All Blog Posts

CCPA Compliance: Requirements and Checklist to Help

Close
Read time
8 mins
Updated
Aug 30, 2026
Share

If your organization already handles GDPR compliance, you have a head start. Many of the underlying practices, such as data mapping, consumer rights handling, and privacy notices, transfer across. What doesn't transfer automatically is the assumption that California's opt-out model works the same way GDPR's opt-in model does, or that a lack of a U.S. office puts you outside the law's reach. It doesn't.

Does the CCPA Apply to Businesses Outside the United States?

Yes, if you meet the applicability thresholds and handle the personal information of California residents. The CCPA doesn't test where your business is incorporated or where your servers sit. It tests whether you're "doing business" in California. This includes functions like taking orders from California residents, targeting California users with marketing, or otherwise engaging California consumers commercially.

A business based in London, Toronto, or Singapore with no physical presence in California can still fall under the CCPA if it meets one of the following thresholds:

  • Annual gross revenue over USD 26,625,000 (CPI-adjusted from the original USD 25 million threshold)
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households annually
  • Derives 50 percent or more of annual revenue from selling or sharing personal information

This differs meaningfully from the GDPR's extraterritorial test, which turns on offering goods or services to, or monitoring, EU data subjects. The CCPA's test is narrower in one sense (it's revenue- and volume-gated) but broader in another (there's no minimum contact requirement beyond meeting a threshold).

Does the CCPA Apply to U.S. Businesses Outside of California?

Yes, on the same basis as businesses abroad. The CCPA doesn't test where a business is headquartered, only whether it meets the applicability thresholds and handles California residents' personal information. A retailer in Texas, a SaaS company in New York, or a marketing agency in Ohio can all fall under the law if they meet one of the three thresholds and have California customers, site visitors, or contacts, no California office required.

This can trip up domestic businesses, usually because "California law" reads as someone else's problem when your headquarters, your servers, and most of your customers sit in another state. The CCPA doesn't share that assumption. If your website takes orders from California residents or your marketing targets them, that's generally enough to bring you into scope once you clear the revenue or data-volume thresholds, regardless of where the rest of your business operates.

What Is the CCPA, and What Did the CPRA Change?

The California Consumer Privacy Act (CCPA) took effect January 1, 2020, granting California residents rights over their personal information: the right to know what's collected, the right to deletion, and the right to opt out of the sale of their data.

The California Privacy Rights Act (CPRA), passed by ballot initiative in November 2020, amended and expanded the CCPA rather than replacing it. CPRA added the right to correct inaccurate data, the right to limit use of sensitive personal information, a new "sharing" category covering cross-context behavioral advertising (closing a gap the original opt-out-of-sale right didn't cover), and the California Privacy Protection Agency (CPPA, or CalPrivacy), a dedicated enforcement body.

The CPRA's amendments took effect January 1, 2023, with CPPA enforcement beginning in February 2024 after litigation delayed the original July 2023 start.

For international teams, the practical upshot is that "CCPA compliance" today means CPRA-level compliance. Older resources describing only the 2020 CCPA rights are working from an outdated baseline.

How CCPA Compliance Compares to Work You've Already Done Under GDPR

If your organization has a mature GDPR program, several pieces translate directly. These include your data inventory, your consumer/data-subject rights process, and your vendor contract language on data processing all give you a running start. Teams building a single global consent and rights-management framework generally do better mapping CCPA as an additional ruleset layered onto GDPR infrastructure, not a lighter version of it.

Where the two laws part ways matters more for planning:

CCPA vs. GDPR Compliance Requirements

CCPA vs. GDPR Compliance Requirements
Consent model

The GDPR generally requires opt-in consent before processing. The CCPA uses an opt-out model for the sale and sharing of personal information; consent isn't the default legal basis, and cookies aren't automatically gated behind an opt-in banner the way many EU implementations require.

Scope of rights

The GDPR's access and portability rights extend to inferred and profiling data in ways the CCPA's access right doesn't fully mirror.

Representative requirement.

Art. 27 GDPR can require a formally designated EU representative for non-EU controllers. The CCPA has no equivalent requirement; there's no mandate for a California-based representative or agent.

Penalty structure

The GDPR fines scale to global annual turnover, up to 4 percent. CCPA penalties are fixed per-violation amounts (currently USD 2,663 unintentional, USD 7,988 intentional, adjusted for inflation every odd year), which can still add up quickly since each affected consumer typically counts as a separate violation.

Core Obligations Once the CCPA Applies to You

Once you've established that the CCPA applies to your business, the obligations themselves fall into a few practical categories, including telling consumers what you're doing with their data, giving them control over it, keeping it secure, and, increasingly, accounting for how automated systems use it. The sections below work through each in turn.

Transparency and Notice

You need to give California consumers clear notice, at or before the point of collection, of what categories of personal information you collect and why. This can live in a standalone cookie notice or as part of a broader privacy policy. Either way, it needs to name the categories of information collected, the purposes, and, if you sell or share the data, that fact specifically.

Consumer Rights and the Opt-Out Mechanism

Consumers have the right to know what's collected, request deletion, correct inaccuracies, and opt out of the sale or sharing of their information. If you sell or share personal information, and cross-context behavioral advertising counts as sharing under CPRA, you need a clear "Do Not Sell or Share My Personal Information" link, typically on your homepage and in your privacy policy. You then need to honor opt-outs and hold off re-requesting authorization to sell for at least 12 months.

CIPA: A Different Consent Standard

The California Invasion of Privacy Act (CIPA) is a separate statute from the CCPA, and it's easy to conflate the two since both concern California and both touch on tracking technologies. However, the consent requirements are quite different, so it's worth covering.

CIPA is an all-party consent wiretapping law, originally aimed at phone calls, that plaintiffs have increasingly applied to website tools such as chat widgets, session replay, and certain tracking pixels, arguing they intercept communications without consent. Unlike the CCPA's opt-out model, CIPA effectively demands opt-in consent before those technologies run, since consent obtained after the fact doesn't cure an interception that's already happened.

This has driven a wave of CIPA litigation independent of CCPA enforcement entirely. A reform bill (SB 690) narrowing one theory of liability passed the California legislature on August 31, 2026, and awaits the Governor's signature, but it addresses only pen-register and trap-and-trace claims under Penal Code § 638.51, not the broader wiretapping theory under § 631. Treat CIPA as a distinct compliance track from CCPA rather than folding it into the same opt-out consent banner logic.

Data Security and the Cybersecurity Audit Rule

The CCPA has always required "reasonable security procedures," without prescribing exact controls. What's new as of January 1, 2026 is that businesses whose processing presents "significant risk" must complete an independent cybersecurity audit. That generally includes those processing the personal information of more than 250,000 consumers or more than 50,000 consumers' sensitive personal information

Certification to the CPPA is staggered by revenue:

  • April 1, 2028 for businesses over USD 100 million in 2026 revenue
  • April 1, 2029 for USD 50–100 million in 2027 revenue
  • April 1, 2030 below USD 50 million in 2028 revenue

If your global security program already produces something like a SOC 2 or ISO 27001 audit, expect meaningful overlap rather than a parallel process.

Automated Decision-Making (ADMT) Obligations

New rules, effective January 1, 2026, govern ADMT used for "significant decisions" about consumers, such as employment, lending, or access to services. Consumer-facing rights (pre-use notice, opt-out, access, appeal) are required from January 1, 2027. Risk assessment obligations for higher-risk processing already apply. If your business runs automated screening, scoring, or eligibility tools that touch California consumers, this is worth scoping before deadlines arrive.

Global Privacy Control and the Browser Mandate

Unlike GDPR's reliance on explicit banner interaction, the CCPA also recognizes a browser-level signal called Global Privacy Control (GPC), which businesses have been required to honor as a valid opt-out request since 2023. If a California visitor's browser sends the signal, that counts as exercising their opt-out right, and no further confirmation step is needed on your end.

From January 1, 2027, California's Opt Me Out Act (AB 566) will require major browsers, not just the privacy-focused ones, to offer this signal by default, which should sharply increase how often your site encounters it. For teams used to GDPR's consent-management-platform model, this is worth building into your architecture. It's a signal your CMP needs to detect and act on, not just a link for visitors to find.

A Working Compliance Checklist for International Teams

Checklist for CCPA Requirements

Checklist for CCPA Requirements
1
Confirm applicability

Check your California revenue, consumer volume, and data-sale activity against the three thresholds; don't assume location exempts you.

2
Map your data

Extend your existing data inventory (built for GDPR or otherwise) to flag California-resident records specifically.

3
Update notices and policies

Add CCPA-specific disclosures, including the categories collected, purposes, and any sale/sharing activity, even if your privacy policy is already GDPR-aligned.

4
Build the opt-out mechanism

Add a "Do Not Sell or Share My Personal Information" link and route it to a working opt-out flow, distinct from your GDPR consent banner logic.

5
Verify vendor and processor agreements

Confirm service provider contracts include CCPA-specific restrictions on data use, not just GDPR processor terms.

6
Scope the new 2026 rules

Determine whether the cybersecurity audit and ADMT rules apply to your processing, and if so, on which phase-in date.

7
Train relevant teams

Customer support, legal, and marketing teams handling California requests need CCPA-specific training, not just GDPR refreshers.

8
Log everything

Keep records of consumer requests and responses for at least 24 months.

Enforcement: Who Polices the CCPA, and What Happens If You Don't Comply

The California Attorney General and the California Privacy Protection Agency share enforcement authority. Both can investigate and bring civil actions. Neither offers the 30-day cure period that used to apply before CPRA removed it for agency enforcement in 2023. A narrower cure period still applies to the separate consumer private right of action for data breaches.

Penalties run up to USD 2,663 per unintentional violation and USD 7,988 per intentional violation or one involving a consumer under 16, with each affected consumer typically counted separately. Consumers can also seek USD 107–USD 799 in statutory damages per incident for qualifying data breaches. Distance from California offers no protection, as enforcement actions have reached companies with no California offices at all, based purely on their handling of California consumers' data.

Like the compliance threshold, the penalty amounts are subject to periodic adjustment for inflation, with the next due in 2027.

Running CCPA alongside GDPR, and increasingly alongside other U.S. state laws, usually means managing several consent frameworks without duplicating the underlying work. Cookiebot CMP scans your site to identify cookies and trackers, detects visitors likely located in California, and can present the required "Do Not Sell or Share My Personal Information" link automatically for that audience, while running your existing GDPR consent flow for EU visitors. It keeps a record of each visitor's choices over time, which supports both CCPA's recordkeeping expectations and GDPR's accountability requirements from a single implementation.

Meet CCPA requirements configured to your business

Get set up in minutes, and manage visitor notices, opt-in and opt-out requirements, GPC, audit logs, and more. Try it free for 14 days.

Frequently asked questions

CCPA compliance refers to adhering to the requirements set forth by the California Consumer Privacy Act, which aims to enhance privacy rights and consumer protection for California residents.

CCPA compliance requires transparency about data collection, enabling access, deletion, and opt-out of personal information sales, and implementing security measures. Businesses must update privacy policies, handle consumer requests, manage vendors, and train employees.

To meet CCPA compliance requirements, businesses must take steps to protect the personal data of California residents and respect their privacy rights. This includes enabling consumers to opt out of data collection and sales. Key actions involve creating a data inventory and auditing it and data operations regularly, updating privacy policies, setting up procedures for handling consumer requests, and ensuring robust data security measures are in place.

Common CCPA compliance solutions include Cookiebot CMP, which provides a consent management platform to help businesses manage user consent and comply with various data privacy regulations, such as the CCPA.

CCPA service provider contracts must ensure that personal information is only used for the agreed business purposes. They should also require the provider to follow CCPA rules, assist with consumer requests, and implement proper security measures.

CCPA DSAR requirements mandate that businesses respond to verified consumer requests for access to their personal information within 45 days, with a possible 45-day extension if necessary. Businesses must provide consumers with the specific personal information collected, the categories of sources and third parties the information is shared with, and the purpose for collecting or selling the data. Individuals can also request deletion of their data.