CCPA
Contents
1. What is CCPA?
The California Consumer Privacy Act (CCPA) is a state privacy law introduced on 1 January 2020. The Act grants California residents rights over their personal information (PI). In order to do so, it imposes obligations on companies which collect and/or process individuals’ PI.
In comparison to GDPR, the Controller and Processor terminology is replaced by ‘Business’ and ‘Service Provider’. E.g If you collect PI in California to send a newsletter you are the Business and an email sender is the Service Provider.
Users are also referred to as ‘Consumers’.
2. Does CCPA apply to you?
To determine if the CCPA applies to your company you must consider:
Does your company collect the personal information (PI) of California residents OR do business in California?
Is your company a for-profit business?
Note that, ‘doing business’ should be interpreted broadly; operating a website accessible to California residents or offering goods to Californians is included.
If the answer to both the above questions is yes, your company may be subject to CCPA. You must consider if it meets one or more of the following thresholds:
Annual gross revenue in excess of $25 million; or
Processes the personal information of 100,000 or more California residents/ households; or
Derives 50% or more of annual revenue from selling or sharing personal information
If your business meets any of these criteria, it is subject to CCPA. You must ensure it remains compliant with the requirements of the CCPA in order to avoid severe penalties.
If however, it is not possible to determine if your business meets one of the criteria in Step 2, you should assume CCPA is applicable to your business.
3. What counts as PI?
The CCPA understands personal information (PI) to be any information that identifies or can be reasonably linked to a particular individual or household (unless a specific statutory exception applies). It is important to note that information can be PI even if it is not tied to a named individual, but rather to a specific family or residence, understood as a ‘household’.
However, unlike GDPR, information is not considered PI if it is publicly available.
4. CCPA data subject rights
Californian consumers have six key data subject rights under the CCPA.
These are:
Right to know
Consumers can request disclosure of:
the PI collected about them, including specific PI
categories of data sources
purposes for collecting, processing or sharing PI
categories of third parties the business shares PI with
categories of PI disclosed to those third parties.
Right to delete
Consumers can request deletion of most PI collected about them, subject to certain exceptions such as legal obligations.
Right to opt out of sale or sharing
Consumers can request that a business stop selling or sharing their PI.
Right to non-discrimination
Consumers cannot be treated differently for choosing to exercise their rights under the CCPA.
Right to correct
Consumers may request correction of inaccurate PI held about them.
Right to limit use and sharing of sensitive PI
Consumers can require businesses to restrict the use and sharing of sensitive PI for limited purposes. Sensitive PI can include precise geolocation, genetic data, or financial account information.
5. What are the penalties for non-compliance?
Fines reach $2,500 for each unintentional violation and up to $7,500 for each intentional violation. However, each affected customer counts as a separate violation, so fines increase rapidly. In 2025, Healthline Media faced a fine of $1.55 million for failing to allow consumers to opt out of targeted advertising and for sharing sensitive health PI with third parties without the protections required under the CCPA.
Significant reputational damage can also occur through CCPA non-compliance; customers and investors may lose trust in your company. Furthermore, if your business chooses not to put in the measures necessary to be CCPA compliant, you risk the loss of business and profits resulting from the lack of access to the Californian market.
6. A basic CCPA compliance checklist
Opt-out Procedures
Consumer Transparency
Publish a comprehensive privacy policy in an accessible location such as on your business website
Secure processes (portals/ phone lines) where consumers can easily access, delete or correct PI. Also where they can retroactively opt out of sale.
Including, maintenance of at least two methods for consumers to submit data subject access requests
Respond to consumer requests within 45 days
Keep records of these consumer requests for 2 years
Third Party PI Monitoring
Communicate your business incentives for sharing consumer PI with third parties
Make sure that contracts with third parties require them to also comply with CCPA
Appointing a Privacy Partner
Assists with all of the above and more.
Last updated

