CCPA / CPRA

A practical introduction to the California Consumer Privacy Act as amended by the California Privacy Rights Act, including who meets the thresholds, who enforces it, what it requires, the 2026 regulations on risk assessments, cybersecurity audits, and automated decision-making, what compliance costs, and how to start.

privacy · california

What is CCPA / CPRA

The California Consumer Privacy Act (CCPA) is California’s comprehensive privacy law, the first of its kind in the United States. Passed in 2018 and in force since January 1, 2020, it was substantially amended by the California Privacy Rights Act (CPRA), a ballot initiative voters approved in November 2020 whose changes took effect January 1, 2023. There is one law, not two: “CPRA” names the amendments and “CCPA” names the act they amended, and this site treats them as one regime.

The law gives California residents rights over the personal information businesses collect about them (to know what is collected, to delete it, to correct it, to stop its sale or sharing, and to limit use of sensitive categories) and puts duties on businesses to give notice, honor those rights, contract with vendors, minimize data, and keep reasonable security. Unlike Europe’s GDPR, it does not require a lawful basis for processing: you may collect and use personal information for disclosed purposes, and the law’s leverage is transparency, opt-outs, and enforcement when the opt-outs do not work.

The CPRA also created the California Privacy Protection Agency, the first U.S. regulator dedicated to privacy, which now brands itself CalPrivacy. Its 2025 regulations, approved September 23, 2025 and effective January 1, 2026, are the largest change since the CPRA. They add three programs that phase in through 2030: risk assessments for high-risk processing, annual independent cybersecurity audits for larger data processors, and rules for automated decision-making technology (ADMT) used to make significant decisions about people. For security teams, the cybersecurity audit is the part that turns a privacy law into an audited standard.

Two misconceptions matter. First, CCPA is not a California-only concern; the thresholds are about revenue and the number of Californians in your data, and a company in Ohio or Ireland with a large U.S. customer base is covered. Second, “we do not sell data” is usually wrong in the law’s terms: sharing personal information with advertising and analytics partners for cross-context behavioral advertising is “sharing,” and disclosing it for anything of value can be a “sale.” Nearly every enforcement action so far has turned on that point.

Who CCPA / CPRA applies to

The law applies to a business: a for-profit entity that does business in California, determines the purposes and means of processing California residents’ personal information, and meets any one of three thresholds:

  1. Annual gross revenue above $26.625 million (the $25 million statutory figure, adjusted for inflation every odd year; the figure is worldwide revenue, not California revenue, measured on January 1 for the prior year).
  2. Annually buys, sells, or shares the personal information of 100,000 or more California consumers or households.
  3. Derives 50 percent or more of annual revenue from selling or sharing consumers’ personal information.

Entities that control or are controlled by a covered business and share its branding are covered too, as are joint ventures. Nonprofits and government agencies are exempt, though vendors to them may not be.

“Consumer” means any California resident, and since January 1, 2023 that includes your employees, job applicants, and business contacts, not just customers. A covered business must handle HR and B2B data under the same rights and notices.

Three roles follow the data:

  • Service providers and contractors process personal information for a business under a written contract with mandatory terms; they have direct duties (assist with requests, no use beyond the contract, flow terms down to subcontractors) and can be fined.
  • Third parties receive personal information through a sale or sharing and must honor the business’s opt-out signals and use the data only for the disclosed purposes.
  • Data brokers (businesses that sell personal information of consumers they have no direct relationship with) must register annually with CalPrivacy under the Delete Act and, since August 1, 2026, process deletion requests from the DROP platform at least every 45 days.

Data-level exemptions remove specific information, not whole companies: protected health information under HIPAA, financial data under the Gramm-Leach-Bliley Act, consumer reports under the FCRA, and driver data under the DPPA are carved out, but the same company’s marketing and employee data remain covered. See the HIPAA page for what that exemption does and does not cover.

The surprise cases are the mid-sized SaaS company whose website trackers alone put it over 100,000 consumers, the employer that never sells anything but crosses the revenue line and now owes rights notices to its California staff, and the vendor that assumed only its customers were “businesses” until a service-provider fine arrived.

Who manages and enforces CCPA / CPRA

Two regulators share the law, and their division of labor is clearer since 2023:

  • CalPrivacy (the California Privacy Protection Agency) writes and updates the regulations, runs administrative enforcement (investigations, orders, fines through its own administrative process), operates the data broker registry and the DROP deletion platform, and, since 2026, runs an Audits Division that opens sector-wide compliance audits (the first, of gig platforms, began July 2026). Its newsroom is the closest thing the law has to a change feed.
  • The California Attorney General keeps civil enforcement authority and has brought most of the largest cases (Sephora, Healthline, Disney/ABC, and the joint $12.75 million General Motors settlement in May 2026). Local prosecutors can join.
  • The Legislature amends the statute each session (SB 923, expanding deletion rights, passed in August 2026 and awaits the Governor), and the courts hear appeals of agency decisions and the private data-breach actions.

Penalties are per violation, which in practice means per consumer: up to $2,663 for each violation and $7,988 for each intentional violation or violation involving a consumer known to be under 16. The 30-day cure period ended January 1, 2023; cure is now at the regulator’s discretion. Settlements have run from about $345,000 to $12.75 million, and nearly all cite the same things: an opt-out link that does not work, Global Privacy Control signals ignored, trackers that keep firing after opt-out, missing contract terms with advertising vendors, or “dark patterns” that make requests harder than consenting.

Consumers have a private right of action for data breaches: if unencrypted or unredacted personal information is exposed because the business failed to keep reasonable security, individuals can sue for $107 to $799 per consumer per incident or actual damages, without proving harm. Class actions under this section follow most large California breaches and are, for many businesses, the biggest financial exposure in the law.

Under the 2025 regulations CalPrivacy and the Attorney General can also demand your risk assessment report with 30 days’ notice and will receive cybersecurity audit certifications and risk assessment attestations annually, which gives the regulators a map of who to examine.

What is in scope

Scope in CCPA is every piece of personal information about California residents that a covered business collects, uses, or discloses, plus every party it goes to. “Personal information” is broad: anything reasonably capable of being associated with a person or household, including identifiers, device and browsing data, inferences, geolocation, and employment data. Sensitive personal information is a defined subset (Social Security and other government numbers, account credentials, precise geolocation, race and ethnicity, religion, union membership, contents of mail and messages, genetic and biometric data, health, sex life, and sexual orientation, citizenship and immigration status) with extra rights and, now, mandatory risk assessments.

Scope grows in the familiar directions:

  • Every collection point: websites and apps (including the tags and SDKs on them), forms, call centers, HR systems, and data bought from brokers.
  • Every recipient: advertising and analytics partners (usually “sharing”), data buyers (“sale”), and service providers, each needing the right contract and the right treatment of opt-outs.
  • Every California resident category: customers, prospects, visitors, employees, applicants, contractors, and business contacts.
  • Automated decision-making: any technology that replaces or substantially replaces human decision-making in employment, lending, housing, insurance, education, healthcare, criminal justice, or access to essential goods, which triggers ADMT duties and a risk assessment.
  • Security: the “reasonable security” duty, the private right of action, and for larger processors the cybersecurity audit reach every system that stores personal information, not only the marketing stack.

A scope exercise you can run this week:

  1. Confirm the threshold: revenue, consumer count (including website visitors), and revenue from selling or sharing.
  2. List every category of personal information you hold, where it came from, where it lives, and who it goes to, flagging sensitive categories.
  3. Load a browser with Global Privacy Control enabled, visit your site, and check which trackers still fire; that is your sale-and-share exposure.
  4. List every vendor and mark each as service provider, contractor, or third party, then check its contract terms.
  5. Check the audit and risk assessment triggers: do you sell or share, process sensitive information, or use ADMT for significant decisions, and do you process 250,000 or more consumers’ data (or 50,000 with sensitive information)?

Data minimization is now a written duty (collection must be reasonably necessary and proportionate to the disclosed purpose), so the cheapest scope reduction is collecting less and cutting off advertising partners you cannot paper.

What CCPA / CPRA requires

The statute lives at Civil Code sections 1798.100 to 1798.199.100; the regulations (Title 11, Division 6 of the California Code of Regulations) carry the operational detail. The core obligations:

Consumer rights, and the machinery to honor them. The rights to know what is collected and disclosed, to delete, to correct, to opt out of sale and sharing, to limit use of sensitive personal information, and to non-discrimination for exercising them. Businesses must offer at least two request methods, verify identity for know, delete, and correct requests (but not for opt-outs), respond within 45 days (extendable once by 45), keep request records for 24 months, and train the staff who handle them.

Notices. A notice at collection at or before the point of collection, a privacy policy updated annually with the required disclosures, and the “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” links (or a single “Your Privacy Choices” link) on the homepage. Businesses must treat Global Privacy Control and similar opt-out preference signals as valid opt-outs.

Purpose limitation and minimization. Collection, use, retention, and sharing must be reasonably necessary and proportionate to the disclosed purposes, and retention periods must be disclosed by category.

Contracts. Written agreements with every service provider, contractor, and third party containing the required terms (limited purposes, no selling or sharing, compliance assistance, notice if the vendor can no longer comply, flow-down to subcontractors). Missing terms turn a vendor into a “sale” and were a factor in the Tractor Supply fine.

Reasonable security (section 1798.100(e)) for personal information, backed by the private right of action for breaches.

The 2025 regulations add three programs (compliance dates in the version history):

  • Risk assessments (Article 10) before processing that presents significant risk: selling or sharing personal information; processing sensitive personal information (with a narrow HR exception); using ADMT for a significant decision; profiling employees, students, or applicants through systematic observation, or consumers in sensitive locations; and training ADMT or identity-verification technology. Each assessment documents purposes, categories, benefits, negative impacts, safeguards, and the decision to proceed, is reviewed at least every three years and within 45 days of a material change, is retained five years, and is summarized in an annual attestation under penalty of perjury to CalPrivacy (first due April 1, 2028 for 2026 and 2027). A GDPR impact assessment can be reused if it covers the required content.
  • Cybersecurity audits (Article 9) for businesses that meet a risk trigger and either earn half their revenue from selling or sharing, or exceed the revenue threshold and processed personal information of 250,000 or more consumers or households (or sensitive information of 50,000 or more) in the prior year. The audit is annual, performed by a qualified, objective, independent auditor (internal or external, with independence rules), covers the components the regulation names (authentication including multi-factor, encryption, account management, inventories, secure configuration, vulnerability and penetration testing, logging and monitoring, segmentation, retention, training, incident response, vendor oversight, and more), may not rely on management assertions alone, is reported to the board or top executive who signs a no-influence statement, and is certified to CalPrivacy by April 1 each year. Records are kept five years. An audit already performed under NIST CSF 2.0, SOC 2, or ISO/IEC 27001 can satisfy it if supplemented to cover every required component.
  • Automated decision-making technology (Article 11) used to make significant decisions: a plain-language pre-use notice, a right to opt out (or a human appeal to a reviewer who can overturn the decision), and a right to access information about the logic and outcome. Compliance is required by January 1, 2027 for existing uses and immediately for new ones.

The documents that matter, and how much weight each carries:

  • The statute is binding and readable; sections 1798.100 to 1798.135 hold the rights and notices, 1798.140 the definitions and thresholds, 1798.150 the breach action.
  • The regulations are binding and where the operational rules (request handling, dark patterns, opt-out signals, the three new programs) live.
  • CalPrivacy’s enforcement advisories and the Attorney General’s settlements show what regulators actually test.
  • The Delete Act (Civil Code 1798.99.80 and following) governs data brokers separately.

How compliance is validated

CCPA is validated by regulatory enforcement, consumer litigation, and, for larger processors from 2028, an annual independent audit. No certificate exists and none is required.

What demonstrating compliance means in practice:

  1. Your own records: the privacy policy and notices, the 24-month request log with response times, vendor contracts, the data inventory, training records, and now the risk assessments and audit reports. Regulators ask for these first, and the risk assessment report must be produced within 30 days of request.
  2. Regulator sweeps and audits. The Attorney General runs investigative sweeps (connected vehicles, streaming, mobile apps, employer notices); CalPrivacy’s Audits Division runs sector audits and can audit any business it believes is violating the law.
  3. Complaints, from consumers through CalPrivacy’s complaint form, drive individual investigations.
  4. Litigation after breaches under section 1798.150, where reasonable security is judged after the fact.
  5. The cybersecurity audit certification and risk assessment attestation, filed annually with CalPrivacy from 2028, which turn the security program into a document a regulator can check.

For the audit itself, the regulation borrows the assurance profession’s rules. The auditor must be qualified in cybersecurity, exercise impartial judgment, be free of business influence, not have designed or operated the controls being tested, and use accepted procedures (AICPA, PCAOB, ISACA, or ISO standards are named). Findings must rest on evidence (documents, testing, interviews), not management’s word. The report goes to the executive responsible for the program, who certifies in writing that the business did not try to influence the auditor and has read the findings.

Who may perform the work

No license is required to help a business comply with CCPA; privacy counsel, consultants, and security firms build programs and run readiness work. The cybersecurity audit is different: the auditor may be an employee or an outside firm, but must meet the independence rules, so an internal auditor must report to someone who does not run the security program and cannot have built or operated what is tested. In practice most businesses will use an external firm, and a SOC 2 or ISO/IEC 27001 auditor already engaged is the natural candidate if the scope is extended.

Aeris Secure performs readiness assessments, risk assessments, and remediation work; whether it or any firm can also perform the formal audit for a client depends on those independence rules, and advisory and audit roles should be separated. Verify a vendor’s CCPA posture by reading its contract terms and testing its handling of your opt-out signals, not by a badge.

The CCPA / CPRA compliance process

A first program at a small or mid-sized business takes two to four months of part-time work; adding the risk assessment and audit programs is a year-long effort for a larger data processor. The steps:

  1. Confirm coverage. Which threshold you meet, whether employee and B2B data is in play, and whether you sell or share (test with Global Privacy Control), process sensitive information, or use ADMT.
  2. Inventory personal information: categories, sources, purposes, retention, recipients, and each recipient’s role.
  3. Fix the consumer-facing layer: privacy policy, notice at collection, the opt-out and limit links, a working opt-out that honors GPC and stops trackers, and two request channels.
  4. Build request handling: verification, the 45-day clock, the 24-month log, staff training.
  5. Paper the vendors with the required terms, and stop sharing with any partner that will not sign.
  6. Assess security against the reasonable-security duty and, if you are above the audit thresholds, map your existing framework to the audit’s components and pick an auditor.
  7. Document risk assessments for each triggering activity (existing ones by December 31, 2027) and prepare the ADMT notices by January 1, 2027.
  8. File the risk assessment attestation and, when due, the audit certification with CalPrivacy each April 1, and keep everything five years.

Who decides, and what to ask them

Most decisions are yours to make and document; the parties who judge them are CalPrivacy, the Attorney General, plaintiffs’ lawyers, and your enterprise customers. The people to consult:

  • Privacy counsel, on whether you sell or share, which exemptions apply, and how to word notices. Ask for the analysis in writing; the regulators’ first question is why you concluded your trackers are not a sale.
  • Your marketing and product teams, who own the tags, SDKs, and ADMT that create the exposure. Ask what fires on the site, what data partners receive, and which decisions software makes about people.
  • Your enterprise customers’ procurement teams, who will send service-provider terms and ask about your audit. Ask which of their obligations they are flowing down.
  • Your auditor, if the cybersecurity audit applies. Ask which framework audit they can extend, how independence will be documented, and when the first covered period starts for your revenue band.

Reality check: the program fails in the browser, not in the policy. An opt-out link that does not stop a single pixel is the fact pattern in most fines; test it with GPC enabled before anything else.

Cost, time, and internal effort

CCPA has no required audit or certification fee for most covered businesses, so this page shows no headline cost range. What compliance costs is internal time plus whatever help and tooling you buy, and from 2028 an annual independent audit for the largest data processors.

External costs, when incurred:

  • Readiness or gap assessment: roughly $5,000 to $25,000 for a small or mid-sized business, more for complex enterprises.
  • Risk assessments: roughly $2,000 to $20,000 when consultant-led; many businesses do them internally using their GDPR impact assessment process.
  • Annual cybersecurity audit: roughly $30,000 to $80,000 in auditor fees for a business above the thresholds, more for large or complex environments. Extending an existing SOC 2 or ISO/IEC 27001 engagement is the cheapest route.
  • Request and consent tooling: roughly $5,000 to $75,000 per year, from small-business packages to enterprise platforms.
  • Counsel, for notices, contracts, and the sale-or-share analysis, typically a few thousand dollars for a small business and far more for a large one.

Published all-in figures put a small business at $5,000 to $75,000 to reach compliance and enterprises at $100,000 to $2 million or more. CalPrivacy’s own estimate when it proposed the 2025 regulations put a small business’s initial cost for the new programs at $7,045 to $92,896 with about $19,000 a year ongoing, and a larger business at up to $122,666 initially and about $26,000 a year; the final rules were narrowed, so treat those as an upper framing.

Internal effort is the larger cost for most businesses. A first program at a small or mid-sized company takes roughly 60 to 500 staff hours across legal, marketing, IT, and HR before remediation; the data inventory, the opt-out plumbing, and vendor paperwork consume most of it. The risk assessment and audit programs add a recurring workload comparable to running a SOC 2.

The page’s ranges are directional, not a quote. The best predictors are whether you sell or share (trackers), whether sensitive information or ADMT is involved, your revenue and consumer count against the audit thresholds, and whether you already run an audited security framework.

Time follows effort. A company with a clean vendor list and no advertising trackers can be defensibly compliant in a quarter. A consumer business with 80 tags, a data-broker relationship, and an ADMT hiring tool is looking at a year, with hard dates in 2027 and 2028.

Maintaining compliance

CCPA compliance decays quickly because the exposure sits in marketing tags and vendor relationships that change weekly. A typical operating rhythm:

  • Test the opt-out monthly with Global Privacy Control enabled and a tag scanner; confirm partners receive and honor the signal.
  • Review the privacy policy annually (a legal requirement) and the notice at collection whenever a purpose or category changes.
  • Track requests against the 45-day clock and audit the log quarterly; keep 24 months.
  • Review vendors annually for contract terms, role classification, and subcontractor flow-down; add CCPA terms to procurement templates.
  • Update risk assessments within 45 days of a material change and at least every three years; file the attestation each April 1.
  • Run the cybersecurity audit each year once you are in scope and file the certification by April 1; keep audit records five years.
  • Run the risk assessment the regulations and the reasonable-security duty assume, at least annually and after major changes. The free risk assessment tool on this site produces a risk register and report in the browser without sending data anywhere.
  • Watch the change feed: CalPrivacy’s newsroom and rulemaking page, Attorney General settlements, inflation adjustments to thresholds and fines every odd year, and bills such as SB 923. Follow this page for major items.

Scope changes silently: a new analytics vendor, a hiring tool with a scoring model, a product for teenagers, or crossing the revenue line can each add obligations. Wire the data inventory into change management and procurement so changes are reviewed before a regulator, or a plaintiff, notices.

How to get started

If CCPA has just landed on your desk, begin with five concrete actions:

  1. Confirm coverage in writing. Revenue against $26.625 million, consumers (including website visitors) against 100,000, and revenue from selling or sharing. Note whether the 250,000-consumer audit threshold or any risk assessment trigger applies.
  2. Test your own site with Global Privacy Control on. Which trackers still fire is your sale-or-share exposure and your first remediation list.
  3. Read the sections you will live by. Statute sections 1798.100 to 1798.135 and 1798.140 to 1798.150 take under an hour; then the regulation articles on requests, opt-out signals, and, if they apply, risk assessments (Article 10), cybersecurity audits (Article 9), and ADMT (Article 11).
  4. Start the data inventory and vendor list. A spreadsheet is fine: categories, sources, purposes, retention, recipients and their role, and contract status. Everything else depends on it.
  5. Run a first risk assessment and a gap review. Use a simple method (the risk assessment tool works) and walk the requirements against your inventory, paying special attention to the opt-out mechanism, vendor terms, and, if the audit applies, which existing framework audit you can extend. If you need help, a gap assessment from privacy counsel or a security consultancy is the usual first purchase.

For official starting points, use the statute for the text, CalPrivacy and its regulations page for the rules and news, and the Attorney General’s CCPA page for enforcement.

The first goal is not the whole statute. It is knowing whether you are covered, whether you sell or share, and whether the 2028 audit clock is running for you. Once those three answers are written down, CCPA is a set of notices, procedures, and contracts you can build, and fixing the opt-out button will do more for your risk than anything else on the list.

Version history

VersionStatusReleasedEffectiveRetiredSummary
2025 regulations (risk assessments, cybersecurity audits, ADMT) current Sep 23, 2025Jan 1, 2026n/aApproved by the Office of Administrative Law on September 23, 2025 after a rulemaking that began in November 2024. Adds mandatory risk assessments for high-risk processing (existing processing assessed by December 31, 2027, attestations to CalPrivacy from April 1, 2028), annual independent cybersecurity audits for larger data processors (first reports due April 1, 2028, 2029, or 2030 by revenue), and pre-use notice, opt-out, and access rights for automated decision-making technology used for significant decisions (compliance by January 1, 2027), plus updates to the existing regulations.
CPRA amendments (Proposition 24) current Nov 3, 2020Jan 1, 2023n/aVoter-approved amendments that created the California Privacy Protection Agency, added the rights to correct and to limit use of sensitive personal information, extended the law to employee and business-contact data, replaced the 30-day cure period with discretionary cure, raised the consumer threshold to 100,000, and mandated the risk assessment, cybersecurity audit, and ADMT regulations. Fully enforceable from January 1, 2023, with the agency's own regulations enforceable from 2024 after a court challenge. The Delete Act (SB 362, 2023) later added the data broker deletion platform, live August 1, 2026.
CCPA (AB 375) retired
→ CPRA amendments (Proposition 24)
Jun 28, 2018Jan 1, 2020Jan 1, 2023The original act, the first comprehensive U.S. state privacy law, enforced by the Attorney General from July 1, 2020 with a 30-day cure period. Gave Californians rights to know, delete, and opt out of sale, and created the "Do Not Sell" link. Superseded in operation by the CPRA amendments on January 1, 2023.

New versions are announced in news. Follow this standard to get notified.