California Consumer Privacy Act, as amended by the CPRA
The duties of the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the CPPA's regulations, expressed as controls. Each cites the Civil Code section or regulation it derives from. Employee and business-contact data are in scope.
California Privacy Protection Agency (CPPA) and the California Attorney General · Cal. Civ. Code §1798.100 et seq. (CPRA amendments in force since 1 January 2023); CCPA Regulations, Cal. Code Regs. tit. 11, §7000 et seq., including the risk-assessment, cybersecurity-audit and ADMT rules effective 1 January 2026 · United States — California residents' personal information; applies to for-profit businesses meeting any threshold: annual gross revenue over $26,625,000 (2025–2026 CPI adjustment), buying/selling/sharing personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing · Official source
At or before the point of collection, the business informs consumers of the categories of personal information (and sensitive personal information) collected, the purposes for which each is collected or used, whether it is sold or shared, and how long each category will be retained — and does not collect additional categories or use them for incompatible purposes without notice.
Collection, use, retention and sharing of personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection, and not further processed incompatibly.
Any sale, sharing or disclosure of personal information to a third party, service provider or contractor for a business purpose is made under an agreement that specifies the limited purposes, obliges the recipient to comply with the CCPA and provide the same level of protection, grants the business rights to take reasonable steps to ensure compliance and to stop unauthorised use, and requires notice if the recipient can no longer comply.
The business implements reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorised or illegal access, destruction, use, modification or disclosure. Consumers whose non-encrypted and non-redacted personal information is breached as a result of a failure to do so may sue for statutory damages.
Consumers may request deletion of personal information the business collected from them. The business deletes it from its records, notifies its service providers and contractors to delete, and notifies third parties to which it sold or shared the information — unless an exception in 1798.105(d) applies.
Consumers may request correction of inaccurate personal information, and the business uses commercially reasonable efforts to correct it, taking into account the nature and purposes of the information.
Consumers may request the categories and specific pieces of personal information collected, the categories of sources, the business or commercial purposes, and the categories of third parties to whom it is disclosed, sold or shared — covering the preceding 12 months, and further back for information collected since 1 January 2022 unless impossible or disproportionate.
Consumers may direct a business that sells personal information or shares it for cross-context behavioural advertising to stop, and the business must honour the opt-out and not ask again for at least 12 months. A business that does not sell or share must say so.
A business with actual knowledge that a consumer is under 16 may not sell or share their personal information unless the consumer (aged 13–15) or a parent or guardian (under 13) has affirmatively authorised it; wilfully disregarding age counts as actual knowledge.
Where a business uses or discloses sensitive personal information (such as SSN, account log-in with credentials, precise geolocation, racial or ethnic origin, health, sex life, biometric data, or contents of communications) for purposes beyond those permitted by regulation, consumers may direct it to limit that use.
Consumers may not be discriminated against — through denial of goods, different prices or quality — for exercising their rights. Any financial incentive or price difference tied to personal information requires a notice of financial incentive, opt-in consent that can be revoked, and a good-faith estimate of the value of the data.
The business offers two or more designated methods for submitting requests to know, delete and correct — including at minimum a toll-free number (online-only businesses with a direct relationship may offer only an email address) — verifies requests, and responds within 45 calendar days, extendable once by 45 days with notice.
The online privacy policy describes consumers' rights and how to exercise them, the categories of personal information collected, sources, purposes, categories disclosed, sold or shared and to whom, and retention — and is updated at least once every 12 months.
All individuals responsible for handling consumer inquiries about the business's privacy practices or CCPA compliance are informed of the requirements and of how to direct consumers to exercise their rights.
A business that sells or shares personal information provides a clear and conspicuous "Do Not Sell or Share My Personal Information" link, and one that uses sensitive personal information beyond permitted purposes provides a "Limit the Use of My Sensitive Personal Information" link — or a single Alternative Opt-out Link — on its homepage and in its privacy policy.
A business that sells or shares personal information treats a browser opt-out preference signal such as Global Privacy Control as a valid request to opt out of sale and sharing for that browser or device and any known consumer, and may display whether the signal was honoured.
Methods for submitting requests and obtaining consent use easy-to-understand language, offer symmetry in choice (declining is no harder than accepting), avoid confusing language, interactive elements or manipulative design, and require minimal steps; agreement obtained through dark patterns is not consent.
The business keeps records of consumer requests made under the CCPA and how it responded for at least 24 months, with reasonable security, and does not use them for other purposes.
From 1 January 2026, a business must conduct a risk assessment before processing that presents significant risk to consumers' privacy — including selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for significant decisions, and certain profiling or AI training — and must submit an attestation and summary to the CPPA by 1 April 2028 for assessments conducted in 2026–2027.
A business whose processing presents significant risk to security — for example one that derives 50% or more of revenue from selling or sharing personal information, or meets the revenue threshold and processes large volumes of personal or sensitive information — must complete an annual independent cybersecurity audit and certify completion to the CPPA, with first certifications due 1 April 2028, 2029 or 2030 depending on revenue.
From 1 January 2027, a business that uses automated decision-making technology to make significant decisions about consumers (financial or lending, housing, education, employment or healthcare) must give a pre-use notice, offer a right to opt out (or a qualifying human appeal) and respond to requests for access to information about the ADMT's use.