TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. State of California Consumer Protection Laws: A 2026 Guide
CCPA

State of California Consumer Protection Laws: A 2026 Guide

Understand state of California consumer protection laws, from CCPA and CPRA privacy rights to the UCL and CLRA. Learn who must comply and how enforcement works.

TermsBox Team|July 26, 202614 min read

The state of California consumer protection framework is the most demanding in the United States, and it reaches far beyond California's borders. If your business collects personal information from California residents, sells products online, or runs advertising that touches Californians, several overlapping laws likely apply to you. This guide covers what those laws require, who they cover, and how enforcement actually works, though you should consult a qualified attorney for advice tailored to your specific situation.

What State of California Consumer Protection Law Covers

California consumer protection is not a single statute. It is a layered system of privacy, advertising, contract, and fair-dealing laws that regulators enforce through separate channels.

The core pillars are:

  • California Consumer Privacy Act (CCPA), Civil Code Section 1798.100 and following, as amended by the California Privacy Rights Act (CPRA). Governs personal information collection, sale, sharing, and consumer rights.
  • Unfair Competition Law (UCL), Business and Professions Code Section 17200. Prohibits any unlawful, unfair, or fraudulent business act or practice.
  • False Advertising Law (FAL), Business and Professions Code Section 17500. Prohibits untrue or misleading statements in advertising.
  • Consumers Legal Remedies Act (CLRA), Civil Code Section 1750. Bans a specific list of 27 deceptive practices in consumer transactions.
  • California Online Privacy Protection Act (CalOPPA), Business and Professions Code Section 22575. Requires a conspicuous privacy policy on any commercial website that collects personally identifiable information from California residents.
  • Automatic Renewal Law (ARL), Business and Professions Code Section 17600. Governs subscription sign-up, disclosure, and cancellation.

The practical takeaway: a business can be fully CCPA compliant and still face a UCL claim, because the two laws regulate different conduct. CCPA governs how you handle data. The UCL governs whether your business practices are honest.

Who Must Comply With California Consumer Protection Rules

Coverage differs by statute, and this trips up most businesses. Being exempt from one law does not mean you are exempt from the others.

CCPA Thresholds

The CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing personal information, and meets at least one of these thresholds:

  1. Annual gross revenue exceeding $25 million in the preceding calendar year.
  2. Buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually.
  3. Deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information.

Note the second threshold counts households and devices, not just individual named people. A mid-sized publisher with heavy ad-tech integration can cross 100,000 far faster than its headcount suggests.

CalOPPA Applies to Almost Everyone

CalOPPA has no revenue or volume threshold. Any commercial website or online service that collects personally identifiable information from California consumers must post a conspicuous privacy policy. A three-person business with a contact form falls under CalOPPA even though the CCPA does not touch it.

Geographic Reach

None of these laws are limited to California-based companies. A Berlin SaaS vendor with California customers and a Miami e-commerce store shipping to Los Angeles are both within scope. The test is whether you do business in California, not where your servers or offices sit.

Consumer Privacy Rights Under California Law

The CCPA as amended by the CPRA grants California residents a defined set of rights. Your business must be able to receive, verify, and fulfill each of them.

  • Right to know (Section 1798.100 and 1798.110): categories and specific pieces of personal information collected, sources, business purposes, and third parties it was disclosed to, covering the 12 months preceding the request.
  • Right to delete (Section 1798.105): deletion of personal information you collected from the consumer, subject to nine enumerated exceptions such as completing a transaction or complying with a legal obligation.
  • Right to correct (Section 1798.106): correction of inaccurate personal information, added by the CPRA.
  • Right to opt out of sale or sharing (Section 1798.120): including cross-context behavioral advertising, which the CPRA brought within scope even when no money changes hands.
  • Right to limit use of sensitive personal information (Section 1798.121): applies to data such as precise geolocation, racial or ethnic origin, biometric data, and contents of private communications.
  • Right to non-discrimination (Section 1798.125): you cannot deny goods, charge different prices, or provide a different quality of service because someone exercised a right.
  • Right to opt out of automated decision-making: covered by CPPA regulations finalized in 2025, with compliance obligations phasing in for businesses using automated decision-making technology in significant decisions.

Requests must go through at least two designated methods, one of which is a toll-free number for businesses that operate offline. Online-only businesses with a direct consumer relationship may offer an email address instead.

Notice and Disclosure Requirements

California consumer protection law is built on disclosure. Most enforcement actions start with a gap between what a company said and what it actually did.

Notice at Collection

Under Section 1798.100(a), you must inform consumers at or before the point of collection about the categories of personal information collected, the purposes for use, whether it is sold or shared, and the retention period for each category. Retention disclosure is a CPRA addition that many older privacy policies still fail to include.

Privacy Policy Contents

Your privacy policy must be updated at least every 12 months and must include:

  • Descriptions of each consumer right and how to exercise it.
  • Categories of personal information collected, sold, shared, and disclosed in the preceding 12 months.
  • Categories of sources and categories of third-party recipients.
  • Business or commercial purposes for collecting, selling, or sharing.
  • Retention periods, or the criteria used to determine them.
  • Contact information for privacy questions.

If you sell or share personal information, you must also post a clear Do Not Sell or Share My Personal Information link on your homepage, plus a Limit the Use of My Sensitive Personal Information link where applicable. A single combined link is permitted if it takes the consumer to a page covering both. A privacy policy generator that builds CCPA-specific sections saves you from assembling these disclosures by hand, and our guide to CCPA requirements walks through the underlying obligations in more depth.

Global Privacy Control

CPPA regulations require businesses that sell or share personal information to honor opt-out preference signals such as Global Privacy Control (GPC) sent by a consumer's browser. Treating GPC as a valid opt-out is mandatory, not optional, and the California Attorney General has made it a specific enforcement focus.

Enforcement Bodies and How Cases Begin

Understanding who enforces what tells you where risk actually comes from.

Body Laws Enforced Typical Action
California Attorney General CCPA, UCL, FAL, CLRA, CalOPPA Investigative sweeps, civil penalty suits, injunctions
California Privacy Protection Agency (CPPA) CCPA and CPRA regulations Administrative enforcement, rulemaking, audits
Department of Financial Protection and Innovation California Consumer Financial Protection Law Financial products and services oversight
District attorneys and city attorneys UCL, FAL Local civil penalty actions
Private plaintiffs CLRA, CCPA Section 1798.150 Class actions, statutory damages

The Attorney General runs periodic enforcement sweeps focused on specific sectors. Past sweeps have targeted connected TV streaming services, mobile apps, online retailers, and employers handling employee data. A sweep typically opens with a letter identifying alleged deficiencies and requesting a response.

Since the CPRA removed the mandatory 30-day cure period as of January 2023, there is no automatic right to fix a violation before penalties attach. Regulators may still consider a good-faith cure, but they are not required to.

Penalties and Financial Exposure

Penalties stack across statutes, and the per-violation structure is what makes California exposure large.

  • CCPA (Section 1798.155): up to $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving the personal information of a consumer under 16. Each affected consumer can count as a separate violation.
  • CCPA private right of action (Section 1798.150): $100 to $750 per consumer per incident, or actual damages if greater, for breaches of nonencrypted and nonredacted personal information caused by failure to maintain reasonable security.
  • UCL (Section 17206): up to $2,500 per violation, with an enhanced penalty of up to $2,500 per violation for conduct targeting senior citizens or people with disabilities under Section 17206.1.
  • False Advertising Law (Section 17536): up to $2,500 per violation.
  • CLRA (Section 1780): actual damages with a $1,000 statutory minimum per plaintiff, punitive damages, and attorney's fees, plus a $5,000 additional award available for senior or disabled plaintiffs.

Real enforcement shows the scale. Sephora paid $1.2 million in 2022 for failing to disclose sales of personal information and failing to honor GPC signals. DoorDash settled for $375,000 in 2024 over a marketing cooperative that constituted an undisclosed sale. Healthline agreed to a $1.55 million settlement in 2025, the largest CCPA penalty at the time, involving sharing of sensitive health-related data.

Advertising, Pricing, and Subscription Rules

Privacy attracts the headlines, but California's older consumer protection statutes generate a steady volume of claims against online businesses.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

Automatic Renewal Law

The ARL, strengthened by AB 2863 with obligations effective in 2025, requires you to:

  1. Present automatic renewal terms clearly and conspicuously before obtaining payment authorization.
  2. Obtain affirmative consent to the renewal terms specifically, not bundled with other terms.
  3. Send an acknowledgment with the renewal terms and cancellation policy in a retainable form.
  4. Provide a cancellation method that is at least as easy as the sign-up method, including online cancellation for online sign-ups.
  5. Send advance renewal reminders for longer-term or free-trial-converted subscriptions.

Failure means the goods or services may be treated as an unconditional gift under Civil Code Section 1584.5, which is why ARL claims are attractive to class-action plaintiffs.

Deceptive Practices Under the CLRA

The CLRA lists specific prohibited acts, including misrepresenting the source or characteristics of goods, advertising goods with intent not to sell them as advertised, and representing that a transaction confers rights or obligations it does not. Drip pricing, where mandatory fees appear only at checkout, became explicitly unlawful under SB 478, which took effect on July 1, 2024. Advertised prices must include all mandatory fees other than government taxes and shipping.

Building a California Compliance Program

Compliance is an operational problem more than a drafting problem. Documents that describe practices you do not actually follow create liability rather than reducing it.

A workable sequence:

  1. Inventory your data. Map every category of personal information, its source, purpose, recipients, and retention period. You cannot write an accurate notice at collection without this.
  2. Scan your website for trackers. Identify every cookie, pixel, and third-party script. Ad-tech and analytics tags are the most common source of undisclosed sharing, and they change without notice when marketing teams add tools.
  3. Classify sensitive personal information. Precise geolocation, health inferences, and account credentials trigger the right to limit, which requires its own link and workflow.
  4. Write disclosures that match reality. Update the privacy policy, notice at collection, and any employee or job applicant notices.
  5. Build request intake and verification. Two methods minimum, with a documented verification standard and a tracked 45-day clock.
  6. Honor GPC at the technical level. Test that the signal actually suppresses your advertising tags, not just that a banner state changes.
  7. Review vendor contracts. Service provider and contractor agreements need the specific terms in Section 1798.100(d), or the transfer counts as a sale.
  8. Re-audit at least annually. Tracker inventories drift. Undisclosed sharing appears when someone installs a new tag.

Steps two and eight are where automation helps most. TermsBox runs scheduled compliance scans that detect new cookies and third-party services on your site and flag when your published documents no longer match what your site actually loads.

Common Compliance Failures

The patterns behind California enforcement actions repeat, and most are avoidable.

  • Treating advertising cookies as not a sale. Under the CPRA's sharing definition, passing identifiers to an ad network for cross-context behavioral advertising is covered even without payment. This was the core of the Sephora action.
  • Ignoring GPC signals. A visible banner is not enough if the browser-level signal is not processed.
  • Missing the retention disclosure. Many policies drafted before the CPRA still omit retention periods per category.
  • Applying opt-outs to the website only. The opt-out must propagate to offline systems, CRMs, and downstream recipients.
  • Forgetting employees and job applicants. The B2B and HR exemptions expired on January 1, 2023. Employee and applicant data is fully covered.
  • Cancellation friction. Requiring a phone call to cancel a subscription bought online violates the ARL.
  • Stale policies. The 12-month update requirement in Section 1798.130(a)(5) is explicit and easy for a regulator to check.

How California Compares to Other US State Laws

California set the template, but nearly 20 states now have comprehensive privacy laws. Building for California generally gets you most of the way to the others, with important exceptions.

Feature California (CCPA/CPRA) Typical other state law
Consent model Opt-out of sale and sharing Opt-out of sale and targeted advertising
Private right of action Yes, for security breaches Almost always none
Dedicated regulator Yes, the CPPA No, attorney general only
Employee and B2B data Covered Generally excluded
Sensitive data Right to limit use Usually opt-in consent required
Cure period None since January 2023 Often 30 to 60 days, some sunsetting

Two structural differences matter most. California is the only state covering employee and business contact data under its comprehensive privacy law, and it is the only one with a standalone privacy agency issuing detailed regulations. If you operate nationally, California is the correct baseline. For a fuller comparison with European rules, see our breakdown of CCPA vs GDPR.

Frequently Asked Questions

What agency handles consumer protection in California?

Consumer protection in California is enforced by several bodies. The California Attorney General's Consumer Protection Section enforces the Unfair Competition Law and the Consumers Legal Remedies Act, while the California Privacy Protection Agency (CPPA) enforces the CCPA as amended by the CPRA. The Department of Financial Protection and Innovation handles financial products and services.

Does California consumer protection law apply to businesses outside California?

Yes. The CCPA applies to any for-profit business that does business in California and meets one of its thresholds, regardless of where the business is physically located. A company headquartered in Texas or Germany that sells to California residents and hits the revenue or data volume threshold must comply.

What are the penalties for violating California consumer protection laws?

Under CCPA Section 1798.155, penalties are up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a minor under 16. Separately, California's Unfair Competition Law (Business and Professions Code Section 17200) allows civil penalties of up to $2,500 per violation, and CCPA Section 1798.150 gives consumers a private right of action for certain data breaches at $100 to $750 per consumer per incident.

Do small businesses have to comply with the CCPA?

Not automatically. The CCPA applies only to for-profit businesses that meet one of three thresholds: over $25 million in annual gross revenue, buying or selling the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Businesses below all three thresholds are exempt from the CCPA, though other laws such as CalOPPA still apply.

What is the difference between the CCPA and the CPRA?

The CPRA is not a separate law but an amendment that expanded the CCPA. Passed as Proposition 24 in 2020 and fully operative since January 2023, it added the right to correct and the right to limit use of sensitive personal information, created the sharing concept for cross-context behavioral advertising, and established the California Privacy Protection Agency as a dedicated enforcement body.

How long do businesses have to respond to a California consumer rights request?

Under CCPA Section 1798.130, businesses must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days. That window can be extended once by an additional 45 days if the business notifies the consumer of the extension and the reason for it.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

CCPA

California Consumer Protection: What Websites Must Do in 2026

California consumer protection laws set strict rules for websites. Learn the CCPA thresholds, consumer rights, opt-out duties, and penalties you must meet.

July 26, 202612 min read
CCPA

California Consumer Rights: A Complete CCPA and CPRA Guide

A practical guide to California consumer rights under the CCPA and CPRA. Learn the seven rights, response deadlines, opt-out signals, and penalties.

July 26, 202615 min read
CCPA

CCPA Requirements: Complete Compliance Guide for Businesses

Understand the CCPA requirements that apply to your business, including thresholds, consumer rights, notice obligations, opt-out links, and penalties.

July 24, 202615 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What State of California Consumer Protection Law Covers
  • Who Must Comply With California Consumer Protection Rules
  • CCPA Thresholds
  • CalOPPA Applies to Almost Everyone
  • Geographic Reach
  • Consumer Privacy Rights Under California Law
  • Notice and Disclosure Requirements
  • Notice at Collection
  • Privacy Policy Contents
  • Global Privacy Control
  • Enforcement Bodies and How Cases Begin
  • Penalties and Financial Exposure
  • Advertising, Pricing, and Subscription Rules
  • Automatic Renewal Law
  • Deceptive Practices Under the CLRA
  • Building a California Compliance Program
  • Common Compliance Failures
  • How California Compares to Other US State Laws
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.