CCPA/CPRA · Opt-out model

California Privacy Law (CCPA & CPRA): Compliance Guide

California wrote the playbook for American privacy law. The California Consumer Privacy Act took effect January 1, 2020 as the first comprehensive state privacy statute in the country, and the California Privacy Rights Act amendments that followed on January 1, 2023 made it stricter still. If your site has meaningful US traffic, this is almost certainly the law you build for first: it created the “Do Not Sell or Share My Personal Information” link now seen across the web, it has its own dedicated enforcement agency, and it is the only state where consumers can sue directly after a data breach.

Effective
January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)
GPC / universal opt-out
Required — 11 CCR §7025
Required link text
Do Not Sell or Share My Personal Information
Handle CCPA/CPRA compliance free

Last reviewed July 19, 2026 · Cal. Civ. Code §1798.100 et seq.; GPC obligation: 11 CCR §7025

Applicability

Who must comply with the CCPA/CPRA

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) applies to businesses that meet the following criteria:

  • Does business in California, and meets at least one of the following:
  • Annual gross revenue above $25 million
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households
  • Derives 50% or more of annual revenue from selling consumers' personal information

Consumer rights

What California consumers can demand

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to correct inaccurate personal information
  • Right to limit the use of sensitive personal information

Opt-out mechanics

California opt-out & GPC requirements

Like every US state privacy law, the CCPA/CPRA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for California is Do Not Sell or Share My Personal Information.

Global Privacy Control: Required — 11 CCR §7025

California regulation 11 CCR §7025 requires covered businesses to honor Global Privacy Control as a valid consumer opt-out of the sale and sharing of personal information — no click required.

Enforcement

CCPA/CPRA penalties & enforcement

  • Up to $2,500 per violation
  • Up to $7,500 per intentional violation
  • $100–$750 per consumer per incident after a data breach, through the private right of action

Cure period: Our reference lists no general cure period. Enforcement runs through the California Privacy Protection Agency and the Attorney General.

State quirks

What makes California different

Three things set California apart from every state that followed. It has the country's only dedicated privacy regulator, the California Privacy Protection Agency, which writes its own detailed regulations. It is the only state whose law gives consumers a private right of action — $100 to $750 per consumer per incident after a data breach, which multiplies fast at scale. And its rulebook keeps moving: a visible opt-out confirmation and a recognizable privacy icon next to the opt-out link both took effect in 2026, with mandatory risk assessments and cybersecurity audits for covered businesses alongside them.

Opt-out confirmation (2026)

Businesses must show a visible confirmation when an opt-out request has been processed, effective January 1, 2026.

Two-click maximum

The opt-out process must be as easy as the opt-in process — no more than two clicks to complete.

Privacy icon (2026)

The opt-out link must appear next to a recognizable privacy icon, effective 2026.

Minors under 16

Selling or sharing a minor's personal information requires opt-IN consent; under 13 requires verifiable parental consent.

Risk assessments and audits

Risk assessments are required for processing that presents significant privacy risk, and cybersecurity audits are mandatory for covered businesses.

Automation

How ConsentKit handles California

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so California visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • California visitors see a persistent Do Not Sell or Share My Personal Information link — the exact statutory text — available to new and returning visitors alike.
  • Because California requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for California visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a California visitor makes a choice.

For California visitors, ConsentKit uses the exact statutory link text “Do Not Sell or Share My Personal Information” — the only state where that wording, rather than “Your Privacy Choices,” is the safe default.

FAQ

California CCPA/CPRA FAQ

Does the CCPA apply to my business?

It applies if you do business in California and meet any one of three thresholds: annual gross revenue above $25 million; buying, selling, or sharing the personal information of 100,000 or more California consumers or households; or deriving 50% or more of annual revenue from selling personal information. Meeting a single prong is enough.

Do I need a cookie banner in California?

No. California uses an opt-out model, so a GDPR-style consent banner is not required. The legal minimum is a conspicuous “Do Not Sell or Share My Personal Information” link — and from 2026, a recognizable privacy icon next to it. Some sites add a banner for user experience, but the link is what the law demands.

Does California require honoring Global Privacy Control?

Yes. Under 11 CCR §7025, a browser's Global Privacy Control signal counts as a valid opt-out of the sale and sharing of personal information, and covered businesses must honor it with no click required. ConsentKit detects the signal automatically for California visitors and records the resulting opt-out.

What are the penalties for violating the CCPA?

Civil penalties run up to $2,500 per violation and up to $7,500 per intentional violation. California is also the only state with a private right of action: after a data breach, consumers themselves can sue for $100 to $750 per consumer per incident.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the CCPA/CPRA.

Comply with California's CCPA/CPRA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.