California Consumer Privacy Act
The California Consumer Privacy Act (CCPA) is a state privacy law that gives California residents more control over the personal information that businesses collect about them. It was enacted in California in 2018 and took effect on January 1, 2020. In November 2020, California voters passed Proposition 24, also known as the California Privacy Rights Act (CPRA), which amended the CCPA.
The CCPA is a California state statute establishing consumer privacy rights for California residents over personal information that businesses collect about them, defined broadly. Enacted in 2018 and effective January 1, 2020, it was subsequently amended by the California Privacy Rights Act (CPRA), passed by voters via Proposition 24 in November 2020; practitioners should treat the CCPA and its CPRA amendments as related but distinct in their specific requirements. The CCPA is a state-level regime and is not interchangeable with other frameworks such as the EU GDPR or UK GDPR; its scope, definitions, and obligations differ, and its applicability generally depends on business thresholds and the nature of processing. This entry defines the law at a high level and does not cover specific consumer rights, business applicability thresholds, enforcement mechanisms, penalties, or the detailed changes introduced by the CPRA; those require separate analysis and current legal review.
Why it matters
The CCPA marked a significant shift in the United States privacy landscape by establishing a comprehensive, state-level regime that gives California residents greater control over the personal information businesses collect about them. For organizations that operate nationally or globally, it demonstrated that meaningful privacy obligations can arise from state law rather than a single federal framework, requiring compliance teams to track jurisdiction-specific requirements rather than assuming a uniform national standard. Because the CCPA defines personal information broadly, businesses that previously scoped their privacy programs narrowly may find that data they did not treat as sensitive falls within its reach.
The law's evolution also matters. In November 2020, California voters passed Proposition 24, known as the California Privacy Rights Act (CPRA), which amended the CCPA. Practitioners should treat the CCPA and its CPRA amendments as related but distinct, because relying on an outdated understanding of the statute can lead to gaps between what a program addresses and what current law requires. This makes ongoing legal review important rather than optional.
Crucially, the CCPA is a state-level regime and is not interchangeable with frameworks such as the EU GDPR or UK GDPR. Its scope, definitions, and obligations differ, and treating them as equivalent is a common and consequential mistake. Applicability generally depends on business thresholds and the nature of processing, so an organization subject to GDPR is not automatically compliant with the CCPA, and vice versa. Separate analysis for each regime is generally advisable.
Who it's relevant to
Inside CCPA
Common questions
Answers to the questions practitioners most commonly ask about CCPA.