California Consumer Privacy Act (CCPA), as amended by the CPRA
CCPA / CPRA · Normalized Research Card v2.1
IN FORCELAST VERIFIED · AUG 26 2026At a glance
Who must comply?
Applicability model: Revenue / volume / sale-share thresholds.
Core threshold: Current statutory thresholds are adjusted periodically; verify against CPPA's current monetary-threshold publication.
Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.
Consumer rights
| Right / protection | Status |
|---|---|
| Access / know | ✓ Included / qualified by statute |
| Correction | ✓ Included / qualified by statute |
| Deletion | ✓ Included / qualified by statute |
| Portability | ✓ Included / qualified by statute |
| Opt-out of sale or sharing | ✓ Included / qualified by statute |
| Limit certain uses/disclosures of sensitive PI | ✓ Included / qualified by statute |
| ADMT access / opt-out under 2026 regulations | ✓ Included / qualified by statute |
Sensitive data & minors
Sensitive-data standard: Special sensitive-personal-information rights; 2026 regulations add ADMT, risk-assessment and cybersecurity-audit requirements.
Heightened rules apply to sale/sharing involving consumers under 16; additional child/teen issues are part of California's broader privacy framework.
Business obligations
Detailed notices, request handling, contracts, data minimization/purpose controls, opt-out preference signals, and — for covered businesses — phased risk assessment, cybersecurity audit and ADMT duties.
Enforcement
Authority: California Privacy Protection Agency + Attorney General
Private right of action: Limited — specified security breaches
Penalty / remedy baseline: Indexed statutory penalties; see current CPPA threshold publication
What makes California different?
California is structurally different from the other states: it has a dedicated privacy regulator, an extensive regulatory code, a data-broker/Delete Act layer and 2026 regulations covering automated decisionmaking technology, risk assessments and cybersecurity audits.
Developments to watch
2026 CCPA regulations and Delete Act/DROP rules are in force. CPPA also lists preliminary rulemaking topics separately; preliminary activity is not current law.
Editorial rule: future-effective, proposed and pending measures are kept separate from current law.
Primary sources & verification
- California Privacy Protection Agency — Laws & Regulations
- CPPA — 2026 CCPA / ADMT / Cybersecurity Regulations
Last verified: August 26, 2026
Research standard: primary official sources prioritized; official guidance used to explain operational requirements.