Skip to main content
Promotional banner for the pentest readiness checklist
Category: Laws and Regulations

California Consumer Privacy Act

Also known as: CCPA, California Consumer Privacy Act of 2018
Simply put

The California Consumer Privacy Act (CCPA) is a state privacy law in California that gives California residents certain rights over how businesses collect and use their personal information. It was passed in 2018 and took effect on January 1, 2020, and is often described as the first comprehensive consumer privacy law in the United States. It applies to organizations handling the personal data of California residents, and differs from EU-style privacy regimes in its approach.

Formal definition

The CCPA is a California state statute, enacted in 2018 and effective January 1, 2020, that establishes consumer privacy rights and corresponding obligations for covered businesses processing the personal information of California residents. In the cookie and tracking context, the CCPA's approach generally relies on an opt-out model (for example, a right to opt out of the sale or sharing of personal information) rather than the prior opt-in consent standard typically required under EU frameworks such as the ePrivacy Directive and GDPR. Practitioners should note that the CCPA's specific scope, applicability thresholds, definitions, and enforcement details are not fully covered by this evidence, and that the CCPA has been amended and expanded by the California Privacy Rights Act (CPRA); this entry does not address CPRA changes or the precise mechanics of CCPA compliance.

Why it matters

The CCPA is significant because, as it is often described, it was the first comprehensive consumer privacy law in the United States, establishing privacy rights for California residents and corresponding obligations for the businesses that handle their personal information. For organizations that operate globally or serve users in multiple jurisdictions, the CCPA marked a shift in the US toward statutory privacy protections that had previously been more characteristic of EU-style regimes, and it has shaped how many businesses approach data collection, tracking, and consumer choice in the American market.

For cookie and tracking compliance specifically, the CCPA matters because its approach differs meaningfully from EU frameworks. Rather than requiring prior opt-in consent before tracking technologies are deployed, the CCPA generally relies on an opt-out model, such as giving consumers a right to opt out of the sale or sharing of their personal information. This distinction has direct practical consequences for how organizations design consent banners, preference mechanisms, and back-end data flows, and it means that a compliance posture built solely around EU-style opt-in may not map cleanly onto CCPA obligations, and vice versa.

Because the CCPA has been amended and expanded by the California Privacy Rights Act (CPRA), practitioners should treat the CCPA as a foundational but evolving framework rather than a static one. The precise applicability thresholds, definitions, and enforcement mechanics are not fully addressed here, and organizations should consult current statutory text and qualified legal advice before drawing conclusions about their specific obligations.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for privacy programs need to understand that the CCPA generally follows an opt-out model that differs from EU-style opt-in requirements. This affects how consumer rights, such as the right to opt out of the sale or sharing of personal information, are operationalized for California residents, and how CCPA obligations sit alongside other regimes an organization may be subject to.
Legal counsel and compliance teams
Attorneys and compliance staff advising businesses that handle the personal information of California residents should note that the CCPA was enacted in 2018 and took effect on January 1, 2020, and that it has been amended and expanded by the CPRA. Because this entry does not address the precise applicability thresholds, definitions, or enforcement details, counsel should consult current statutory text before advising on specific obligations.
Web developers and marketing compliance teams
Teams building consent banners, preference centers, and tracking implementations should recognize that the CCPA's opt-out approach may require different mechanisms than EU-style opt-in consent flows. Designing for California residents may involve providing a means to opt out of the sale or sharing of personal information rather than obtaining prior affirmative consent before tracking technologies are deployed.

Inside CCPA

Scope and applicability
The CCPA is a California state privacy law that applies to certain for-profit businesses meeting statutory thresholds and that collect personal information from California residents. It does not apply universally across the United States, and other states have enacted their own separate frameworks.
Opt-out model
Unlike the EU's prior opt-in consent standard for non-essential cookies, the CCPA generally relies on an opt-out approach, allowing consumers to direct businesses not to sell or share their personal information rather than requiring affirmative consent before processing in most cases.
Do Not Sell or Share right
The CCPA provides California consumers with a right to opt out of the sale or sharing of their personal information, which can be relevant where cookies, pixels, or similar tracking technologies transfer data to third parties. The precise scope of what constitutes a sale or share depends on the facts.
Consumer rights
The CCPA grants California residents rights such as access to, deletion of, and information about personal information collected. These rights may extend to data collected through cookies and similar technologies where that data constitutes personal information under the statute.
Relationship to opt-out signals
The CCPA framework contemplates honoring user-enabled opt-out preference signals, such as the Global Privacy Control, though implementation details and enforcement positions continue to evolve.
CPRA amendments
The California Privacy Rights Act (CPRA) amended and expanded the CCPA, including the concept of sharing for cross-context behavioral advertising. The two are often referenced together when describing California's current privacy regime.

Common questions

Answers to the questions practitioners most commonly ask about CCPA.

Does the CCPA require an opt-in cookie consent banner like the EU model?
Generally, no. Unlike the EU regime, where valid consent must typically be obtained before non-essential cookies are placed, the CCPA (as amended by the CPRA) primarily operates on an opt-out model. Businesses within scope generally must give California consumers the ability to opt out of the sale or sharing of their personal information rather than collect prior affirmative consent for most cookie use. Note that opt-in consent may be required in specific situations, such as for minors, so this is not a universal rule even within California. The precise obligations depend on the facts and on evolving regulatory guidance.
Does complying with the CCPA mean I am also compliant with the GDPR and ePrivacy rules?
No. The CCPA governs the handling of personal information of California consumers under a US state framework, and it does not satisfy EU obligations. In most EU jurisdictions, the ePrivacy Directive as nationally implemented governs the placing of and access to cookies and similar technologies (typically requiring prior consent), while the GDPR governs the subsequent processing of personal data. These regimes use different consent standards and lawful bases, so meeting one does not automatically meet the other. Organizations operating across regions generally need to assess each applicable framework separately.
Which businesses are actually subject to the CCPA?
The CCPA applies to certain for-profit businesses that do business in California and meet specified thresholds relating to factors such as revenue, the volume of consumers or households whose personal information is processed, or the share of revenue derived from selling or sharing personal information. Because the exact thresholds and their interpretation can change and depend on your specific circumstances, you should confirm scope against the current statutory text and any applicable regulatory guidance rather than relying on a general summary. This entry does not determine whether any particular organization is in scope.
How should the opt-out of sale or sharing be implemented for cookies on a website?
In practice, businesses within scope typically provide a clearly identified opt-out mechanism, such as a link commonly framed around opting out of the sale or sharing of personal information, and configure their cookie and tag management so that opting out actually stops the relevant data flows to third parties. Because cookies, pixels, SDKs, and similar tracking technologies can all involve sharing personal information, the opt-out generally needs to reach those technologies and not only literal cookies. The specific design and wording should be checked against current requirements, as regulatory expectations continue to evolve.
Do we need to honor Global Privacy Control (GPC) signals under the CCPA?
Recognition of browser-based opt-out preference signals such as Global Privacy Control has been treated as an important part of honoring opt-out rights in the California context. Implementing this generally requires detecting the signal and applying the resulting opt-out to relevant cookies and tracking technologies for that consumer. Because the technical and legal expectations around opt-out preference signals continue to develop, you should confirm the current requirements and how a consent management platform or your own tooling detects and applies these signals; a tool can support this but does not by itself guarantee compliance.
What role does a consent management platform (CMP) play in CCPA implementation?
A CMP can support CCPA-related implementation by presenting opt-out choices, detecting opt-out preference signals, controlling when cookies and tags fire, and maintaining records of consumer preferences. However, a CMP supports compliance rather than establishing it; correct configuration, accurate mapping of data flows, and legal judgment about scope and obligations remain essential. Whether a given CMP setup meets CCPA requirements depends on facts specific to your business and on current regulatory guidance, so it should not be assumed to be sufficient on its own.

Common misconceptions

CCPA compliance means you must obtain opt-in cookie consent like in the EU.
The CCPA generally follows an opt-out model rather than the prior affirmative opt-in consent standard applied to non-essential cookies in most EU jurisdictions. Meeting CCPA obligations does not automatically satisfy EU requirements under the ePrivacy Directive and GDPR, and vice versa. Businesses operating across regions typically need to address each framework separately.
The CCPA is a nationwide US privacy law.
The CCPA is a California state law that applies to businesses meeting its thresholds in relation to California residents. Other US states have enacted their own distinct privacy laws, so obligations vary by state and should not be treated as uniform across the United States.
Deploying a consent management platform (CMP) makes a business CCPA-compliant.
A CMP can support compliance by managing opt-out choices, honoring preference signals, and maintaining records, but it does not by itself guarantee compliance. Legal judgment is still required to determine applicability, what counts as a sale or share, and how consumer rights are handled based on the specific facts.

Best practices

Assess whether the CCPA applies to your organization based on the statutory thresholds and your handling of California residents' personal information before assuming obligations or exemptions.
Implement and clearly present a mechanism for consumers to opt out of the sale or sharing of personal information where cookies, pixels, or similar tracking technologies transfer data to third parties.
Configure your consent or preference management tooling to recognize and honor user-enabled opt-out preference signals such as the Global Privacy Control, monitoring evolving guidance on implementation.
Treat CCPA obligations separately from EU ePrivacy and GDPR requirements, and do not assume that satisfying one framework's opt-out or opt-in standard satisfies the other.
Account for CPRA amendments, including concepts such as sharing for cross-context behavioral advertising, when scoping your tracking technologies and disclosures.
Maintain records of opt-out requests and preference handling, and involve legal counsel to interpret contested points such as what constitutes a sale or share for your specific data flows.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide