Skip to main content
Evergreenwhat is ccpa

What Is CCPA? The California Consumer Privacy Act Explained for Tech Companies

CCPA (California Consumer Privacy Act) is a state privacy law that gives California residents rights over their personal data and imposes obligations on.

By QuickTrust EditorialUpdated 2026-03-22

What Is CCPA? The California Consumer Privacy Act Explained for Tech Companies

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) in 2023, is the most comprehensive state-level privacy law in the United States. It grants California residents specific rights over their personal information and imposes data protection obligations on businesses that collect, sell, or share that information. For technology companies -- especially SaaS platforms, data analytics providers, and any business with California customers -- CCPA compliance is a legal obligation that carries civil penalties of up to $7,500 per intentional violation.

The CCPA applies broadly. It covers any for-profit business that collects personal information from California residents and meets certain revenue or data volume thresholds -- regardless of whether the company is based in California. If your product serves California consumers or you collect data from California residents, the CCPA likely applies to you.


TL;DR -- Key Takeaways

  • CCPA applies to for-profit businesses that meet any one of three thresholds: $25 million+ annual revenue, data on 100,000+ consumers/households, or 50%+ revenue from selling/sharing personal information
  • The CPRA (effective January 2023) significantly strengthened the original CCPA with new rights, new data categories, and a dedicated enforcement agency
  • California consumers have rights to know, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information
  • Penalties range from $2,500 per unintentional violation to $7,500 per intentional violation, enforced by the California Privacy Protection Agency (CPPA)
  • CCPA is not the same as GDPR -- but companies compliant with one are well-positioned for the other

Who Must Comply With CCPA?

The CCPA applies to any for-profit entity that does business in California and meets any one of the following thresholds:

ThresholdCriteria
RevenueAnnual gross revenue exceeding $25 million
Data volumeBuys, sells, or shares the personal information of 100,000 or more California consumers, households, or devices annually
Revenue from dataDerives 50% or more of annual revenue from selling or sharing consumers' personal information

Important clarifications:

  • You do not need to be headquartered in California. If you collect personal information from California residents and meet any threshold, the CCPA applies.
  • The CPRA removed the 50,000-consumer threshold from the original CCPA and raised it to 100,000.
  • "Selling" under CCPA is broadly defined -- it includes making personal information available to a third party for monetary or "other valuable consideration," which can include advertising data sharing arrangements.
  • "Sharing" (added by CPRA) covers cross-context behavioral advertising, even without monetary exchange.

What Personal Information Does CCPA Protect?

CCPA defines "personal information" broadly -- much broader than many businesses expect. It includes any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

CategoryExamples
IdentifiersName, email, phone number, IP address, account name, SSN, driver's license number
Commercial informationPurchase history, products/services purchased, consuming histories or tendencies
Internet activityBrowsing history, search history, interaction with websites or applications
Geolocation dataPrecise physical location information
Professional/employment informationCurrent or past job history, performance evaluations
Education informationNon-publicly available records from educational institutions
InferencesConsumer profiles drawn from any of the above, reflecting preferences, characteristics, behavior, attitudes
Sensitive personal information (CPRA)SSN, financial account credentials, precise geolocation, racial/ethnic origin, religious beliefs, biometric data, health data, sex life/sexual orientation data, contents of mail/email/text messages

The CPRA added "sensitive personal information" as a distinct category with enhanced protections, including the consumer right to limit how businesses use and disclose it.


Consumer Rights Under CCPA/CPRA

California residents have the following rights under the current law:

Right to Know

Consumers can request that a business disclose what personal information it has collected about them, the sources of that information, the business purpose for collection, the categories of third parties with whom it is shared, and the specific pieces of personal information collected.

Right to Delete

Consumers can request deletion of their personal information, with certain exceptions (legal obligations, completing transactions, security purposes, internal uses consistent with consumer expectations).

Right to Correct

Added by CPRA. Consumers can request that inaccurate personal information be corrected.

Right to Opt Out of Sale or Sharing

Consumers can direct a business to stop selling or sharing their personal information. Businesses must provide a clear "Do Not Sell or Share My Personal Information" link on their website.

Right to Limit Use of Sensitive Personal Information

Added by CPRA. Consumers can direct a business to limit its use of sensitive personal information to what is necessary to perform the services or provide the goods they requested.

Right to Non-Discrimination

Businesses cannot discriminate against consumers who exercise their CCPA rights -- no price increases, reduced service quality, or denial of goods or services.


CCPA vs. GDPR: Key Differences

Companies operating globally often need to comply with both CCPA and the EU's General Data Protection Regulation (GDPR). While they share similar goals, there are meaningful structural differences.

CCPA/CPRAGDPR
ScopeFor-profit businesses meeting revenue/data thresholds; California residents onlyAny organization processing personal data of EU/EEA residents, regardless of size
Legal basis for processingOpt-out model -- businesses can collect and use data unless consumers opt outOpt-in model -- requires a lawful basis (consent, contract, legitimate interest, etc.) before processing
Consent modelImplied consent for collection; explicit opt-out for sale/sharingExplicit opt-in consent required for most processing activities
Right to deleteYes, with broader exceptionsYes, with narrower exceptions
Data portabilityLimitedExplicit right to receive data in machine-readable format
Private right of actionLimited to data breaches involving certain categories of unencrypted personal informationNo direct private right of action in most cases (varies by member state)
Enforcement bodyCalifornia Privacy Protection Agency (CPPA) + California Attorney GeneralNational Data Protection Authorities in each EU member state
Maximum penalties$7,500 per intentional violation (no cap)Up to 4% of annual global turnover or 20 million euros, whichever is higher
Applies to nonprofitsNoYes

Bottom line: GDPR is generally stricter (opt-in vs. opt-out), but CCPA has broader definitions of personal information and a private right of action for data breaches that GDPR lacks.


CCPA Penalties and Enforcement

The CPRA established the California Privacy Protection Agency (CPPA) as a dedicated enforcement body -- the first of its kind in the United States. Enforcement is shared between the CPPA and the California Attorney General.

Violation TypePenalty
Unintentional violationUp to $2,500 per violation
Intentional violationUp to $7,500 per violation
Violations involving minors' dataUp to $7,500 per violation (treated as intentional)

There is no annual cap on aggregate penalties. Because penalties are assessed per violation (per consumer, per incident), enforcement actions against companies with large user bases can result in substantial liability.

Additionally, CCPA provides a private right of action for data breaches. If a business fails to implement reasonable security measures and suffers a breach of certain categories of unencrypted or non-redacted personal information, affected consumers can sue for statutory damages of $100 to $750 per consumer per incident -- or actual damages, whichever is greater. Class action lawsuits under this provision have already resulted in multi-million-dollar settlements.


How CCPA Relates to Other Compliance Frameworks

CCPA does not exist in isolation. Organizations pursuing multiple compliance certifications will find significant overlap:

FrameworkRelationship to CCPA
GDPRSignificant overlap in data subject rights and data protection requirements; GDPR compliance provides a strong foundation for CCPA
SOC 2 (Privacy TSC)SOC 2's Privacy Trust Service Criterion evaluates controls for personal information collection, use, retention, and disclosure -- directly aligned with CCPA obligations
ISO 27701Extension to ISO 27001 specifically for privacy information management; maps well to CCPA's data handling requirements
HIPAAHIPAA-covered health information is generally exempt from CCPA, but health-adjacent data (wellness apps, fitness trackers) may fall under CCPA
PCI DSSPayment card data protected under PCI DSS overlaps with CCPA's personal information categories; strong PCI DSS controls support CCPA compliance for payment data

How QuickTrust Helps With CCPA Compliance

CCPA compliance requires more than updating your privacy policy. It demands technical implementation across data collection, storage, access, and deletion systems. QuickTrust's Security and DevOps engineers implement the infrastructure-level controls that make CCPA compliance operational:

  • Data mapping and inventory -- Identify all personal information collected, where it is stored, how it flows through your systems, and which third parties receive it
  • Consumer request infrastructure -- Build and test the technical workflows for honoring right-to-know, right-to-delete, right-to-correct, and opt-out requests within the required 45-day response window
  • Access controls and audit logging -- Implement role-based access to personal information, enforce least privilege, and maintain audit trails documenting who accessed what data and when
  • Data retention and deletion -- Configure automated data retention policies and verified deletion processes across all storage systems, including backups and third-party integrations
  • Vendor data sharing controls -- Inventory all third parties receiving personal information, implement technical controls to honor opt-out signals (including Global Privacy Control), and manage data processing agreements
  • Security measures -- Implement the "reasonable security" measures that protect against the private right of action -- encryption, access controls, vulnerability management, and monitoring

Result: CCPA compliance built into your infrastructure, not just your legal documents. 100% audit pass rate across 100+ audits. Engineering-included.


CCPA FAQ

Does CCPA apply if my company is not based in California?

Yes. CCPA applies to any for-profit business that collects personal information from California residents and meets the revenue, data volume, or data revenue thresholds -- regardless of where the business is located.

Is CCPA compliance a one-time project?

No. CCPA requires ongoing operational capabilities -- responding to consumer requests within 45 days, maintaining up-to-date data inventories, honoring opt-out signals, conducting regular risk assessments, and updating privacy notices when practices change. The CPPA also continues to issue new regulations that may impose additional requirements.

What is the difference between CCPA and CPRA?

The CPRA (California Privacy Rights Act), approved by voters in November 2020 and effective January 1, 2023, amends and strengthens the original CCPA. Key additions include: the right to correct inaccurate data, the right to limit use of sensitive personal information, creation of the CPPA enforcement agency, expanded data minimization requirements, and new requirements for data sharing (not just selling). When people refer to "CCPA" today, they generally mean the CCPA as amended by CPRA.

Do we need to comply with both CCPA and GDPR?

If you collect personal information from California residents and personal data from EU/EEA residents, yes. The good news is that many controls overlap. Companies that have implemented GDPR compliance are well-positioned for CCPA, and vice versa. QuickTrust helps organizations build unified privacy controls that satisfy both frameworks.


Ready to Get CCPA Compliant?

Privacy compliance requires engineering implementation -- data mapping, deletion workflows, access controls, and audit systems. QuickTrust's team builds these capabilities directly into your infrastructure.

Get your privacy compliance assessment at trust.quickintell.com

Engineering-included. Audit-ready in 6-10 weeks. 100% audit pass rate.



Ready to get audit-ready?

Our engineers implement controls, prepare evidence, and coordinate your audit.

Get a Free Assessment

Related Articles