---------------------------
Title: CCPA Compliance: Requirements and Checklist to Help
URL: https://www.cookiebot.com/en/ccpa-compliance/
---------------------------

# CCPA Compliance: Requirements and Checklist to Help

An overview of how the California Consumer Privacy Act applies to businesses anywhere in the world with California customers, what the CPRA changed, and the practical steps to help meet the requirements.

## Key Takeaways

- The CCPA/CPRA applies based on where your consumers are, not where your business is based; there's no physical-presence requirement.
- Coverage thresholds: annual gross revenue over $26,625,000, personal information from 100,000+ California consumers or households, or 50 percent or more of revenue from data sales.
- Unlike the GDPR, the CCPA does not require a designated EU-style representative, data protection officer, or local entity in California. CIPA is a separate law, but relevant to California visitors, with different tracking/opt-in requirements.
- New 2026 rules add cybersecurity audits, risk assessments, and automated decision-making obligations, phased in through 2030.
- Honoring the GPC signal is required, and 2027 requirements mandate it be built into browsers.
- Violations carry penalties of up to $7,988 per intentional violation, enforced by the California Attorney General and the CPPA.

If your organization already handles GDPR compliance, you have a head start. Many of the underlying practices, such as data mapping, consumer rights handling, and privacy notices, transfer across. What doesn't transfer automatically is the assumption that California's opt-out model works the same way GDPR's opt-in model does, or that a lack of a U.S. office puts you outside the law's reach. It doesn't.

## Does the CCPA Apply to Businesses Outside the United States?

Yes, if you meet the applicability thresholds and handle the personal information of California residents. The CCPA doesn't test where your business is incorporated or where your servers sit. It tests whether you're "doing business" in California. This includes functions like taking orders from California residents, targeting California users with marketing, or otherwise engaging California consumers commercially.

A business based in London, Toronto, or Singapore with no physical presence in California can still fall under the CCPA if it meets one of the following thresholds:

- Annual gross revenue over USD 26,625,000 (CPI-adjusted from the original USD 25 million threshold)
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households annually
- Derives 50 percent or more of annual revenue from selling or sharing personal information

This differs meaningfully from the GDPR's extraterritorial test, which turns on offering goods or services to, or monitoring, EU data subjects. The CCPA's test is narrower in one sense (it's revenue- and volume-gated) but broader in another (there's no minimum contact requirement beyond meeting a threshold).

### Does the CCPA Apply to U.S. Businesses Outside of California?

Yes, on the same basis as businesses abroad. The CCPA doesn't test where a business is headquartered, only whether it meets the applicability thresholds and handles California residents' personal information. A retailer in Texas, a SaaS company in New York, or a marketing agency in Ohio can all fall under the law if they meet one of the three thresholds and have California customers, site visitors, or contacts, no California office required.

This can trip up domestic businesses, usually because "California law" reads as someone else's problem when your headquarters, your servers, and most of your customers sit in another state. The CCPA doesn't share that assumption. If your website takes orders from California residents or your marketing targets them, that's generally enough to bring you into scope once you clear the revenue or data-volume thresholds, regardless of where the rest of your business operates.

## What Is the CCPA, and What Did the CPRA Change?

The [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/en/what-is-ccpa/) took effect January 1, 2020, granting California residents rights over their personal information: the right to know what's collected, the right to deletion, and the right to opt out of the sale of their data.

The [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/en/cpra/), passed by ballot initiative in November 2020, amended and expanded the CCPA rather than replacing it. CPRA added the right to correct inaccurate data, the right to limit use of sensitive personal information, a new "sharing" category covering cross-context behavioral advertising (closing a gap the original opt-out-of-sale right didn't cover), and the [California Privacy Protection Agency (CPPA, or CalPrivacy)](https://www.cookiebot.com/en/escalating-cppa-enforcement/), a dedicated enforcement body.

The CPRA's amendments took effect January 1, 2023, with CPPA enforcement beginning in February 2024 after litigation delayed the original July 2023 start.

For international teams, the practical upshot is that "CCPA compliance" today means CPRA-level compliance. Older resources describing only the 2020 CCPA rights are working from an outdated baseline.

## How CCPA Compliance Compares to Work You've Already Done Under GDPR

If your organization has a mature GDPR program, several pieces translate directly. These include your data inventory, your consumer/data-subject rights process, and your vendor contract language on data processing all give you a running start. Teams building a single global consent and rights-management framework generally do better mapping CCPA as an additional ruleset layered onto GDPR infrastructure, not a lighter version of it.

Where the two laws part ways matters more for planning:

## CCPA vs. GDPR Compliance Requirements

- **Consent model** — The GDPR generally requires opt-in consent before processing. The CCPA uses an opt-out model for the sale and sharing of personal information; consent isn't the default legal basis, and cookies aren't automatically gated behind an opt-in banner the way many EU implementations require.
- **Scope of rights** — The GDPR's access and portability rights extend to inferred and profiling data in ways the CCPA's access right doesn't fully mirror.
- **Representative requirement.** — Art. 27 GDPR can require a formally designated EU representative for non-EU controllers. The CCPA has no equivalent requirement; there's no mandate for a California-based representative or agent.
- **Penalty structure** — The GDPR fines scale to global annual turnover, up to 4 percent. CCPA penalties are fixed per-violation amounts (currently USD 2,663 unintentional, USD 7,988 intentional, adjusted for inflation every odd year), which can still add up quickly since each affected consumer typically counts as a separate violation.

## Core Obligations Once the CCPA Applies to You

Once you've established that the CCPA applies to your business, the obligations themselves fall into a few practical categories, including telling consumers what you're doing with their data, giving them control over it, keeping it secure, and, increasingly, accounting for how automated systems use it. The sections below work through each in turn.

### Transparency and Notice

You need to give California consumers clear notice, at or before the point of collection, of what categories of personal information you collect and why. This can live in a standalone cookie notice or as part of a broader privacy policy. Either way, it needs to name the categories of information collected, the purposes, and, if you sell or share the data, that fact specifically.

### Consumer Rights and the Opt-Out Mechanism

Consumers have the right to know what's collected, request deletion, correct inaccuracies, and opt out of the sale or sharing of their information. If you sell or share personal information, and cross-context behavioral advertising counts as sharing under CPRA, you need a clear "Do Not Sell or Share My Personal Information" link, typically on your homepage and in your privacy policy. You then need to honor opt-outs and hold off re-requesting authorization to sell for at least 12 months.

#### CIPA: A Different Consent Standard

The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is a separate statute from the CCPA, and it's easy to conflate the two since both concern California and both touch on tracking technologies. However, the consent requirements are quite different, so it's worth covering.

CIPA is an all-party consent wiretapping law, originally aimed at phone calls, that plaintiffs have increasingly applied to website tools such as chat widgets, session replay, and certain tracking pixels, arguing they intercept communications without consent. Unlike the CCPA's opt-out model, CIPA effectively demands opt-in consent before those technologies run, since consent obtained after the fact doesn't cure an interception that's already happened.

This has driven a wave of [CIPA litigation](https://www.cookiebot.com/us/understand-and-respond-to-cipa-demand-letter/) independent of CCPA enforcement entirely. A reform bill (SB 690) narrowing one theory of liability passed the California legislature on August 31, 2026, and awaits the Governor's signature, but it addresses only pen-register and trap-and-trace claims under Penal Code § 638.51, not the broader wiretapping theory under § 631. Treat CIPA as a distinct compliance track from CCPA rather than folding it into the same opt-out consent banner logic.

### Data Security and the Cybersecurity Audit Rule

The CCPA has always required "reasonable security procedures," without prescribing exact controls. What's new as of January 1, 2026 is that businesses whose processing presents "significant risk" must complete an independent cybersecurity audit. That generally includes those processing the personal information of more than 250,000 consumers or more than 50,000 consumers' sensitive personal information

Certification to the CPPA is staggered by revenue:

- **April 1, 2028** for businesses over USD 100 million in 2026 revenue
- **April 1, 2029** for USD 50–100 million in 2027 revenue
- **April 1, 2030** below USD 50 million in 2028 revenue

If your global security program already produces something like a SOC 2 or ISO 27001 audit, expect meaningful overlap rather than a parallel process.

### Automated Decision-Making (ADMT) Obligations

New rules, effective January 1, 2026, govern ADMT used for "significant decisions" about consumers, such as employment, lending, or access to services. Consumer-facing rights (pre-use notice, opt-out, access, appeal) are required from January 1, 2027. Risk assessment obligations for higher-risk processing already apply. If your business runs automated screening, scoring, or eligibility tools that touch California consumers, this is worth scoping before deadlines arrive.

### **Global Privacy Control and the Browser Mandate**

Unlike GDPR's reliance on explicit banner interaction, the CCPA also recognizes a browser-level signal called [Global Privacy Control (GPC)](https://www.cookiebot.com/us/global-privacy-control-gpc/), which businesses have been required to honor as a valid opt-out request since 2023. If a California visitor's browser sends the signal, that counts as exercising their opt-out right, and no further confirmation step is needed on your end.

From January 1, 2027, California's Opt Me Out Act (AB 566) will require major browsers, not just the privacy-focused ones, to offer this signal by default, which should sharply increase how often your site encounters it. For teams used to GDPR's consent-management-platform model, this is worth building into your architecture. It's a signal your CMP needs to detect and act on, not just a link for visitors to find.

## A Working Compliance Checklist for International Teams

## Checklist for CCPA Requirements

- **Confirm applicability** — Check your California revenue, consumer volume, and data-sale activity against the three thresholds; don't assume location exempts you.
- **Map your data** — Extend your existing data inventory (built for GDPR or otherwise) to flag California-resident records specifically.
- **Update notices and policies** — Add CCPA-specific disclosures, including the categories collected, purposes, and any sale/sharing activity, even if your privacy policy is already GDPR-aligned.
- **Build the opt-out mechanism** — Add a "Do Not Sell or Share My Personal Information" link and route it to a working opt-out flow, distinct from your GDPR consent banner logic.
- **Verify vendor and processor agreements** — Confirm service provider contracts include CCPA-specific restrictions on data use, not just GDPR processor terms.
- **Scope the new 2026 rules** — Determine whether the cybersecurity audit and ADMT rules apply to your processing, and if so, on which phase-in date.
- **Train relevant teams** — Customer support, legal, and marketing teams handling California requests need CCPA-specific training, not just GDPR refreshers.
- **Log everything** — Keep records of consumer requests and responses for at least 24 months.

### Enforcement: Who Polices the CCPA, and What Happens If You Don't Comply

The California Attorney General and the California Privacy Protection Agency share enforcement authority. Both can investigate and bring civil actions. Neither offers the 30-day cure period that used to apply before CPRA removed it for agency enforcement in 2023. A narrower cure period still applies to the separate consumer private right of action for data breaches.

Penalties run up to USD 2,663 per unintentional violation and USD 7,988 per intentional violation or one involving a consumer under 16, with each affected consumer typically counted separately. Consumers can also seek USD 107–USD 799 in statutory damages per incident for qualifying data breaches. Distance from California offers no protection, as enforcement actions have reached companies with no California offices at all, based purely on their handling of California consumers' data.

Like the compliance threshold, the penalty amounts are subject to periodic adjustment for inflation, with the next due in 2027.

### How Cookiebot Helps Non-U.S. Teams Manage California Consent

Running CCPA alongside GDPR, and increasingly alongside other U.S. state laws, usually means managing several consent frameworks without duplicating the underlying work. Cookiebot CMP scans your site to identify cookies and trackers, detects visitors likely located in California, and can present the required "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link automatically for that audience, while running your existing GDPR consent flow for EU visitors. It keeps a record of each visitor's choices over time, which supports both CCPA's recordkeeping expectations and GDPR's accountability requirements from a single implementation.

Meet CCPA requirements configured to your business
Get set up in minutes, and manage visitor notices, opt-in and opt-out requirements, GPC, audit logs, and more. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Preamble

California is the physical frontier of America, where the continent plunges into the Pacific.
With the California Consumer Privacy Act (CCPA), it is now also the frontier of data privacy law in the US.
In this article, we take a close look at the CCPA and how Cookiebot consent management platform (CMP) helps your website become compliant.

## Summary

An overview of how the California Consumer Privacy Act applies to businesses anywhere in the world with California customers, what the CPRA changed, and the practical steps to help meet the requirements.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)