State of California Consumer Protection Laws: A 2026 Guide
Understand state of California consumer protection laws, from CCPA and CPRA privacy rights to the UCL and CLRA. Learn who must comply and how enforcement works.
The state of California consumer protection framework is the most demanding in the United States, and it reaches far beyond California's borders. If your business collects personal information from California residents, sells products online, or runs advertising that touches Californians, several overlapping laws likely apply to you. This guide covers what those laws require, who they cover, and how enforcement actually works, though you should consult a qualified attorney for advice tailored to your specific situation.
What State of California Consumer Protection Law Covers
California consumer protection is not a single statute. It is a layered system of privacy, advertising, contract, and fair-dealing laws that regulators enforce through separate channels.
The core pillars are:
- California Consumer Privacy Act (CCPA), Civil Code Section 1798.100 and following, as amended by the California Privacy Rights Act (CPRA). Governs personal information collection, sale, sharing, and consumer rights.
- Unfair Competition Law (UCL), Business and Professions Code Section 17200. Prohibits any unlawful, unfair, or fraudulent business act or practice.
- False Advertising Law (FAL), Business and Professions Code Section 17500. Prohibits untrue or misleading statements in advertising.
- Consumers Legal Remedies Act (CLRA), Civil Code Section 1750. Bans a specific list of 27 deceptive practices in consumer transactions.
- California Online Privacy Protection Act (CalOPPA), Business and Professions Code Section 22575. Requires a conspicuous privacy policy on any commercial website that collects personally identifiable information from California residents.
- Automatic Renewal Law (ARL), Business and Professions Code Section 17600. Governs subscription sign-up, disclosure, and cancellation.
The practical takeaway: a business can be fully CCPA compliant and still face a UCL claim, because the two laws regulate different conduct. CCPA governs how you handle data. The UCL governs whether your business practices are honest.
Who Must Comply With California Consumer Protection Rules
Coverage differs by statute, and this trips up most businesses. Being exempt from one law does not mean you are exempt from the others.
CCPA Thresholds
The CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing personal information, and meets at least one of these thresholds:
- Annual gross revenue exceeding $25 million in the preceding calendar year.
- Buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually.
- Deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information.
Note the second threshold counts households and devices, not just individual named people. A mid-sized publisher with heavy ad-tech integration can cross 100,000 far faster than its headcount suggests.
CalOPPA Applies to Almost Everyone
CalOPPA has no revenue or volume threshold. Any commercial website or online service that collects personally identifiable information from California consumers must post a conspicuous privacy policy. A three-person business with a contact form falls under CalOPPA even though the CCPA does not touch it.
Geographic Reach
None of these laws are limited to California-based companies. A Berlin SaaS vendor with California customers and a Miami e-commerce store shipping to Los Angeles are both within scope. The test is whether you do business in California, not where your servers or offices sit.
Consumer Privacy Rights Under California Law
The CCPA as amended by the CPRA grants California residents a defined set of rights. Your business must be able to receive, verify, and fulfill each of them.
- Right to know (Section 1798.100 and 1798.110): categories and specific pieces of personal information collected, sources, business purposes, and third parties it was disclosed to, covering the 12 months preceding the request.
- Right to delete (Section 1798.105): deletion of personal information you collected from the consumer, subject to nine enumerated exceptions such as completing a transaction or complying with a legal obligation.
- Right to correct (Section 1798.106): correction of inaccurate personal information, added by the CPRA.
- Right to opt out of sale or sharing (Section 1798.120): including cross-context behavioral advertising, which the CPRA brought within scope even when no money changes hands.
- Right to limit use of sensitive personal information (Section 1798.121): applies to data such as precise geolocation, racial or ethnic origin, biometric data, and contents of private communications.
- Right to non-discrimination (Section 1798.125): you cannot deny goods, charge different prices, or provide a different quality of service because someone exercised a right.
- Right to opt out of automated decision-making: covered by CPPA regulations finalized in 2025, with compliance obligations phasing in for businesses using automated decision-making technology in significant decisions.
Requests must go through at least two designated methods, one of which is a toll-free number for businesses that operate offline. Online-only businesses with a direct consumer relationship may offer an email address instead.
Notice and Disclosure Requirements
California consumer protection law is built on disclosure. Most enforcement actions start with a gap between what a company said and what it actually did.
Notice at Collection
Under Section 1798.100(a), you must inform consumers at or before the point of collection about the categories of personal information collected, the purposes for use, whether it is sold or shared, and the retention period for each category. Retention disclosure is a CPRA addition that many older privacy policies still fail to include.
Privacy Policy Contents
Your privacy policy must be updated at least every 12 months and must include:
- Descriptions of each consumer right and how to exercise it.
- Categories of personal information collected, sold, shared, and disclosed in the preceding 12 months.
- Categories of sources and categories of third-party recipients.
- Business or commercial purposes for collecting, selling, or sharing.
- Retention periods, or the criteria used to determine them.
- Contact information for privacy questions.
If you sell or share personal information, you must also post a clear Do Not Sell or Share My Personal Information link on your homepage, plus a Limit the Use of My Sensitive Personal Information link where applicable. A single combined link is permitted if it takes the consumer to a page covering both. A privacy policy generator that builds CCPA-specific sections saves you from assembling these disclosures by hand, and our guide to CCPA requirements walks through the underlying obligations in more depth.
Global Privacy Control
CPPA regulations require businesses that sell or share personal information to honor opt-out preference signals such as Global Privacy Control (GPC) sent by a consumer's browser. Treating GPC as a valid opt-out is mandatory, not optional, and the California Attorney General has made it a specific enforcement focus.
Enforcement Bodies and How Cases Begin
Understanding who enforces what tells you where risk actually comes from.
| Body | Laws Enforced | Typical Action |
|---|---|---|
| California Attorney General | CCPA, UCL, FAL, CLRA, CalOPPA | Investigative sweeps, civil penalty suits, injunctions |
| California Privacy Protection Agency (CPPA) | CCPA and CPRA regulations | Administrative enforcement, rulemaking, audits |
| Department of Financial Protection and Innovation | California Consumer Financial Protection Law | Financial products and services oversight |
| District attorneys and city attorneys | UCL, FAL | Local civil penalty actions |
| Private plaintiffs | CLRA, CCPA Section 1798.150 | Class actions, statutory damages |
The Attorney General runs periodic enforcement sweeps focused on specific sectors. Past sweeps have targeted connected TV streaming services, mobile apps, online retailers, and employers handling employee data. A sweep typically opens with a letter identifying alleged deficiencies and requesting a response.
Since the CPRA removed the mandatory 30-day cure period as of January 2023, there is no automatic right to fix a violation before penalties attach. Regulators may still consider a good-faith cure, but they are not required to.
Penalties and Financial Exposure
Penalties stack across statutes, and the per-violation structure is what makes California exposure large.
- CCPA (Section 1798.155): up to $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving the personal information of a consumer under 16. Each affected consumer can count as a separate violation.
- CCPA private right of action (Section 1798.150): $100 to $750 per consumer per incident, or actual damages if greater, for breaches of nonencrypted and nonredacted personal information caused by failure to maintain reasonable security.
- UCL (Section 17206): up to $2,500 per violation, with an enhanced penalty of up to $2,500 per violation for conduct targeting senior citizens or people with disabilities under Section 17206.1.
- False Advertising Law (Section 17536): up to $2,500 per violation.
- CLRA (Section 1780): actual damages with a $1,000 statutory minimum per plaintiff, punitive damages, and attorney's fees, plus a $5,000 additional award available for senior or disabled plaintiffs.
Real enforcement shows the scale. Sephora paid $1.2 million in 2022 for failing to disclose sales of personal information and failing to honor GPC signals. DoorDash settled for $375,000 in 2024 over a marketing cooperative that constituted an undisclosed sale. Healthline agreed to a $1.55 million settlement in 2025, the largest CCPA penalty at the time, involving sharing of sensitive health-related data.
Advertising, Pricing, and Subscription Rules
Privacy attracts the headlines, but California's older consumer protection statutes generate a steady volume of claims against online businesses.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowAutomatic Renewal Law
The ARL, strengthened by AB 2863 with obligations effective in 2025, requires you to:
- Present automatic renewal terms clearly and conspicuously before obtaining payment authorization.
- Obtain affirmative consent to the renewal terms specifically, not bundled with other terms.
- Send an acknowledgment with the renewal terms and cancellation policy in a retainable form.
- Provide a cancellation method that is at least as easy as the sign-up method, including online cancellation for online sign-ups.
- Send advance renewal reminders for longer-term or free-trial-converted subscriptions.
Failure means the goods or services may be treated as an unconditional gift under Civil Code Section 1584.5, which is why ARL claims are attractive to class-action plaintiffs.
Deceptive Practices Under the CLRA
The CLRA lists specific prohibited acts, including misrepresenting the source or characteristics of goods, advertising goods with intent not to sell them as advertised, and representing that a transaction confers rights or obligations it does not. Drip pricing, where mandatory fees appear only at checkout, became explicitly unlawful under SB 478, which took effect on July 1, 2024. Advertised prices must include all mandatory fees other than government taxes and shipping.
Building a California Compliance Program
Compliance is an operational problem more than a drafting problem. Documents that describe practices you do not actually follow create liability rather than reducing it.
A workable sequence:
- Inventory your data. Map every category of personal information, its source, purpose, recipients, and retention period. You cannot write an accurate notice at collection without this.
- Scan your website for trackers. Identify every cookie, pixel, and third-party script. Ad-tech and analytics tags are the most common source of undisclosed sharing, and they change without notice when marketing teams add tools.
- Classify sensitive personal information. Precise geolocation, health inferences, and account credentials trigger the right to limit, which requires its own link and workflow.
- Write disclosures that match reality. Update the privacy policy, notice at collection, and any employee or job applicant notices.
- Build request intake and verification. Two methods minimum, with a documented verification standard and a tracked 45-day clock.
- Honor GPC at the technical level. Test that the signal actually suppresses your advertising tags, not just that a banner state changes.
- Review vendor contracts. Service provider and contractor agreements need the specific terms in Section 1798.100(d), or the transfer counts as a sale.
- Re-audit at least annually. Tracker inventories drift. Undisclosed sharing appears when someone installs a new tag.
Steps two and eight are where automation helps most. TermsBox runs scheduled compliance scans that detect new cookies and third-party services on your site and flag when your published documents no longer match what your site actually loads.
Common Compliance Failures
The patterns behind California enforcement actions repeat, and most are avoidable.
- Treating advertising cookies as not a sale. Under the CPRA's sharing definition, passing identifiers to an ad network for cross-context behavioral advertising is covered even without payment. This was the core of the Sephora action.
- Ignoring GPC signals. A visible banner is not enough if the browser-level signal is not processed.
- Missing the retention disclosure. Many policies drafted before the CPRA still omit retention periods per category.
- Applying opt-outs to the website only. The opt-out must propagate to offline systems, CRMs, and downstream recipients.
- Forgetting employees and job applicants. The B2B and HR exemptions expired on January 1, 2023. Employee and applicant data is fully covered.
- Cancellation friction. Requiring a phone call to cancel a subscription bought online violates the ARL.
- Stale policies. The 12-month update requirement in Section 1798.130(a)(5) is explicit and easy for a regulator to check.
How California Compares to Other US State Laws
California set the template, but nearly 20 states now have comprehensive privacy laws. Building for California generally gets you most of the way to the others, with important exceptions.
| Feature | California (CCPA/CPRA) | Typical other state law |
|---|---|---|
| Consent model | Opt-out of sale and sharing | Opt-out of sale and targeted advertising |
| Private right of action | Yes, for security breaches | Almost always none |
| Dedicated regulator | Yes, the CPPA | No, attorney general only |
| Employee and B2B data | Covered | Generally excluded |
| Sensitive data | Right to limit use | Usually opt-in consent required |
| Cure period | None since January 2023 | Often 30 to 60 days, some sunsetting |
Two structural differences matter most. California is the only state covering employee and business contact data under its comprehensive privacy law, and it is the only one with a standalone privacy agency issuing detailed regulations. If you operate nationally, California is the correct baseline. For a fuller comparison with European rules, see our breakdown of CCPA vs GDPR.
Frequently Asked Questions
What agency handles consumer protection in California?
Consumer protection in California is enforced by several bodies. The California Attorney General's Consumer Protection Section enforces the Unfair Competition Law and the Consumers Legal Remedies Act, while the California Privacy Protection Agency (CPPA) enforces the CCPA as amended by the CPRA. The Department of Financial Protection and Innovation handles financial products and services.
Does California consumer protection law apply to businesses outside California?
Yes. The CCPA applies to any for-profit business that does business in California and meets one of its thresholds, regardless of where the business is physically located. A company headquartered in Texas or Germany that sells to California residents and hits the revenue or data volume threshold must comply.
What are the penalties for violating California consumer protection laws?
Under CCPA Section 1798.155, penalties are up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a minor under 16. Separately, California's Unfair Competition Law (Business and Professions Code Section 17200) allows civil penalties of up to $2,500 per violation, and CCPA Section 1798.150 gives consumers a private right of action for certain data breaches at $100 to $750 per consumer per incident.
Do small businesses have to comply with the CCPA?
Not automatically. The CCPA applies only to for-profit businesses that meet one of three thresholds: over $25 million in annual gross revenue, buying or selling the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Businesses below all three thresholds are exempt from the CCPA, though other laws such as CalOPPA still apply.
What is the difference between the CCPA and the CPRA?
The CPRA is not a separate law but an amendment that expanded the CCPA. Passed as Proposition 24 in 2020 and fully operative since January 2023, it added the right to correct and the right to limit use of sensitive personal information, created the sharing concept for cross-context behavioral advertising, and established the California Privacy Protection Agency as a dedicated enforcement body.
How long do businesses have to respond to a California consumer rights request?
Under CCPA Section 1798.130, businesses must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days. That window can be extended once by an additional 45 days if the business notifies the consumer of the extension and the reason for it.