The CCPA covers for-profit businesses that do business in California and meet any one of these thresholds:
• Annual gross revenue over $25 million; or
• Buy, sell or share the personal information of 100,000+ California consumers or households a year; or
• Derive 50% or more of annual revenue from selling or sharing personal information.
Meet one and you are covered — there is no requirement to be located in California. Unlike GDPR, the CCPA is an opt-out regime: you may collect by default, but consumers must be able to say stop.
Does the CCPA apply to you?
Three thresholds, any one of which brings you in scope. Two points people miss:
- The 100,000 threshold counts households as well as consumers, and "sharing" includes disclosing data for cross-context behavioural advertising. A content site running ad tech at scale can hit this without ever selling a list.
- Revenue is global, not Californian. A $30 million business with a modest California customer base is covered by the revenue threshold alone.
Opt-out, not opt-in
This is the structural difference from GDPR and it changes everything about implementation.
| GDPR (EU/UK) | CCPA (California) | |
|---|---|---|
| Default state | No processing until consent | Collection allowed by default |
| User action required | Opt in | Opt out |
| Cookie banner | Required for non-essential cookies | Not required; opt-out link is |
| Browser signals | Not mandated | Global Privacy Control must be honoured |
| Applies to | Any size organisation | Only businesses meeting a threshold |
| Individual lawsuits | Art. 82 compensation claims | Limited to certain data breaches |
A fuller side-by-side is in our GDPR vs CCPA comparison.
The six consumer rights
- Know — what you collect, the sources, the purposes, and who you disclose it to
- Delete — subject to a list of exceptions including completing a transaction and legal obligations
- Correct — added by the CPRA amendment
- Opt out of sale or sharing — the right that drives the "Do Not Sell or Share" link
- Limit use of sensitive personal information — precise geolocation, race, religion, health, biometrics, contents of communications
- Non-discrimination — you cannot degrade service because someone exercised a right, though genuine loyalty programmes remain permitted
The ten-item checklist
- ☐ Confirm whether a threshold applies — and write down the reasoning, whichever way it comes out
- ☐ Publish a notice at collection — at or before the point of collection, listing categories collected and the purposes
- ☐ Update your privacy policy — CCPA-specific disclosures, refreshed at least every 12 months
- ☐ Add a "Do Not Sell or Share My Personal Information" link — clear and conspicuous on your homepage
- ☐ Add a "Limit the Use of My Sensitive Personal Information" link — if you use sensitive data beyond permitted purposes
- ☐ Honour Global Privacy Control automatically — treat the signal as a valid opt-out without asking for confirmation
- ☐ Provide two request methods — typically a web form plus a toll-free number, though online-only businesses may use an email address
- ☐ Meet the deadlines — acknowledge in 10 business days, respond in 45 calendar days, honour opt-outs in 15 business days
- ☐ Put service provider contracts in place — the CCPA requires specific contractual terms with vendors handling personal information
- ☐ Train whoever handles requests — the regulations require it, and it is the step that is always skipped
Global Privacy Control
Global Privacy Control is a browser-level signal that broadcasts a consumer's opt-out to every site they visit. California regulations require covered businesses to honour it as a valid opt-out request — automatically, with no confirmation prompt.
This has teeth. California's first CCPA enforcement action, against Sephora in 2022, settled for $1.2 million and centred substantially on the failure to process GPC signals. The Attorney General's office has run repeated enforcement sweeps on the same issue since.
Penalties and enforcement
Two enforcement routes exist. The California Privacy Protection Agency and the Attorney General bring civil penalty actions; the CPPA re-adjusts both penalty figures for inflation every odd-numbered January using California's Consumer Price Index.
Separately, consumers have a private right of action — but only for data breaches caused by a failure to maintain reasonable security. You cannot be sued directly for a missing opt-out link; you can be sued as a class for a breach.
The multiplier is what makes this serious. Each affected consumer can be a separate violation, so a systematic failure across 10,000 California users does not cost $2,663 — it is $2,663 multiplied by the number of consumers, before any negotiation.
The other state laws
California was first, not last. Roughly twenty states had comprehensive consumer privacy laws in force at the start of 2026, and the number has continued to climb as further states enacted laws through the year.
The good news is convergence. Most follow a Virginia-style template: opt-out of targeted advertising and sale, opt-in for sensitive data, rights to access, delete, correct and port, and a universal opt-out signal requirement. If you build for CCPA properly, you cover most of the rest.
- California remains the strictest and has the only dedicated privacy regulator
- Thresholds differ by state — many use a 100,000-resident trigger with no revenue test, which can pull in companies that CCPA misses
- Universal opt-out signals are spreading — Colorado, Connecticut, Texas and others require honouring them
- Sensitive data increasingly requires opt-in, closer to the GDPR model than to California's
Building one opt-out mechanism that honours universal signals and applies your strictest standard nationally is usually cheaper than maintaining fifty state-specific behaviours.
Complying with CCPA and GDPR together
Most businesses with traffic from both regions run a single consent platform in dual mode: a GDPR opt-in banner for EEA and UK visitors, CCPA opt-out mechanics for Californians, detected by IP.
- Pick a CMP that supports both regimes Termly, iubenda and CookieYes all handle geo-detection with different rule sets per region.
- Set EEA and UK to opt-in Nothing non-essential fires before consent.
- Set California to opt-out Tags fire, with a working Do Not Sell or Share link and automatic GPC handling.
- Write one privacy policy with both sections A single document with a clearly labelled California section is easier to maintain than two.
- Use one request intake for everything The GDPR 30-day window is tighter than California's 45 days, so build to the tighter one and you satisfy both.
Termly
Of the tools we have tested, Termly handles the CCPA side most completely — Do Not Sell or Share mechanics, GPC signal handling, and geo-targeted rules alongside GDPR opt-in for European visitors, with policy generation in the same subscription.
Frequently asked questions
Who has to comply with the CCPA?
A for-profit business that does business in California and meets any one of three thresholds: annual gross revenue above $25 million; buying, selling or sharing the personal information of 100,000 or more California consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing personal information. Meeting one threshold is enough.
How much are CCPA fines?
Civil penalties are $2,663 per violation and $7,988 per intentional violation or violation involving the personal information of a consumer under 16. Those figures took effect on 1 January 2025, replacing the original $2,500 and $7,500 caps, and the California Privacy Protection Agency adjusts them for inflation every odd-numbered year. Each affected consumer can count as a separate violation.
Does the CCPA require a cookie banner?
Not in the GDPR sense. The CCPA is an opt-out regime: you may set cookies by default, but you must give consumers a clear way to opt out of the sale or sharing of their personal information, and most advertising and analytics cookies count as sharing. In practice that means a Do Not Sell or Share My Personal Information link and honouring browser opt-out preference signals.
What is an opt-out preference signal?
A browser-level setting, most commonly Global Privacy Control, that broadcasts a consumer's opt-out choice to every site they visit. California regulations require covered businesses to treat a Global Privacy Control signal as a valid opt-out request — you must honour it automatically, without asking the consumer to confirm.
What is the difference between the CCPA and the CPRA?
The CPRA is an amendment to the CCPA rather than a separate law. It added the right to correct and the right to limit use of sensitive personal information, created the category of sharing for cross-context behavioural advertising, removed the automatic 30-day cure period, and established the California Privacy Protection Agency as a dedicated regulator. People generally still say CCPA to mean the amended law.
Do I need to comply with the CCPA if I am not in California?
Location does not exempt you. The test is whether you do business in California and meet a threshold. A company anywhere in the world that markets to and collects data from California residents at sufficient scale is covered. There is no physical presence requirement.
How long do I have to respond to a CCPA request?
You must confirm receipt within 10 business days and respond substantively within 45 calendar days. You may extend once by a further 45 days if you notify the consumer of the extension and the reason for it. Opt-out requests are different and must be honoured within 15 business days.
Can I use the same cookie banner for CCPA and GDPR?
Yes, if your consent platform supports geo-targeted rules. The banner detects location and applies opt-in behaviour for EEA and UK visitors while presenting opt-out mechanics for Californians. Applying GDPR opt-in worldwide is also valid and simpler, at the cost of measurable data from US traffic.