All Blog Posts

CCPA Consumer Rights in 2026 Explained

Close
Read time
7 mins
Updated
Aug 28, 2026
Share
  • The CCPA and its CPRA amendments give California consumers eight distinct rights, from knowing what data is collected about them to opting out of its sale.
  • Two of these rights, notice and opt-out regarding automated decision-making, only became fully enforceable on January 1, 2026, under new CPPA regulations.
  • The law applies based on whose data a business processes, not where that business is located, so it can reach companies anywhere in the world that meet its applicability thresholds.
  • California also has a separate, older law, the California Invasion of Privacy Act (CIPA), that creates its own consent requirements and litigation risk around website tracking tools.
  • A consent management platform helps operationalize several of these rights: notice at collection, the opt-out mechanism, and audit-ready consent records.

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents specific rights over their personal information. Those rights apply regardless of where the business collecting the data is based, so companies well outside California, and outside the U.S. entirely, are often in scope without realizing it. This guide walks through each right in plain language, what it actually protects, and what changed under the rules the California Privacy Protection Agency (CPPA) finalized for 2026.

Who Does the CCPA Protect, and Which Businesses Must Comply?

The CCPA protects California residents specifically, regardless of where they're interacting with a business from. It applies to any for-profit business that collects their personal information and meets at least one of three thresholds:

  • Annual gross revenue exceeding USD 26,625,000 (adjusted to the Consumer Price Index; next update in 2027)
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year
  • Deriving 50 percent or more of annual revenue from selling or sharing California consumers' personal information

Because the law is triggered by whose data you process rather than where your business sits, it reaches companies based anywhere, including outside the United States, that do business with California residents and meet one of these thresholds. Nonprofits and government agencies are exempt. Businesses collecting data primarily from other U.S. states or other countries should still check these thresholds carefully, since even a small share of California customers can bring a global business into scope.

The Eight CCPA and CPRA Consumer Rights

The original CCPA established the rights to know, delete, opt out of sale, and non-discrimination. The CPRA formally added two more: the right to correct and the right to limit use of sensitive personal information. Since then, CalPrivacy's rulemaking has turned automated decision-making transparency, something the CPRA authorized but left to regulation, into two additional operative rights: notice and access regarding ADMT, and the right to opt out of it. Together, that's eight rights consumers can act on today.

Right to Know

Consumers can request that a business disclose the categories and specific pieces of personal information it has collected about them over the past twelve months, including where the data came from, why it was collected, and which third parties it was shared with. Businesses must offer at least two request methods and respond within 45 days, extendable once by another 45 days with notice.

Right to Delete

Consumers can request that a business delete personal information it holds about them, with defined exceptions such as completing a transaction, detecting security incidents, or complying with a legal obligation. When a business deletes data, it must also instruct any service providers and third parties who received it to do the same.

Right to Correct

Added by the CPRA, this right gives consumers the ability to request that a business correct inaccurate personal information it holds about them, using commercially reasonable efforts appropriate to the nature of the data and how it's used.

Right to Opt Out of Sale or Sharing

Consumers can direct a business to stop selling or sharing their personal information with third parties. "Sharing" was added by the CPRA specifically to capture cross-context behavioral advertising, even where no money changes hands. Businesses must post a "Do Not Sell or Share My Personal Information" link (or "Your Privacy Choices"), and must recognize the Global Privacy Control, a browser-level signal, as a valid opt-out request without requiring a separate submission.

Minors get stronger protection here: businesses need opt-in consent from a parent or guardian to sell or share the data of consumers under 13, and opt-in consent from the minor directly for those aged 13 to 15.

Right to Limit Use of Sensitive Personal Information

The CPRA created a defined category of sensitive personal information, things like precise geolocation, health data, and government ID numbers, and gives consumers the right to limit its use to what's necessary for the goods or services they've requested. A "Limit the Use of My Sensitive Personal Information" link is required for opt-outs if you perform processing on this category of data.

Right to Notice and Access Regarding Automated Decision-Making

As of January 1, 2026, businesses using automated decision-making technology (ADMT) for a "significant decision," such as employment, lending, or healthcare outcomes, must give consumers a pre-use notice explaining what the ADMT does and what happens if they opt out. Consumers can also request access to information about how a specific decision was made about them.

Right to Opt Out of Automated Decision-Making

Consumers can opt out of a business's use of ADMT for significant decisions. Businesses already using qualifying ADMT must be compliant by January 1, 2027; those beginning use after that date must comply immediately.

Right to Non-Discrimination

Businesses cannot deny goods or services, charge different prices, or reduce service quality because a consumer exercised a CCPA right. The one carve-out is financial incentive programs, where a different price or service level is permitted if it's reasonably related to the value the consumer's data provides and clearly disclosed.

The Private Right of Action for Data Breaches

Separately from the rights above, California consumers can sue a business directly over certain data breaches, specifically, breaches of unencrypted personal information caused by a business's failure to maintain reasonable security. Consumers must first give the business 30 days to fix the issue. If unresolved, they can recover statutory damages of USD 107 to USD 799 per consumer per incident.

New for 2026: Cybersecurity Audits and Risk Assessments

Beyond the consumer-facing rights, the CPPA's 2026 regulations added an operational layer businesses should know about, even if it isn't a "right" consumers exercise directly.

Risk Assessments

These are now required before a business starts any processing activity presenting significant risk, including selling or sharing personal information, using ADMT for significant decisions, or processing sensitive personal information.

Cybersecurity Audits

These apply to businesses meeting the revenue threshold that also process personal information of 250,000 or more consumers, or sensitive personal information of 50,000 or more, with phased first-audit deadlines from April 2028 through April 2030 depending on revenue.

CIPA: A Separate, Older California Law Worth Knowing

The California Invasion of Privacy Act (CIPA) is not part of the CCPA framework, and CCPA compliance does not protect a business from CIPA liability. It's worth a mention because of its current impact on the litigation landscape.

Enacted in 1967 to address telephone wiretapping, CIPA requires all-party consent before a communication is intercepted or recorded. Since a 2022 Ninth Circuit ruling opened the door, plaintiffs' attorneys have applied that theory to everyday website tools, cookies, tracking pixels, session replay software, and chat widgets, arguing they intercept a visitor's interaction with a site without consent.

Two sections carry most of this exposure:

  • Section 631 (wiretapping) and Section 632 (eavesdropping and confidential recording), prohibiting interception or recording of a communication without all parties' consent
  • Section 638.51 (pen register and trap-and-trace), prohibiting devices that capture routing or addressing information about a communication without a court order

Unlike the CCPA, CIPA carries its own private right of action, so any California resident can sue directly rather than relying on regulatory enforcement. Plaintiffs' firms have filed thousands of Section 638.51 claims against businesses using standard analytics and marketing tools, and courts remain genuinely split on whether these tools qualify as pen registers under a decades-old statute never written with websites in mind.

SB 690: Reform Is Pending

Senate Bill 690 would remove the private right of action for Section 638.51 claims arising from website, app, or online conduct, leaving enforcement to the California Attorney General alone, and would apply retroactively to claims filed within the two years before the bill takes effect. SB 690 has passed the Assembly Appropriations Committee but still needs a full floor vote and Senate concurrence before the legislature's August 31, 2026 deadline, plus the Governor's signature. It would not touch Sections 631 or 632, so that exposure continues regardless of SB 690's outcome.

The practical takeaway: a CMP handling CCPA notice and opt-out obligations does not, by itself, address CIPA risk. That requires a separate look at what a website's tracking tools actually do and whether visitors have a meaningful basis to say they consented to it. Adopting an opt-in template that blocks trackers from firing until visitors provide consent is a best practice.

A consent management platform (CMP) doesn't cover every CCPA obligation on its own, ADMT governance and cybersecurity audits are broader operational programs, but it directly supports several of the rights above.

Cookiebot™ CMP scans a website for the cookies and tracking technologies in use, providing an accurate inventory of what personal information is collected and shared, the same information needed for an accurate notice at collection and for responding to right-to-know requests. For the opt-out right, Cookiebot CMP can present the "Your Privacy Choices" link and recognize Global Privacy Control signals automatically, while maintaining a timestamped, audit-ready record of consent choices.

Frequently asked questions

The CCPA empowers California residents with the right to opt out of third-party data sales; the right to be informed of data collection, processing, and their rights regarding it; the right to have collected data disclosed; the right to have collected data deleted, and the right to equal services and prices.

The CCPA right to access, also known as the "right to know," allows California residents to request and obtain details about the personal information businesses have collected, used, and shared about them.

Personal information under the CCPA is any kind of information that can directly or indirectly identify an individual. This includes anything from names, postal addresses, social security numbers, health data, location data, IP addresses, cookies, search, and browser history.

According to the CCPA, a business is defined as a company or for-profit organization that meets one of the following criteria: having an annual gross revenue exceeding USD 26,625,000; deriving 50 percent or more of its annual revenue from selling consumer’s personal information; or buying, receiving, selling, or sharing the personal information of more than 100,000 California residents, households, or devices per year.

Your website must enable users to exercise their CCPA rights. For example, you need to inform users about your personal information collection and processing practices. You must also provide instructions on how users can request disclosure and deletion of their information. Additionally, your website should prominently feature a clear "Do Not Sell or Share My Personal Information" link that users can use to opt out of having their data sold to or shared with third parties.

The CCPA grants California consumers rights to know what personal information businesses collect and how it's used, to opt out of its sale, to request its deletion, and to avoid discrimination in service and pricing for exercising these rights. It also allows consumers to sue businesses for data breaches involving their unencrypted personal information, where reasonable security practices were not upheld.

The CCPA grants six key rights to California consumers. The California Privacy Rights Act (CPRA) later added two additional rights: the right to correct inaccurate personal information and the right to limit the use and disclosure of sensitive personal information.

Not in most cases. Personal information can be collected and processed, including sold, without user consent, unless the data is categorized as sensitive or belongs to a child. Then it needs prior consent. Users must have the right to opt out of sale, sharing, profile, or targeted advertising under the CCPA and CPRA, however.