The California Consumer Privacy Act builds its whole framework on defined terms in Civil Code Section 1798.140, and those CCPA definitions decide everything that follows: who is protected, what data is covered, which companies must comply, and which data transfers give you the right to opt out. The terms below reflect the statute as amended by the California Privacy Rights Act, with the inflation-adjusted thresholds in effect for 2025.
Who Counts as a Consumer
A “consumer” under the CCPA is narrower than the everyday word suggests. It means a natural person who lives in California on more than a temporary basis. Someone domiciled in the state but traveling briefly still qualifies. Tourists, business visitors passing through, and anyone whose presence is transitory do not.1California Legislative Information. California Code CIV 1798.140 – Definitions
Residency is the dividing line, not citizenship or immigration status. If you maintain a home in California and treat it as your permanent base, the CCPA’s rights apply to you no matter where you happen to be on a given day.
What Counts as Personal Information
Personal information is any data that identifies, relates to, or could reasonably be linked to a specific person or household. That covers the obvious identifiers such as your name and Social Security number, and it reaches further into data many people don’t think of as personal: IP addresses, browsing history, purchase records, geolocation data, and biometric information all qualify. Employment history and professional information count too, so long as they can be tied back to an individual.1California Legislative Information. California Code CIV 1798.140 – Definitions
The threshold phrase is “reasonably linkable.” A business cannot escape the law by claiming its records are anonymous when combining a few data points would identify someone.
Inferences
Profiles a company builds about you by analyzing your data are themselves personal information. If a business uses your browsing habits, purchases, and location to conclude something about your preferences, attitudes, or behavior, that conclusion carries the same protections as any direct identifier.2California Privacy Protection Agency. California Consumer Privacy Act of 2018
Sensitive Personal Information
The CPRA added a higher-protection tier for data that carries greater risk if exposed or misused. It includes:1California Legislative Information. California Code CIV 1798.140 – Definitions
- Social Security numbers, driver’s license numbers, state ID numbers, and passport numbers
- Account login details and credit or debit card numbers combined with any required security code or password
- Precise geolocation, meaning your exact location rather than a city or region
- Contents of your mail, email, and text messages, unless the business was the intended recipient
- Genetic and neural data, including information generated by measuring nervous system activity
- Biometric data processed to uniquely identify you
- Health information collected and analyzed about you
- Data collected and analyzed about sex life or sexual orientation
- Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership
The tier matters because consumers have a separate right to limit how a business uses sensitive personal information. You can direct a company to use this data only for the purposes necessary to provide the service you asked for, blocking secondary uses like profiling or advertising.3State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
Which Companies Are a “Business”
The CCPA only applies to for-profit entities that collect California consumers’ personal information and meet at least one of three size tests:1California Legislative Information. California Code CIV 1798.140 – Definitions
- Annual gross revenues over $25 million in the preceding calendar year. This figure is adjusted for inflation each year; the 2025 threshold is $26,625,000.4California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
- Buying, selling, or sharing the personal information of 100,000 or more consumers or households annually
- Deriving 50 percent or more of annual revenue from selling or sharing consumer personal information
Only one of the three tests has to be met.
Common Branding and Control
The definition also pulls in related entities. If one company controls another and they share a name, service mark, or trademark that an average consumer would recognize as common ownership, the controlled entity is treated as a business too. Control means owning more than 50 percent of voting shares, directing a majority of the board, or exercising a controlling influence over management.1California Legislative Information. California Code CIV 1798.140 – Definitions
This blocks the workaround of spinning consumer data into a subsidiary and calling the subsidiary too small to comply. Shared brand plus parent control means both must follow the law.
Service Providers, Contractors, and Third Parties
The CCPA sorts entities that handle personal information for or in connection with a business into three categories. Each carries different obligations, and which label applies decides whether a data transfer counts as a sale.
Service Providers
A service provider processes personal information on behalf of a business under a written contract. That contract must prohibit the service provider from selling or sharing the data, using it beyond what the contract specifies, or combining it with information from other sources. Payment processors and cloud storage vendors are typical examples.1California Legislative Information. California Code CIV 1798.140 – Definitions
Contractors
A contractor is a person or entity a business makes personal information available to for a business purpose, also under a written contract. The core restrictions match those for service providers, plus two extras:1California Legislative Information. California Code CIV 1798.140 – Definitions
- The contractor must certify in writing that it understands the restrictions and will comply
- The contract must let the business monitor compliance through manual reviews, automated scans, or audits at least once every 12 months
If a contractor subcontracts any data processing, it must notify the original business, and the subcontractor has to be bound by the same written restrictions.
Third Parties
Third party is defined by exclusion: anyone who isn’t the business the consumer dealt with, isn’t a service provider to that business, and isn’t a contractor to that business. When personal information moves to a third party, the transfer is far more likely to count as a “sale” or “share” that triggers opt-out rights. Advertisers, data brokers, and analytics companies typically sit in this bucket.1California Legislative Information. California Code CIV 1798.140 – Definitions
Sale and Sharing
The statute treats selling and sharing personal information as separate concepts, and each one gives consumers its own opt-out right.
Sale
A sale is any transfer of personal information to another party for valuable consideration. Cash isn’t required. If a business hands over consumer data in exchange for a service, analytics access, or any other benefit, that counts. The definition is deliberately broad to defeat creative barter arrangements.1California Legislative Information. California Code CIV 1798.140 – Definitions
Sharing
Sharing is narrower. It means transferring personal information to a third party specifically for cross-context behavioral advertising, the practice of targeting ads to you based on activity across multiple unrelated sites or apps. A company passing your browsing data to an ad network so the network can follow you around the internet is sharing your information even without any money changing hands.1California Legislative Information. California Code CIV 1798.140 – Definitions
The two opt-outs run independently. A business must honor a request to stop sharing for behavioral advertising even if you haven’t opted out of sales, and the reverse holds too.
What the Law Excludes From Personal Information
Three categories sit outside the definition of personal information.
Publicly Available Information
Information lawfully obtained from federal, state, or local government records is not personal information under the CCPA. The same goes for information the consumer has made available to the general public or shared without restricting the audience. One carve-out inside the carve-out: biometric information a business collects about a consumer without the consumer’s knowledge never qualifies as publicly available.1California Legislative Information. California Code CIV 1798.140 – Definitions
De-Identified Data
De-identified data is information stripped of identifying details so it cannot reasonably be used to figure out who it belongs to. Removing names isn’t enough. The law requires all three of the following:1California Legislative Information. California Code CIV 1798.140 – Definitions
- Reasonable technical measures to ensure the data cannot be linked back to any consumer or household
- A public commitment to keep the data in de-identified form and not attempt to re-identify it, except to test whether the de-identification process actually works
- Contractual obligations binding any recipient of the data to the same rules
Stripping names without contractually binding downstream recipients doesn’t get a company to de-identified status.
Aggregate Consumer Information
Aggregate data summarizes information about a group of consumers so that no individual is identifiable and no data point is reasonably linkable to a specific person or household. A statement that 60 percent of customers in a region prefer a certain product is aggregate. Grouping individual de-identified records together doesn’t create aggregate data on its own; true aggregation means no single consumer can be picked out of the set.1California Legislative Information. California Code CIV 1798.140 – Definitions
Verifiable Consumer Requests
When you exercise CCPA rights, the business needs a way to confirm the request came from you or from someone you authorized. A verifiable consumer request is one the business can reasonably confirm as legitimate. An authorized agent can be a natural person or a business registered with the Secretary of State.
Verification standards scale with the sensitivity of the request. Asking what categories of data a business holds about you takes less certainty than asking for the specific pieces or demanding deletion. For a request to receive specific data, the business may need to match multiple data points and require a signed statement under penalty of perjury. Opt-out requests are different: they don’t require verification at all, and a business cannot force you through identity-confirmation hoops just to stop the sale or sharing of your information.
Dark Patterns
A dark pattern is a user interface designed or manipulated to substantially undermine your ability to make a genuine choice. Burying the opt-out behind confusing menus, using misleading language that steers you toward agreeing, or making “yes” easy and “no” frustrating all qualify.1California Legislative Information. California Code CIV 1798.140 – Definitions
The legal consequence is direct. Any consent obtained through a dark pattern is not valid. If a business uses manipulative design to get you to agree to a sale of your data, the agreement doesn’t count, and the business is treated as if no consent existed.
Penalties Tied to These Definitions
Because every enforcement action turns on whether an entity is a business, whether the data is personal information, and whether a transfer was a sale or share, the penalty numbers sit on top of the definitions above. The California Privacy Protection Agency holds primary enforcement authority, and the California Attorney General retains civil action authority as well.
Statutory penalties are up to $2,500 per violation and up to $7,500 for each intentional violation or each violation involving the data of a minor the business knew was under 16.5California Legislative Information. California Code CIV 1798.199.90 These amounts adjust annually for inflation. The 2025 adjusted figures are $2,663 per violation and $7,988 per intentional violation or violation involving a minor’s data.4California Privacy Protection Agency. Updated Monetary Thresholds in CCPA Penalties are assessed per violation, so a single data practice affecting thousands of consumers can produce enormous aggregate liability.