CCPA Compliance Requirements: Rights, Contracts, and Penalties

To comply with the California Consumer Privacy Act, a covered business must give California residents clear notice of what personal information it collects, honor six consumer rights within 45 days, bind its vendors with specific contract terms, and — as of January 1, 2026 — document risk assessments for high-risk processing and complete an annual cybersecurity audit when thresholds apply. Falling short can cost up to $7,500 per violation, and there is no mandatory grace period to fix problems before fines attach. The CCPA compliance requirements below walk through who is covered, what you must do, and where enforcement risk concentrates.

Who the Law Covers

The CCPA reaches for-profit businesses that collect personal information from California residents and meet any one of three thresholds. The first is gross annual revenue above $26.625 million in the preceding calendar year, a figure adjusted periodically for inflation. The second catches any company that annually buys, sells, or shares the personal information of 100,000 or more California residents or households. The third captures businesses of any size that earn 50 percent or more of their annual revenue from selling or sharing personal information.1California Privacy Protection Agency. Frequently Asked Questions (FAQs)

The law also reaches entities that control or are controlled by a covered business, and certain joint ventures composed of covered businesses.1California Privacy Protection Agency. Frequently Asked Questions (FAQs) Reassess annually. Growth in revenue or data volume can pull a company under the law the next year.

What Counts as Personal Information

Personal information under the CCPA is anything that identifies, relates to, or could reasonably be linked to a particular consumer or household. That covers names, email addresses, Social Security numbers, IP addresses, purchase histories, browsing activity, geolocation data, biometric information, employment records, and inferences drawn to build a consumer profile.2California Legislative Information. California Code CIV 1798.140 – Definitions

A subset receives heightened protection as sensitive personal information:

  • Government identifiers such as Social Security, passport, and driver’s license numbers
  • Account log-in details combined with passwords or security codes
  • Precise geolocation
  • Racial or ethnic origin, citizenship or immigration status, religious beliefs, and union membership
  • Contents of emails, texts, and messages not directed to the business
  • Biometric and genetic data, including fingerprints, facial recognition data, DNA, and neural data
  • Health, sex life, or sexual orientation

Consumers can restrict how a business uses these categories, so any company collecting them needs a separate disclosure and opt-out mechanism.3State of California – Privacy Protection Agency. What Is Personal Information?

Notice at Collection and Privacy Policy

Before collecting any personal information, a business must provide a notice at collection that identifies the categories being gathered, the purposes for collecting or using each category, and whether the information will be sold or shared. Sensitive personal information gets its own disclosure within that same notice. The notice must also state how long each category will be kept, or the criteria used to decide.4California Legislative Information. California Code CIV 1798.100 – General Duties of a Business That Collects Personal Information Collecting new categories, or repurposing existing data for incompatible uses, requires a fresh notice.

Beyond that, the business must publish a full privacy policy listing categories collected in the preceding twelve months, categories of third parties that received data, and the business or commercial purposes behind each disclosure. If the business sells personal information, the policy must identify what is sold and who receives it. The policy must be refreshed at least every twelve months, linked from the homepage, and formatted so consumers with disabilities can access it.5California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements

Consumer Rights You Must Honor

California residents hold six rights, and every covered business needs a process for each one.

Right to know. Consumers can request the specific pieces of personal information collected about them, the categories of sources, the purposes, and the categories of third parties that received the data. The response is free and delivered in a portable, readily usable format.4California Legislative Information. California Code CIV 1798.100 – General Duties of a Business That Collects Personal Information

Right to delete. A verified deletion request obliges the business to erase the data from its records and to direct its service providers, contractors, and any third parties it sold or shared the information with to do the same.6California Legislative Information. California Code CIV 1798.105 – Consumers Right to Delete Personal Information Denial is allowed in narrow situations: the data is needed to complete a transaction or honor a warranty, for security purposes, to comply with a legal obligation or defend a legal claim, or the business cannot verify the requester’s identity.7State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

Right to correct. If a business holds inaccurate personal information, the consumer can direct a correction and the business must use commercially reasonable efforts to make it.8California Legislative Information. California Code CIV 1798.106 – Consumers Right to Correct Inaccurate Personal Information

Right to opt out of sale or sharing. Businesses that sell or share must post a clearly visible homepage link titled “Do Not Sell or Share My Personal Information.”9California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information Businesses that collect personal information online must also treat the Global Privacy Control browser signal as a valid opt-out request.10State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC) Ignoring GPC is a common and underestimated enforcement risk.

Right to limit sensitive information use. A business that uses sensitive personal information for purposes beyond what is necessary to deliver the requested product or service must offer a “Limit the Use of My Sensitive Personal Information” link alongside its opt-out mechanisms.9California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information

Right to non-discrimination. A business cannot deny goods or services, charge different prices, provide lower quality, or retaliate against employees or applicants for asserting these rights.11California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights Loyalty programs and financial incentives tied to data collection are allowed if the price or service difference is reasonably related to the value the data provides.

How to Receive and Respond to Requests

A business must offer at least two ways for consumers to submit requests to know, delete, or correct. One must be a toll-free phone number, and if the business has a website, requests must also be accepted there. Online-only businesses can substitute an email address for the phone number.1California Privacy Protection Agency. Frequently Asked Questions (FAQs)

Verify identity before fulfilling any request, typically by matching details the requester provides against data already on file. Additional identifying information may be requested, but can only be used for verification.7State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) An authorized agent submitting a request can be required to produce signed permission, and the consumer can be asked to confirm the arrangement.

Once verified, the response clock is 45 days. If the request is unusually complex, that window can be extended by another 45 days, provided the consumer is notified within the original period.5California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements Missed deadlines are one of the fastest routes to enforcement attention.

Employees, Applicants, and B2B Contacts

The law is not limited to customers. As of January 1, 2026, the regulations make clear that CCPA’s full protections cover personal information collected about employees, job applicants, independent contractors, and individuals contacted in business-to-business transactions.12California Privacy Protection Agency. California Consumer Privacy Act Regulations

Employers must provide a notice at collection to their workforce before gathering personal information, with the same required elements as any consumer notice: categories collected, purposes, whether data is sold or shared, retention periods, and a link to the privacy policy.12California Privacy Protection Agency. California Consumer Privacy Act Regulations Employees hold the full set of rights, and the non-retaliation rule reaches employment decisions.11California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights Routine HR processing — payroll, employment authorization checks, benefits administration, and legally required wage reporting — does not require a separate risk assessment.

Vendor and Service Provider Contracts

Vendor relationships are where classification mistakes turn into unplanned sales. The CCPA separates “service providers” from “third parties,” and the label decides whether handing over data counts as a sale. A service provider processes data on the business’s behalf under a written contract restricting how the data can be used. Fall short of that definition and the transfer may legally qualify as selling the data, triggering opt-out obligations.

Every contract with a service provider or contractor must include specific provisions:12California Privacy Protection Agency. California Consumer Privacy Act Regulations

  • Identify the specific business purposes for processing and prohibit any other use; generic descriptions are not allowed
  • Prohibit the vendor from selling or sharing the personal information
  • Bar the vendor from retaining, using, or disclosing the data outside the direct business relationship
  • Require the vendor to provide the same level of privacy protection the CCPA imposes on the business
  • Preserve the business’s right to take reasonable steps to confirm the vendor is using data consistently with those obligations
  • Require the vendor to notify the business if it can no longer meet its CCPA obligations
  • Require the vendor to help fulfill consumer requests, or to comply with them directly when instructed

Contracts written before the CPRA amendments almost certainly need updating. A boilerplate promise that a vendor “will protect data” does not satisfy the list above; each item has to be addressed on its own terms.

Data Broker Registration

If your business collects and sells personal information about consumers with whom you have no direct relationship, you also qualify as a data broker and pick up additional obligations. Registration with the California Privacy Protection Agency runs from January 1 to January 31 each year, with a $6,000 annual fee, and missing January 31 can bring administrative fines. Registration runs through the Delete Request and Opt-Out Platform (DROP), and requires disclosure of whether the broker collects sensitive data types such as sexual orientation or citizenship status, the kinds of personal information handled, whether data has been shared with foreign actors, law enforcement, or developers of generative AI systems, plus metrics on prior-year consumer requests and response times.13California Privacy Protection Agency. Data Broker Registry

Beginning August 1, 2026, data brokers must access DROP at least once every 45 days to retrieve and process consumer deletion requests. When a consumer’s information matches broker records, all associated personal data, including inferences, must be deleted unless a legal exemption applies, with status reported within 45 days and a permanent log kept to ensure the data stays deleted.14California Privacy Protection Agency. California Approves Delete Act Regulations If you deal only with your own customers, none of this applies to you.

Risk Assessments and Cybersecurity Audits

Two obligations that took effect on January 1, 2026, require affirmative documentation rather than just sound practices.

A written risk assessment must be completed before engaging in certain high-risk processing: selling or sharing personal information, processing sensitive personal information, and using or training automated decision-making technology. Each assessment must document the purpose, the personal information and operational elements involved, the benefits and potential harms, and the safeguards in place.15California Privacy Protection Agency. Things to Know Before 2026 CCPA Updates Take Effect Routine HR activities like payroll and benefits are carved out.12California Privacy Protection Agency. California Consumer Privacy Act Regulations

Businesses whose processing presents significant risk to consumer security must complete an annual cybersecurity audit and submit a written certification to the California Privacy Protection Agency by April 1 of the following year.16California Privacy Protection Agency. California Consumer Privacy Act Regulations – Effective January 1, 2026 This applies to businesses earning 50 percent or more of revenue from selling or sharing personal information, and to larger businesses (over $28 million in gross revenue) that process personal information on 250,000 or more consumers or sensitive personal information on 50,000 or more consumers.17California Privacy Protection Agency. Fact Sheet – Draft Cybersecurity Audit Regulations

Penalties and Private Lawsuits

The California Privacy Protection Agency and the Attorney General share enforcement authority. There is no mandatory cure period. The original 30-day grace window expired on January 1, 2023, when the CPRA amendments took effect. Enforcement staff may still offer time to come into compliance, but that is entirely discretionary.

Each violation carries an administrative fine of up to $2,500. Intentional violations, and violations involving the personal information of a consumer the business knew was under 16, run up to $7,500 per violation.18California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement Both amounts are subject to periodic inflation adjustment. A practice affecting tens of thousands of consumers can produce a fine calculation per affected consumer.

Consumers hold a limited private right of action, but only for data breaches caused by a failure to maintain reasonable security. If unencrypted personal information is stolen or exposed because of inadequate security, affected consumers can recover statutory damages of $100 to $750 per person per incident, or actual damages if higher, and can seek injunctive relief.19California Legislative Information. California Code CIV 1798.150 – Personal Information Security Breaches Private suits do not extend to other CCPA violations such as ignored opt-outs or missed response deadlines; only the agencies enforce those.