California Consumer Privacy Act
The California Consumer Privacy Act (CCPA) is a state privacy law in California that gives California residents certain rights over how businesses collect and use their personal information. It was passed in 2018 and took effect on January 1, 2020, and is often described as the first comprehensive consumer privacy law in the United States. It applies to organizations handling the personal data of California residents, and differs from EU-style privacy regimes in its approach.
The CCPA is a California state statute, enacted in 2018 and effective January 1, 2020, that establishes consumer privacy rights and corresponding obligations for covered businesses processing the personal information of California residents. In the cookie and tracking context, the CCPA's approach generally relies on an opt-out model (for example, a right to opt out of the sale or sharing of personal information) rather than the prior opt-in consent standard typically required under EU frameworks such as the ePrivacy Directive and GDPR. Practitioners should note that the CCPA's specific scope, applicability thresholds, definitions, and enforcement details are not fully covered by this evidence, and that the CCPA has been amended and expanded by the California Privacy Rights Act (CPRA); this entry does not address CPRA changes or the precise mechanics of CCPA compliance.
Why it matters
The CCPA is significant because, as it is often described, it was the first comprehensive consumer privacy law in the United States, establishing privacy rights for California residents and corresponding obligations for the businesses that handle their personal information. For organizations that operate globally or serve users in multiple jurisdictions, the CCPA marked a shift in the US toward statutory privacy protections that had previously been more characteristic of EU-style regimes, and it has shaped how many businesses approach data collection, tracking, and consumer choice in the American market.
For cookie and tracking compliance specifically, the CCPA matters because its approach differs meaningfully from EU frameworks. Rather than requiring prior opt-in consent before tracking technologies are deployed, the CCPA generally relies on an opt-out model, such as giving consumers a right to opt out of the sale or sharing of their personal information. This distinction has direct practical consequences for how organizations design consent banners, preference mechanisms, and back-end data flows, and it means that a compliance posture built solely around EU-style opt-in may not map cleanly onto CCPA obligations, and vice versa.
Because the CCPA has been amended and expanded by the California Privacy Rights Act (CPRA), practitioners should treat the CCPA as a foundational but evolving framework rather than a static one. The precise applicability thresholds, definitions, and enforcement mechanics are not fully addressed here, and organizations should consult current statutory text and qualified legal advice before drawing conclusions about their specific obligations.
Who it's relevant to
Inside CCPA
Common questions
Answers to the questions practitioners most commonly ask about CCPA.

