ResearchState Privacy Laws › California
CALIFORNIA · STATE RESEARCH PROFILE

California Consumer Privacy Act (CCPA), as amended by the CPRA

CCPA / CPRA · Normalized Research Card v2.1

IN FORCELAST VERIFIED · AUG 26 2026

At a glance

ScopeRevenue / volume / sale-share thresholds
ThresholdCurrent statutory thresholds are adjusted periodically; verify against CPPA's current monetary-threshold publication.
Sensitive dataSpecial sensitive-personal-information rights; 2026 regulations add ADMT, risk-assessment and cybersecurity-audit requirements.
Universal opt-outYes / opt-out preference signals
EnforcementCalifornia Privacy Protection Agency + Attorney General
Private actionLimited — specified security breaches
PenaltyIndexed statutory penalties; see current CPPA threshold publication
EffectiveJanuary 1, 2020; major CPRA provisions January 1, 2023

Who must comply?

Applicability model: Revenue / volume / sale-share thresholds.

Core threshold: Current statutory thresholds are adjusted periodically; verify against CPPA's current monetary-threshold publication.

Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.

Consumer rights

Right / protectionStatus
Access / know✓ Included / qualified by statute
Correction✓ Included / qualified by statute
Deletion✓ Included / qualified by statute
Portability✓ Included / qualified by statute
Opt-out of sale or sharing✓ Included / qualified by statute
Limit certain uses/disclosures of sensitive PI✓ Included / qualified by statute
ADMT access / opt-out under 2026 regulations✓ Included / qualified by statute

Sensitive data & minors

Sensitive-data standard: Special sensitive-personal-information rights; 2026 regulations add ADMT, risk-assessment and cybersecurity-audit requirements.

Heightened rules apply to sale/sharing involving consumers under 16; additional child/teen issues are part of California's broader privacy framework.

Business obligations

Detailed notices, request handling, contracts, data minimization/purpose controls, opt-out preference signals, and — for covered businesses — phased risk assessment, cybersecurity audit and ADMT duties.

Enforcement

Authority: California Privacy Protection Agency + Attorney General

Private right of action: Limited — specified security breaches

Penalty / remedy baseline: Indexed statutory penalties; see current CPPA threshold publication

What makes California different?

California is structurally different from the other states: it has a dedicated privacy regulator, an extensive regulatory code, a data-broker/Delete Act layer and 2026 regulations covering automated decisionmaking technology, risk assessments and cybersecurity audits.

Developments to watch

2026 CCPA regulations and Delete Act/DROP rules are in force. CPPA also lists preliminary rulemaking topics separately; preliminary activity is not current law.

Editorial rule: future-effective, proposed and pending measures are kept separate from current law.

Primary sources & verification

Last verified: August 26, 2026

Research standard: primary official sources prioritized; official guidance used to explain operational requirements.

← ALL STATE PRIVACY LAWS

  Colorado →

USDataLaws.com provides independent legal and regulatory research for informational purposes. It does not provide legal advice. Laws, regulations and enforcement positions may change after the stated verification date.