---------------------------
Title: What Is Personal Information Under the CCPA?
URL: https://www.cookiebot.com/us/ccpa-personal-information-ccpa-compliance-with-cookiebot-cmp/
---------------------------

# What Is Personal Information Under the CCPA?

The CCPA/CPRA defines personal information broadly enough to cover cookies, IP addresses, and inferred data, not just names and emails. This guide breaks down the categories of personal information under California law, what counts as a household, which businesses the thresholds apply to, and how that broad definition connects to a separate, growing litigation risk under CIPA.

## At a Glance

- The CCPA/CPRA defines personal information broadly enough to cover indirect identifiers like cookies, IP addresses, and browsing history, not just names and emails.
- Data that isn't personal information on its own can still qualify if it's used to draw inferences. Building behavioral or advertising profiles from browsing data is a common way "anonymous" data becomes personal information.
- De-identified and aggregate data is exempt, but only if it genuinely can't be re-identified. Household data is a distinct, separately defined category.
- The CCPA/CPRA only applies to for-profit businesses that meet at least one threshold: gross annual revenue over $26,625,000, buying/selling/sharing the personal information of 100,000+ California consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.
- This same broad definition of cookies and IP addresses as identifiers is also the basis for a separate, unrelated litigation risk under California's wiretapping law, CIPA.
- A consent management platform such as Cookiebot CMP can identify every cookie and tracker collecting this kind of data on your site and manage consent accordingly.

Whether something counts as "personal information" under California law determines almost everything else about CCPA/CPRA compliance, including whether the law applies to your business at all. The definition is broader than most people expect, and it's changed since the CCPA first passed. Here's what currently counts, what doesn't, and where the lines get blurry.

## How the CCPA/CPRA Defines Personal Information

The [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/) and [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/us/cpra/) define personal information as information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household."

That "reasonably capable" language is doing a lot of work, as it means the definition covers data that makes identification possible, not just data that identifies someone outright. There's no format or medium limitation, so images and audio recordings can qualify if they fall under the definition, just as text-based data can.

## Personal Information Under CCPA/CPRA

- **Direct identifiers** — Real name, alias, postal address, email address, Social Security number, driver's license or passport number, signature.
- **Indirect identifiers** — Cookies, IP addresses, device or account identifiers, beacons, pixel tags.
- **Biometric data** — Face, retina, fingerprint, voice recordings, and similar data.
- **Geolocation data** — When it's precise enough to identify a person within a defined radius.
- **Internet or network activity** — Browsing history, search history, interaction data with a website or app.
- **Sensitive personal information** — Social Security number, racial or ethnic origin, immigration status, genetic data, precise geolocation, and similar categories that carry additional protections.

### What Doesn't Count as Personal Information

De-identified and aggregate data are exempt, but the exemption only holds if the data genuinely can't be re-identified. This is a narrower carve-out than it sounds. Data that seems anonymous on its own, but that a business can reasonably link back to a device, browser, or household (including through inference) doesn't qualify for the exemption.

This is the mechanism behind a common compliance mistake, that of treating "anonymized analytics data" as automatically exempt. If that data is later used to draw inferences for the purpose of creating an advertising or behavioral profile, it can become personal information at that point, even if it wasn't when first collected.

### Household Information Is a Separate Category

The CCPA/CPRA also covers household information, which is defined in the implementing regulations as a person or group of people who reside at the same address, share a common device or service, and are identified by the business as sharing a group account or unique identifier. It's a narrower and more specifically defined category than the general personal information definition above, and it's been debated since the law passed for its ambiguity in practice.

Know what you're actually collecting
Cookiebot CMP scans your entire site to identify every cookie and tracker collecting personal information under California law. Automated for  evolving privacy requirements. Try it free.

[Start Scan](https://www.cookiebot.com/us/cookie-checker/)

### Who Has to Comply?

Three separate paths trigger CCPA/CPRA coverage, and a business only needs to cross one of them:

- Gross annual revenue above USD 25 million (the current CPI-adjusted 2025 figure is USD 26,625,000, to be updated again in 2027)
- Handling the personal information of more than 100,000 California consumers or households in a given year, whether bought, sold, received, or shared
- Generating 50 percent or more of annual revenue from selling or sharing personal information

Location doesn't factor in. A business headquartered anywhere in the world is covered the moment it crosses one of these lines and touches a California resident's data.

### Global Privacy Control (GPC) and Personal Information

Because cookies and IP addresses qualify as personal information under the CCPA/CPRA, visitors need a way to exercise their opt-out rights over that data. The CPRA doesn't limit that to a manual click. It requires businesses to treat a [Global Privacy Control (GPC)](https://www.cookiebot.com/us/global-privacy-control-gpc/) signal, sent automatically by a visitor's browser, as a valid request to opt out of the sale or sharing of their personal information.

In practice, this means a business's systems need to recognize the signal and stop selling or sharing that visitor's personal information without waiting for them to find and click a link. The CPPA has named GPC compliance an active enforcement priority.

### Enforcement Is Active

The CPRA took effect January 1, 2023. Its implementing regulations were finalized in stages, and a legal challenge briefly delayed enforcement, until California's Third District Court of Appeal ruled on February 9, 2024 that the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/), known publicly as CalPrivacy, could enforce them immediately, effective back to July 1, 2023. The CPPA now shares enforcement authority with the California Attorney General, though a business can't be penalized by both for the same violation.

### Cookies, IP Addresses, and CIPA: A Related but Separate Risk

The same broad "indirect identifier" definition that makes cookies and IP addresses personal information under the CCPA/CPRA is also, separately, the basis for a wave of private lawsuits under California's decades-old wiretapping law, the [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/). While it's a separate statute from the CCPA/CPRA, it's worth mentioning due to the litigation, and because even full CCPA compliance does not protect against [CIPA claims](https://www.cookiebot.com/us/understand-and-respond-to-cipa-demand-letter/).

Plaintiffs argue that cookies and tracking pixels capturing this kind of data before a visitor consents can qualify as an unlawful pen register or wiretap. The courts are currently split on this theory. CIPA carries no revenue or volume threshold, so it applies even to businesses that fall well under every CCPA/CPRA compliance threshold above.

Any individual can file a claim, and no proof of harm is currently required. There is legislation to address some of the issues, but even if passed it will be some time before it comes into effect, and it doesn't touch two of the major sources of litigation.

### How Cookiebot CMP Helps with Privacy Compliance for Personal Information

[Cookiebot CMP](https://www.cookiebot.com/us/cookie-consent-solution/) scans your site to detect every cookie, tracker, and third party collecting this kind of data, categorizes what it finds, and keeps your cookie declaration current. It can also block non-essential cookies from firing until a visitor has made a consent choice, and configure the "Do Not Sell or Share My Personal Information" link automatically for visitors it detects are in California. Because it recognizes GPC signals directly, visitors never have to hunt down a link to exercise a right that systems should already be honoring.

Obtain compliant consent for personal information
See how Cookiebot CMP detects, categorizes, and manages consent for every cookie and tracker on your site. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Summary

The CCPA/CPRA defines personal information broadly enough to cover cookies, IP addresses, and inferred data, not just names and emails. This guide breaks down the categories of personal information under California law, what counts as a household, which businesses the thresholds apply to, and how that broad definition connects to a separate, growing litigation risk under CIPA.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)