---------------------------
Title: CCPA and Cookies: Privacy Compliance Support for California-Facing Websites
URL: https://www.cookiebot.com/us/ccpa-cookies/
---------------------------

# CCPA and Cookies: Privacy Compliance Support for California-Facing Websites

Cookies and similar tracking technologies qualify as personal information under the CCPA/CPRA when they act as unique identifiers, even without a name or email attached. This guide covers who the CCPA/CPRA applies to, what it requires for cookie use, and the separate litigation risk California cookies carry under CIPA, regardless of CCPA/CPRA compliance.

## At a Glance

- Cookies and similar tracking technologies count as personal information under the CCPA/CPRA, even when the data itself is described as "anonymized." This includes IP addresses and device IDs.
- The CCPA/CPRA only applies to businesses meeting at least one threshold: gross annual revenue over $26,625,000, buying/selling/sharing the personal information of more than 100,000 California consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
- If your business sells or shares personal information collected through cookies, you need a "Do Not Sell or Share My Personal Information" link and must honor Global Privacy Control (GPC) signals automatically, not just a manual click.
- Separately from CCPA/CPRA compliance, California's decades-old wiretapping law (CIPA) is fueling a wave of private lawsuits over cookies and tracking pixels — a risk that exists even for businesses that meet no CCPA/CPRA threshold at all.
- A consent management platform such as Cookiebot CMP can scan your site for every cookie in use, categorize it, and block non-essential ones until a visitor has made a consent choice.

Cookies are why the CCPA/CPRA applies to most websites in the first place, and, separately, why California cookie use has become a genuine litigation risk on its own. Here's what the law actually says about cookies, who it applies to, and what to do about both.

## What Does the CCPA Have to Do With Cookies?

The [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/), as amended and expanded by the [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/us/cpra/), gives California residents enforceable rights over the personal information collected about them online. Cookies are the mechanism through which much of that collection happens.

The CCPA/CPRA operates on an opt-out consent model, which means that in most cases, a business doesn't need a visitor's consent before setting cookies. What it does need is a way for visitors to find out what's being collected and to opt out of having it sold or shared. This is where cookie-specific obligations come in.

## Are Cookies "Personal Information" Under the CCPA/CPRA?

Yes, in most cases. The CCPA/CPRA defines personal information broadly, as information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." This explicitly includes unique identifiers, which is a category that covers cookies, IP addresses, device IDs, and similar technologies capable of recognizing a browser or device across visits and services.

This matters because of a common misconception: that cookie data is exempt if it's "anonymized." It isn't, automatically, and there are a few distinctions worth knowing:

- **First-party cookies**: Set by your own website, lower risk but not automatically exempt as they still fall under the personal information definition if they persist and identify a device.
- **Third-party cookies**: Set by ad networks, analytics tools, or embedded plugins, and carry more risk, since they typically send data to a party outside your business.
- **Aggregate and anonymous data**: Exempt, but only if it genuinely can't be re-identified. Data that seems anonymous but can be linked back to a device or household through inference doesn't qualify for the exemption.

## Who Does the CCPA/CPRA Apply To?

Not every website with cookies has to comply with the CCPA/CPRA. It applies to for-profit businesses that meet at least one of these thresholds:

- Gross annual revenue over USD 26,625,000 (that's the 2025 CPI-adjusted figure of the USD 25 million baseline; next adjustment due January 1, 2027)
- Buying, selling, or sharing personal information belonging to 100,000 or more California consumers or households each year
- Generating 50 percent or more of annual revenue from the sale or sharing of personal information

None of that depends on location. A company based anywhere — inside California, elsewhere in the U.S., or abroad — is covered once it crosses one of these lines and its cookies touch a California resident's data.

See every cookie and tracker on your site
Cookiebot CMP scans your entire site to detect all cookie and trackers in use. It can block them from firing until consent is given where required. Scans are automated to help you stay up to date. Try it free.

[Start Scan](https://www.cookiebot.com/us/cookie-checker/)

## What the CCPA/CPRA Requires If You Use Cookies

If your business meets one of the thresholds above, cookie compliance comes down to four things.

### 1. Disclose Cookie Use in Your Privacy Policy

Your [privacy policy](https://www.cookiebot.com/us/how-to-write-privacy-policy-guide/) needs to state, in plain terms, that your website uses cookies, what categories of personal information they collect, whether that information is sold or shared, and which third parties receive it. It must also outline individuals' rights regarding their personal data and how to exercise them.

### 2. Add the Required Opt-Out Links

If cookies on your site sell or share personal information, you need a visible **"**[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)**"** link. If any of that data qualifies as sensitive personal information, you also need a **"**[Limit the Use of My Sensitive Personal Information](https://usercentrics.com/guides/website-disclaimers/limit-the-use-of-my-sensitive-personal-information/)**"** link. Both can be combined into a single link where applicable. Most important is that the link enables a compliant opt-out process.

### 3. Honor Global Privacy Control Signals

Visitors can set a [Global Privacy Control (GPC)](https://www.cookiebot.com/us/global-privacy-control-gpc/) signal once, in their browser or via an extension, and it broadcasts their opt-out preference to every site they visit afterward. The CPRA requires businesses to treat that signal as equivalent to a visitor clicking the opt-out link directly, with no separate confirmation needed.

For cookies specifically, that means your consent setup has to recognize the signal and stop selling or sharing data tied to that visitor's cookies before they've had to find your link at all. At least a dozen U.S. states now require honoring GPC or an equivalent signal, and it's a stated enforcement priority for the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/).

### 4. Respond to Consumer Requests

A request to know, correct, or delete the data your cookies have collected is a [data subject access request (DSAR)](https://usercentrics.com/knowledge-hub/data-subject-access-requests/). The CCPA/CPRA gives you 45 days to respond to a verifiable request, extendable by another 45 days when reasonably necessary, and 15 days to act on an opt-out request.

## Cookies and CIPA: A Separate and Growing Risk

There's a second California statute worth knowing about here, and it has nothing to do with the CCPA/CPRA's compliance thresholds. It's worth mentioning, however, so companies don't mistakenly think that CCPA/CPRA compliance will protect their operations on this front as well.

The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is a 1967 wiretapping law, is currently being used against cookies and tracking pixels in a wave of private lawsuits and demand letters. No CCPA/CPRA threshold applies to it at all, which means even a small site with no CCPA/CPRA obligations can still be a target.

Plaintiffs' theory rests on two provisions:

- [§ 638.51](https://california.public.law/codes/penal_code_section_638.51), written for tracking telephone calls, which prohibits capturing "routing" or "addressing" information without authorization
- [§ 631](https://california.public.law/codes/penal_code_section_631), the general wiretapping provision

The argument is that a cookie or pixel collecting an IP address or identifier and sending it to a third party before consent does exactly what those sections were written to prohibit. Whether either theory actually reaches website cookies is unsettled. Courts have split both ways, and two California Courts of Appeal are reviewing the question now.

What makes this different from CCPA/CPRA exposure is that there is no revenue or data-volume threshold, plus statutory damages of USD 5,000 per violation (or treble actual damages) with no requirement to prove harm. That combination is why demand letters and filings have kept climbing since 2022, and it's why [SB 690](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB690) only closes part of the gap, even if it passes by its August 31, 2026 deadline. That bill is aimed at eliminating the private right to sue over the § 638.51 theory specifically, but it leaves § 631 untouched, and § 631 is the theory used in most current suits.

Disclosure isn't the fix here. The mitigation that actually matters is blocking non-essential cookies from firing until a visitor has made a consent choice (an opt-in consent model), with comprehensive consent logs to be able to prove they never fired without consent in the first place, rather than proving you told visitors they might.

### How Cookiebot CMP Helps

[Cookiebot CMP](https://www.cookiebot.com/us/cookie-consent-solution/) scans your entire site to detect every cookie and tracker in use, categorizes them, and keeps your banner and cookie declaration current automatically. It also blocks non-essential cookies from firing until a visitor has given consent. This is the same mechanism that helps with CIPA risk mitigation, not just CCPA/CPRA disclosure. For visitors it detects are in California, Cookiebot CMP can configure the "Do Not Sell or Share My Personal Information" link automatically and Cookiebot automatically honors and acknowledges GPC signals.

*Usercentrics does not provide legal advice, and information is provided for educational purposes only. We recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.*

Get ahead of California cookie compliance
See how Cookiebot CMP handles cookie scanning, consent, and opt-out signals for the CCPA/CPRA and other privacy laws in one setup. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Summary

Cookies and similar tracking technologies qualify as personal information under the CCPA/CPRA when they act as unique identifiers, even without a name or email attached. This guide covers who the CCPA/CPRA applies to, what it requires for cookie use, and the separate litigation risk California cookies carry under CIPA, regardless of CCPA/CPRA compliance.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)