Skip to content
GlanceDeskJurisdiction

Home › Law library › CCPA/CPRA

US-CA

CCPA/CPRA

California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA)

Sourced. Last verified 9 October 2026

California, United States Privacy

Status
In force (CCPA since 1 Jan 2020; CPRA amendments operative 1 Jan 2023). New CPPA regulations on ADMT, risk assessments and cybersecurity audits effective 1 Jan 2026 with phased deadlines.
Who it applies to
For-profit businesses doing business in California that collect California residents' personal information and meet a threshold, wherever the business is located. Nonprofits and government agencies are generally not covered.
Size thresholds
Any one of: annual gross revenue over $26,625,000 (CPI-adjusted from $25M on 1 Jan 2025; adjusted every odd-numbered year); buys, sells or shares personal info of 100,000+ California consumers or households; or 50%+ of annual revenue from selling or sharing personal info.
Regulator
California Privacy Protection Agency (CPPA, branded 'CalPrivacy') and the California Attorney General
Breach or incident reporting
Under Civil Code 1798.82 as amended by SB 446 (effective 1 Jan 2026): notify affected residents within 30 calendar days of discovering a breach; if 500+ residents are affected, notify the Attorney General within 15 days of notifying consumers.
Deadline to answer personal data requests
Requests to know, delete or correct: 45 calendar days, extendable once by 45 days (90 total) with notice. Opt-out of sale/sharing: as soon as feasible and no later than 15 business days.
Data protection officer
Being verified
Local representative
Being verified
Sending data abroad
Being verified
Cookies and consent
Opt-out model: businesses that sell or share personal info (including for cross-context behavioral ads via cookies) must offer a 'Do Not Sell or Share' option and honor Global Privacy Control as a valid opt-out request. Opt-in consent is required to sell/share data of consumers under 16.
Maximum penalty
Administrative fines/civil penalties up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers under 16 (from 1 Jan 2025). Data-breach private actions: $107-$799 per consumer per incident or actual damages.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

2026 regulations (OAL-approved 22 Sep 2025, effective 1 Jan 2026): ADMT compliance by 1 Jan 2027; risk-assessment attestation due 1 Apr 2028; cyber audits due 1 Apr 2028/2029/2030 by revenue tier. SB 446 30-day breach notice from 1 Jan 2026. Data brokers must use DROP from 1 Aug 2026.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].