The California Consumer Privacy Act (CCPA) is California’s main consumer privacy law. It gives California residents rights over personal information that covered businesses collect about them, sets rules for how businesses describe, use, sell and share that information, and requires reasonable security. The California Privacy Rights Act (CPRA), approved by voters in 2020, amended the CCPA rather than replacing it, so most people now mean “the CCPA as amended.” This entry is an overview for buyers, not legal advice.
At a glance
- It applies to for-profit businesses that do business in California and meet at least one threshold based on revenue, data volume or revenue from selling or sharing personal information.
- Residents can ask to know, delete and correct their data, opt out of its sale or sharing, and limit use of sensitive personal information.
- Vendors that process data for you need the required contract terms and must actually stay within service provider or contractor limits; otherwise a disclosure can count as selling or sharing.
- The California Attorney General and the California Privacy Protection Agency (CPPA) both enforce it; individuals can generally sue only over certain data breaches.
- Newer regulations add cybersecurity audits, risk assessments and rules on automated decision-making for some businesses, phased in over several years.
What problem it solves
Before the CCPA, most US companies could collect, combine and sell consumer data with little disclosure and no obligation to delete it on request. The law gives Californians a way to see what a business holds, stop it being sold or shared for cross-context advertising, and have much of it erased.
For a mid-market buyer, it shows up in practical ways: a website that uses ad and analytics tags, a CRM full of California contacts, a contact center that records calls, an HR platform holding California employees’ records. Each one raises the same questions about what personal information is collected, which vendors receive it, and on what contract terms.
How it works
Coverage. A business is covered if it meets any one threshold. The revenue threshold is adjusted periodically for inflation, so check the current figure with the CPPA. Nonprofits and government agencies are generally outside it.
Notices and rights. Covered businesses publish a privacy policy and give notice at collection. They must handle requests to know, delete and correct, honor opt-outs of selling or sharing (including browser-based opt-out signals), and offer a way to limit use of sensitive personal information such as precise location or account credentials.
Contracts down the chain. Data passed to vendors needs the contract terms the CCPA specifies, such as limiting the vendor to the stated business purposes, barring it from selling or sharing the data or combining it with other data except as permitted, and having it certify that it understands the restrictions. The contract alone is not enough: the vendor’s actual use, retention and disclosure must stay within those limits for it to qualify as a service provider or contractor and for the transfer not to be treated as a sale or sharing.
Security and breaches. Businesses must use reasonable security. Where a breach of certain unencrypted personal information results from a failure to do so, affected consumers can sue for damages; a claim for statutory damages generally requires first giving the business notice and a chance to cure.
Audits and assessments. CPPA regulations effective in 2026 require some businesses to carry out annual cybersecurity audits by a qualified, independent auditor (internal or external) and to file certifications, and to conduct risk assessments for higher-risk processing.
Roles and audit tiers
The CCPA has no certification levels. Its structure is a set of roles plus, for cybersecurity audits, a revenue-based phase-in.
| Role or tier | Who it applies to | What is required | Typical evidence |
|---|---|---|---|
| Business | For-profit entity that meets a threshold and decides why and how personal information is processed | Notices, consumer request handling, opt-outs, reasonable security, vendor contracts | Privacy policy, request metrics, data inventory |
| Service provider or contractor | Vendor processing data for a business under the required written contract, within the CCPA’s limits | Use, retain and disclose data only for the contracted business purposes; no selling, sharing or combining except as permitted; help the business respond to requests | CCPA contract terms, plus evidence of how the vendor actually uses the data |
| Third party | Recipient not acting within service provider or contractor limits | Disclosures to it can be a sale or sharing, subject to opt-out | Contract terms, opt-out records |
| Cybersecurity audit, first round | Businesses meeting the significant-risk tests, phased by revenue size | Independent audit and an executive’s certification filed with the CPPA | Audit report, certification |
When it matters for buyers
- When choosing SaaS, cloud, CCaaS or marketing vendors. Each one that touches California personal information needs service provider or contractor terms, and processing that actually stays within them.
- When adding ad tech or analytics. Tracking tags can turn routine website traffic into sharing that consumers may opt out of.
- When you cross a threshold. Growth or an acquisition can bring a company into scope, sometimes without anyone noticing.
- When audit or assessment duties may apply. Providers’ own security evidence helps feed your audit.
Our governance, risk and compliance overview covers advisors and tools that map privacy obligations to controls.
Questions to ask vendors
- Will you sign CCPA service provider or contractor terms, and how do you make sure your actual use, retention and disclosure of our data stay within them?
- Do you use our data, even de-identified, to improve your own products or for advertising?
- How do you help us answer requests to know, delete and correct, and how fast?
- Which subprocessors receive our data, and how will we be told about changes?
- What security evidence can you share, and is it scoped to the service we’d buy?
- How quickly will you notify us of a breach involving our customers’ data?
How it differs from GDPR
The General Data Protection Regulation (GDPR) requires a lawful basis before personal data is used at all. The CCPA largely lets businesses collect data with notice and focuses on transparency, opt-outs from selling and sharing, and individual rights. Both cover broader data than many US definitions of personally identifiable information (PII), and both expect contracts with processors, but the terms, thresholds and enforcement differ, so a GDPR program does not automatically satisfy the CCPA. Canada’s PIPEDA is a consent-based law closer to GDPR’s model. Within a governance, risk and compliance (GRC) program, the CCPA sits alongside breach-notification laws and broader data security compliance duties; a data breach can trigger several at once.
