CCPA Privacy Policy: California Compliance Guide [2026]
CCPA and CPRA compliance explained: who must comply, the 6 consumer rights, required privacy policy disclosures, and fines up to $7,500 per violation.
Generate a privacy policy in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Is CCPA — and Has It Changed?
The California Consumer Privacy Act (CCPA) went into effect January 1, 2020, giving California residents unprecedented control over their personal data. In November 2020, California voters passed Proposition 24, which created the California Privacy Rights Act (CPRA). The CPRA significantly expanded the CCPA and took full effect on January 1, 2023.
When people say "CCPA compliance" today, they mean the combined CCPA/CPRA framework. This article covers both.
California's law is the strictest consumer privacy regulation in the United States. Unlike federal law in the US — which is fragmented and sector-specific — California's law applies broadly to most consumer-facing businesses that meet the coverage thresholds, regardless of where the business is physically located.
Who Must Comply
You must comply with CCPA/CPRA if your business:
- Does business in California (this includes online businesses that serve California residents), AND
- Meets at least one of these thresholds:
- Annual gross revenue over $25 million
- Buys, sells, or shares personal information of 100,000 or more California consumers or households per year
- Derives 50% or more of annual revenue from selling or sharing consumers' personal information
Most startups and small businesses with fewer than 100,000 California users and under $25M in revenue are not directly covered. But if you work with covered businesses as a vendor or service provider, your contracts will almost certainly include CCPA data protection obligations anyway.
Consumer Rights Under CCPA/CPRA
California law gives consumers six enforceable rights over their personal information:
| Right | What It Means |
|---|---|
| Right to Know | Consumers can request what personal information you've collected, used, shared, or sold — including the categories and specific pieces of data |
| Right to Delete | Consumers can request deletion of their personal information (with some exceptions, like fraud prevention or legal obligations) |
| Right to Correct | Added by CPRA — consumers can request correction of inaccurate personal information you hold |
| Right to Opt Out | Consumers can opt out of the sale or sharing of their personal information for cross-context behavioral advertising |
| Right to Limit Use of Sensitive PI | Consumers can limit how you use and disclose sensitive personal information (e.g., health data, precise geolocation, racial/ethnic origin, financial data) |
| Right to Non-Discrimination | You cannot deny service, charge higher prices, or provide a lower quality of service because a consumer exercised any of these rights |
Response Time Requirements
You must respond to verifiable consumer requests within 45 days. You can extend by an additional 45 days if necessary, but you must notify the consumer within the first 45 days. You cannot charge a fee for requests unless they are manifestly unfounded or excessive.
What Your California Privacy Policy Must Include
Under California Civil Code Section 1798.130, any covered business must maintain a privacy policy that includes:
1. Categories of Personal Information Collected
List each category of personal information you collect. CCPA defines 11 statutory categories, including:
- Identifiers (name, email, IP address, device IDs)
- Commercial information (purchase history, browsing activity)
- Biometric information
- Internet or electronic network activity
- Geolocation data
- Professional or employment information
- Sensitive personal information (health, financial, racial/ethnic origin)
2. Purposes for Collection and Use
Explain the business or commercial purpose for collecting each category of data. Vague purposes like "to improve our services" won't hold up under scrutiny — be specific.
3. Categories of Third Parties You Share Data With
List the types of companies you share personal information with: advertising networks, analytics providers, payment processors, cloud services, marketing platforms, and so on.
4. Consumer Rights and How to Exercise Them
Explain all six consumer rights and provide at least two methods for submitting requests — typically a toll-free phone number and an email address or web form. If your business operates primarily online, a web form with email is generally sufficient.
5. How Long You Retain Personal Information
CPRA requires disclosure of retention periods for each category of personal information, or the criteria used to determine retention periods.
6. "Do Not Sell or Share My Personal Information" Link
If you sell or share personal information (including for cross-context behavioral advertising), you must include a clear and conspicuous link titled "Do Not Sell or Share My Personal Information" in your website footer and in your privacy policy.
This catches many businesses off-guard. Running Meta Pixel for retargeting, using Google Analytics with advertising features, or syncing your customer list with ad platforms likely qualifies as "sharing" under CPRA. The California Attorney General has confirmed this position.
7. Sensitive Personal Information Section
If you collect sensitive personal information — health data, precise geolocation, Social Security numbers, financial account credentials, racial/ethnic origin, union membership, sexual orientation, or biometric data — you need a separate "Limit the Use of My Sensitive Personal Information" link or section, giving consumers the ability to restrict its use to necessary purposes only.
8. "Shine the Light" Notice (California Civil Code Section 1798.83)
Businesses that disclose personal information to third parties for their direct marketing purposes must either provide an opt-out or disclose which third parties received data in the past year. This applies to a broader set of businesses than CCPA.
The Global Privacy Control (GPC) Requirement
Since January 2023, the CPPA has confirmed that covered businesses must honor the Global Privacy Control signal — a browser-level setting that automatically signals a consumer's opt-out preference. If a California consumer's browser sends a GPC signal, you must treat it as a valid opt-out of sale and sharing.
This has real technical implications: your consent management platform (CMP) or cookie consent tool must be configured to detect and respect GPC signals automatically, not just in-session cookie preferences.
Update (July 2026): New Rules for AI and Automated Decision-Making
The CPPA finalized new regulations on automated decision-making technology (ADMT) — the first update to CCPA regulations that specifically targets AI. Compliance is required starting January 1, 2027, so this is worth planning for now, not just noting for later.
The rules apply if your business uses ADMT to make a "significant decision" about a consumer — one affecting access to financial or lending services, housing, healthcare, insurance, education, employment, or independent contracting. That covers a lot of ordinary business tools: AI-based hiring screens, tenant-screening algorithms, and automated credit or pricing decisions all qualify.
If ADMT applies to you, the regulations (11 CCR § 7220 and related sections) require:
- A pre-use notice in plain language, delivered before you collect the data or use it for ADMT — no generic "we use AI to improve your experience" language allowed; the notice has to name the specific decision.
- An opt-out, with at least two easy ways for a consumer to say no to being subject to the ADMT decision.
- A right to access, so consumers can ask how the ADMT reached its decision about them.
- A risk assessment, documenting the ADMT's purpose and privacy risks before deployment.
Most small businesses using off-the-shelf AI tools for hiring or lending screens are covered here — "we didn't build the AI ourselves" isn't an exemption. If any part of your product uses automated scoring or screening for employment, housing, or credit decisions, add an ADMT section to your privacy policy well before the January 1, 2027 deadline.
CCPA vs. GDPR: Key Differences
Many businesses need to comply with both. Here's how they compare on the most important points:
| Topic | CCPA/CPRA | GDPR |
|---|---|---|
| Who it protects | California residents | EU residents |
| Opt-in vs. opt-out | Opt-out model (default is allowed unless consumer objects) | Opt-in for most processing (consent required) |
| Sensitive data | Requires opt-in consent before use for inferring characteristics | Explicit consent or other Article 9 condition required |
| Private right of action | Data breach only | Complaint to supervisory authority; class actions possible |
| Data subject requests | 45 days to respond | 30 days to respond |
| Max penalty | $7,500 per intentional violation | €20M or 4% of global revenue |
| Legal basis required | No — businesses can process most data without a formal basis | Yes — every processing activity needs a documented lawful basis |
If your business serves both EU and California residents, you'll need a privacy policy that satisfies both frameworks. In practice, meeting GDPR's higher standard often covers CCPA requirements, but the CCPA-specific disclosures (opt-out link, sensitive PI section, retention periods) must be added explicitly.
Penalties and Enforcement
Enforcement is handled by two bodies:
- California Attorney General (AG): Can bring civil actions for $2,500 per unintentional violation or $7,500 per intentional violation. Under CPRA, the 30-day cure period was eliminated for most violations after January 1, 2023.
- California Privacy Protection Agency (CPPA): The first dedicated state privacy regulator in the US. The CPPA can independently investigate, issue fines, and audit businesses — including auditing businesses proactively before a complaint is filed.
In 2025 and 2026, the CPPA has focused enforcement on:
- Businesses failing to honor opt-out signals (including GPC)
- Dark patterns in privacy consent flows
- Incomplete or misleading privacy policies
- Failure to establish vendor contracts (Service Provider Agreements) with adequate CCPA protections
Common Mistakes California Businesses Make
- No opt-out link — Running any form of online advertising and not having a "Do Not Sell or Share" link is one of the most common and cited violations.
- Outdated thresholds — Many businesses still reference the old 50,000 consumer threshold; CPRA raised it to 100,000, but the scope of "sharing" also expanded significantly.
- Missing sensitive PI section — If you collect precise geolocation (e.g., for delivery or location-based features), health information, or financial data, you need the separate sensitive PI opt-out.
- Not honoring GPC signals — Technically required since 2023; many CMPs are not correctly configured.
- No vendor agreements — CCPA requires you to have written Service Provider Agreements with any vendor that processes personal information on your behalf. These are California's equivalent of GDPR's Data Processing Agreements.
- Ignoring employee data — Since the CPRA exemptions expired, all California employee data is covered. Employers need compliant employee privacy notices.
Creating a CCPA-Compliant Privacy Policy
Your privacy policy needs to be tailored to your actual data practices — generic templates won't cut it when regulators come knocking. With Pactlio, describe your business, the data you collect, and which jurisdictions you operate in. Our AI generates a privacy policy that addresses your specific circumstances, including the required California disclosures, opt-out language, and sensitive PI provisions.
Create your California-compliant privacy policy →
This article is for informational purposes. Pactlio generates professional drafts for review — not legal advice.
Frequently Asked Questions
Who must comply with CCPA and CPRA?▾
Any for-profit business that does business in California AND meets at least one of three thresholds: annual gross revenue over $25 million; buys, sells, or shares personal information of 100,000 or more California consumers or households per year; or derives 50% or more of annual revenue from selling or sharing consumers' personal information. Non-profits and government entities are generally exempt.
What is the difference between CCPA and CPRA?▾
The CPRA (California Privacy Rights Act) is an amendment that significantly strengthened the original CCPA. It took full effect on January 1, 2023, and raised the data threshold from 50,000 to 100,000 consumers or households, created a new category of 'sensitive personal information' with stricter protections, established the California Privacy Protection Agency (CPPA) as a dedicated regulator, added a 'right to correct' inaccurate data, and extended opt-out rights to data 'sharing' for cross-context behavioral advertising — not just outright 'selling.'
What rights do California consumers have under CCPA/CPRA?▾
California consumers have six core rights: the right to know what personal information a business collects, uses, and discloses; the right to delete that information; the right to correct inaccurate data (added by CPRA); the right to opt out of the sale or sharing of their personal information; the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising any of these rights.
What are the penalties for CCPA violations?▾
The California Attorney General can impose civil penalties of $2,500 per unintentional violation and $7,500 per intentional violation. In cases of data breaches involving unencrypted personal information, consumers also have a private right of action for statutory damages between $100 and $750 per consumer per incident, or actual damages if higher. The CPPA can now initiate enforcement independently, without a 30-day cure period.
Does CCPA apply to employee and B2B data?▾
Yes — since January 1, 2023, the employee and B2B exemptions expired under CPRA. Employees, job applicants, contractors, and business contact information are all fully covered under CCPA/CPRA. Employers doing business in California must now provide CCPA-compliant notices to employees and honor their data rights.
Do I need a 'Do Not Sell or Share' link if I use Google Analytics or Meta Pixel?▾
Likely yes. The CPRA extended opt-out rights to cover 'sharing' for cross-context behavioral advertising, which includes sharing data with ad networks and analytics platforms for targeted advertising. If you use Google Analytics with advertising features enabled, run retargeting campaigns, or use Meta Pixel, you almost certainly need a 'Do Not Sell or Share My Personal Information' link.
Does CCPA regulate AI and automated decision-making?▾
Yes. New CPPA regulations on automated decision-making technology (ADMT) require compliance starting January 1, 2027. If you use ADMT to make a 'significant decision' about a consumer — covering employment, lending, housing, healthcare, education, or insurance — you must give a pre-use notice, offer an opt-out, and let consumers access how the ADMT reached its decision. Most small businesses using off-the-shelf AI tools for these purposes are covered.