All Blog Posts

CCPA Privacy Policy: Requirements and Best Practices

Close
Read time
12 mins
Updated
Jul 30, 2026
Share

  • The CCPA gives California residents rights to know, delete, correct, opt out of sale/sharing, and limit use of their sensitive personal information. Your privacy policy must explain all of them and how to exercise them.
  • Coverage isn't limited to companies based in California. It applies if you meet any one of three thresholds: over $25M in annual gross revenue, buying/selling/sharing data for 100,000+ California residents or households, or deriving 50% or more of revenue from selling that data.
  • Your policy needs a prominent "privacy" link, a "Do Not Sell or Share My Personal Information" link if you sell data, and a "Limit the Use of My Sensitive Personal Information" link if you handle sensitive categories.
  • It must disclose what personal information categories you've collected, sourced, and disclosed in the last 12 months, and must be reviewed and updated at least annually.
  • The CPRA expanded the original CCPA and created the California Privacy Protection Agency (CPPA), which took over enforcement in February 2024.
  • New CCPA regulations effective January 1, 2026 add mandatory cybersecurity audits, risk assessments, and ADMT rules alongside the privacy policy requirements above.

What Is the California Consumer Privacy Act (CCPA)?

The California Consumer Privacy Act (CCPA) is the first modern and comprehensive state-level data privacy law in the United States. It took effect on January 1, 2020 and governs the collection, processing, and selling of California residents' personal information.

The CCPA empowers California residents (referenced as “consumers” under the law) with several rights regarding their personal information.

  • Right to know: Consumers can request information about the collection, use, and sharing of their personal data by businesses.
  • Right to delete: Consumers can ask businesses to delete their personal information, with certain exceptions.
  • Right to opt out: Consumers can opt out of the sale to or sharing of their personal information with third parties.
  • Right to nondiscrimination: Businesses cannot discriminate against consumers who exercise their CCPA rights.
  • Right to correct: Consumers can ask businesses to correct inaccurate or incomplete information about them.
  • Right to limit: Consumers can request to limit the use of sensitive personal information collected from/about them, such as Social Security Number or financial account information, for restricted purposes.

The CCPA regulation took effect January 1, 2020, though enforcement by the California Attorney General’s office did not start until July 1 of that year. The CCPA regulation specifies practical and technical aspects of how to achieve compliance.

What Is the California Privacy Rights Act (CPRA)?

On November 3, 2020, the California Privacy Rights Act (CPRA), which amended and expanded the CCPA, was passed into law in a general election.

The CPRA expanded the rights of California residents, created additional business requirements and compliance thresholds, and established the California Privacy Protection Agency (CPPA) to take over enforcement and other functions from the Attorney General.

The CPRA took full effect on January 1, 2023 and was supposed to become enforceable on July 1, 2023, though applicable to data collected and shared from January 2022. However, a Sacramento County Superior Court ruling delayed enforcement of the CPRA regulations to March 29, 2024.

Examples personal information under the CCPA

What Is Personal Information Under the CCPA? Definition and Examples

Personal information is the crux of the CCPA’s regulatory function, as it was enacted to protect consumers’ personal information and regulate the collection, use, and sharing of it.

The CCPA defines personal information as “information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”

Categories of personal information, for example, as outlined in in CCPA privacy policies, include:

  • Direct identifiers (names, addresses, IP addresses, email, Social Security numbers, etc.)
  • Sensitive information, i.e. that which could enable particular harm to a person if it was misused, thus requiring certain restrictions and special handling (age, ethnicity, religion, political affiliation, health and healthcare, gender, sexual orientation, etc.)
  • Commercial information (credit card history, transaction details, payment info, etc.)
  • Geolocation data, if used for the purposes of identifying someone
  • Professional, employment, or education information
  • Inferences from any of above for the purpose of profiling

Information that is made lawfully available from federal, state, or local government records, information that is made publicly available (e.g. by a person’s online activities), or information that is deidentified or aggregated, is not considered personal information under the law.

Purposes of Collecting Personal Information

Common purposes why businesses may collect personal information include:

  • Operating, managing, and maintaining the business
  • Processing transactions and providing the consumer with a product or service 
  • Product development based on customer feedback and usage data
  • Personalizing user experience on websites or apps based on preferences and behaviors
  • Marketing and advertising to target specific customer segments
  • Website analytics
  • Compliance with legal and regulatory requirements

Who Must Comply with the CCPA?

A for-profit entity that does business in California and handles personal information of California residents must comply with the CCPA if it meets any one of the following criteria:

  • Gross annual revenue of over USD 25 million (periodically adjusted to the Consumer Price Index)
  • Buy, sell, or share the personal information of 100,000 or more California residents or households
  • Derive 50 percent or more of annual revenue from selling California residents’ personal information

Companies that meet any of these conditions must comply with the CCPA, even if the business is not located in California. It only matters if the people whose data is being processed are located in that state.

The CCPA/CPRA also apply to data brokers, defined by the California Civil Code as “a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.”

Businesses that are required to comply with the CCPA must notify consumers about data that is collected, how, for what purposes, and who may have access to it. They must also notify consumers about their rights and how they can exercise them via a privacy policy or privacy notice. Typically this is a page on a website.

CCPA Privacy Notice Requirements

There are two types of privacy notices required under the CCPA: a ”notice at collection” and a ”privacy policy”.

The notice at collection requires you to inform consumers, at or before the point of collection of personal information, about:

  • Categories of personal information, including sensitive personal information, that you will collect
  • Purpose(s) for which you will collect or use the personal information
  • How long you will keep each category of personal information

If you sell consumers’ personal information, your notice at collection must include a link to a web page that enables consumers to exercise their right to opt out of sale, sharing, targeted advertising, or profiling. The link must use the specific words “Do Not Sell or Share My Personal Information”. In most cases it is not required to obtain prior consent before collecting and processing personal information, though there are exceptions.

Businesses must also honor recognized opt-out preference signals, such as Global Privacy Control (GPC), as a valid method for consumers to submit a 'Do Not Sell or Share' request. This is in addition to, not instead of, the required opt-out link.

The notice at collection must also link to your privacy policy, which provides more detail about how you collect and use consumers’ personal information (including sale or sharing), consumers’ rights, and how to exercise them.

Personal information from consumers online is often collected through the use of tracking technologies such as cookies. A cookie banner can be used to fulfill the notice at collection requirements by providing clear information about cookie usage and opt-out options, and directing users to the full CCPA privacy notice or policy for more details.

CCPA Privacy Policy Requirements

If you collect or process data from European Union (EU) residents, your website may already have a privacy policy, which is also a requirement of other international data privacy laws like the EU’s General Data Protection Regulation (GDPR), which preceded and influenced the CCPA.

However, the CCPA has specific requirements for what your privacy policy must include and what ongoing CCPA compliance requires. Let’s look at the CCPA’s privacy policy requirements.

1. Easy to Access

Companies must provide a clear and prominent link to your privacy policy on the website, and the link must include the word “privacy” in it. “Privacy Policy”, “California Privacy Policy”,  or "California Privacy Rights" are all acceptable under the CCPA.

The privacy policy should be accessible and legible regardless of the device consumers are using, including smartphones, tablets, and desktop computers. It should also be reasonably accessible to consumers with disabilities.

2. Provide Information About Consumer Rights

The privacy policy must inform consumers about their rights under the CCPA and how they can exercise these rights.

Some rights, such as the right to delete, correct, or access information, require provision of two methods by which consumers can exercise their rights, which the privacy policy must communicate. An exception to this requirement is businesses that operate exclusively online, which only need to provide an email address for submitting these requests.

The "Do Not Sell or Share My Personal Information" link should also be included in the privacy policy to enable consumers to opt out of the sale of their personal information. Businesses that process sensitive personal information have to implement a link reading “Limit the Use of My Sensitive Personal Information” or comparable as long as it enables consumers to opt out or limit disclosure of their sensitive personal information.

3. Inform Consumers About How You Use Their Personal Information

A CCPA privacy policy must provide details about your personal information handling and privacy practices, including:

  • Categories of personal information collected in the last 12 months
  • Categories of sources from where personal information is collected
  • Specific purposes for which personal information is used

Companies that disclose, sell or share personal information must also inform consumers about:

  • Categories of personal information disclosed, sold, or shared in the last 12 months
  • To whom the personal information was disclosed, sold, or shared
  • Specific purposes for which the disclosure, sale, or sharing was done
  • Whether the company has actual knowledge of the sale or sharing of personal information of minor consumers under the age of 16 years

Opt-in consent is required specifically for the sale or sharing of personal information belonging to a consumer known to be under 16. Consumers aged 13–15 may authorize this themselves; for those under 13, a parent or guardian must authorize it. If a minor or their guardian declines, businesses must wait at least 12 months before asking again.

Selling has a broad definition in the CCPA that includes disclosure and sharing personal information “for monetary or other valuable consideration“. Categories of personal information that companies disclosed to third parties, e.g. through third-party cookies on the website, should, therefore, be included in the privacy policy even if the company did not make money from sharing the personal information.

4. Update at Least Every 12 Months

The CCPA requires companies to review and update their privacy policy every 12 months so that consumers are made aware if the business starts collecting new categories of personal information, or if it starts collecting personal information with a different purpose than before.

If there are changes to how you handle consumers’ personal information in the interim, update your privacy policy as business operations, technologies in use, and/or regulatory requirements change.

Your CCPA privacy policy should also include the date on which it was last updated.

5. Use Language That Is Easy to Understand

Write the privacy policy in clear, straightforward language that anyone can understand without requiring specialized legal knowledge. Structure it so it's easy for consumers to navigate, using clear headings and subheadings to organize the information effectively.

If the website caters to a multilingual audience, the company must provide the privacy policy in all the languages offered on the site.

CCPA vs GDPR Privacy Policy Requirements

The GDPR, one of the world’s most stringent privacy laws, requires businesses to have a privacy policy regarding the processing of personal data of EU residents. Both the GDPR and CCPA require that privacy policies be written in simple language that is easy for anyone to understand without requiring technical or legal knowledge. However, there are also several differences between their requirements.

FunctionCCPAGDPR
ContentRequires disclosures of:

- Categories of personal information collected
- Purposes for collection
- Consumer rights (access, deletion, opt-out of sale, etc.)
- How consumers can exercise their rights
    Requires disclosures of:

    - Legal basis for processing
    - Purposes for processing
    - Data retention periods
    - Detailed rights of individuals (access, erasure, restriction, rectification, etc.) including the right to lodge a complaint with a supervisory authority
    - Information about automated decision-making
      Consent and opt-out or withdrawalAs the law incorporates an opt-out model for the sale of personal information, it requires a link to a web page for consumers to exercise this right, with the specific words "Do Not Sell or Share My Personal Information" linked.The privacy policy must explain how users can give or reject consent for collection and processing of their personal information at a granular level, and can change or withdraw consent for any processing based on consent.
      Updating frequencyStipulates that privacy policies must be updated at least once every 12 months.Does not specify a mandatory update frequency but requires that information be kept up to date and accurate. User consent should also be refreshed regularly, e.g. every 12 months, or if processing conditions change.
      Risk-based obligationsNew regulations effective January 1, 2026 require annual cybersecurity audits and risk assessments for larger or higher-risk businesses, plus new rules governing automated decision-making technology (ADMT).- No blanket annual audit mandate
      - Article 32 requires ongoing, risk-appropriate security measures
      - Article 35 mandates a Data Protection Impact Assessment (DPIA) before most high-risk or automated-decision-making processing
      - Article 22 gives individuals rights around solely automated decisions with legal or similarly significant effects
      Transparency and detailingFocuses on informing consumers about the business’s data collection practices and consumer rights.Requires more detailed explanations, including specifics about data transfer to third countries and the safeguards in place.

      CCPA Privacy Policy Checklist

      Here is a CCPA privacy policy checklist of what you must include in order to support compliance with California's data privacy law.

      Your CCPA privacy policy must:

      • Be prominently linked to on your website, with the word “privacy” included in the link
      • Include detailed information about CCPA consumer rights and how to exercise them
      • Include a link titled "Do Not Sell or Share My Personal Information" that goes to a web page where consumers can opt out of the sale of their personal information
      • Include a link titled “Limit the Use of My Sensitive Personal Information” if the company processes sensitive personal information, enabling consumers to opt out or restrict processing of it
      • Provide a list of all categories of personal information collected in the last 12 months
      • Specify categories of sources from where personal information is collected
      • Disclose the specific purposes for which personal information is used
      • Detail categories of personal information disclosed, sold, or shared in the last 12 months, including recipients and purposes
      • Be updated at least every 12 months to reflect any new data collection or usage purposes and include the last update date within the policy
      • Be written in clear, straightforward language accessible to all readers
      • Available in all languages available in the website

      Privacy Policy Tips for CCPA Compliance

      Here are some steps your business can take to comply with the CCPA privacy policy requirements.

      1. Audit and map out all data collection activities to understand what personal information is being collected, used, and shared, including through cookies.
      2. Display a notice at the point of collection, such as a cookie banner, to inform consumers about collection, use, and sharing of personal information.
      3. Update your privacy policy to include CCPA-required information, such as descriptions of consumer rights and how to exercise them, at least every 12 months.
      4. Establish a straightforward and easily accessible process for consumers to exercise their CCPA rights, including requests to access, delete, or opt out of the sale of their personal information, and share this in the privacy policy.
      5. Develop a procedure to verify the identity of individuals making requests related to their personal information to prevent unauthorized access or deletion.
      6. Regularly review and update data protection practices to support ongoing compliance with the CCPA, CPRA, and any future amendments or regulations.
      7. Use a consent management platform (CMP) like Cookiebot™ CMP to streamline the process of managing user consents and preferences in line with CCPA requirements, for transparent and user-friendly consent experiences.

      Frequently asked questions

      The California Consumer Privacy Act (CCPA) is a state law that regulates how businesses are allowed to collect, share, and sell the personal information of California residents. The CCPA empowers California residents with the right to opt out of the sale or sharing of their personal information with third parties, the right to access already collected personal information, and the right to have it deleted.

      Businesses must comply with the CCPA if they have an annual gross revenue exceeding $26,625,000 (the original $25 million baseline, adjusted for inflation as of January 1, 2025), derive more than 50 percent of annual revenues from personal information sales, or buy, receive, sell, or share the personal information of 100,000 or more California residents or households.

      A CCPA-compliant privacy policy must inform consumers of what categories of personal information the business collects, including the specific purposes of collection and sources for each category of personal information. A CCPA privacy policy must also inform consumers of what categories of personal information the business has sold to or shared with third parties in the last 12 months.

      As of January 1, 2026, it must also describe consumers' right to opt out of automated decision-making technology (ADMT) and, where applicable, to access the logic behind ADMT-based decisions. A CCPA privacy policy must be updated annually and be easily accessible from the website's homepage.

      A for-profit business that collects personal information of California residents and meets at least one of the three following thresholds must create a CCPA privacy policy:

      1. Has an annual gross revenue exceeding USD 26,625,000
      2. Derives 50% or more of its annual revenues from selling or sharing the personal information of California residents
      3. Buys, receives, sells, or shares the personal information of 100,000 or more California residents or households annually.

      A company doesn't have to be based in California to be liable under the CCPA. If a company in Texas or Europe meets any of the three thresholds above, it must comply with the CCPA.

      Yes, the CCPA is designed to protect the privacy rights of California residents specifically. It applies to businesses that collect personal information from residents of California, regardless of where the business itself is located.

      The CCPA already defines "resident" by incorporating California's existing tax-law definition (18 CCR § 17014): someone in California for other than a temporary or transitory purpose, or someone domiciled in California who is only temporarily outside the state. Applying that test can still require a fact-specific judgment call, for example, whether a college student living in California part of the year counts as a resident depends on the specifics of their situation, not on a gap in the law.

      The CCPA empowers California residents with the following rights:

      • To opt out of having their personal information shared with or sold to third parties
      • To know about the collection, sharing, and selling of their personal information
      • To have already collected data deleted
      • To equal services and prices regardless of whether they choose to exercise any of these rights (anti-discrimination)
      • To have inaccurate information about them corrected
      • To limit the use of their sensitive personal information
      • To receive a copy of collected personal information in a portable, readily usable format
      • To opt out of automated decision-making technology (ADMT) that produces legal or similarly significant effects, and to access the logic behind such decisions (effective January 1, 2026)

      The penalty for not having a CCPA/CPRA privacy policy can result in penalties of up to $7,988 per intentional violation or $2,663 per unintentional violation (adjusted for inflation effective January 1, 2025).

      These fines can escalate rapidly, as each individual consumer's rights violation constitutes a separate violation. Additionally, failure to comply with the privacy policy requirements, such as maintaining a CCPA/CPRA-compliant privacy policy and responding to consumer requests, can also result in penalties.