Retail & E-commerce Privacy Law
Retailers collect browsing behavior, purchase history, payment details and delivery addresses, and several bodies of law reach that data at once. This guide describes when state consumer privacy statutes apply to a retailer, how sale and sharing are defined, the rules on loyalty programs, tracking technology, marketing messages and breaches, each by the terms of the law itself.
When a Retailer Falls Under the CCPA
The California Consumer Privacy Act applies to a for-profit business doing business in California that meets any one of three thresholds: gross annual revenue over 25 million dollars; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50 per cent or more of annual revenue from selling or sharing personal information. The thresholds are alternatives, not cumulative, so a mid-sized retailer with heavy advertising integration can be covered on the second or third limb while sitting well below the revenue figure.
Personal information is defined expansively as information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household. That includes device identifiers, IP addresses, browsing history and inferences drawn to create a profile. A separate category of sensitive personal information, covering precise geolocation, racial or ethnic origin, contents of communications and similar data, carries an additional right to limit use.
Other states have their own comprehensive statutes with different thresholds and different exemptions, so applicability is a state-by-state question rather than a single determination. The rights they grant are broadly similar; the mechanics of who is covered are not.
Sale, Share and Why the Contract Decides
The statute defines a sale broadly: disclosing personal information to another business or third party for monetary or other valuable consideration. Sharing is a separate defined term covering disclosure for cross-context behavioural advertising, whether or not money changes hands. Between them these definitions capture a large amount of routine adtech activity that no one involved would describe as selling data.
The exclusion that matters is the service provider relationship. A disclosure to a service provider or contractor under a compliant written contract is neither a sale nor a share. The contract must specify the limited purposes, prohibit retention, use or disclosure outside those purposes, prohibit combining the information with data from other sources except in permitted circumstances, and grant rights to monitor compliance. Where those terms are absent, the same data flow that would have been exempt becomes a sale, and the opt-out obligations attach to it.
Opt-Out Mechanics
A business that sells or shares personal information must provide a clear and conspicuous link titled Do Not Sell or Share My Personal Information, and a separate link to limit the use of sensitive personal information, or a single combined link. It must also treat an opt-out preference signal transmitted by a browser or device, such as Global Privacy Control, as a valid request from that consumer, which means the obligation cannot be satisfied by a link alone if the signal is being ignored.
The regulations issued by the California Privacy Protection Agency constrain how choices are collected. A method designed with the substantial effect of subverting or impairing a consumer’s autonomy, decision-making or choice is a dark pattern, and consent obtained through one is not consent. Symmetry is the operative test: accepting and declining must take a comparable number of steps and comparable prominence.
Loyalty Programs and Financial Incentives
Loyalty programs sit inside the statute’s financial incentive provisions rather than outside the regime. A business may offer a different price, rate, level or quality of goods or services in exchange for personal information, provided it gives notice of the incentive’s material terms, obtains opt-in consent that the consumer may revoke at any time, and can show that the difference is reasonably related to the value the data provides to the business. The statute separately prohibits discriminating against a consumer for exercising a privacy right, and the line between a permitted incentive and prohibited discrimination is drawn by that value calculation, which has to be documented rather than asserted.
Tracking Technology and Private Litigation
The most active area of retail privacy litigation does not run on privacy statutes at all. Plaintiffs have applied older laws to modern tracking: the Video Privacy Protection Act at 18 U.S.C. 2710, drafted for videotape rental records, has been used against pixels on pages containing video content; state wiretapping and session-recording statutes have been used against chat tools, session replay and analytics that transmit page activity to a third party in real time.
What makes these claims commercially serious is the remedy rather than the theory. Several carry statutory damages per violation and a private right of action, which converts a technical configuration decision into class exposure without any regulator becoming involved. The defences are fact-specific and turn on questions such as whether the recipient was a party to the communication and whether disclosure and consent were adequate at the point of collection.
Advertising, Email and Telephone Rules
Marketing carries its own regime independent of the privacy statutes. CAN-SPAM governs commercial email, requiring accurate header and subject information, identification of the message as an advertisement, a valid physical postal address, a functioning opt-out honoured within ten business days, and responsibility that cannot be delegated away to an agency. The Telephone Consumer Protection Act governs calls and texts, requires prior express written consent for marketing messages sent using regulated technology, and carries statutory damages per message.
Section 5 of the FTC Act sits above all of it, prohibiting unfair or deceptive acts and practices. In privacy matters the Commission has applied it where a privacy policy did not match actual practice, where security representations were unsupported, and where a data practice caused substantial injury consumers could not reasonably avoid, none of which requires a specific privacy statute to be in play.
Breach Obligations
All fifty states have breach notification statutes, and they differ on the definition of personal information, the trigger for notice, the deadline, whether the attorney general must be told and at what threshold, and whether a risk-of-harm analysis can excuse notice. A retailer with customers in multiple states is complying with several of these at once for a single incident.
California adds a private right of action for a breach of defined categories of personal information resulting from a failure to maintain reasonable security, with statutory damages available without proof of actual loss. That is the only part of the CCPA a consumer can enforce directly, and it is the reason security programme documentation is generally treated as litigation material rather than as compliance paperwork.
Frequently Asked Questions
Does the CCPA apply to my store?
It applies to a for-profit business doing business in California that meets any one of three thresholds: gross annual revenue over 25 million dollars; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50 percent or more of annual revenue from selling or sharing personal information.
What counts as selling personal information?
The statute defines a sale broadly as disclosing personal information to another business or a third party for monetary or other valuable consideration. Disclosures to a service provider under a compliant contract are excluded, which is why the contract terms decide whether a data flow is a sale.
Do I have to honour browser opt-out signals?
California requires a business to treat an opt-out preference signal, such as Global Privacy Control, as a valid request to opt out of the sale and sharing of personal information sent from that browser or device.
Are loyalty programs still allowed?
The CCPA permits financial incentives for the collection of personal information, but requires notice of the incentive, opt-in consent, a right to withdraw at any time, and that any difference in price or service be reasonably related to the value the data provides to the business.
Why are tracking pixels a litigation risk?
Plaintiffs have applied older statutes to them, including the Video Privacy Protection Act at 18 U.S.C. 2710 and state wiretapping and session-recording laws, where a pixel or replay tool transmits user activity to a third party without disclosure.
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- California Consumer Privacy Act, Cal. Civ. Code 1798.100 et seq. statute
- California Privacy Protection Agency, CCPA regulations regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
- FTC cases and proceedings enforcement action
- 18 U.S.C. 2710 — Video Privacy Protection Act statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.