CCPA/CPRA compliance guide for California privacy (2026)

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), is the most comprehensive US state privacy law and the one many non-California businesses still have to obey. The CCPA took effect January 1, 2020; the CPRA — passed by ballot initiative in November 2020 — substantially amended it, with most provisions operational since January 1, 2023 (Recording Law — California data privacy laws; Security Compliance Guide). "CCPA compliance" in 2026 means the combined CCPA/CPRA framework, enforced by both the California Privacy Protection Agency (CPPA) and the Attorney General. If you also serve EU visitors, the GDPR compliance guide covers the parallel regime.

1. Who must comply (the three thresholds)

A for-profit business that does business in California and meets any one of these triggers is in scope (Jackson Lewis — CCPA FAQs):

  • Annual gross revenue over $26.625 million (CPI-adjusted from the original $25M, effective Jan. 1, 2025);
  • Buys, sells, or shares the personal information of 100,000 or more consumers or households; or
  • Derives 50% or more of annual revenue from selling or sharing consumers' personal information.

Physical presence in California is not required — an online retailer in another state (or country) that meets a threshold must comply. Nonprofits and government agencies are generally exempt, though control-chain and common-branding rules can pull related entities in.

2. The consumer rights you must honour

California residents hold an expanded set of rights, and you need working workflows to answer verifiable requests, usually within 45 calendar days (extendable by another 45): right to know/access, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information (Recording Law). You must also honour the Global Privacy Control (GPC) signal as an opt-out. "Sensitive personal information" — SSNs, financial account credentials, precise geolocation, health, biometric, genetic, and similar — gets its own "limit use" right (Dataci — CCPA 2026).

3. New in 2026: risk assessments, cybersecurity audits, ADMT

Regulations adopted by the CPPA in 2025 — covering automated decision-making technology (ADMT), risk assessments, and cybersecurity audits — generally took effect January 1, 2026 (Jackson Lewis — clarifying regulations effective 1.1.26). Covered businesses that sell/share, process sensitive PI at scale, or use ADMT may need documented risk assessments and, for elevated-risk processing, regular cybersecurity audits. This pulls California meaningfully closer to GDPR's accountability model. A data inventory is the foundation both for rights requests and for these assessments.

4. Enforcement and penalties

The CPPA and the AG can pursue civil penalties of $2,500 per unintentional violation and $7,500 per intentional violation (or violations involving minors), calculated per consumer and per incident (Cal. Civ. Code §1798.155) (Security Compliance Guide). 2025 settlements included Tractor Supply ($1.35M), American Honda ($632,500), and Todd Snyder ($345,178). The statutory private right of action for certain breaches adds separate exposure.

5. A practical CCPA/CPRA checklist

  1. Run the threshold test — revenue, 100k consumers, or 50% revenue from sale/share.
  2. Build a data inventory of what PI you collect and where it flows (see PII detection methods).
  3. Publish an accurate privacy notice — categories, purposes, recipients, retention, SPI.
  4. Stand up rights-request workflows with 45-day SLAs and GPC honouring.
  5. Add "Do Not Sell or Share" and "Limit Use of SPI" links.
  6. Sign compliant vendor contracts limiting secondary use.
  7. Prepare risk assessments / cybersecurity audits if 2026 regs apply.
  8. Align cookie and tracker disclosures with your notice (see cookie consent best practices).

Decision-support note. PrivScan can surface likely privacy gaps — undisclosed trackers, missing or weak consent UX, and data-collection points — and return a prioritized checklist mapped to obligations like notice accuracy and opt-out mechanisms. It is a scanner, not legal advice, and does not certify CCPA/CPRA compliance.