sharing of their data, and you must honour opt-out preference signals such as GPC.

 

What is Global Privacy Control and is it mandatory?

  

GPC is a signal a browser or extension sends automatically to tell websites the user opts out of the sale or sharing of their personal information. Under California rules it must be honoured as a valid opt-out request — treating it as optional is a compliance gap.

 

What is the difference between selling and sharing?

  

Selling means disclosing personal information for monetary or other valuable consideration. Sharing was added by the CPRA and covers disclosure for cross-context behavioural advertising, even where no money changes hands — which is why most advertising pixels are in scope.

 

Is one banner enough for California and Europe?

  

Only if it adapts. The two regimes ask for opposite defaults: Europe requires consent before non-essential tags run, California requires a route to opt out afterwards. A single static banner satisfies one and fails the other, which is why the experience should change based on where the visitor is. See our ePrivacy Directive page for the European side.

Corpowid, Gartner tarafından tanınan bir platformdur.

Corpowid, dijital erişilebilirlik alanındaki yenilikçi yaklaşımı ve performansı nedeniyle dünyanın önde gelen araştırma ve danışmanlık şirketlerinden biri olan Gartner tarafından takdir edilmiştir. Bu rozetler, yapay zeka destekli ve kapsayıcı web deneyimleri oluşturma konusundaki kararlılığımızı yansıtmaktadır.

Corpowid hakkında sorularınız mı var?

Bizimle iletişime geçin.

Size en kısa sürede geri dönüş sağlayacağız.