California Cookie Law Requirements and Consumer Rights

The California cookie law is not a single statute or a banner requirement. It is the set of rules under the California Consumer Privacy Act, as expanded by the California Privacy Rights Act, that govern how businesses collect and use personal information through cookies and other tracking tools. Unlike Europe, California does not require you to click “accept” before a site can begin tracking you. Instead, covered businesses must tell you what they collect, let you opt out of the sale or sharing of your data, and honor that choice within a set time.

Opt-Out, Not Opt-In

If you have visited a European site and been stopped by a consent banner before the page loads, that is the General Data Protection Regulation at work. The GDPR requires opt-in consent, so tracking cannot begin until you agree. California uses the opposite model. Under the CCPA and CPRA, a business can start collecting personal information through cookies immediately, but it has to disclose what it is doing, give you a way to stop the sale or sharing of your data, and act on your request promptly.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

So California law does not actually mandate a cookie consent banner. What it does mandate is a conspicuous homepage link titled “Do Not Sell or Share My Personal Information” and, for sites that collect sensitive data, a second link titled “Limit the Use of My Sensitive Personal Information.” Many businesses run banners anyway because they also serve European visitors or because a banner is a convenient way to surface the required choices. The banner itself is not the legal requirement.

Which Businesses Have to Follow the Rules

The rules apply to for-profit entities that do business in California and meet at least one of three thresholds. A business is covered if it had annual gross revenue over $26,625,000 in the preceding calendar year, the current inflation-adjusted figure.2California Privacy Protection Agency. Updated Monetary Thresholds in CCPA It is also covered if it buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or if it makes 50 percent or more of its annual revenue from selling or sharing personal data.3California Legislative Information. California Civil Code 1798.140 – Definitions

Physical location does not matter. A company based anywhere that collects data from California residents and hits one of those benchmarks is subject to the law. That pulls in businesses that would not think of themselves as data companies. A retailer with a loyalty program tracking purchases across 100,000 California households, for example, is covered even if it never sells the data.

What a Website Has to Tell You

The core disclosure is the Notice at Collection, which must reach you at or before the moment a site begins gathering your personal information. If the notice is not provided before collection begins, the business cannot legally collect the data.4Cornell Law Institute. 11 CCR 7012 – Notice at Collection of Personal Information

The notice must cover:

  • The categories of personal information being collected, described in a way that gives you a real sense of what is being tracked (identifiers, browsing history, commercial activity, and so on).
  • The purpose for each category and how the data will be used, in plain language.
  • Whether any category is sold or shared with third parties, and if so, a link to the opt-out page.
  • How long the business plans to keep each category, or the criteria it uses to decide when data is deleted.5California Privacy Protection Agency. What General Notices Are Required By The CCPA

For online collection, the notice can be a link on the page where the data is gathered, written in straightforward language.

Your Rights Over Data Collected Through Cookies

California residents have six core rights over personal information that businesses collect through cookies and other tracking:1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

  • The right to know what a business has collected about you, where it came from, why, and who it was shared with. You can ask twice a year at no cost.
  • The right to delete personal information a business collected from you. The business must also direct its service providers to delete it, though exceptions exist for things like completing a transaction or meeting a legal obligation.
  • The right to correct inaccurate data a business holds about you.
  • The right to opt out of the sale of your personal information or its sharing for cross-context behavioral advertising, which means ads targeted based on your activity across multiple sites.
  • The right to limit use of sensitive personal information (Social Security numbers, financial account details, precise geolocation, biometrics, health data) to what is necessary to provide the service you asked for.
  • The right to equal treatment. A business cannot charge you more, give you worse service, or deny service because you exercised any of these rights.

A business cannot make you create an account just to exercise these rights. It can verify your identity to protect against unauthorized disclosure, but the process has to be simple enough that it does not discourage requests.

How to Opt Out

A business that sells or shares personal information has to post a homepage link titled “Do Not Sell or Share My Personal Information.” Clicking it should take you to a simple page where you can register your choice without extra steps. Sites that collect sensitive personal information beyond what is needed for the requested service also need a “Limit the Use of My Sensitive Personal Information” link. The two can be combined into a single “Your Privacy Choices” link if it covers both.

Beyond the manual links, businesses must recognize and honor Global Privacy Control signals from your browser. GPC is a technical standard that transmits a universal opt-out preference automatically, so you do not have to visit each site’s opt-out page.6Global Privacy Control. Global Privacy Control Under California law, a GPC signal is a legally valid opt-out request.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

Once a request comes in through either route, the business has a maximum of 15 business days to stop selling or sharing your information. If it happens to sell data after the request but before finishing processing, it has to tell the third-party recipients to stop using the data as well.

Banner Design and Dark Patterns

California law defines a dark pattern as a user interface designed or manipulated in a way that undermines your ability to make a real choice about your privacy. Consent obtained through a dark pattern does not count as consent.3California Legislative Information. California Civil Code 1798.140 – Definitions

The California Privacy Protection Agency has said businesses must offer symmetrical choices. In practice, the button to decline cookies or opt out has to be as prominent and easy to find as the button to accept.7California Privacy Protection Agency. CPPA Enforcement Advisory Stresses the Importance of Avoiding Dark Patterns A big colorful “Accept” button paired with a small “Decline” link buried behind a settings screen is exactly what the agency is targeting.

Other practices that risk being classified as dark patterns include pre-checked boxes that assume you want all cookies enabled, requiring more clicks to reject tracking than to accept it, and wording the decline option in a way designed to guilt you into consenting. Hovering over, muting, pausing, or closing a cookie banner does not count as consent, so a site that treats a dismissed banner as acceptance is violating the law. Businesses using third-party consent management platforms are still on the hook for how those interfaces are designed.

Extra Protection for Minors

Adults have to actively opt out to stop the sale or sharing of their data. For minors, the default flips. A business with actual knowledge that a consumer is under 16 cannot sell or share that person’s data without first getting affirmative opt-in consent. A teenager between 13 and 15 can give that consent themselves; for a child under 13, a parent or guardian has to authorize it.8California Legislative Information. California Civil Code 1798.120 – Consumers Right to Opt-Out of Sale or Sharing

A business that willfully ignores a consumer’s age is treated as though it knew. Violations involving minors’ data carry the higher penalty tier, the same rate as intentional violations by adults.

Penalties and Private Lawsuits

The California Privacy Protection Agency and the state Attorney General share enforcement authority. The original CCPA gave businesses a 30-day window to fix a violation before penalties applied. The CPRA got rid of that mandatory cure period on January 1, 2023, so regulators can bring enforcement actions immediately.

Fines are adjusted annually for inflation. As of the most recent adjustment, penalties run up to $2,663 per unintentional violation and up to $7,988 per intentional violation or any violation involving the data of a consumer the business knew was under 16.9California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties Because each violation is counted separately, a single practice affecting thousands of consumers can produce very large aggregate liability.

Consumers have a limited private right of action, but only when a data breach exposes their unencrypted personal information because a business failed to maintain reasonable security. Before suing for statutory damages, you have to give the business 30 days’ written notice identifying the violation. If the business genuinely fixes the problem and provides written assurance it will not recur, the suit for statutory damages is blocked. Improving security after a breach does not count as curing that specific incident. If the business does not fix the problem, statutory damages run from $100 to $750 per consumer per incident, or actual damages, whichever is greater.10California Legislative Information. California Civil Code 1798.150 – Personal Information Security Breaches Courts weigh the seriousness of the misconduct, the number of violations, and whether the business acted willfully when setting the amount within that range.