Home › Law library › CCPA/CPRA
US-CA
CCPA/CPRA
California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA)
Sourced. Last verified 9 October 2026
California, United States Privacy
- Status
- In force (CCPA since 1 Jan 2020; CPRA amendments operative 1 Jan 2023). New CPPA regulations on ADMT, risk assessments and cybersecurity audits effective 1 Jan 2026 with phased deadlines.
- Who it applies to
- For-profit businesses doing business in California that collect California residents' personal information and meet a threshold, wherever the business is located. Nonprofits and government agencies are generally not covered.
- Size thresholds
- Any one of: annual gross revenue over $26,625,000 (CPI-adjusted from $25M on 1 Jan 2025; adjusted every odd-numbered year); buys, sells or shares personal info of 100,000+ California consumers or households; or 50%+ of annual revenue from selling or sharing personal info.
- Regulator
- California Privacy Protection Agency (CPPA, branded 'CalPrivacy') and the California Attorney General
- Breach or incident reporting
- Under Civil Code 1798.82 as amended by SB 446 (effective 1 Jan 2026): notify affected residents within 30 calendar days of discovering a breach; if 500+ residents are affected, notify the Attorney General within 15 days of notifying consumers.
- Deadline to answer personal data requests
- Requests to know, delete or correct: 45 calendar days, extendable once by 45 days (90 total) with notice. Opt-out of sale/sharing: as soon as feasible and no later than 15 business days.
- Data protection officer
- Being verified
- Local representative
- Being verified
- Sending data abroad
- Being verified
- Cookies and consent
- Opt-out model: businesses that sell or share personal info (including for cross-context behavioral ads via cookies) must offer a 'Do Not Sell or Share' option and honor Global Privacy Control as a valid opt-out request. Opt-in consent is required to sell/share data of consumers under 16.
- Maximum penalty
- Administrative fines/civil penalties up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers under 16 (from 1 Jan 2025). Data-breach private actions: $107-$799 per consumer per incident or actual damages.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Post a privacy policy and give a notice at collection listing categories, purposes and retention periods.
- Answer requests to know, delete and correct within 45 days; process opt-outs within 15 business days.
- Provide a 'Do Not Sell or Share' link and honor Global Privacy Control signals.
- Run and document risk assessments for significant-risk processing; pre-2026 processing must be assessed by 31 Dec 2027.
- If using ADMT for significant decisions, give pre-use notice, opt-out and access rights by 1 Jan 2027.
- If in scope, certify an independent cybersecurity audit to the CPPA (first due 1 Apr 2028-2030 by revenue tier).
- Sign CCPA-compliant contracts with service providers, contractors and third parties.
Recent changes
2026 regulations (OAL-approved 22 Sep 2025, effective 1 Jan 2026): ADMT compliance by 1 Jan 2027; risk-assessment attestation due 1 Apr 2028; cyber audits due 1 Apr 2028/2029/2030 by revenue tier. SB 446 30-day breach notice from 1 Jan 2026. Data brokers must use DROP from 1 Aug 2026.
Sources
- Primary source: https://cppa.ca.gov/regulations/ccpa_updates.html
- Second source: https://www.thompsoncoburn.com/insights/californias-2026-ccpa-regulations-summary-and-preparation-guide/
- Regulator: California Privacy Protection Agency (CPPA, branded 'CalPrivacy') and the California Attorney General
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].