California Consumer Protection: What Websites Must Do in 2026
California consumer protection laws set strict rules for websites. Learn the CCPA thresholds, consumer rights, opt-out duties, and penalties you must meet.
California consumer protection is now the toughest privacy compliance burden most United States websites face, and it reaches far beyond companies based in the state. If you sell to California residents, run ads to them, or embed analytics that share their data, the California Consumer Privacy Act likely applies to you. This guide covers the laws, thresholds, consumer rights, and enforcement actions you need to plan around, though you should consult a qualified attorney for advice tailored to your specific business.
What California Consumer Protection Means for Websites
California consumer protection is a set of state laws that give residents enforceable rights over how businesses collect, use, sell, and secure their personal information, and that penalize deceptive or unfair commercial practices. For a website operator, it translates into concrete duties: disclose what you collect, let people opt out, honor deletion requests, and never make the process harder than the law allows.
Two things make California different from the rest of the country. First, it has a dedicated regulator, the California Privacy Protection Agency (CPPA), with rulemaking and enforcement power. Second, the Attorney General enforces in parallel, and consumers themselves can sue over data breaches.
The practical result is that a small marketing mistake, such as a cookie banner that ignores opt-out signals, becomes a regulatory finding with a dollar figure attached.
The Laws Behind California Consumer Protection
Most people use "CCPA" as shorthand for the whole regime, but several statutes work together. Knowing which one applies to a given obligation tells you who enforces it and what the exposure looks like.
- California Consumer Privacy Act (CCPA), Civil Code 1798.100 and following, amended by the California Privacy Rights Act (CPRA) effective January 1, 2023. The core privacy rights and business duties live here.
- CalOPPA, Business and Professions Code 22575 to 22579. Requires a conspicuously posted privacy policy for any commercial site collecting personally identifiable information from Californians, and requires disclosure of how you respond to Do Not Track signals.
- Shine the Light, Civil Code 1798.83. Requires disclosure when personal information is shared with third parties for their direct marketing purposes.
- Unfair Competition Law, Business and Professions Code 17200. Broad prohibition on unlawful, unfair, or fraudulent business acts. Regulators use it to reach conduct the CCPA does not explicitly cover.
- Automatic Renewal Law, Business and Professions Code 17600 and following. Governs subscription sign-up disclosures, consent, and cancellation, with additional requirements added by amendments taking effect in 2025.
- California Invasion of Privacy Act (CIPA), Penal Code 630 and following. Originally a wiretapping statute, now the basis for a wave of class actions over session replay tools, chat widgets, and advertising pixels.
- Delete Act (SB 362), which requires registered data brokers to honor deletion requests through the CPPA's Delete Request and Opt-Out Platform.
For a deeper breakdown of how the CPRA changed the original statute, see the California Privacy Rights Act guide.
Who Must Comply With California Consumer Protection Rules
The CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing personal information, and meets at least one threshold in Section 1798.140(d):
- Annual gross revenue above $25 million in the preceding calendar year.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households.
- Derives 50 percent or more of annual revenue from selling or sharing personal information.
Three details trip businesses up. The revenue threshold counts global revenue, not California revenue. The 100,000 threshold counts households and devices, not just individuals, so an ad-supported publisher can cross it faster than expected. And "sharing" includes disclosing data for cross-context behavioral advertising, which means running Meta or Google advertising pixels can qualify even with no money changing hands.
Affiliates that share common branding with a covered business are pulled in too. There is no small business carve-out beyond the thresholds themselves.
Consumer Rights You Must Support
California consumer protection law grants residents seven operative rights. Your intake process, verification workflow, and privacy policy all have to reflect each one.
- Right to know (Sections 1798.100 and 1798.110): categories and specific pieces of personal information collected, sources, business purposes, and the third parties it went to.
- Right to delete (Section 1798.105), subject to exceptions for completing a transaction, security, legal compliance, and internal uses reasonably aligned with consumer expectations.
- Right to correct inaccurate personal information (Section 1798.106), added by the CPRA.
- Right to opt out of sale or sharing (Section 1798.120).
- Right to limit use of sensitive personal information (Section 1798.121).
- Right to non-discrimination (Section 1798.125) for exercising any of the above. Financial incentive programs are allowed but must be disclosed and reasonably related to the value of the data.
- Right to data portability, delivered in a readily usable format when a consumer requests access electronically.
The standard look-back for a right to know request is 12 months. Under Section 1798.130(a)(2)(B), consumers may also request information beyond that window for data collected on or after January 1, 2022, unless doing so proves impossible or requires disproportionate effort.
Response Deadlines
Acknowledge a request within 10 business days and substantively respond within 45 calendar days. You may extend once by another 45 days if you tell the consumer about the extension and why. Opt-out requests get a tighter clock: 15 business days to process, and you must notify third parties you sold or shared the data with in the preceding 90 days.
Notice at Collection and Privacy Policy Duties
Section 1798.100(a) requires a notice at or before the point of collection listing the categories of personal information collected, the purposes of use, whether that information is sold or shared, and the retention period for each category. The generic "we may collect information to improve our services" paragraph fails this test.
Your privacy policy must be updated at least once every 12 months under Section 1798.130(a)(5). Regulators check the last-updated date, and a stale date is a cheap way to signal noncompliance.
A CCPA-ready privacy policy needs to include:
- Categories of personal information collected in the preceding 12 months, mapped to the statutory categories in Section 1798.140(v).
- Categories of sources and categories of third parties receiving the data.
- Business and commercial purposes for collection, selling, and sharing.
- Retention periods, or the criteria used to determine them.
- A description of each consumer right and at least two designated request methods.
- Instructions for authorized agents submitting requests on a consumer's behalf.
If you are building or rewriting this document, a privacy policy generator that maps the statutory categories for you is faster and more reliable than editing a template by hand. The disclosure requirements differ meaningfully from Europe's, which is why a GDPR and CCPA comparison is worth reading before you try to run one policy for both.
Do Not Sell, Do Not Share, and Opt-Out Signals
If you sell or share personal information, Section 1798.135 requires a clear and conspicuous "Do Not Sell or Share My Personal Information" link on your homepage, or a single alternative opt-out link combined with the sensitive information limit. The Do Not Sell page requirements get more specific about placement and wording.
The bigger operational obligation is automated. Regulation 11 CCR 7025 requires businesses that sell or share data to honor opt-out preference signals, in practice the Global Privacy Control (GPC), as valid opt-out requests. This is not optional and cannot be substituted with a banner alone.
Two rules govern how the choice is presented. Symmetry of choice means rejecting must be as easy as accepting, so an "Accept All" button paired with a buried settings menu is a violation. Dark patterns that obscure or subvert the choice invalidate any consent obtained.
Sensitive personal information gets a separate control. Under Section 1798.121, consumers can limit its use to what is necessary to provide the requested goods or services. Sensitive categories include Social Security and government ID numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of private communications, genetic and biometric data, and health, sex life, or sexual orientation information.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowPenalties and Enforcement Under California Consumer Protection
Section 1798.155 sets the administrative and civil penalty ceiling: up to $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving the personal information of a consumer under 16. Because penalties are counted per violation and often per affected consumer, aggregate exposure scales quickly.
Section 1798.150 adds a private right of action. If nonencrypted and nonredacted personal information is exposed through a breach caused by failure to maintain reasonable security, consumers can recover statutory damages of $100 to $750 per consumer per incident, or actual damages if greater.
Recent public enforcement shows what regulators actually pursue:
- Sephora, $1.2 million settlement with the Attorney General in 2022, for failing to disclose the sale of personal information and failing to honor Global Privacy Control signals.
- DoorDash, $375,000 settlement in 2024, over disclosure of customer data through a marketing cooperative that the state treated as a sale.
- American Honda, $632,500 in the CPPA's 2025 enforcement order, covering an asymmetric consent flow and excessive verification for opt-out requests.
- Healthline, $1.55 million in 2025, the largest CCPA settlement to date, involving advertising disclosures tied to sensitive health inferences.
The pattern is consistent. Nearly every action involves consent mechanics, opt-out handling, or third-party ad tech, not exotic data misuse.
Building a California Consumer Protection Program
Compliance is a data inventory problem before it is a legal drafting problem. Work in this order:
- Scan your site for cookies, tags, pixels, and third-party scripts. You cannot disclose what you have not inventoried, and most sites carry trackers no one on the team remembers adding.
- Classify the data into the statutory categories, flagging anything that qualifies as sensitive personal information under Section 1798.140(ae).
- Decide, per vendor, whether the transfer is a sale, a share, or a service provider relationship. Service provider status requires a written contract with the restrictions in Section 1798.140(ag), otherwise the transfer is a sale by default.
- Deploy a consent and opt-out mechanism that reads Global Privacy Control, blocks advertising tags for opted-out users, and logs each decision with a timestamp.
- Publish the notice at collection and updated privacy policy, including retention periods and at least two request channels.
- Build the request workflow with verification, deadlines, and a record of responses. Regulators ask for these logs first.
- Re-scan on a schedule. A new marketing tag added in a Tuesday sprint can invalidate Monday's accurate disclosures.
That last step is where manual compliance usually breaks down. Automated platforms such as TermsBox scan a site on a recurring schedule, detect newly added trackers, and flag when hosted policy documents no longer match what the site actually loads.
Common California Consumer Protection Mistakes
- Treating an EU cookie banner as sufficient. The GDPR model is opt-in consent before collection; California's is opt-out plus a homepage link and GPC support. Neither substitutes for the other.
- Ignoring GPC because the banner exists. This was the central failure in the Sephora action and it remains the most common finding.
- Over-verifying opt-out requests. Section 1798.135 and the regulations prohibit requiring account creation or excessive identity proof for an opt-out, which was part of the Honda order.
- Missing service provider contracts. Without the required contractual terms, disclosures to analytics and ad vendors count as sales, which triggers the full opt-out apparatus.
- Forgetting the annual policy refresh. The 12-month update requirement in Section 1798.130(a)(5) is trivially checkable from outside.
- Overlooking pixel-based CIPA claims. Chat widgets, session replay, and conversion pixels have generated more private litigation in California than the CCPA itself.
Also watch the regulatory calendar. The CPPA finalized rules in 2025 covering cybersecurity audits, risk assessments, and automated decisionmaking technology, with phased compliance dates beginning in 2026 and extending into 2027 for larger businesses. If you use automated tools to make significant decisions about consumers, budget time for risk assessment documentation now rather than in the final quarter before your deadline.
Frequently Asked Questions
What laws make up California consumer protection for websites?
The core law is the California Consumer Privacy Act (Civil Code 1798.100 and following), as amended by the California Privacy Rights Act. Websites are also covered by CalOPPA (Business and Professions Code 22575), the Shine the Light law (Civil Code 1798.83), the Unfair Competition Law (Business and Professions Code 17200), and the Automatic Renewal Law for subscription billing.
Does the CCPA apply to businesses outside California?
Yes. The CCPA applies to any for-profit business that does business in California and meets one of the thresholds in Section 1798.140(d), regardless of where the company is headquartered. A company in Texas or Germany selling to California residents is covered if it hits the revenue or data volume threshold.
What are the CCPA thresholds for compliance?
A business must comply if it has more than $25 million in annual gross revenue in the preceding calendar year, buys, sells, or shares the personal information of 100,000 or more California consumers or households, or derives 50 percent or more of annual revenue from selling or sharing personal information. Meeting any one threshold is enough.
What are the penalties for violating California consumer protection laws?
Under Section 1798.155, the California Privacy Protection Agency and the Attorney General can seek up to $2,500 per unintentional violation and $7,500 per intentional violation or violation involving a minor's personal information. Section 1798.150 also allows consumers to sue after certain data breaches for $100 to $750 per consumer per incident.
Do I have to honor the Global Privacy Control signal?
Yes. California regulations at 11 CCR 7025 require businesses that sell or share personal information to treat an opt-out preference signal such as Global Privacy Control as a valid opt-out request. Sephora paid $1.2 million in 2022 largely for failing to honor these signals.
How quickly must I respond to a California consumer rights request?
You must confirm receipt within 10 business days and respond substantively within 45 calendar days under Section 1798.130. You may extend once by another 45 days, for a maximum of 90 days total, if you notify the consumer of the extension and the reason for it.