All Blog Posts

CCPA and Cookies: Privacy Compliance Support for California-Facing Websites

Close
Read time
6 mins
Updated
Aug 12, 2026
Share
  • Cookies and similar tracking technologies count as personal information under the CCPA/CPRA, even when the data itself is described as "anonymized." This includes IP addresses and device IDs.
  • The CCPA/CPRA only applies to businesses meeting at least one threshold: gross annual revenue over $26,625,000, buying/selling/sharing the personal information of more than 100,000 California consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
  • If your business sells or shares personal information collected through cookies, you need a "Do Not Sell or Share My Personal Information" link and must honor Global Privacy Control (GPC) signals automatically, not just a manual click.
  • Separately from CCPA/CPRA compliance, California's decades-old wiretapping law (CIPA) is fueling a wave of private lawsuits over cookies and tracking pixels — a risk that exists even for businesses that meet no CCPA/CPRA threshold at all.
  • A consent management platform such as Cookiebot CMP can scan your site for every cookie in use, categorize it, and block non-essential ones until a visitor has made a consent choice.

What Does the CCPA Have to Do With Cookies?

The California Consumer Privacy Act (CCPA), as amended and expanded by the California Privacy Rights Act (CPRA), gives California residents enforceable rights over the personal information collected about them online. Cookies are the mechanism through which much of that collection happens.

The CCPA/CPRA operates on an opt-out consent model, which means that in most cases, a business doesn't need a visitor's consent before setting cookies. What it does need is a way for visitors to find out what's being collected and to opt out of having it sold or shared. This is where cookie-specific obligations come in.

Are Cookies "Personal Information" Under the CCPA/CPRA?

Yes, in most cases. The CCPA/CPRA defines personal information broadly, as information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." This explicitly includes unique identifiers, which is a category that covers cookies, IP addresses, device IDs, and similar technologies capable of recognizing a browser or device across visits and services.

This matters because of a common misconception: that cookie data is exempt if it's "anonymized." It isn't, automatically, and there are a few distinctions worth knowing:

  • First-party cookies: Set by your own website, lower risk but not automatically exempt as they still fall under the personal information definition if they persist and identify a device.
  • Third-party cookies: Set by ad networks, analytics tools, or embedded plugins, and carry more risk, since they typically send data to a party outside your business.
  • Aggregate and anonymous data: Exempt, but only if it genuinely can't be re-identified. Data that seems anonymous but can be linked back to a device or household through inference doesn't qualify for the exemption.

Who Does the CCPA/CPRA Apply To?

Not every website with cookies has to comply with the CCPA/CPRA. It applies to for-profit businesses that meet at least one of these thresholds:

  • Gross annual revenue over USD 26,625,000 (that's the 2025 CPI-adjusted figure of the USD 25 million baseline; next adjustment due January 1, 2027)
  • Buying, selling, or sharing personal information belonging to 100,000 or more California consumers or households each year
  • Generating 50 percent or more of annual revenue from the sale or sharing of personal information

None of that depends on location. A company based anywhere — inside California, elsewhere in the U.S., or abroad — is covered once it crosses one of these lines and its cookies touch a California resident's data.

See every cookie and tracker on your site

Cookiebot CMP scans your entire site to detect all cookie and trackers in use. It can block them from firing until consent is given where required. Scans are automated to help you stay up to date. Try it free.

What the CCPA/CPRA Requires If You Use Cookies

If your business meets one of the thresholds above, cookie compliance comes down to four things.

Your privacy policy needs to state, in plain terms, that your website uses cookies, what categories of personal information they collect, whether that information is sold or shared, and which third parties receive it. It must also outline individuals' rights regarding their personal data and how to exercise them.

If cookies on your site sell or share personal information, you need a visible "Do Not Sell or Share My Personal Information" link. If any of that data qualifies as sensitive personal information, you also need a "Limit the Use of My Sensitive Personal Information" link. Both can be combined into a single link where applicable. Most important is that the link enables a compliant opt-out process.

3. Honor Global Privacy Control Signals

Visitors can set a Global Privacy Control (GPC) signal once, in their browser or via an extension, and it broadcasts their opt-out preference to every site they visit afterward. The CPRA requires businesses to treat that signal as equivalent to a visitor clicking the opt-out link directly, with no separate confirmation needed.

For cookies specifically, that means your consent setup has to recognize the signal and stop selling or sharing data tied to that visitor's cookies before they've had to find your link at all. At least a dozen U.S. states now require honoring GPC or an equivalent signal, and it's a stated enforcement priority for the California Privacy Protection Agency (CPPA).

4. Respond to Consumer Requests

A request to know, correct, or delete the data your cookies have collected is a data subject access request (DSAR). The CCPA/CPRA gives you 45 days to respond to a verifiable request, extendable by another 45 days when reasonably necessary, and 15 days to act on an opt-out request.

Cookies and CIPA: A Separate and Growing Risk

There's a second California statute worth knowing about here, and it has nothing to do with the CCPA/CPRA's compliance thresholds. It's worth mentioning, however, so companies don't mistakenly think that CCPA/CPRA compliance will protect their operations on this front as well.

The California Invasion of Privacy Act (CIPA) is a 1967 wiretapping law, is currently being used against cookies and tracking pixels in a wave of private lawsuits and demand letters. No CCPA/CPRA threshold applies to it at all, which means even a small site with no CCPA/CPRA obligations can still be a target.

Plaintiffs' theory rests on two provisions:

  • § 638.51, written for tracking telephone calls, which prohibits capturing "routing" or "addressing" information without authorization
  • § 631, the general wiretapping provision

The argument is that a cookie or pixel collecting an IP address or identifier and sending it to a third party before consent does exactly what those sections were written to prohibit. Whether either theory actually reaches website cookies is unsettled. Courts have split both ways, and two California Courts of Appeal are reviewing the question now.

What makes this different from CCPA/CPRA exposure is that there is no revenue or data-volume threshold, plus statutory damages of USD 5,000 per violation (or treble actual damages) with no requirement to prove harm. That combination is why demand letters and filings have kept climbing since 2022, and it's why SB 690 only closes part of the gap, even if it passes by its August 31, 2026 deadline. That bill is aimed at eliminating the private right to sue over the § 638.51 theory specifically, but it leaves § 631 untouched, and § 631 is the theory used in most current suits.

Disclosure isn't the fix here. The mitigation that actually matters is blocking non-essential cookies from firing until a visitor has made a consent choice (an opt-in consent model), with comprehensive consent logs to be able to prove they never fired without consent in the first place, rather than proving you told visitors they might.

How Cookiebot CMP Helps

Cookiebot CMP scans your entire site to detect every cookie and tracker in use, categorizes them, and keeps your banner and cookie declaration current automatically. It also blocks non-essential cookies from firing until a visitor has given consent. This is the same mechanism that helps with CIPA risk mitigation, not just CCPA/CPRA disclosure. For visitors it detects are in California, Cookiebot CMP can configure the "Do Not Sell or Share My Personal Information" link automatically and Cookiebot automatically honors and acknowledges GPC signals.

Usercentrics does not provide legal advice, and information is provided for educational purposes only. We recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.

Get ahead of California cookie compliance

See how Cookiebot CMP handles cookie scanning, consent, and opt-out signals for the CCPA/CPRA and other privacy laws in one setup. Try it free for 14 days.

Frequently asked questions

The California Consumer Privacy Act (CCPA) is a state law that regulates how businesses are allowed to collect, share, and sell the personal information of California residents. The CCPA empowers California residents with the right to opt out of the sale or sharing of their personal information with third parties, the right to access already collected personal information, and the right to have it deleted.

Businesses must comply with the CCPA if they have an annual gross revenue exceeding $26,625,000 (the original $25 million baseline, adjusted for inflation as of January 1, 2025), derive more than 50 percent of annual revenues from personal information sales, or buy, receive, sell, or share the personal information of 100,000 or more California residents or households.

No, in most cases. The CCPA/CPRA is an opt-out consent law, so businesses generally don't need a visitor's consent before setting cookies, with an exception for minors under 16. What's required is disclosure and a way for visitors to opt out of the sale or sharing of the data those cookies collect.

Cookies, IP addresses, device IDs, and other unique identifiers count as personal information if they're capable of recognizing a consumer, household, or device over time and across services — regardless of whether the data includes a name or email address.

Generally yes. Third-party cookies, set by ad networks, analytics tools, or embedded plugins, typically transmit data to a party outside your business, which is more likely to be characterized as a "sale" or "share" of personal information under the CCPA/CPRA than data your own first-party cookies retain.

 

Not necessarily. A separate California law, the California Invasion of Privacy Act (CIPA), is being used in private lawsuits to challenge cookies and tracking pixels on wiretapping and pen-register theories, independent of CCPA/CPRA compliance. A business can meet every CCPA/CPRA requirement and still face CIPA litigation risk. Learn more about CIPA requirements.

Our free cookie checker can scan your site and show you what's currently running. For ongoing management, a consent management platform can scan continuously, categorize what it finds, and keep your disclosures current as your site changes.