CCPA Requirements: Complete Compliance Guide for Businesses
Understand the CCPA requirements that apply to your business, including thresholds, consumer rights, notice obligations, opt-out links, and penalties.
If your website collects data from California residents, the CCPA requirements may apply to you even if your business has never set foot in the state. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), sets out specific obligations around notice, consumer rights, opt-out mechanisms, and vendor contracts. This guide breaks down each requirement, who it applies to, and what compliance actually looks like in practice. It is educational rather than legal advice, so consult a qualified privacy attorney for guidance specific to your business.
What the CCPA Is and Who It Covers
The California Consumer Privacy Act is a state privacy law that gives California residents the right to know what personal information businesses collect about them, to delete it, to correct it, and to opt out of its sale or sharing. It took effect on January 1, 2020, and was substantially expanded by the CPRA, whose provisions became fully enforceable on January 1, 2023.
The law does not apply to every company. Under Section 1798.140(d), a business falls under the CCPA if it is for-profit, does business in California, determines the purposes and means of processing personal information, and meets at least one of these thresholds:
- Annual gross revenue above $25 million in the preceding calendar year.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households annually.
- Derives 50 percent or more of annual revenue from selling or sharing personal information.
Your physical location is irrelevant. A SaaS company in Berlin with 120,000 California users meets the second threshold and carries the same CCPA requirements as a company headquartered in San Francisco.
The Threshold That Catches People Off Guard
The 100,000 consumer threshold is the one most businesses misjudge. It counts consumers and households whose personal information you collect, and personal information includes IP addresses, device identifiers, and cookie IDs. A content site with 100,000 unique California visitors a year can trigger the CCPA without processing a single payment.
Two entities also inherit obligations without meeting a threshold themselves: any entity that controls or is controlled by a qualifying business and shares common branding, and any joint venture where a qualifying business holds at least 40 percent.
CCPA Requirements for Notice and Disclosure
Notice is where most CCPA enforcement begins because it is the easiest thing for a regulator to check from the outside. The law requires several distinct notices, and combining them all into one buried paragraph does not satisfy the requirement.
Notice at collection must appear at or before the point where you collect personal information, under Section 1798.100(a). It must list the categories of personal information collected, the purposes for each category, whether that information is sold or shared, and how long you retain each category. For a website, this typically means a banner or a conspicuous link near forms, plus the full detail in your privacy policy.
The privacy policy itself carries the heaviest disclosure burden under Section 1798.130(a)(5). It must be updated at least every 12 months and must describe:
- The categories of personal information collected in the preceding 12 months.
- The categories of sources from which the information was collected.
- The business or commercial purpose for collecting, selling, or sharing it.
- The categories of third parties to whom you disclose personal information.
- The specific categories sold or shared, and the categories disclosed for a business purpose.
- Each consumer right under the law and at least two methods for submitting requests.
- Retention periods for each category, or the criteria used to determine them.
Notice of right to opt out is required if you sell or share personal information, and notice of financial incentive is required if you offer discounts or loyalty benefits in exchange for data. Building these disclosures correctly is the main reason to use a privacy policy generator that maps output to actual CCPA sections rather than a generic template.
The 12 Month Lookback
Every category disclosure covers the preceding 12 months, which means your privacy policy is a rolling document, not a one-time artifact. If you added a new analytics vendor six months ago, that vendor's category of data and the purpose of the disclosure belong in your current policy.
Consumer Rights You Must Honor
The CCPA grants California residents seven rights. Each one carries operational requirements, not just a paragraph in your policy.
- Right to know (Section 1798.110): consumers can request the categories and specific pieces of personal information you have collected, the sources, the purposes, and the third parties involved.
- Right to delete (Section 1798.105): consumers can request deletion of personal information you collected from them, subject to nine statutory exceptions including completing a transaction, security, legal compliance, and internal uses reasonably aligned with consumer expectations.
- Right to correct (Section 1798.106): added by the CPRA, this lets consumers fix inaccurate personal information.
- Right to opt out of sale or sharing (Section 1798.120): consumers can direct you to stop selling or sharing their data, including for cross-context behavioral advertising.
- Right to limit use of sensitive personal information (Section 1798.121): consumers can restrict use of data such as precise geolocation, racial or ethnic origin, contents of messages, and biometric identifiers to what is necessary to provide the service.
- Right to non-discrimination (Section 1798.125): you cannot deny goods, charge different prices, or provide a different quality of service because someone exercised a right, unless the difference is reasonably related to the value the data provides.
- Right to data portability (Section 1798.100): consumers who request their information in an electronic format must receive it in a readily usable, portable form.
Request Handling Timelines
Timelines are a hard CCPA requirement and a common failure point. Under Section 1798.130, you must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days. You may extend once by an additional 45 days, giving you 90 days total, but only if you notify the consumer of the extension and the reason within the original window.
You must provide at least two designated methods for submitting requests, including a toll-free telephone number, unless you operate exclusively online and have a direct relationship with the consumer, in which case an email address is sufficient. Opt-out requests specifically must be honored within 15 business days, and you must notify third parties who received the data in the preceding 90 days.
Do Not Sell or Share Requirements
If you sell or share personal information, you must post a clear and conspicuous link titled "Do Not Sell or Share My Personal Information" on your homepage, per Section 1798.135. The link must lead to a page where the consumer can exercise the opt-out without creating an account.
The definitions matter more than most businesses expect. "Sale" under Section 1798.140(ad) means disclosing personal information to a third party for monetary or other valuable consideration. "Sharing" under Section 1798.140(ah) means disclosing personal information for cross-context behavioral advertising, whether or not money changes hands.
That second definition sweeps in ordinary advertising tooling. If your site runs the Meta Pixel, Google Ads remarketing tags, or TikTok's pixel, you are almost certainly sharing personal information and need the opt-out link. A useful first step is running a scan of your own site to inventory which third-party scripts actually fire, because most site owners underestimate the count by a wide margin.
Global Privacy Control
California regulations require businesses to honor opt-out preference signals, and the Global Privacy Control (GPC) is the recognized implementation. When a browser sends a GPC signal, you must treat it as a valid opt-out request for that consumer, with no separate confirmation step.
The California Attorney General has enforced this directly. The 2022 settlement with Sephora included a $1.2 million penalty, driven in part by the company's failure to process GPC signals and its failure to disclose that it sold personal information. Your consent banner and tag manager need to read the signal and suppress advertising tags accordingly.
CCPA Requirements for Sensitive Personal Information
The CPRA created a distinct category with its own CCPA requirements. Sensitive personal information under Section 1798.140(ae) includes:
- Social Security, driver's license, state ID, and passport numbers.
- Account log-in, financial account, debit, or credit card numbers combined with access credentials.
- Precise geolocation, meaning within a radius of 1,850 feet.
- Racial or ethnic origin, religious or philosophical beliefs, or union membership.
- The contents of mail, email, and text messages where you are not the intended recipient.
- Genetic data, biometric data used for unique identification, health data, and data about sex life or sexual orientation.
If you use this data beyond what is necessary to deliver the requested service, you must post a "Limit the Use of My Sensitive Personal Information" link and honor those requests. The two required links can be combined into a single "Your Privacy Choices" link with the standard California opt-out icon.
CCPA Requirements for Vendors and Contracts
The CCPA imposes contractual obligations that live outside your website entirely. Under Section 1798.100(d), every contract with a service provider, contractor, or third party that receives personal information must include specific terms.
Required contract terms include:
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate Now- Specification of the limited and specified purposes for which the data is disclosed.
- A prohibition on selling or sharing the personal information.
- A prohibition on retaining, using, or disclosing the data outside the business relationship.
- An obligation to comply with the CCPA and provide the same level of privacy protection.
- A grant of rights to take reasonable and appropriate steps to stop and remediate unauthorized use.
- An obligation to notify you if the vendor can no longer meet its obligations.
Without these terms, a disclosure to a vendor can be reclassified as a sale, which pulls you into opt-out obligations you thought you had avoided. Audit your data processing agreements with analytics providers, email platforms, CRMs, and advertising networks against this list.
Data Minimization and Retention
Section 1798.100(c) requires that collection, use, retention, and sharing be reasonably necessary and proportionate to the disclosed purpose. This is a substantive limit, not a disclosure obligation. Collecting date of birth for a newsletter signup fails the proportionality test regardless of what your policy says.
You must also disclose retention periods per category, or the criteria used to set them. Indefinite retention is not a defensible answer.
Penalties and Enforcement
Enforcement comes from two directions. The California Attorney General and the California Privacy Protection Agency (CPPA) can pursue administrative and civil penalties under Section 1798.155 of up to $2,500 per unintentional violation and up to $7,500 per intentional violation or any violation involving a consumer under 16 years old. Penalties are counted per consumer affected, so a single misconfigured tag across a large user base compounds fast.
Consumers hold a private right of action under Section 1798.150, but only for data breaches involving nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security. Statutory damages run $100 to $750 per consumer per incident, or actual damages if higher.
The 30-day cure period that existed under the original CCPA was removed by the CPRA effective January 1, 2023. Regulators are no longer obligated to give you a chance to fix a violation before assessing penalties. Recent enforcement has focused on advertising technology, opt-out mechanisms that do not work, and privacy policies that misstate data practices.
A Practical CCPA Compliance Checklist
Turning the statute into action is mostly a sequencing problem. Work through these steps in order:
- Confirm applicability. Check your revenue, your California consumer count including web visitors, and your revenue mix from data. Document the analysis so you can show your reasoning later.
- Inventory your data. Map what personal information you collect, the sources, the purposes, where it is stored, who receives it, and how long you keep it.
- Scan your website. Identify every cookie, pixel, and third-party script actually running. This tells you whether you sell or share data.
- Classify sensitive data. Flag anything in the Section 1798.140(ae) list and determine whether your use exceeds what is necessary.
- Update your privacy policy. Include all category disclosures, retention periods, consumer rights, and request methods. Date it and recommit to a 12 month review.
- Build the opt-out path. Post the required links, make the opt-out work without an account, and configure your consent tooling to read GPC signals.
- Stand up a request workflow. Define verification steps, assign an owner, and track the 10 day acknowledgment and 45 day response clocks.
- Fix your contracts. Add the required CCPA terms to every vendor agreement covering personal information.
- Train your team. Anyone handling consumer inquiries must know how to recognize and route a rights request.
- Monitor for change. New tools add new trackers. Re-scan on a schedule rather than after an incident.
Platforms like TermsBox automate the scanning, consent banner, and document sides of this list, with policies that update when the scanner detects a new tracker on your site. The contract and workflow items still need a human owner inside your business.
How the CCPA Compares to Other Privacy Laws
Understanding where CCPA requirements diverge from other regimes prevents both over-compliance and gaps.
| Aspect | CCPA / CPRA | GDPR |
|---|---|---|
| Consent model | Opt out of sale or sharing | Opt in before processing |
| Who is protected | California residents | Individuals in the EU and EEA |
| Applicability test | Revenue and volume thresholds | Any processing of EU personal data |
| Max regulatory penalty | $7,500 per intentional violation | 20 million EUR or 4 percent of global turnover |
| Individual lawsuits | Data breaches only | Broad right to compensation |
| Regulator | California AG and CPPA | National DPAs such as the ICO, CNIL, and DPC |
More than a dozen other US states, including Virginia, Colorado, Connecticut, Texas, and Oregon, have passed comprehensive privacy laws with overlapping but distinct requirements. Most follow an opt-out structure closer to the CCPA than to the GDPR. A privacy policy built to satisfy both the CCPA and the GDPR covers the substantial majority of state law obligations, and the GDPR and CCPA comparison goes deeper on where the two frameworks pull in different directions.
Frequently Asked Questions
Who has to comply with the CCPA?
The CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds under Section 1798.140(d): over $25 million in annual gross revenue, buying or selling the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Location does not matter, so a company based in Texas or Germany can fall under the CCPA if it meets a threshold and targets California residents.
Does the CCPA apply to small businesses?
Most small businesses fall outside the CCPA because they do not meet any of the three thresholds in Section 1798.140(d). The trap is the 100,000 consumer threshold, which counts unique California visitors whose data you collect through cookies and trackers, not just paying customers. A content site with heavy California traffic can cross that line without ever selling a product.
What is the difference between the CCPA and the CPRA?
The CPRA is an amendment that expanded the CCPA rather than a separate law, and its provisions have been fully enforceable since January 1, 2023. It added the category of sensitive personal information, created rights to correction and to limit use of sensitive data, extended the law to employee and B2B contacts, and established the California Privacy Protection Agency as a dedicated regulator.
Do I need a Do Not Sell My Personal Information link?
You need one only if you sell or share personal information as those terms are defined in Section 1798.140, and sharing includes disclosing data for cross-context behavioral advertising. If you run advertising pixels such as Meta Pixel or Google Ads remarketing, you almost certainly share data and must post a clear and conspicuous Do Not Sell or Share My Personal Information link on your homepage.
What are the penalties for violating the CCPA?
The California Attorney General and the California Privacy Protection Agency can seek civil penalties of up to $2,500 per unintentional violation and $7,500 per intentional violation or violation involving a minor under Section 1798.155. Consumers also have a private right of action for breaches of unencrypted personal information under Section 1798.150, with statutory damages of $100 to $750 per consumer per incident.
How long do I have to respond to a CCPA consumer request?
You must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days under Section 1798.130. You may extend once by another 45 days, for 90 days total, if you notify the consumer of the extension and the reason within the initial period.