California Privacy Law
California has established itself as the national leader in consumer privacy protection. With the California Consumer Privacy Act (CCPA) and its expansion through the California Privacy Rights Act (CPRA), the Golden State offers consumers the strongest privacy rights in the United States. These comprehensive laws fundamentally change how businesses collect, use, and share personal information.
How the CCPA and CPRA Fit Together
California’s framework is one statute in two layers. The California Consumer Privacy Act took effect in 2020. The California Privacy Rights Act, approved by ballot initiative in 2020 and operative from January 2023, amended it rather than replacing it, so the operative text is the CCPA as amended. The CPRA added a right to correct, a new category of sensitive personal information with its own right to limit use, a defined concept of sharing aimed at cross-context behavioural advertising, data minimisation and retention duties, and a dedicated regulator.
That regulator is the California Privacy Protection Agency, the first administrative body in the United States created solely to enforce a consumer privacy law. It holds rulemaking authority and investigative and enforcement powers, exercised alongside the Attorney General rather than instead of them.
Who Is Covered
The statute reaches a for-profit business that does business in California, determines the purposes and means of processing personal information, and meets any one of three thresholds: gross annual revenue over 25 million dollars in the preceding calendar year; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50 per cent or more of annual revenue from selling or sharing personal information. The thresholds are alternatives, so a company well below the revenue figure can be covered on data volume alone.
Two other categories are pulled in by relationship rather than by threshold. An entity controlling or controlled by a covered business and sharing common branding is covered. So is a joint venture or partnership composed of covered businesses. Separately, service providers and contractors take on their own statutory obligations through the contracts that give them that status.
Personal information is defined broadly enough to include device identifiers, IP addresses, browsing history, geolocation, inferences drawn to build a profile, and information about a household rather than a named individual. Publicly available government records and deidentified or aggregated data sit outside the definition, though the standard for deidentification is itself set by the statute.
Consumer Rights and How They Operate
California residents can require a business to disclose the categories and specific pieces of personal information it has collected, the sources, the business or commercial purposes, and the categories of third parties to whom it was disclosed. They can require deletion of information collected from them, subject to nine enumerated exceptions covering matters such as completing a transaction, security incidents, legal compliance and certain internal uses. They can require correction of inaccurate information, and can obtain their data in a portable, readily usable format.
Three rights operate as opt-outs rather than requests for information. A consumer can opt out of the sale or sharing of personal information, can limit the use and disclosure of sensitive personal information to what is necessary to provide the service, and, for consumers under 16, must opt in before any sale or sharing occurs at all, with consumers under 13 requiring parental consent. Finally, a business may not discriminate against a consumer for exercising any of these rights.
The mechanics matter as much as the rights. A business generally has 45 days to respond, extendable once by a further 45 days with notice. It must offer at least two designated methods for submitting requests, and must verify the requester’s identity before disclosing or deleting. It must also honour an opt-out preference signal such as Global Privacy Control transmitted by a browser or device, which means a compliant opt-out link is not sufficient on its own if the signal is being ignored.
What the Statute Requires of Businesses
Transparency duties run from the notice at collection, given at or before the point of collection and stating the categories collected, the purposes, whether the information is sold or shared, and the retention period, through to a privacy policy updated at least every twelve months. Where a business sells or shares personal information it must post a clear and conspicuous Do Not Sell or Share My Personal Information link, and where it processes sensitive personal information beyond permitted purposes, a link to limit that use.
The CPRA added obligations that operate on the data itself rather than on disclosure. Collection, use, retention and sharing must be reasonably necessary and proportionate to the disclosed purpose, and information may not be retained longer than reasonably necessary for that purpose. A business must implement reasonable security procedures appropriate to the nature of the information. Contracts with service providers, contractors and third parties must contain the terms the statute specifies, and without them a transfer may constitute a sale.
Enforcement, and the One Claim Consumers Can Bring
Administrative enforcement runs through the California Privacy Protection Agency and the Attorney General, with civil penalties available per violation and a higher per-violation figure where the violation involves a consumer under 16. The cure period that existed under the original CCPA was removed by the CPRA, so a business is no longer entitled to a fixed window to fix a problem before enforcement can proceed; whether to allow time to cure is now discretionary.
The private right of action is narrow and specific. It applies only to a breach of defined categories of unencrypted and unredacted personal information resulting from a failure to maintain reasonable security. It provides statutory damages per consumer per incident without proof of actual loss, which is why it drives litigation despite its narrow scope. Consumers cannot sue for the other violations in the statute: an ignored access request or a missing opt-out link is a regulator’s matter, not a plaintiff’s.
The Rest of the California Framework
The CCPA is the largest piece but not the only one. The Confidentiality of Medical Information Act governs medical information in the hands of providers and, through later amendments, certain businesses outside the traditional care setting. The Song-Beverly Credit Card Act restricts collecting personal identification information during card transactions. The Shine the Light law gives consumers a right to learn how personal information has been shared with third parties for direct marketing. The state’s breach notification statute, one of the earliest in the country, sets its own notice obligations independent of the CCPA.
The California Age-Appropriate Design Code Act was enacted to impose design and assessment duties on services likely to be accessed by children, and has been the subject of constitutional litigation, so its operative status is best checked against the current record rather than assumed. The Delete Act separately requires data brokers to register with the California Privacy Protection Agency and builds toward a single deletion mechanism covering registered brokers.
Why California Sets the National Baseline
Many businesses apply California’s requirements everywhere rather than maintaining separate treatment by state, because the cost of segmenting behaviour by residence usually exceeds the cost of the stricter rule. That is a commercial decision rather than a legal requirement, and it is the mechanism by which California’s standard became a national floor in practice while remaining a state statute in law.
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- California Consumer Privacy Act, Cal. Civ. Code 1798.100 et seq. statute
- California Privacy Protection Agency, CCPA regulations regulation
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.