In short
- The CCPA applies to for-profit businesses that do business in California and meet one of three thresholds. The revenue threshold is now $26,625,000.
- Consumers, including employees and job applicants, can ask to know, delete and correct their personal information, opt out of its sale or sharing, and limit the use of sensitive information.
- Confirm requests within 10 business days and answer within 45 calendar days. Opt-outs must take effect within 15 business days, with no identity verification.
- Browser privacy signals such as Global Privacy Control count as opt-outs. Since January 1, 2026, you must also show the consumer that you honored the signal.
Who the CCPA covers
The CCPA applies to a for-profit entity that does business in California, collects consumers' personal information, and meets at least one of these tests (Civ. Code § 1798.140(d)(1)):
| Test | Threshold |
|---|---|
| Annual gross revenue | Over $26,625,000 in the preceding calendar year (the statutory $25 million, adjusted for inflation on January 1, 2025) |
| Volume of data | Buys, sells or shares the personal information of 100,000 or more consumers or households a year |
| Data revenue | Gets 50% or more of annual revenue from selling or sharing personal information |
The California Privacy Protection Agency, which now calls itself CalPrivacy, must adjust the dollar thresholds for inflation every odd-numbered year (Civ. Code § 1798.199.95(d)). The current figures are on its monetary thresholds page.
Next adjustment: January 1, 2027. Re-check your revenue against the new figure when CalPrivacy publishes it.
A "consumer" is any California resident, including your own employees, job applicants and independent contractors. See Employee data. Health information already governed by HIPAA or California's medical privacy law is exempt, but the other data a healthcare provider holds is not. See Health information.
The rights consumers have
| Right | What it means | Source |
|---|---|---|
| Know / access | The categories of personal information collected, its sources and purposes, who it's disclosed to, and the specific pieces collected. | § 1798.110, § 1798.115 |
| Delete | Deletion of personal information the business collected from the consumer, subject to exceptions. | § 1798.105 |
| Correct | Correction of inaccurate personal information. | § 1798.106 |
| Opt out of sale or sharing | Stop the business from selling personal information or sharing it for cross-context behavioral advertising, at any time. | § 1798.120 |
| Limit sensitive information | Limit the use of sensitive personal information to what's needed to provide the goods or services. | § 1798.121 |
| Portability | Receive access responses in a structured, commonly used, machine-readable format. | § 1798.130(a) |
| No retaliation | No discrimination or retaliation for exercising rights, including against employees, applicants and contractors. | § 1798.125 |
| Automated decisionmaking | Opt out of, and get information about, automated decisionmaking technology used for significant decisions (compliance required from January 1, 2027). | 11 CCR §§ 7221, 7222 |
You must offer at least two ways to submit requests, including a toll-free number. A business that operates only online and has a direct relationship with the consumer may offer just an email address (Civ. Code § 1798.130(a)(1)).
Deadlines for answering requests
| Step | Deadline | Source |
|---|---|---|
| Confirm receipt of a request to know, delete or correct | 10 business days | 11 CCR § 7021(a) |
| Respond to a request to know, delete or correct | 45 calendar days from receipt, extendable once by 45 days with notice | Civ. Code § 1798.130(a)(2); 11 CCR § 7021(b) |
| Stop selling or sharing after an opt-out | As soon as feasible, no later than 15 business days | 11 CCR § 7026(f) |
| Stop non-permitted uses after a request to limit | As soon as feasible, no later than 15 business days | 11 CCR § 7027(g) |
| Ask an opted-out consumer to opt back in | Wait at least 12 months | Civ. Code § 1798.135(c)(4) |
The 45-day clock starts when you receive the request, not when you finish verifying the consumer's identity. The full workflow is in Responding to consumer privacy requests.
Opt-outs, "selling" and "sharing"
"Selling" means making personal information available to a third party for money or other valuable consideration. "Sharing" means making it available for cross-context behavioral advertising, whether or not anything is paid (Civ. Code § 1798.140(ad), (ah)). Advertising pixels and cookies on a website can fall within "sharing."
If you sell or share, the rules are strict:
- A cookie banner alone is not an opt-out method (11 CCR § 7026(a)(4)).
- No identity verification and no account creation for opt-outs. You may ask only for what you need to act on the request (11 CCR §§ 7026(c)–(d), 7060(b)).
- Opt-out preference signals, such as Global Privacy Control, must be treated as a valid opt-out for the browser or device and for the consumer if known (11 CCR § 7025).
- New in 2026: you must display whether you processed the signal as an opt-out, and give consumers a way to confirm that their opt-out or limit request was processed (11 CCR §§ 7025(c)(6), 7026(g), 7027(h)).
See Honoring Global Privacy Control for how this works in practice.
Sensitive personal information
Sensitive personal information includes government ID numbers, account log-ins with passwords, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious beliefs, union membership, message contents, genetic data, neural data (added in 2024), biometric data used to identify someone, health information, and information about sex life or sexual orientation (Civ. Code § 1798.140(ae)). Consumers can limit its use to what is needed to provide the goods or services they asked for (Civ. Code § 1798.121).
Children and teens
If you know a consumer is under 16, you may not sell or share their personal information without opt-in consent: from the teen if aged 13 to 15, or from a parent or guardian if under 13 (Civ. Code § 1798.120(c)). Your privacy policy must say whether you have actual knowledge that you sell or share information of consumers under 16 (11 CCR § 7011(e)(1)).
Enforcement
Both CalPrivacy and the Attorney General enforce the CCPA. Fines are $2,663 per violation and $7,988 per intentional violation or violation involving minors, as adjusted for inflation (Civ. Code § 1798.155(a); § 1798.199.90). The current statute gives businesses no right to cure before a fine. Consumers can sue only over data breaches (see Security).
| Business | Amount | Date | What went wrong |
|---|---|---|---|
| General Motors | $12.75 million | May 8, 2026 | Sold drivers' location and driving data to data brokers. The Attorney General called it the largest CCPA penalty in California history and the first data-minimization case. |
| Disney | $2.75 million | Feb. 11, 2026 | Applied opt-outs, including Global Privacy Control, one device or service at a time, even for logged-in users. |
| Tractor Supply | $1.35 million | Sept. 30, 2025 | Deficient privacy policy, no notice to job applicants, opt-outs and GPC not honored, missing vendor contracts. |
| Healthline Media | $1.55 million | July 1, 2025 | Opt-outs not honored; article titles suggesting medical conditions shared for ad targeting, violating purpose limitation. |
| American Honda | $632,500 | Mar. 12, 2025 | Excessive verification, lopsided privacy choices, burdens on authorized agents, missing ad-tech contracts. |
| Todd Snyder | $345,178 | May 6, 2025 | A misconfigured privacy tool left opt-outs unprocessed for 40 days; required verification for opt-outs. |
The pattern: opt-outs that don't actually work, verification demands that make opt-outs harder, and missing vendor contracts. A third-party privacy tool doesn't move responsibility off the business that uses it.
Checklist
- Check whether you meet a threshold, and re-check when the figures are adjusted in January 2027.Civ. Code § 1798.140(d); § 1798.199.95(d)
- Map what personal information you collect, where it comes from, why, who receives it, and how long you keep it.Civ. Code §§ 1798.100(a), 1798.110
- Offer at least two request methods, and build a workflow that confirms within 10 business days and responds within 45 calendar days.Civ. Code § 1798.130(a); 11 CCR § 7021
- Verify identity in proportion to risk for know, delete and correct requests, and never for opt-outs or requests to limit.11 CCR §§ 7060–7062
- Find out whether your website's pixels and cookies amount to "selling" or "sharing." If they do, post the opt-out link and a working opt-out form.Civ. Code §§ 1798.140(ad), (ah), 1798.135
- Honor Global Privacy Control across the browser, and across the account when you know who the user is. Show that it was honored.11 CCR § 7025(c)
- Stop selling or sharing within 15 business days of an opt-out, and tell downstream third parties.11 CCR § 7026(f)
- Get opt-in consent before selling or sharing information of consumers you know are under 16.Civ. Code § 1798.120(c)
- Test your opt-out tools regularly, including any third-party consent-management platform.CalPrivacy, Todd Snyder decision (2025)
- Put CCPA contract terms in place with every service provider, contractor and third party.Civ. Code § 1798.100(d); 11 CCR §§ 7051, 7053
Guides in this topic
- How-toResponding to consumer privacy requestsStep-by-step CCPA request handling: intake methods, the 10-business-day confirmation, the 45-day response, verification standards, and why opt-outs are different.
- ExplainerHonoring Global Privacy Control and other opt-out signalsCalifornia requires businesses that sell or share personal information to honor Global Privacy Control, display that they did, and apply it across devices for known users.
- Topic guidePrivacy noticesWhat California requires in a privacy policy, notice at collection, Do Not Sell or Share link, Limit link, financial incentive notice, and CalOPPA Do Not Track disclosure.
Official sources
- California Consumer Privacy Act, Civil Code § 1798.100 and following (California Legislative Information)
- CCPA regulations, 11 Cal. Code Regs. § 7000 and following, effective January 1, 2026 (CalPrivacy)
- Monetary thresholds in the CCPA (CalPrivacy)
- 2025 regulations on ADMT, risk assessments and cybersecurity audits (CalPrivacy)
- Privacy enforcement actions (California Attorney General)