CCPA FAQ: California Privacy Questions Answered

Quick, direct answers to the most common CCPA and CPRA questions: who must comply, consumer rights, opt-out rules, fines, and more.


by Riad Us Salehin • 12 July 2026


The CCPA (California Consumer Privacy Act) gives California residents rights over the personal information businesses collect about them. It applies to any for-profit business that meets one of three thresholds, regardless of where that business is located.

This FAQ answers the questions site owners, agencies, and small businesses ask most. That means who must comply, what rights consumers have, how opt-out and Do Not Sell work, and what a violation costs. Each answer links to a deeper guide for the full breakdown.

CCPA Basics

The CCPA is California's core consumer privacy law, amended and expanded by the CPRA. It remains active and enforced in 2026.

What is the CCPA?

The CCPA (California Consumer Privacy Act) is a California law that gives California residents rights over the personal information businesses collect about them. It took effect on January 1, 2020. The CPRA (the California Privacy Rights Act) later amended and expanded it, adding new categories of protected data and a dedicated enforcement agency. See what the California Consumer Privacy Act covers for the full picture.

What is the CPRA, and how is it different from the CCPA?

The CPRA (Proposition 24, passed in November 2020) amended the CCPA rather than replacing it. It added sensitive personal information protections, a data-broker registry, and the California Privacy Protection Agency (CPPA) as a dedicated enforcer. Those amendments took full effect on January 1, 2023. See how the CPRA changed the CCPA for the complete comparison.

Is the CCPA still in effect in 2026?

Yes. The CCPA is active and enforced, and its CPRA amendments have applied since January 1, 2023. New regulations covering cybersecurity audits, risk assessments, and automated decision-making technology are phasing in through 2026 to 2028. They add to the existing law rather than replace it.

Does the CCPA apply to cookies and website tracking?

Yes, when cookies, pixels, or trackers sell or share personal information, which is common with advertising and analytics tools. California law defines personal information broadly enough to include persistent identifiers like cookies and mobile ad IDs. That triggers the CCPA's Do Not Sell or Share opt-out requirement.

Who Has to Comply With the CCPA?

Three thresholds determine CCPA coverage. They cover annual revenue, the volume of California consumer data a business handles, and the share of revenue tied to selling or sharing that data.

Who does the CCPA apply to?

The CCPA applies to for-profit businesses doing business in California that meet at least one of these thresholds:

  • Annual gross revenue over $26.625 million
  • Buying, selling, or sharing the data of 100,000 or more California consumers or households
  • Earning 50% or more of annual revenue from selling or sharing personal information
The three CCPA applicability thresholds: revenue, consumer volume, and data-sale revenue share

Meeting just one threshold is enough. See the full CCPA business checklist for every requirement once you're covered.

Does the CCPA apply to businesses outside California?

Yes. Out-of-state and international businesses must comply if they meet a threshold and handle California residents' personal information. Location does not exempt a business; what counts is whether it transacts with California residents and crosses one of the three thresholds above.

Does the CCPA apply to small businesses?

Only if a small business meets one of the three thresholds. Many small businesses fall below all three and are exempt. Running heavy advertising or analytics can cross the 100,000-consumer threshold faster than expected, even for a business with modest revenue.

What counts as "selling" personal information under the CCPA?

Broadly more than most businesses expect. "Selling" and "sharing" under the CCPA cover disclosing personal information for monetary or other value, including cross-context behavioral advertising. Uploading a customer list to an ad platform can count as a sale, and so can running standard analytics. No money needs to change hands. This is the single biggest misconception businesses have about the law.

Does the CCPA apply to nonprofits and government agencies?

Generally, no. Nonprofits and government agencies are not "businesses" under the CCPA's definition, which requires operating for the profit or financial benefit of shareholders. The exception is a nonprofit that is controlled by, or shares common branding with, a covered for-profit business.

Consumer Rights and Data Requests

California consumers hold six specific rights under the CCPA. Businesses must respond to consumer requests within a fixed window.

What rights do consumers have under the CCPA?

California consumers have six rights under the CCPA:

  • Know what personal information is collected
  • Delete that information
  • Correct inaccuracies
  • Opt out of its sale or sharing
  • Limit use of sensitive personal information
  • Receive equal treatment for exercising any of these rights
The six CCPA consumer rights, from the right to know to non-discrimination

Businesses cannot charge different prices or provide worse service because a consumer exercised a right. Get a full walkthrough of the six CCPA consumer rights.

How long does a business have to respond to a CCPA request?

A business has 45 days from receipt to respond to a consumer request. That window is extendable once by another 45 days, for a total of 90 days, as long as the business notifies the consumer. Businesses may verify the requester's identity before acting, but cannot use that information for anything else. Follow our guide to handling a CCPA request for the full response workflow.

What is a CCPA data subject request?

A CCPA data subject request, also called a consumer request, is how a California resident exercises a right under the law. It asks a business to disclose, delete, or correct the personal information it holds about them. It can arrive by web form, toll-free number, or another method the business designates. See data subject requests explained for how requests work end to end.

How does a business respond to a CCPA deletion request?

To respond to a deletion request: verify the requester's identity, then locate their personal information across every system and service provider that holds it. Delete it, subject to legal exceptions like completing a transaction or complying with another law, and confirm completion within the 45-day window.

Do Not Sell, Opt-Out, and Cookie Banners

The CCPA runs on an opt-out model. Businesses may process personal information by default until a consumer actively opts out of its sale or sharing.

What is the "Do Not Sell or Share My Personal Information" requirement?

Businesses that sell or share personal information must post a clear "Do Not Sell or Share My Personal Information" link. That link lets California consumers opt out. It is the CCPA's core mechanism for giving consumers control over their data without requiring upfront consent. Set up the Do Not Sell or Share opt-out correctly on your site.

Does the CCPA require an opt-out instead of an opt-in?

Yes. The CCPA uses an opt-out model, unlike the GDPR's opt-in approach. A business may process personal information by default until a California consumer actively opts out of its sale or sharing. That is one of the sharpest differences between US and EU privacy law. See how the CCPA and GDPR compare on opt-out versus opt-in consent.

Does the CCPA require honoring Global Privacy Control (GPC)?

Yes. California law requires covered businesses to honor opt-out preference signals like Global Privacy Control (GPC). A browser-level GPC signal counts as a valid request to stop selling or sharing personal information.

Under law, it must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information.

That is the California Attorney General's office stating the requirement directly. Read Global Privacy Control to understand how the signal works.

Does the CCPA require a cookie banner?

Not a specific banner format. Cookies that sell or share personal information still trigger the requirement to offer a Do Not Sell or Share opt-out on the site. Most businesses meet this requirement with a consent banner. It delivers the opt-out link and records the visitor's choice in one place. See how to add a CCPA-ready consent banner to your site.

Fines, Penalties, and Enforcement

CCPA penalties stack per violation and per affected consumer, with no overall cap. Exposure grows fast with the size of the affected population.

What are the fines and penalties for violating the CCPA?

The statutory base is $2,500 per violation, adjusted for inflation to $2,663 per violation effective January 1, 2025. Intentional violations, or ones involving a consumer the business knows is under 16, carry a statutory base of $7,500, adjusted to $7,988. These inflation-adjusted figures were set by the California Privacy Protection Agency. Because they apply per violation and per affected consumer, totals can climb into the millions for a mass incident. See CCPA fines and penalties in detail.

Can consumers sue a business under the CCPA?

Only for data breaches. The CCPA's private right of action lets consumers recover statutory damages of $100 to $750 per consumer per incident, or actual damages if higher. This applies when unencrypted personal information is exposed because a business failed to maintain reasonable security. Consumers cannot sue over most other CCPA violations.

Who enforces the CCPA?

The California Privacy Protection Agency (CPPA) and the California Attorney General both enforce the CCPA. The CPPA, created by the CPRA, has moved toward more active enforcement and audits in recent years, alongside its existing rulemaking role. See examples of recent CCPA enforcement.

CCPA vs Other Privacy Laws

California started the wave of US state privacy laws. The CCPA differs from the GDPR on consent model, scope, and penalty structure.

What is the difference between the CCPA and the GDPR?

The GDPR is an EU law that requires opt-in consent before processing any personal data. It applies to any organization worldwide handling EU residents' data. The CCPA is a California law that uses an opt-out model and applies only to for-profit businesses meeting its revenue or data-volume thresholds. GDPR penalties can reach €20 million or 4% of global annual revenue, whichever is higher, well above CCPA's per-violation civil penalties.

What other US states have privacy laws like the CCPA?

California started the wave. Nineteen states now have comprehensive consumer privacy laws, including Virginia's CDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, and Texas's TDPSA. Each law sets its own thresholds, consumer rights, and enforcement mechanisms, so CCPA compliance does not automatically satisfy the others. Explore the US state privacy law map for the full state-by-state breakdown.

What is personal information under the CCPA?

Personal information under the CCPA is any data that identifies, relates to, or could reasonably be linked to a California consumer or household. That includes identifiers, browsing history, geolocation, and inferences drawn from other data. Sensitive personal information, a CPRA-added category, carries extra protections and a separate right to limit its use. See how personal information is defined for the complete category list.

Complying With the CCPA

Practical CCPA compliance combines required disclosures, an opt-out mechanism, and a process for handling consumer requests on time.

How do I make my website CCPA compliant?

To make a website CCPA compliant:

  • Post a notice at collection describing what personal information you gather and why
  • Add a Do Not Sell or Share opt-out link
  • Honor Global Privacy Control signals automatically
  • Respond to consumer requests within 45 days

A consent management tool automates most of this instead of building it by hand.

What are the CCPA's requirements for businesses?

Covered businesses must provide a notice at collection and honor all six consumer rights. They must also offer a Do Not Sell or Share opt-out, honor opt-out preference signals like GPC, and maintain reasonable security for personal information. Missing any one of these is a common source of enforcement actions.

What is the best software for CCPA compliance?

The best CCPA compliance software automates the Do Not Sell or Share opt-out, displays a US-specific opt-out banner, and logs consent without charging per domain. Compare the best consent tools for US privacy to see how the leading consent management platforms stack up on price and feature depth.

Have there been any CCPA enforcement actions?

Yes. California has brought settlements against companies for missing Do Not Sell links and for ignoring consumer opt-out signals. The CPPA continues to investigate new cases.

CCPA Compliance Without the Hassle

Getting every one of these obligations right by hand is where most small teams lose time. Opt-out signals and a live Do Not Sell link are the two most commonly missed.

Set up CCPA-ready consent with Consently for a US opt-out template, cookie scanning, and consent logging on every plan, with no per-domain pricing.

AUTHOR

Riad Us Salehin is the content lead at Dorik. He is a passionate content creator who lets the work speak for itself. Focused on taking brands and causes to the next level.

Read More

Subscribe to Consently
Newsletter

Subscribe to our newsletter to stay updated with latest articles from our blog.