CA

California Privacy Law

California Consumer Privacy Act / California Privacy Rights Act

Effective: January 1, 2020ActiveReviewed by PrivacyLawMap editorial teamLast verified: August 13, 2026

Overview

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state privacy law in the United States. Originally enacted in 2018 and effective January 1, 2020, the CPRA amendments took effect on January 1, 2023, significantly expanding consumer rights and business obligations. California's law serves as the benchmark against which all other state privacy laws are measured.

The CCPA/CPRA grants California residents extensive rights over their personal information, including the right to know, delete, correct, and port their data, as well as the right to opt out of the sale or sharing of personal information. The law also created the California Privacy Protection Agency (CPPA, now branded as CalPrivacy), the first dedicated state privacy enforcement agency in the nation. Businesses must honor Global Privacy Control (GPC) signals as valid opt-out requests.

The CPPA has been actively issuing regulations since its creation. The most recent comprehensive regulation package — covering CCPA updates, insurance, cybersecurity audits, risk assessments, and automated decision-making technology (ADMT) — was adopted in September 2025 and took effect January 1, 2026. The agency is currently conducting preliminary rulemaking on data broker audits, reducing friction in privacy rights exercise, and opt-out preference signals (OOPS).

The law applies to for-profit businesses that collect California residents' personal information and meet one of three thresholds: annual gross revenue exceeding $25 million, buying/selling/sharing the personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Penalties can reach $7,988 per intentional violation (inflation-adjusted for 2026), and consumers have a private right of action for data breaches involving certain categories of unencrypted personal information.

What sets California apart from the other states with comprehensive privacy laws is the scope and depth of its regime. The CCPA/CPRA covers more entities (the $25 million revenue threshold is by far the lowest in the country), grants more rights (including correction, automated decision-making opt-out, and the right to limit use of sensitive personal information), and includes a private right of action for data breaches that no other state matches. California is also the only state where employee, job-applicant, contractor, and B2B contact data is fully covered by the comprehensive privacy law, after the HR and B2B exemptions sunset on December 31, 2022. Unlike Virginia, Colorado, or Connecticut, the CCPA has no cure period and is enforced by a dedicated agency with audit authority in addition to the Attorney General.

The most-misunderstood concept under California law is the distinction between "selling" and "sharing" personal information. The CCPA defines selling broadly as disclosing personal information to a third party for monetary or other valuable consideration. The CPRA added "sharing" as a separate category, defined as making personal information available to third parties for cross-context behavioral advertising — regardless of whether money changes hands. This means common ad-tech setups, including third-party cookies, tracking pixels, and pixel-based audience matching, can qualify as either a sale or a share even when the business does not see itself as selling data. CalPrivacy enforcement actions against Sephora, DoorDash, Disney, Ford, and General Motors have all hinged on the broad sale-or-share definition combined with deficient opt-out mechanisms, data minimization gaps, or undisclosed downstream data use.

In 2026, CalPrivacy's enforcement focus has shifted from notice-of-violation sweeps to systemic, well-funded investigations of opt-out friction, GPC processing, connected-vehicle data, and youth-data handling. The General Motors $12.75 million settlement in May 2026 is now the largest CCPA penalty in California history and the first major CCPA data-minimization case; Disney's $2.75 million opt-out settlement and PlayOn's $1.1 million student-privacy order show that multi-million-dollar fines are no longer unusual. Businesses operating in California in 2026 should treat the following as immediate priorities: automated GPC signal recognition and end-to-end opt-out propagation across all advertising and analytics partners; a data inventory that captures inferences, behavioral data, location data, and connected-device telemetry; risk assessments for any high-risk processing as defined in the September 2025 regulations; preparation for the cybersecurity audit requirement (first audit certifications due April 1, 2028 for businesses with $100 million or more in annual revenue); and an ADMT inventory in advance of the January 1, 2027 consumer opt-out deadline.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

$25M+
Annual gross revenue
100,000+
California consumers' data processed

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Updated CCPA text and new CCPA regulations (covering cybersecurity audits, risk assessments, and insurance) took effect January 1, 2026 — ADMT consumer opt-out rights have a separate compliance date of January 1, 2027
  • Delete Act DROP platform launched January 1, 2026 — consumers can now submit one-stop deletion requests to all registered data brokers
  • Data brokers must begin processing DROP deletion requests by August 1, 2026 (check every 45 days)
  • CalPrivacy (formerly CPPA) launched Data Broker Enforcement Strike Force in November 2025, with new round of broker enforcement actions in January 2026
  • CalPrivacy named Sabrina Boyson Ross as Chief Auditor and formed a new Audits Division (February 2026) to conduct cybersecurity audits under the new regulations
  • CPPA announced inflation-adjusted fine amounts for 2026: $2,663 per unintentional violation (up from $2,500) and $7,988 per intentional violation (up from $7,500)
  • Major enforcement actions in 2026: General Motors $12.75M for connected-vehicle data sales and data-minimization violations (May 2026), Ford $375K for opt-out friction (March 2026), PlayOn Sports $1.1M for youth privacy violations (March 2026), Disney $2.75M for opt-out failures (February 2026)
  • CalPrivacy sponsoring AB 2021 (whistleblower protections for privacy complaints) and SB 923 (expanding deletion rights and accessibility requirements)
  • Preliminary rulemaking underway on data broker audits (comment period through May 7, 2026), reducing friction in privacy rights, and opt-out preference signals (OOPS)
  • Nicole Ozer appointed to CPPA Board by Assembly Speaker (January 2026), strengthening enforcement-oriented board composition

Regulatory Timeline

June 28, 2018

CCPA signed into law (AB 375)

January 1, 2020

CCPA takes effect — California becomes first state with comprehensive privacy law

November 3, 2020

Proposition 24 (CPRA) passed by California voters, creating the CPPA

January 1, 2023

CPRA amendments take effect — expanded rights, new sensitive data category, cure period eliminated

March 30, 2023

First set of CCPA regulations approved by Office of Administrative Law

October 11, 2023

California Delete Act (SB 362) signed by Governor Newsom

February 9, 2024

CPPA wins Court of Appeal decision against California Chamber of Commerce challenge to regulations

November 8, 2024

CPPA adopts data broker registration regulations and advances ADMT rulemaking

March 14, 2025

Tom Kemp named as CalPrivacy Executive Director

September 23, 2025

CalPrivacy finalizes comprehensive regulation package covering cybersecurity audits, risk assessments, ADMT, and insurance

November 13, 2025

Delete Act regulations approved

November 19, 2025

CalPrivacy launches Data Broker Enforcement Strike Force

January 1, 2026

New CCPA regulations and Delete Act DROP platform take effect — major regulatory milestone

February 3, 2026

CalPrivacy names Sabrina Boyson Ross as Chief Auditor, forms new Audits Division

April 7, 2026

Preliminary rulemaking on data broker audits opens (comment period through May 7, 2026)

May 8, 2026

California AG, four District Attorneys, and CalPrivacy announce $12.75 million General Motors CCPA / UCL connected-vehicle data settlement

June 1, 2026

Cumulative CCPA, CPRA, and Delete Act civil penalties surpass $24.6 million across more than a dozen publicly resolved actions

Enforcement Details

Enforced By
California Privacy Protection Agency (CPPA) and California Attorney General
Penalty Per Violation
$7,988
Cure Period
None — immediate enforcement
Private Right of Action
Yes — consumers can sue directly

California CCPA/CPRAFines & Penalties(2026 inflation-adjusted)

These are the statutory per-violation amounts written into California Consumer Privacy Act / California Privacy Rights Act— in practice, aggregate fines in major enforcement actions reach into the millions. See the table below for per-incident figures and the “Notable Enforcement Actions” section for real California settlements. For the full cross-state database of CCPA/CPRA fines and privacy penalties across every US privacy law, see the penalties tracker. To weigh these penalties against what compliance would cost, estimate your CCPA/CPRA compliance cost.

Per intentional violation
$7,988

Inflation-adjusted for 2026 (statutory base $7,500). The CPRA tripled this cap for violations involving consumers under 16.

Per unintentional violation
$2,663

Inflation-adjusted for 2026 (statutory base $2,500).

Private right of action — statutory damages
$107–$799per consumer, per incident

Inflation-adjusted statutory damages range for the CCPA private right of action on certain unencrypted-data breaches.

Real-world enforcement scale

Cumulative CCPA monetary penalties in practice: General Motors $12.75M (May 2026), Disney $2.75M (Feb 2026), Healthline $1.55M (Jul 2025), Jam City $1.4M (Nov 2025), Tractor Supply $1.35M (Sep 2025), Sephora $1.2M (Aug 2022), PlayOn Sports $1.1M (Mar 2026), Honda $632.5K (Mar 2025), Sling TV $530K (Oct 2025), Tilting Point $500K (2024), Ford $375,703 (Mar 2026), DoorDash $375K (Jan 2023), S&P Global $62,600 (Jan 2026, Delete Act), and Datamasters $45,000 (Jan 2026, Delete Act). Combined CalPrivacy + CA AG civil penalties on CCPA, CPRA, and the Delete Act exceed $24.6 million since the first enforcement action in August 2022.

Notable Enforcement Actions

Source check: date_retrieved 2026-08-13. This table is generated from the canonical penalties tracker, so new AG and CalPrivacy actions appear here without duplicating state-page copy. Public monetary penalties shown below total $109,620,803.

General Motors

CCPA / UCL · Driving Data Sale / Data Minimization

$12,750,000

California Attorney General Rob Bonta, four California District Attorneys, and CalPrivacy announced a $12.75 million General Motors settlement over allegations that GM sold Californians' OnStar location and driving behavior data to LexisNexis and Verisk in violation of the CCPA and Unfair Competition Law. The settlement bans sales of driving data to consumer reporting agencies for five years and requires a privacy program for OnStar data collection.

May 8, 2026Source

Ford Motor Company

CCPA · Adding Unnecessary Friction to Opt-Out Process

$375,703

The California Privacy Protection Agency (CPPA) fined Ford Motor Company $375,703 for adding unnecessary friction to the consumer opt-out process. Ford required consumers to verify their email address before their opt-out requests would be processed — those who did not click the confirmation link had their requests ignored. This was CalPrivacy's second enforcement action stemming from its connected vehicles investigative sweep. Ford must process all previously unfulfilled opt-out requests, provide compliant opt-out submission methods, audit tracking technologies on its website, and ensure proper handling of opt-out preference signals.

March 5, 2026Source

PlayOn Sports (GoFan)

CCPA · Student Privacy / Failure to Provide Opt-Out

$1,100,000

The California Privacy Protection Agency (CPPA) issued a $1.10 million fine against PlayOn Sports, whose GoFan platform sells digital tickets for approximately 1,400 California schools. PlayOn used tracking technologies to deliver targeted ads to ticketholders without providing a sufficient opt-out mechanism, instead directing users to third-party ad industry tools rather than operating its own opt-out. This is the first CPPA enforcement action addressing student privacy violations.

March 3, 2026Source

The Walt Disney Company

CCPA · Failure to Honor Opt-Out Across Services

$2,750,000

California Attorney General Rob Bonta secured the largest CCPA settlement in state history — $2.75 million against Disney for failing to fully effectuate consumer opt-out requests across all streaming services and devices linked to their Disney accounts. When consumers opted out on one Disney streaming app, the opt-out did not carry across to other Disney platforms like Hulu or ESPN+.

February 11, 2026Source

Rickenbacher Data LLC (Datamasters)

California Delete Act (SB 362) · Failure to Register as Data Broker

$45,000

The CPPA's Data Broker Enforcement Strike Force fined Rickenbacher Data LLC (d/b/a Datamasters) $45,000 for failing to register as a data broker under the California Delete Act (SB 362). Datamasters bought and resold names, addresses, phone numbers, and email addresses of millions of people with health conditions including Alzheimer's disease and drug addiction for targeted advertising. The company was also ordered to stop selling all Californians' personal information.

January 8, 2026Source

S&P Global, Inc.

California Delete Act (SB 362) · Failure to Register as Data Broker

$62,600

The CPPA fined S&P Global, Inc. $62,600 for failing to register as a data broker under the California Delete Act (SB 362). The New York-based provider of data and technology failed to register due to an administrative error. After discovering the error, the company promptly registered and agreed to implement procedures to ensure ongoing compliance with California's data broker registration requirements.

January 8, 2026Source

Jam City, Inc.

CCPA · Children's Privacy / Failure to Honor Opt-Out

$1,400,000

California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, a mobile gaming company, for CCPA violations including lacking opt-out mechanisms in 20 of 21 apps and selling personal information of minors aged 13-16 without obtaining required affirmative authorization.

November 21, 2025Source

Sling TV L.L.C. and Dish Media Sales L.L.C.

CCPA · Opt-Out Friction / Children's Privacy

$530,000

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV and Dish Media Sales for confusing CCPA opt-out flows, requiring unnecessary webform steps from logged-in users, lacking in-app opt-out methods on living-room devices, and failing to provide sufficient children's privacy protections.

October 30, 2025Source

Tractor Supply Company

CCPA/CPRA · Failure to Honor Opt-Out / Privacy Notice Violations

$1,350,000

The California Privacy Protection Agency (CPPA) issued its largest monetary penalty to date — $1.35 million against Tractor Supply Company for failing to properly notify consumers and job applicants of their privacy rights, failing to maintain adequate service provider agreements, and failing to provide effective opt-out mechanisms.

September 30, 2025Source

Healthline Media LLC

CCPA · Failure to Honor Opt-Out Requests

$1,550,000

California Attorney General Rob Bonta announced a $1.55 million settlement with Healthline Media LLC for violating the CCPA by failing to honor opt-out requests and improperly sharing consumer data with third parties.

July 1, 2025Source

American Honda Motor Co.

CCPA · Opt-Out Friction / Excessive Verification

$632,500

The California Privacy Protection Agency (CPPA) fined Honda $632,500 for requiring excessive verification or personal information for privacy rights requests, using asymmetrical privacy choices, making authorized-agent requests difficult, and sharing personal information with ad tech companies without required contract terms.

March 12, 2025Source

Tilting Point Media

CCPA / COPPA · Children's Privacy Violation

$500,000

Mobile game developer Tilting Point Media settled for $500,000 for collecting personal information from children under 13 playing its games without parental consent.

June 19, 2024Source

DoorDash

CCPA · Unauthorized Sale of Personal Information

$375,000

DoorDash was fined for selling consumers' personal information to a marketing cooperative without providing notice or an opportunity to opt out of the sale.

January 10, 2023Source

Sephora

CCPA · Failure to Honor Opt-Out

$1,200,000

Sephora settled with the California AG for $1.2 million for failing to disclose it was selling consumers' personal information, failing to process opt-out requests via Global Privacy Control (GPC), and failing to cure violations within 30 days.

August 24, 2022Source

Zoom Video Communications

CCPA / FTC Act · Deceptive Security Practices

$85,000,000

Zoom settled a class action for $85 million related to privacy and security issues including sharing user data with Facebook, Google, and LinkedIn, and falsely claiming end-to-end encryption.

August 1, 2021Source

Sensitive Data Categories

Consent model: opt-in

Social Security number and government identifiersFinancial account information with credentialsPrecise geolocation dataRacial or ethnic originReligious or philosophical beliefsBiometric information for identification

Universal Opt-Out / GPC Requirements

GPC / Universal Opt-Out Required

Businesses must honor Global Privacy Control (GPC) and other opt-out preference signals as valid opt-out requests under the CPRA. The CPPA has issued regulations clarifying technical requirements for recognizing these signals.

Effective: March 29, 2024

Minor / Child Protections

Businesses must obtain opt-in consent before selling or sharing personal information of consumers under 16. For children under 13, a parent or guardian must provide consent. The CPRA tripled penalties for violations involving minors to $7,500 per violation.

Compliance Checklist

  1. 1Conduct a CCPA-aligned data inventory mapping all 11 categories of personal information defined in Civil Code §1798.140(o), including IP addresses, browsing history, geolocation, biometric identifiers, and inferences drawn from any of the above
  2. 2Publish a Notice at Collection at or before the point of data collection listing the categories collected, the purposes of use, and the retention period for each category, as required by §1798.100
  3. 3Update the privacy policy at least every 12 months and include all CPRA-required disclosures: categories sold or shared in the past 12 months, sources of personal information, purposes of disclosure, and a description of the consumer rights request process
  4. 4Implement automated Global Privacy Control (GPC) signal recognition at both the server layer (Sec-GPC HTTP header) and the client layer (navigator.globalPrivacyControl), and verify that GPC suppresses sale and sharing immediately and consistently across all sub-domains and ad-tech partners
  5. 5Add a "Do Not Sell or Share My Personal Information" link in the website footer, and a separate "Limit the Use of My Sensitive Personal Information" link if you process sensitive PI for non-permitted purposes
  6. 6Establish a rights-request workflow that acknowledges consumer requests within 10 business days and substantively responds within 45 calendar days, with a documented basis for any additional 45-day extension
  7. 7Audit every contract with service providers, contractors, and third parties for CPRA-mandated DPA terms — purpose limitation, no further sale, certification of compliance, and audit rights — and remediate gaps before the next contract review cycle
  8. 8Conduct and document data protection assessments for high-risk processing — including the sale of personal data processing of sensitive data and profiling of consumers — under the September 2025 CCPA risk assessment rules and retain assessments for at least three years
  9. 9Prepare a written information security program; if your business has $100 million or more in annual revenue, scope the cybersecurity audit you must certify to CalPrivacy by April 1, 2028
  10. 10Inventory every use of automated decision-making technology (ADMT) that produces a legally or similarly significant effect on a consumer in financial services, housing, education, employment, or healthcare; document logic, training data, and human-review process before the January 1, 2027 ADMT opt-out deadline
  11. 11Confirm whether your business meets the data broker definition under SB 362, and if so register with CalPrivacy and integrate with the DROP platform to process universal deletion requests at least every 45 days starting August 1, 2026
  12. 12Provide a dedicated employee privacy notice covering HR, applicant, contractor, and B2B contact data — California is the only state where these data subjects retain full CCPA rights including access, deletion, correction, and portability
  13. 13Document retention periods for each category of personal information, including the criteria used and any legitimate business need that justifies retention beyond the initial collection purpose
  14. 14Train employees who handle consumer inquiries, marketing, ad-tech configuration, and HR on CCPA/CPRA requirements, response procedures, and the broad sale-or-share definition that catches common cookie-based and pixel-based advertising
  15. 15Subscribe to CalPrivacy rulemaking notices so the team is alerted to active proceedings on data broker audits, opt-out preference signals (OOPS), and friction-reduction rules expected in 2026
Put CCPA/CPRA Into Practice on Your SiteSponsored

Termly builds and maintains a California-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests CCPA/CPRA grants.

Start Free with Termly

California Privacy Law FAQ

Official Resources