California Consumer Privacy Act (CCPA): compliance guide for marketers

Your CCPA compliance guide covering: what are the CCPA compliance requirements, the differences between GDPR and CCPA cookie compliance, and the best solutions to comply with the California law.

What is the CCPA?

The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of California. Enacted in 2018 and effective from January 1, 2020, the CCPA represents a significant step in data privacy law in the United States.
The CCPA provides California residents with specific rights over their personal information, allowing them to know what personal data is being collected about them, whether it is sold or disclosed and to whom, and to say no to the sale of personal data.

Who does the CCPA apply to?

The CCPA applies to businesses that operate in California, collect personal information of consumers, and meet at least one of the following criteria:

It’s important to note that these businesses need not be physically located in California. If they collect personal data from California residents, they are subject to the CCPA cookie compliance requirements.

What are the CCPA compliance requirements? CCPA regulations for obtaining consent and processing data

Under the CCPA, businesses must provide notice to consumers at or before the point of data collection. This notice should be easy to understand and accessible, providing consumers with a clear understanding of the categories of information to be collected and for what purpose it will be used.
Furthermore, businesses must create a clear and conspicuous link on their website, labelled ‘Do Not Sell My Personal Information,’ allowing consumers to opt out of the sale of their personal data. When it comes to minors under 16, businesses must obtain explicit opt-in consent.

Stop stressing over CCPA compliance. We’re here to help.

Scan your website, block non-compliant cookies, and achieve compliance in minutes with Cookie Information’s cookie consent banner tool.

What happens if you fail to comply? CCPA fines for non-compliance

Non-compliance with the CCPA can result in civil penalties. For intentional violations, businesses can be fined up to $7,500 per violation, and for unintentional violations, the fine is up to $2,500 per violation. These fines can quickly add up considering each affected user may count as a separate violation.
Additionally, the CCPA allows individuals to seek statutory or actual damages in the event of a data breach, with statutory damages ranging from $100 to $750 per incident or actual damages, whichever is greater.

What does the California CCPA cover?

The CCPA law applies to a broad range of personal information, including but not limited to:

The CCPA text also covers cookies and online trackers. Businesses must inform consumers about the use of cookies and similar tracking technologies and obtain their consent.

The Digital Services Act enhances transparency and accountability

CCPA cookie compliance: what does the CCPA say about the use of cookies in websites?

Under the California Consumer Privacy Act (CCPA), cookies are considered as personal information. Businesses must inform consumers about the use of cookies and obtain their consent.

What are cookies under CCPA?

Cookies are small files that websites store on your computer or device. They can contain various types of information, including personal data such as your browsing history or preferences. Under the CCPA, this information is considered personal because it can be used to identify, describe, or be directly or indirectly linked with a particular consumer or household.

CCPA consent banner requirements: informing consumers about the use of cookies

Businesses must disclose their use of cookies to consumers. This information is usually presented in a clear and accessible way, often through a cookie consent banner or notice that appears when a user first visits a website. This notice should explain what cookies are, how they are used, and why they are used.

Obtaining CCPA-compliant consent for the use of cookies

Under the CCPA, businesses must obtain consumer consent before using cookies. This is typically done through an opt-in mechanism on the cookie notice or consent banner. The consumer must actively agree to the use of cookies on the website, typically by clicking a button or checkbox that indicates their consent. It’s important to note that under the CCPA, silence or inactivity cannot be interpreted as consent.

Opting out and accessing cookie information

The CCPA gives consumers the right to opt out of the sale of their personal information, including information collected through cookies. Businesses should provide an easy way for consumers to exercise this right, such as a “Do Not Sell My Personal Information” link on their website.

In addition, the CCPA law provides consumers with the right to know what personal information a business collects about them, including through cookies. Businesses should provide a way for consumers to request this information and must respond to these requests within 45 days.

To comply with the CCPA, websites must also recognize and respect the universal opt-out signal, also known as Global Privacy Control (GPC). This feature allows users to configure their privacy and consent preferences directly within their browser, ensuring that their choices are automatically applied across all websites they visit.

CCPA vs CPRA: what's the difference?

The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), are two major privacy laws designed to enhance data protection rights for California residents.

The CCPA, which took effect in 2020, introduced groundbreaking consumer rights, including the right to access, delete, and opt out of the sale of personal data. However, as data privacy concerns evolved, so did the need for stricter regulations. 

This led to the passage of the CPRA, which builds upon the CCPA by expanding consumer rights, introducing new obligations for businesses, and establishing a dedicated enforcement agency – the California Privacy Protection Agency (CPPA).

While the CCPA laid the foundation for consumer data rights, the CPRA strengthens and refines these protections. Key changes include the introduction of Sensitive Personal Information (SPI) regulations, expanded opt-out rights for data sharing (not just sales), and stricter data retention and security requirements. 

The CPRA also raises compliance thresholds for businesses, potentially exempting smaller companies from certain obligations. 

CCPA vs GDPR: key differences between GDPR and CCPA compliance

The California Consumer Privacy Act (CCPA) and the European Union’s General Data Protection Regulation (GDPR) are two major data privacy regulations that impact businesses handling personal data. While both aim to protect consumer privacy, they have key differences in scope, requirements, and enforcement. 

GDPR, which applies to EU citizens, is broader in its definition of personal data and consent requirements. CCPA, focused on California residents, emphasizes consumer rights like opting out of data sales. If you’re operating in both jurisdictions, make sure you understand the nuances to achieve compliance.

By adhering to these cookie requirements, you can ensure that your website complies with the CCPA’s provisions regarding the use of cookies.

CCPA (California)

GDPR (EU)

Scope

Businesses meeting revenue or data thresholds that handle California residents’ data.

Any organization processing the personal data of EU citizens, regardless of location.

Personal data definition

Covers personal identifiers, household data, and inferences drawn from personal information.

Broadly defines personal data, including directly or indirectly identifiable information.

Consumer rights

Right to know, delete, opt-out of sale, and non-discrimination.

Right to access, rectify, erase, restrict processing, data portability, and object to processing.

Consent requirements

Opt-out model for data sales; implied consent for most data processing.

Requires explicit opt-in consent for data collection and processing in most cases.

Penalties

$2,500 per unintentional violation, $7,500 per intentional violation.

Up to €20 million or 4% of global annual revenue, whichever is higher.

Enforcement

California Attorney General and the California Privacy Protection Agency (CPPA).

Data protection authorities (DPAs) across EU member states.

Applicability outside of jurisdiction

Affects businesses outside California if they process California residents’ personal information.

Affects businesses worldwide if they process EU citizens’ data.

How to comply with the CCPA? Data compliance requirements

Businesses can take several steps to achieve compliance with the CCPA:

1. Understand your data: Know what personal information you collect, why you collect it, how you store it, who you share it with, and how long you retain it.

2. Update privacy policies and procedures: Make sure your privacy policies are.

How to achieve CCPA compliance: checklist for marketers and website owners

CCPA stands for California Consumer Privacy Act and refers to a data protection law that standardizes the rights of California consumers. As of January 1, 2023, the CCPA has been amended to include the CPRA (California Privacy Rights Act). If you run a profit-oriented business that collects, processes, or sells data from California citizens, you may be required to comply with the CCPA if you meet some additional criteria.

CCPA defines what personal data, or personally identifiable information (PII) is and is not affected. The information includes name, address, email address, social security number, biometric information, job data, educational information, and browsing history. It does not cover publicly available information, like that found in government documents or newspaper articles, and personal health information, which is regulated separately under Health Insurance Portability and Accountability Act (HIPAA).

Californian consumers have the right to be disclosed by companies exactly what personal information is collected. A request in this regard may be made by consumers up to twice a year. Additionally, an individual must be notified of these intentions at or before the point of data collection. To inform your consumers about your data processing activities, you can use a pop-up window or banner that appears when a page is first accessed. Tell your customers that you collect data, for what purpose, and also include links with additional information about your CCPA practices.

Section 1798.130. of CCPA requires you to provide consumers with two or more methods to contact you to make requests such as disclosures of personal information. Here, you must provide a toll-free telephone number and your website address. If a request is raised, you only have 45 days to comply. To make it as easy as possible for consumers to practice their CCPA rights, you should place your contact information prominently on your website.

To fully comply with CCPA, you need a privacy policy that complies with current CCPA/CPRA rules and is updated at least every 12 months. The privacy policy should elaborate that data is collected and why. Furthermore, how to deny access to personal information for specific purposes must be stated in the CCPA privacy policy. Do not forget to mention that you do not discriminate against once someone takes away your right for data storage.

Under the CCPA, consent does not have to be obtained for data processing – but consumers must be able to opt out of the sale of personal data to third parties at any time. The opt-out option must include a separate page in your online presence with the mandatory heading, “Do not sell my personal information.” Create the mandatory opt-out page and preferably link to it in your footer as well as your privacy policy.

Californian consumers have the right to have their data that has been collected by the company deleted, and therefore to “be forgotten.” In certain cases, you do not have to comply with this obligation to delete, namely if it was necessary for your company to continue maintaining the requested data to detect security incidents, comply with legal obligations, or the like, as described in Section 1798.105. Make sure your IT team knows exactly where personal data is stored and how to delete it in a CCPA-compliant manner.

Need to ensure CCPA compliance? Sign up for a free trial of Cookie Information CMP.

Does your website collect personal data from California residents? Let's help you collect valid consent

Cookie Information CMP offers a CCPA compliance solution that simplifies the process of complying with the California privacy law. Our cookie consent management platform (CMP) automatically scans your website to detect all cookies and tracking technologies in use. This data is then used to populate your cookie banner and notice, ensuring your website visitors receive the required accurate and transparent privacy information. 

By displaying a fully compliant CCPA consent banner, you can meet CCPA requirements while also aligning with other global privacy regulations, including GDPR, LGPD, and PDPA.

What’s included in Cookie Information CMP?

Automated scanning

to detect cookies and trackers on your website.

Compliant consent banners

that allow users to opt out.

Integration with Global Privacy Control (GPC)

for universal opt-outs.

Customizable

cookie consent popup to match your website design.

Automated privacy policy

updates to reflect new legal requirements.

Secure consent storage

and audit logs for regulatory compliance.

Experience it for yourself

Try Cookie Information CMP for 14 days – free of charge! No credit card required.

Frequently asked questions

What is CCPA compliance?

CCPA compliance refers to adherence to the California Consumer Privacy Act, which requires businesses to protect consumer privacy, including data transparency, consumer rights management, and security measures. Compliance with the CCPA ensures your company provides the necessary disclosures, allows opt-out options, and responds to consumer data requests.

Why was the CCPA introduced?

The California Consumer Privacy Act (CCPA) was introduced to enhance consumer data privacy rights and increase transparency in how businesses collect, use, and share personal information. It was designed to give California residents more control over their personal data in response to growing concerns about data privacy and misuse.

When did the CCPA go into effect?

The CCPA went into effect on January 1, 2020, and enforcement began on July 1, 2020. The California Privacy Rights Act (CPRA) later amended and strengthened the CCPA, with its provisions fully enforceable as of July 1, 2023.

Who must comply with the CCPA?

Businesses operating in California that meet any of the following criteria:​

  • Annual gross revenues exceeding $25 million.
  • Buy, receive, sell, or share personal information of 100,000 or more consumers or households.
  • Derive 50% or more of annual revenues from selling consumers’ personal information.
What is the CCPA threshold?

Businesses must comply with the CCPA if they meet at least one of the following criteria:

  • Have annual gross revenue exceeding $25 million.
  • Buy, receive, sell, or share personal information of 100,000 or more California residents or households.
  • Derive 50% or more of their annual revenue from selling or sharing consumers’ personal information.
Does CCPA compliance affect businesses outside of California?

Yes, any business that collects personal information from California residents and meets the applicability criteria must comply, regardless of its physical location.

What are the privacy rights consumers have under the CCPA?

The CCPA grants California residents the following key data privacy rights:

  • Right to know what personal data is collected and how it’s used.
  • Right to delete personal data held by businesses.
  • Right to opt out of the sale or sharing of personal data.
  • Right to non-discrimination for exercising their privacy rights.
  • Right to correct inaccurate personal data (added by CPRA).
  • Right to limit the use of sensitive personal information (added by CPRA).
What are CCPA compliance requirements?

CCPA requires businesses to: 

  • Notify consumers about data collection at or before the point of collection.
  • Provide a “Do Not Sell or Share My Personal Information” link.
  • Respond to consumer requests for data access, deletion, and opt-out.
  • Honor Global Privacy Control (GPC) signals for opt-out requests.
  • Update privacy policies with clear disclosures on data usage.
  • Ensure data security measures to protect against breaches.
What is CCPA website compliance?

CCPA website compliance involves properly informing website visitors about data collection, providing an opt-out option, and ensuring that cookies and tracking technologies respect user privacy preferences. Businesses must display a compliant cookie consent banner, update their privacy policy, and integrate a Global Privacy Control (GPC) mechanism.

Under the CCPA, cookies that collect personal information are subject to compliance. Businesses must inform users about data collection via cookies and provide opt-out mechanisms if the data is sold. This can be done, for example, via a website cookie consent banner that respects CCPA text requirements.

Unlike the GDPR, which requires explicit opt-in consent for cookies, the CCPA/CPRA does not mandate cookie banners by default. However, businesses that sell or share personal data must:

  • Provide a “Do Not Sell or Share My Personal Information” link to allow consumers to opt out.
  • Honor Global Privacy Control (GPC) signals, which allow users to opt out of data sales via browser settings.
  • Disclose cookie and tracking technologies in their privacy policy and explain how data is used.

While cookie consent banners are not explicitly required, many businesses use them to ensure transparency and simplify compliance by allowing users to manage tracking preferences.

How to be CCPA compliant?

You can achieve CCPA compliance by:

  • Conducting a data audit to understand what personal information is collected.
  • Implementing a compliant cookie consent solution that respects user preferences.
  • Updating privacy policies with required CCPA disclosures.
  • Setting up processes for handling consumer requests (access, deletion, opt-out).
  • Providing a clear opt-out mechanism, such as a “Do Not Sell My Personal Information” link.
  • Ensuring contracts with third-party service providers include CCPA compliance terms.
What is the best CCPA compliance solution?

The best CCPA compliance software depends on your business needs, but a cookie consent management platform (CMP) like Cookie Information CMP can help you automate the process. Key features include:

  • Automated website cookie scanning to detect trackers.
  • Compliant cookie banners that allow users to opt out.
  • Integration with Global Privacy Control (GPC) for universal opt-outs.
  • Consent storage and audit logs for regulatory compliance.
  • Automatic privacy policy updates to reflect new legal requirements.

By using a reliable CCPA compliance solution like our website cookie banner, you can streamline the compliance process while improving consumer trust and transparency.

How can businesses comply with the CCPA’s opt-out requirements?

Businesses that sell or share personal data must provide a clear and accessible “Do Not Sell or Share My Personal Information” link on their website. They must also honor Global Privacy Control (GPC) signals, which allow users to set privacy preferences in their browser that apply across all websites.

What are the penalties for noncompliance with the CCPA?

Businesses that fail to comply with the CCPA can face fines of:

  • $2,500 per unintentional violation
  • $7,500 per intentional violation

Additionally, the law allows consumers to sue businesses in the case of a data breach due to inadequate security measures.

How does CCPA compliance differ from GDPR compliance?

While both laws aim to protect consumer privacy, key differences include:​

  • Scope: GDPR applies to all EU residents, whereas CCPA applies to California residents.
  • Consent: GDPR requires opt-in consent for data collection; CCPA allows opt-out.
  • Penalties: GDPR imposes higher fines compared to CCPA.
Does CCPA apply to mobile apps?

Yes, CCPA applies to apps if they meet the law’s applicability thresholds.

How does CCPA affect mobile apps?

Apps that collect personal information, such as user behavior, location data, or device identifiers, must comply with CCPA by:

  • Providing a privacy notice explaining data collection.
  • Allowing users to request access, deletion, or opt-out of data sales.
  • Including a “Do Not Sell or Share My Personal Information” link if data is sold or shared.
  • Honoring Global Privacy Control (GPC) signals for opt-out requests.
  • Ensuring security measures to protect user data from breaches.

Even if an app does not sell data, it may still need to comply if it shares personal data with third parties for targeted advertising or analytics purposes.

There is no standalone “Cookie Act” in California, but cookies and online tracking are regulated under the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA). These laws govern how businesses collect, store, and share personal information, including personal data collected through cookies.

Under the CCPA/CPRA, cookies that collect personal information (such as IP addresses, browsing behavior, and device identifiers) must be disclosed, and consumers must be given the option to opt out of the sale or sharing of their personal data.

What is a CCPA compliance checklist?

A CCPA compliance checklist is a tool that outlines the steps you must take to comply with the CCPA, including data mapping, updating privacy policies, implementing consumer rights processes, and training employees.

What are CCPA cookies?

CCPA cookies refer to cookies that collect personal information and are subject to CCPA regulations. These include tracking cookies, analytics cookies, and advertising cookies that store user behavior, preferences, and identifiers.

What is the difference between CCPA cookies and GDPR cookies?
  • Under the CCPA, cookies can be used by default, but users must have the option to opt out if their data is sold or shared.
  • Under GDPR, websites must obtain explicit opt-in consent before storing non-essential cookies, making it a stricter regulation for cookie compliance.