All Blog Posts

What Is Personal Information Under the CCPA?

Close
Read time
5 mins
Updated
Aug 11, 2026
Share
  • The CCPA/CPRA defines personal information broadly enough to cover indirect identifiers like cookies, IP addresses, and browsing history, not just names and emails.
  • Data that isn't personal information on its own can still qualify if it's used to draw inferences. Building behavioral or advertising profiles from browsing data is a common way "anonymous" data becomes personal information.
  • De-identified and aggregate data is exempt, but only if it genuinely can't be re-identified. Household data is a distinct, separately defined category.
  • The CCPA/CPRA only applies to for-profit businesses that meet at least one threshold: gross annual revenue over $26,625,000, buying/selling/sharing the personal information of 100,000+ California consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.
  • This same broad definition of cookies and IP addresses as identifiers is also the basis for a separate, unrelated litigation risk under California's wiretapping law, CIPA.
  • A consent management platform such as Cookiebot CMP can identify every cookie and tracker collecting this kind of data on your site and manage consent accordingly.

Whether something counts as "personal information" under California law determines almost everything else about CCPA/CPRA compliance, including whether the law applies to your business at all. The definition is broader than most people expect, and it's changed since the CCPA first passed. Here's what currently counts, what doesn't, and where the lines get blurry.

How the CCPA/CPRA Defines Personal Information

The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) define personal information as information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household."

That "reasonably capable" language is doing a lot of work, as it means the definition covers data that makes identification possible, not just data that identifies someone outright. There's no format or medium limitation, so images and audio recordings can qualify if they fall under the definition, just as text-based data can.

Personal Information Under CCPA/CPRA

Personal Information Under CCPA/CPRA
Direct identifiers

Real name, alias, postal address, email address, Social Security number, driver's license or passport number, signature.

Indirect identifiers

Cookies, IP addresses, device or account identifiers, beacons, pixel tags.

Biometric data

Face, retina, fingerprint, voice recordings, and similar data.

Geolocation data

When it's precise enough to identify a person within a defined radius.

Internet or network activity

Browsing history, search history, interaction data with a website or app.

Sensitive personal information

Social Security number, racial or ethnic origin, immigration status, genetic data, precise geolocation, and similar categories that carry additional protections.

What Doesn't Count as Personal Information

De-identified and aggregate data are exempt, but the exemption only holds if the data genuinely can't be re-identified. This is a narrower carve-out than it sounds. Data that seems anonymous on its own, but that a business can reasonably link back to a device, browser, or household (including through inference) doesn't qualify for the exemption.

This is the mechanism behind a common compliance mistake, that of treating "anonymized analytics data" as automatically exempt. If that data is later used to draw inferences for the purpose of creating an advertising or behavioral profile, it can become personal information at that point, even if it wasn't when first collected.

Household Information Is a Separate Category

The CCPA/CPRA also covers household information, which is defined in the implementing regulations as a person or group of people who reside at the same address, share a common device or service, and are identified by the business as sharing a group account or unique identifier. It's a narrower and more specifically defined category than the general personal information definition above, and it's been debated since the law passed for its ambiguity in practice.

Know what you're actually collecting

Cookiebot CMP scans your entire site to identify every cookie and tracker collecting personal information under California law. Automated for  evolving privacy requirements. Try it free.

Who Has to Comply?

Three separate paths trigger CCPA/CPRA coverage, and a business only needs to cross one of them:

  • Gross annual revenue above USD 25 million (the current CPI-adjusted 2025 figure is USD 26,625,000, to be updated again in 2027)
  • Handling the personal information of more than 100,000 California consumers or households in a given year, whether bought, sold, received, or shared
  • Generating 50 percent or more of annual revenue from selling or sharing personal information

Location doesn't factor in. A business headquartered anywhere in the world is covered the moment it crosses one of these lines and touches a California resident's data.

Global Privacy Control (GPC) and Personal Information

Because cookies and IP addresses qualify as personal information under the CCPA/CPRA, visitors need a way to exercise their opt-out rights over that data. The CPRA doesn't limit that to a manual click. It requires businesses to treat a Global Privacy Control (GPC) signal, sent automatically by a visitor's browser, as a valid request to opt out of the sale or sharing of their personal information.

In practice, this means a business's systems need to recognize the signal and stop selling or sharing that visitor's personal information without waiting for them to find and click a link. The CPPA has named GPC compliance an active enforcement priority.

Enforcement Is Active

The CPRA took effect January 1, 2023. Its implementing regulations were finalized in stages, and a legal challenge briefly delayed enforcement, until California's Third District Court of Appeal ruled on February 9, 2024 that the California Privacy Protection Agency (CPPA), known publicly as CalPrivacy, could enforce them immediately, effective back to July 1, 2023. The CPPA now shares enforcement authority with the California Attorney General, though a business can't be penalized by both for the same violation.

The same broad "indirect identifier" definition that makes cookies and IP addresses personal information under the CCPA/CPRA is also, separately, the basis for a wave of private lawsuits under California's decades-old wiretapping law, the California Invasion of Privacy Act (CIPA). While it's a separate statute from the CCPA/CPRA, it's worth mentioning due to the litigation, and because even full CCPA compliance does not protect against CIPA claims.

Plaintiffs argue that cookies and tracking pixels capturing this kind of data before a visitor consents can qualify as an unlawful pen register or wiretap. The courts are currently split on this theory. CIPA carries no revenue or volume threshold, so it applies even to businesses that fall well under every CCPA/CPRA compliance threshold above.

Any individual can file a claim, and no proof of harm is currently required. There is legislation to address some of the issues, but even if passed it will be some time before it comes into effect, and it doesn't touch two of the major sources of litigation.

How Cookiebot CMP Helps with Privacy Compliance for Personal Information

Cookiebot CMP scans your site to detect every cookie, tracker, and third party collecting this kind of data, categorizes what it finds, and keeps your cookie declaration current. It can also block non-essential cookies from firing until a visitor has made a consent choice, and configure the "Do Not Sell or Share My Personal Information" link automatically for visitors it detects are in California. Because it recognizes GPC signals directly, visitors never have to hunt down a link to exercise a right that systems should already be honoring.

Obtain compliant consent for personal information

See how Cookiebot CMP detects, categorizes, and manages consent for every cookie and tracker on your site. Try it free for 14 days.

Frequently asked questions

Personal information is any data that identifies, relates to, or could reasonably be linked to a particular consumer or household, including names and addresses, but also cookies, IP addresses, browsing history, geolocation data, and biometric data.

The consumer's CCPA rights to request information include:

  • Personal information the business has collected about them
  • Sources from which the personal information is collected
  • Purposes for collecting and processing personal information
  • Categories of third parties and service providers with whom the business shares or to which it sells personal information

Consumers can also opt out of collection and processing of some data, e.g. sensitive information, as well as opt out of sharing or sale of their data. Consent for collection and processing of children’s data must be obtained before any data is collected.

Companies that receive requests from consumers exercising their rights must reply to or fulfill them within a reasonable time frame, or provide clear and reasonable reasons why they cannot fulfill the request or need additional time to do so.

Yes. Cookies are classified as unique or persistent identifiers under the CCPA/CPRA because of their ability to recognize a browser or device across visits and services, even without a name or email attached.

Businesses that meet at least one of three thresholds: annual gross revenue over USD 25 million (currently $26,625,000 adjusted for the CPI), buying/selling/sharing the personal information of 100,000 or more California consumers or households annually, or deriving 50 percent or more of revenue from selling or sharing personal information.

A consent management platform (CMP) can scan your site to detect every cookie and tracker in use, including third-party ones added through plugins, ad tags, or embedded widgets, and block non-essential ones from firing until a visitor has made a consent choice. Cookiebot CMP does this automatically and keeps your cookie declaration current as your site changes, rather than requiring a manual re-audit every time you add a new tool.