California Consumer Privacy Act is the California state law (in force since 2020, expanded by the CPRA in 2023) granting consumers rights over the personal information businesses collect about them.
The California Consumer Privacy Act (CCPA) was enacted in 2018 and took effect on 1 January 2020, codified at California Civil Code sections 1798.100 et seq. It was substantially expanded by the California Privacy Rights Act (CPRA, Proposition 24, 2020), which fully took effect on 1 January 2023 and created the California Privacy Protection Agency (CPPA) as a dedicated regulator.
CCPA/CPRA gives California residents the right to know what personal information a business collects, the right to delete, the right to correct, the right to opt out of sale or sharing for cross-context behavioural advertising, the right to limit use of sensitive personal information, and the right to non-discrimination for exercising any of those rights.
A business is in scope if it does business in California and meets one of three thresholds: annual gross revenue over 25 million USD, buys or sells the personal information of 100,000 or more California consumers or households per year, or derives 50 percent or more of annual revenue from selling or sharing personal information.
You will encounter CCPA when your website or product reaches California consumers and you cross any of the three thresholds. Practical artefacts include the Do Not Sell or Share My Personal Information link, an opt-out signal handler (Global Privacy Control / GPC), a privacy notice with the 12 prescribed disclosures, and a verified consumer-request workflow.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.