Skip to main content
Category: Privacy Regulations

California Consumer Privacy Act

Also known as: CCPA, California Consumer Privacy Act of 2018
Simply put

The California Consumer Privacy Act (CCPA) is a state privacy law that gives California residents more control over the personal information that businesses collect about them. It was enacted in California in 2018 and took effect on January 1, 2020. In November 2020, California voters passed Proposition 24, also known as the California Privacy Rights Act (CPRA), which amended the CCPA.

Formal definition

The CCPA is a California state statute establishing consumer privacy rights for California residents over personal information that businesses collect about them, defined broadly. Enacted in 2018 and effective January 1, 2020, it was subsequently amended by the California Privacy Rights Act (CPRA), passed by voters via Proposition 24 in November 2020; practitioners should treat the CCPA and its CPRA amendments as related but distinct in their specific requirements. The CCPA is a state-level regime and is not interchangeable with other frameworks such as the EU GDPR or UK GDPR; its scope, definitions, and obligations differ, and its applicability generally depends on business thresholds and the nature of processing. This entry defines the law at a high level and does not cover specific consumer rights, business applicability thresholds, enforcement mechanisms, penalties, or the detailed changes introduced by the CPRA; those require separate analysis and current legal review.

Why it matters

The CCPA marked a significant shift in the United States privacy landscape by establishing a comprehensive, state-level regime that gives California residents greater control over the personal information businesses collect about them. For organizations that operate nationally or globally, it demonstrated that meaningful privacy obligations can arise from state law rather than a single federal framework, requiring compliance teams to track jurisdiction-specific requirements rather than assuming a uniform national standard. Because the CCPA defines personal information broadly, businesses that previously scoped their privacy programs narrowly may find that data they did not treat as sensitive falls within its reach.

The law's evolution also matters. In November 2020, California voters passed Proposition 24, known as the California Privacy Rights Act (CPRA), which amended the CCPA. Practitioners should treat the CCPA and its CPRA amendments as related but distinct, because relying on an outdated understanding of the statute can lead to gaps between what a program addresses and what current law requires. This makes ongoing legal review important rather than optional.

Crucially, the CCPA is a state-level regime and is not interchangeable with frameworks such as the EU GDPR or UK GDPR. Its scope, definitions, and obligations differ, and treating them as equivalent is a common and consequential mistake. Applicability generally depends on business thresholds and the nature of processing, so an organization subject to GDPR is not automatically compliant with the CCPA, and vice versa. Separate analysis for each regime is generally advisable.

Who it's relevant to

Privacy and compliance officers
Professionals responsible for privacy programs need to determine whether their organization meets the CCPA's applicability thresholds and to keep their understanding current with the CPRA amendments. Because the CCPA is distinct from the EU and UK GDPR, they should avoid assuming that compliance with one regime satisfies another and should scope obligations to the specific statute.
Data protection officers and privacy counsel
Legal and privacy leads must map how the CCPA, as amended by the CPRA, applies to the personal information their organization collects about California residents, noting that the term is defined broadly. This entry does not substitute for detailed legal review of consumer rights, enforcement, or penalties, which require jurisdiction-specific analysis.
Information governance and data stewardship leads
Those responsible for data ownership, inventories, and lineage benefit from understanding that the CCPA's broad definition of personal information may bring data into scope that a narrower governance model overlooked. Demonstrable evidence of what data is held and how it is processed generally supports accountability, though governance activity alone does not establish legal compliance.
Organizations serving California residents
Businesses that collect personal information about California residents may fall within the CCPA's scope depending on business thresholds and the nature of their processing. Applicability is not automatic, so each organization should assess its own position against the current statute and its CPRA amendments.

Inside CCPA

Scope and Applicability
The CCPA is a California state privacy law that applies to certain for-profit businesses that collect personal information of California residents and meet defined thresholds (such as revenue, volume of consumers, or share of revenue from selling personal information). It does not apply universally to all organizations, and its treatment differs from the EU GDPR, UK GDPR, and other US sector-specific regimes such as HIPAA.
Consumer Rights
The CCPA generally grants California consumers rights such as the right to know what personal information is collected, the right to access and delete certain personal information, and the right to opt out of the sale of personal information. The specific mechanics and exceptions for these rights are defined in the statute and its regulations.
Personal Information Definition
The CCPA defines personal information broadly to include information that identifies, relates to, or could reasonably be linked with a California consumer or household. This definition is framed under California law and should not be assumed identical to the definition of personal data under the EU or UK GDPR.
Business, Service Provider, and Third Party Roles
The CCPA distinguishes between a business (which determines the purposes and means of processing), a service provider (which processes on behalf of a business under contract), and third parties. These roles carry different obligations and are conceptually distinct from the controller and processor roles used under the GDPR, though comparisons are sometimes drawn.
Relationship to CPRA
The California Privacy Rights Act (CPRA) amended and expanded the CCPA. Practitioners should treat the CCPA as amended by the CPRA rather than as static, and should not assume the two are interchangeable with each other or with other regimes.
Notice and Transparency Obligations
The CCPA generally requires businesses to provide consumers with notice about the categories of personal information collected and the purposes for which it is used, typically through a privacy policy or notice at collection.

Common questions

Answers to the questions practitioners most commonly ask about CCPA.

Is the CCPA the same as the GDPR, just for California?
No. Although both address privacy, they are distinct instruments with different scoping, terminology, and obligations. The CCPA (as amended by the CPRA) is a California statute that generally applies to for-profit businesses meeting certain thresholds and grants consumer rights such as access, deletion, and opt-out of sale or sharing. The EU GDPR and UK GDPR are comprehensive data protection regimes built around lawful bases for processing, controller and processor obligations, and data subject rights that do not map one-to-one onto CCPA concepts. Do not assume a control or notice that satisfies one regime satisfies the other; treatment differs by jurisdiction. This answer does not cover cross-border transfer mechanics or enforcement penalties.
Does complying with the CCPA mean I automatically comply with other U.S. state privacy laws or HIPAA?
No. The CCPA is specific to California and should not be treated as interchangeable with other state privacy statutes or with federal sector laws such as HIPAA, which addresses protected health information in defined contexts. Compliance obligations depend on jurisdiction, sector, and the specific data at issue, and requirements, definitions, and exemptions vary across these regimes. A CCPA program is not, on its own, evidence of compliance elsewhere. This entry does not enumerate the exemptions or interactions between the CCPA and other laws.
How should a business determine whether the CCPA applies to it?
Applicability generally turns on statutory thresholds concerning whether an entity is a for-profit business doing business in California and meets criteria the statute sets out. Because the precise thresholds and definitions are set by the statute and its amendments, organizations should confirm current criteria against the authoritative statutory text or qualified legal counsel rather than relying on general summaries. Scoping is a legal determination, and this answer does not restate specific numeric thresholds.
What operational capabilities does a business typically need to honor consumer rights under the CCPA?
In most cases, a business needs mechanisms to receive and verify consumer requests, to locate relevant personal information across its systems, and to respond within the timeframes the statute prescribes. This generally requires knowing where personal information resides, which ties into data governance activities such as cataloging and lineage, as well as security controls for verifying requester identity. These capabilities support, but do not by themselves guarantee, compliance, and their adequacy depends on implementation. This answer does not detail specific response deadlines or verification standards.
How does the CCPA distinction between a business and a service provider affect accountability?
The CCPA assigns different obligations depending on the role an entity plays, broadly separating a business that determines the purposes of processing from a service provider that processes personal information on the business's behalf under contractual restrictions. This is a role-based allocation of responsibility and should not be conflated with the controller and processor terminology of the GDPR, even where the concepts appear analogous. Contractual terms typically govern the relationship, and accountability generally requires demonstrable evidence of the arrangement. This answer does not restate the specific contractual clauses the statute requires.
Does encrypting or de-identifying personal information remove it from CCPA obligations?
Not automatically. Encryption and tokenization are security measures that protect data but do not, on their own, render information non-personal, so encrypted personal information generally remains within scope. De-identification is treated differently and depends on meeting the statutory standard for de-identified data, including appropriate safeguards and commitments against re-identification. Organizations should evaluate whether data meets the applicable standard rather than assuming any single technique places data out of scope. This answer does not restate the specific de-identification criteria.

Common misconceptions

The CCPA is essentially the same as the GDPR, so GDPR compliance means CCPA compliance.
The CCPA and the EU or UK GDPR are separate instruments with different scopes, definitions, roles, and rights. For example, the CCPA centers on rights such as opting out of the sale of personal information and uses business and service provider terminology, whereas the GDPR uses controller and processor roles and lawful bases for processing. Compliance with one does not guarantee compliance with the other.
Any business that handles California residents' data is automatically subject to the CCPA.
The CCPA applies to for-profit businesses that meet defined statutory thresholds. Organizations below those thresholds, or that fall within specific exemptions, may not be covered. Applicability should be assessed against the statute rather than assumed.
The CCPA's opt-out right for the sale of personal information is a consent mechanism equivalent to obtaining affirmative consent.
An opt-out right generally allows a consumer to direct a business to stop selling their personal information, which is distinct from obtaining affirmative opt-in consent before processing. These are different mechanisms and should not be conflated.

Best practices

Assess CCPA applicability against the statute's defined thresholds and exemptions rather than assuming coverage, and document the basis for your determination as demonstrable evidence.
Map the roles of your organization and its partners as business, service provider, or third party under the CCPA, and put appropriate contractual terms in place, keeping these distinct from GDPR controller and processor analysis.
Maintain accurate notices and privacy disclosures covering the categories of personal information collected and the purposes of use, and update them as practices change.
Implement and test operational processes to handle consumer requests to know, access, delete, and opt out of the sale of personal information within the mechanics the law requires.
Track the CCPA as amended by the CPRA and monitor for regulatory updates, treating the framework as evolving rather than fixed.
Avoid treating tokenization, encryption, or similar security controls as removing information from the CCPA's scope, and coordinate governance and security teams while keeping their distinct responsibilities clear.