California was the first US state to give consumers broad control over the personal information businesses collect about them — and its rules have become the template much of the country now follows. If your website reaches visitors in California, the CCPA applies to you regardless of where your company is based. This page explains what the law requires, what changed under the CPRA, what it means for your website in practice, and how to comply.
The California Consumer Privacy Act (CCPA) took effect on 1 January 2020, granting California residents rights over the personal information businesses collect, use, disclose and sell.
The California Privacy Rights Act (CPRA), approved by voters in November 2020 and effective from 1 January 2023, did not replace the CCPA — it amended and expanded it. Three changes matter most:
The CPRA also established the California Privacy Protection Agency (CPPA), the first dedicated privacy regulator in the United States, and removed the automatic 30-day window businesses previously had to fix a violation before enforcement.
The law applies to for-profit businesses that do business in California and meet at least one of these thresholds:
Two points are commonly missed. First, there is no California office requirement — a company anywhere in the world can be caught if it does business with California consumers. Second, service providers and contractors have their own obligations flowing down through contracts.
| Right | What it means in practice |
|---|---|
| Know / access | Consumers can ask what personal information you collected, from where, why, and with whom you shared it. |
| Delete | Consumers can ask you to delete personal information, subject to exceptions. |
| Correct | Consumers can ask you to fix inaccurate personal information. |
| Opt out of sale or sharing | Consumers can tell you to stop selling or sharing their data for cross-context behavioural advertising. |
| Limit sensitive information | Consumers can restrict use of sensitive data to what is necessary to provide the service. |
| Portability | Consumers can receive their data in a usable format. |
| Non-discrimination | You cannot penalise a consumer for exercising these rights. |
Minors are treated differently: consumers aged 13–16 must opt in before their data is sold or shared, and for children under 13 a parent or guardian must consent.
Unlike the GDPR, California operates on an opt-out model: you generally do not need consent before advertising tags load, but you must give the consumer a genuine and easy way to say no. In practice, your website needs:
Enforcement sits with the CPPA and the California Attorney General. Civil penalties reach up to $2,500 per violation and $7,500 per intentional violation or violations involving minors — amounts that are adjusted for inflation. Because penalties are assessed per violation and a single misconfigured tag can affect every visitor, exposure scales with traffic rather than with intent.
There is also a private right of action for consumers whose non-encrypted personal information is exposed in a data breach caused by inadequate security.
California is no longer alone. More than a dozen other US states now have comprehensive privacy laws in force, and while the details differ, the mechanics repeat: notice at collection, an opt-out route for targeted advertising, recognition of universal opt-out signals, and rights to access and delete. A website built to satisfy California typically satisfies most of them — provided the experience adapts to where each visitor actually is.
Corpowid detects where each visitor is and applies the framework that governs them — an opt-out experience for California, an opt-in banner for Europe, and the correct notice elsewhere — from a single installation. Our scanner inventories every cookie, tag, pixel and browser-storage write on your site so nothing runs undisclosed; GPC signals are recognised and applied automatically; and every preference is written to a searchable, exportable record you can produce on request. Because Corpowid also carries your accessibility layer and your legal pages in the same interface, the privacy choices you offer are usable by every visitor — including those using a keyboard or a screen reader.
Yes. The law applies based on doing business with California residents and meeting one of the thresholds, not on where your company is located. A European or Turkish company with California customers can be in scope.
Not in the European sense. California uses an opt-out model, so you generally do not need prior consent before tags load — but you do need a clear, working way for consumers to opt out of the sale or sharing of their data, and you must honour opt-out preference signals such as GPC.
GPC is a signal a browser or extension sends automatically to tell websites the user opts out of the sale or sharing of their personal information. Under California rules it must be honoured as a valid opt-out request — treating it as optional is a compliance gap.
Selling means disclosing personal information for monetary or other valuable consideration. Sharing was added by the CPRA and covers disclosure for cross-context behavioural advertising, even where no money changes hands — which is why most advertising pixels are in scope.
Only if it adapts. The two regimes ask for opposite defaults: Europe requires consent before non-essential tags run, California requires a route to opt out afterwards. A single static banner satisfies one and fails the other, which is why the experience should change based on where the visitor is. See our ePrivacy Directive page for the European side.
Corpowid, dijital erişilebilirlik alanındaki yenilikçi yaklaşımı ve performansı nedeniyle dünyanın önde gelen araştırma ve danışmanlık şirketlerinden biri olan Gartner tarafından takdir edilmiştir. Bu rozetler, yapay zeka destekli ve kapsayıcı web deneyimleri oluşturma konusundaki kararlılığımızı yansıtmaktadır.