---------------------------
Title: CCPA Consumer Rights: Business Requirements in 2026
URL: https://www.cookiebot.com/us/ccpa-rights-for-consumers-ccpa-compliance-with-cookiebot-cmp/
---------------------------

# CCPA Consumer Rights: Business Requirements in 2026

This guide covers all eight CCPA and CPRA consumer rights that apply to businesses handling California residents' personal information, from the right to know and delete to the newer automated decision-making rights. Written for U.S. businesses, it includes the CPPA's 2026 ADMT, cybersecurity audit, and risk assessment rules, and how a consent management platform helps you meet them.

## At a Glance

- The CCPA and its CPRA amendments give California consumers eight distinct rights; two, notice and opt-out regarding automated decision-making (ADMT), became enforceable January 1, 2026, with full compliance required by January 1, 2027 for businesses already using ADMT for significant decisions.
- The CCPA applies to any for-profit business handling California consumers' personal information that clears one of three thresholds: over $26,625,000 in annual gross revenue, buying or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.
- Larger businesses now face phased cybersecurity audit deadlines running from 2028 through 2030, plus a risk assessment requirement for high-risk processing activities.
- California remains the only state offering consumers a private right of action for certain data breaches, with statutory damages of $107 to $799 per consumer per incident.
- Beyond the CCPA, the California Invasion of Privacy Act (CIPA) is a separate, older law with its own private right of action for website tracking tools, currently the subject of pending reform (SB 690) that wouldn't take effect until 2027 at the earliest.
- A consent management platform helps operationalize several of these rights at once: notice at collection, the opt-out link, and audit-ready consent records.

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents specific rights over their personal information, and gives businesses specific obligations for honoring them. This guide walks through each right, what it actually requires operationally, and what changed under the California Privacy Protection Agency's (CPPA) regulations that took effect January 1, 2026.

## Which Businesses Does the CCPA Apply To?

The CCPA applies to any for-profit business that collects personal information from California residents and meets at least one of three thresholds:

- Annual gross revenue exceeding USD 26,625,000 (the statute's original USD 25,000,000 figure, adjusted for inflation; next adjustment due January 2027)
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households per year
- Derives 50 percent or more of annual revenue from selling or sharing California consumers' personal information

Location doesn't matter. A business based anywhere, in another state or another country, is covered if it does business in California and meets one of these thresholds. Nonprofits and government agencies are exempt, as are certain categories of data already governed by other federal laws, such as protected health information under HIPAA.

## The Eight CCPA and CPRA Consumer Rights

The original [CCPA](https://www.cookiebot.com/us/what-is-ccpa/) established consumer rights to know, delete, opt out of sale, and non-discrimination. The [CPRA](https://www.cookiebot.com/us/cpra/) formally added two more: the right to correct and the right to limit use of sensitive personal information. Since then, rulemaking by the [CPPA](https://www.cookiebot.com/en/escalating-cppa-enforcement/) (now publicly known as CalPrivacy) has turned automated decision-making transparency, something the CPRA authorized but left to regulation, into two additional operative rights: notice and access regarding ADMT, and the right to opt out of it. Together, that's eight rights consumers can act on today.

### Right to Know

California consumers can request that a business disclose the categories and specific pieces of personal information it has collected about them in the preceding 12 months, including:

- Categories of personal information collected
- Sources the information came from
- Business or commercial purpose for collecting, selling, or sharing it
- Categories of third parties the business shares it with

Businesses must offer at least two request methods, one of which must be a toll-free number or a web form, and must respond within 45 days (extendable once by another 45 days if the consumer is notified before the first period expires). Requests must be handled without requiring the consumer to create an account, though an existing account can be used to verify identity.

### Right to Delete

Consumers can request deletion of personal information a business holds about them, subject to statutory exceptions. When a business receives a verified deletion request, it must delete the information from its own records and instruct any service providers and third parties who received it to do the same.

The exceptions are specific, not a general opt-out for businesses: completing a transaction the consumer initiated, detecting security incidents, exercising free speech rights, complying with a legal obligation, and a small number of other defined purposes. A business must acknowledge a deletion request within 10 business days and respond substantively within 45 days.

### Right to Correct

Added by the CPRA, this right gives consumers the ability to request that a business correct inaccurate personal information it holds about them. The business must use commercially reasonable efforts to make the correction, considering the nature of the information and the purposes for which it's processed.

### Right to Opt Out of Sale or Sharing

Consumers can direct a business to stop selling or sharing their personal information with third parties. Under the CCPA, "sale" is defined broadly, covering selling, renting, disclosing, or otherwise making personal information available to a third party for valuable consideration. The CPRA separately added "sharing," which captures cross-context behavioral advertising even where no money changes hands.

Businesses that sell or share personal information must post a "Your Privacy Choices" link (or the older "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link) so consumers can opt out without creating an account. Consumers using a [Global Privacy Control](https://www.cookiebot.com/en/global-privacy-control/)–enabled browser or extension can trigger this opt-out automatically, without submitting a separate request. Businesses that sell or share personal information for cross-context behavioral advertising must honor this signal.

Minors have additional protections. Businesses need affirmative opt-in consent from a parent or guardian to sell or share the personal information of consumers under 13, and opt-in consent from the minor directly for consumers aged 13 to 15.

### Right to Limit Use of Sensitive Personal Information

The CPRA created a defined category of sensitive personal information (Social Security numbers, precise geolocation, health data, and similar categories) and gave consumers the right to limit its use and disclosure to what's necessary to provide the requested goods or services. Businesses using sensitive personal information beyond that must offer a "[Limit the Use of My Sensitive Personal Information](https://usercentrics.com/guides/website-disclaimers/limit-the-use-of-my-sensitive-personal-information/)" link.

### Right to Notice and Access Regarding Automated Decision-Making

This is the right that changed most substantially heading into 2026. The CPPA's regulations, effective January 1, 2026, require businesses using automated decision-making technology (ADMT) for a "significant decision" (employment, lending, healthcare, and similar high-stakes outcomes) to give consumers a pre-use notice explaining what the ADMT does, how it works, and what happens if the consumer opts out. Consumers can also request access to information about how a specific ADMT decision was made about them.

### Right to Opt Out of Automated Decision-Making

Alongside the notice and access right, consumers can opt out of a business's use of ADMT for significant decisions. Businesses already using qualifying ADMT must be compliant by January 1, 2027; businesses that begin using it after that date must comply immediately. If your business uses automated tools for hiring, credit decisions, or similar significant outcomes, this is worth treating as a near-term project, not a 2027 problem to defer.

### Right to Non-Discrimination

Businesses cannot penalize consumers for exercising any CCPA right. Specifically, a business cannot deny goods or services, charge different prices, or provide a different quality of service because a consumer opted out of a sale, requested deletion, or exercised any other right.

Financial incentive programs are the one carve-out: a business can offer a different price or service level in exchange for personal information, provided the difference is reasonably related to the value the data provides, and the program is clearly disclosed.

### Right to Sue for Data Breaches

California remains the only state offering consumers a private right of action under its comprehensive privacy law, and it's narrower than it might sound. It applies only to a data breach involving unencrypted, unredacted personal information (things like a Social Security number, driver's license number, or financial account number combined with a name), and only where the breach resulted from the business's failure to maintain reasonable security procedures.

Consumers must first notify the business in writing and give it 30 days to cure the issue before filing suit. If the business doesn't resolve it, consumers can recover statutory damages of USD 107 to USD 799 per consumer per incident, or actual damages, whichever is greater.

## New for 2026: Cybersecurity Audits and Risk Assessments

The CCPA's core rights are the part most content covers. What's newer, and what most 2022-era guidance on this topic misses entirely, is the operational compliance layer the CPPA finalized in 2025.

### Risk Assessments

Businesses must complete a risk assessment before starting any processing activity that presents "significant risk" to consumers, including selling or sharing personal information, using ADMT for significant decisions, or processing sensitive personal information. Assessments no longer need to be submitted to the CPPA annually, but must be completed or updated within 45 days of a material change to the underlying processing activity.

### Cybersecurity Audits

Businesses that meet the revenue threshold and either process personal information of 250,000 or more consumers or households, or sensitive personal information of 50,000 or more consumers, must complete independent annual cybersecurity audits. The first-audit deadlines are phased by revenue:

- **April 1, 2028**, for businesses with more than USD 100 million in 2026 revenue
- **April 1, 2029**, for businesses with USD 50 million to USD 100 million in 2027 revenue
- **April 1, 2030**, for businesses with less than USD 50 million in 2028 revenue

These deadlines feel distant, but the underlying documentation, what data you process, where, and under what security controls, is worth building now rather than in a scramble the year before your audit is due.

## CIPA: A Separate, Older Privacy Law With Its Own Teeth

The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is not part of the CCPA framework, and CCPA compliance does not protect you from CIPA liability. However, it's worth a mention as consent is directly relevant.

Enacted in 1967 to address telephone wiretapping, CIPA requires all-party consent before a communication is intercepted or recorded. Since a 2022 Ninth Circuit ruling opened the door, plaintiffs' attorneys have applied that theory to everyday website tools: cookies, tracking pixels, session replay software, and chat widgets, arguing that these technologies intercept a visitor's interaction with a site without the visitor's consent.

Two sections carry most of this exposure:

- **Section 631 (wiretapping)** and **Section 632 (eavesdropping and confidential recording)**, which prohibit intercepting or recording a communication without consent from all parties
- **Section 638.51 (pen register and trap-and-trace)**, which prohibits installing or using a device that captures routing or addressing information about a communication without a court order

Unlike the CCPA, CIPA carries its own private right of action for these provisions, meaning any California resident, not just the Attorney General, can sue directly. Plaintiffs' firms have filed [thousands of Section 638.51 claims against businesses](https://www.cookiebot.com/us/understand-and-respond-to-cipa-demand-letter/) using standard analytics and marketing tools, and courts remain genuinely split on whether these tools qualify as pen registers under a decades-old statute never written with websites in mind.

### **Reform is pending, not final**

[Senate Bill 690](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB690) would remove the private right of action for Section 638.51 claims arising from website, app, or online conduct, leaving enforcement to the California Attorney General alone, and would apply retroactively to pending claims filed within the two years before the bill takes effect. As of this writing, SB 690 has passed the Assembly Appropriations Committee but still needs a full floor vote and Senate concurrence before the legislature's August 31, 2026 deadline, plus the Governor's signature. It would not touch Sections 631 or 632, so wiretapping and eavesdropping exposure continues regardless of how SB 690 turns out.

For businesses, the practical takeaway is that a CMP handling CCPA notice and opt-out obligations does not, by itself, address CIPA risk. That requires a separate look at what your website's tracking tools actually do and whether visitors have a meaningful basis to say they consented to it. Best practices would involve adoption of a GDPR-like template so opt-in consent is required from all visitors, before any tracking tools fire when they arrive on your website.

## How a Consent Management Platform Supports CCPA Compliance

A consent management platform (CMP) doesn't handle every CCPA obligation, ADMT governance and cybersecurity audits are broader operational programs, but it directly supports several of the rights above.

[Cookiebot™ CMP by Usercentrics](https://www.cookiebot.com/us/cookie-consent-solution/) scans your website for the cookies and tracking technologies in use, giving you an accurate, current inventory of what personal information you collect and share with third parties. That inventory is the foundation of an accurate notice at collection, and it's the same information you'll need on hand if a consumer submits a right-to-know request.

For the right to opt out, Cookiebot CMP can present the "Do Not Sell or Share" link and honor Global Privacy Control signals automatically, so consumers who've set an opt-out preference in their browser don't need to submit a separate request on your site. The platform also maintains a timestamped, audit-ready record of consent choices, which helps support your compliance position if CalPrivacy or a plaintiff's attorney asks questions later.

## Your CCPA Compliance Checklist

Check whether your business meets any of the three CCPA applicability thresholds

- Publish a notice at collection describing what personal information you collect and why
- Post a working "Your Privacy Choices" (or "Do Not Sell or Share") link and honor Global Privacy Control signals
- Provide at least two verifiable request methods for access, correction, and deletion requests
- Build a documented process for the 45-day (access, deletion) and 15-business-day (opt-out) response windows
- If you use ADMT for significant decisions, start building your pre-use notice and opt-out mechanism now, ahead of the January 1, 2027 compliance date
- If you're approaching the revenue and data-volume thresholds for cybersecurity audits, begin documenting your security program before the phased deadlines arrive

## Simple, powerful, automated consent management

Cookiebot™ CMP scans your site, categorizes cookies and trackers, handles opt-ins and opt-outs, and keeps an audit-ready consent record, so you can spend less time on maintenance and assembling CCPA documentation by hand. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup)

## Preamble

Note: The California Privacy Rights Act (CPRA) went into effect in January 2023, and expands and amends the CCPA, including providing consumers with modified and additional rights.
On January 1, 2020, the state of California passed the first compressive data privacy law in the US.
The California Consumer Privacy Act (CCPA) gives California residents ownership and control over their personal information, including much of the data they generate every day online, through new personal rights.
As a business, if you operate in California, it’s important to know about compliance requirements for businesses, the multiple CCPA consumer rights, how to navigate them, what is and is not allowed, and how you can achieve and maintain compliance using a consent management platform.

## Summary

This guide covers all eight CCPA and CPRA consumer rights that apply to businesses handling California residents' personal information, from the right to know and delete to the newer automated decision-making rights. Written for U.S. businesses, it includes the CPPA's 2026 ADMT, cybersecurity audit, and risk assessment rules, and how a consent management platform helps you meet them.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)