---------------------------
Title: How to Comply With CCPA: Step-by-Step Compliance Support for Businesses
URL: https://www.cookiebot.com/us/how-to-comply-with-ccpa/
---------------------------

# How to Comply With CCPA: Step-by-Step Compliance Support for Businesses

We cover steps to help achieve and maintain CCPA compliance, including a step-by-step checklist for business owners, website managers, and compliance leads. Learn about CCPA requirements, get assistance confirming whether the law applies, and information on setting up a compliant opt-out link and a consumer request process. This article also covers CPRA updates and how enforcement is changing the landscape.

## At a Glance

- The CCPA applies to for-profit businesses that meet at least one of three thresholds tied to revenue, data volume, or data monetization.
- Covered businesses must display a "Do Not Sell or Share My Personal Information" link — exact wording matters — and follow additional rules for handling sensitive personal information.
- Businesses generally have 45 calendar days to respond to a verifiable consumer request, extendable once by another 45 days with notice.
- CPRA expanded consumer rights and added a sensitive personal information category, including recognizing the Global Privacy Control (GPC) browser signal as a valid, legally required opt-out, so a compliance approach built for the original CCPA may no longer be complete.
- CCPA compliance doesn't protect against potential violations of CIPA, VPPA, or ECPA.
- A consent management platform can help automate much of the technical work involved, including cookie scanning, consent management and record-keeping, and GPC detection.

If you run a website that collects data from California residents, California Consumer Privacy Act (CCPA) compliance can sound like a legal minefield. In practice, it comes down to a defined, repeatable set of steps. Companies do need to stay up to date on the evolving regulatory landscape, but best practices to support ongoing CCPA compliance don’t need to be resource drains.

It’s always a good idea to consult qualified legal counsel, especially as business operations, technologies in use, and regulations change. To support compliance activities, we provide a practical, plain-language set of steps and a checklist covering what most small and midsize businesses (SMBs) need to put in place and keep up to date.

This ranges from confirming whether the law applies to your organization, through opt-out mechanisms and consumer request handling, to keeping your setup current as the rules evolve. We also touch on other regulatory considerations and how Cookiebot™ CMP can help.

## Does CCPA Apply to Your Business?

The CCPA does not apply to every business, and figuring out whether it applies to yours is the first compliance step. The law generally covers for-profit businesses doing business in California that meet at least one of three thresholds.

Organizations that meet at least one of the following thresholds are required to comply:

- Annual gross revenue exceeds USD 25 million (adjusted periodically to the Consumer Price Index, and currently at USD 26.625 million)
- Buying, selling, or sharing the personal information of 100,000 or more California residents or households per year
- 50 percent or more of annual revenue comes from selling or sharing personal information

If you checked any one of these, CCPA applies to you. Note that physical location is irrelevant here: a business based anywhere in the world is in scope if it collects personal information from California residents and meets one of the thresholds above. This can include individuals online viewing targeted ads, e-commerce customers, even employees and job applicants.

## What Is Personal Information Under CCPA?

Personal information under the [California Consumer Privacy Act (CCPA)](/en/what-is-ccpa/) is any data that identifies, relates to, or could reasonably be linked with a particular consumer or household.

That covers obvious identifiers such as names and email addresses, as well as less obvious ones like IP addresses, cookie IDs, browsing behavior, and geolocation data.

The [California Privacy Rights Act (CPRA)](/en/cpra/) also introduced a sensitive personal information category, which includes Social Security numbers, precise geolocation, health data, and financial account details, among others. This category carries stricter handling and security requirements than standard personal information.

## CCPA vs. CPRA: What Changed?

The CPRA is not entirely a separate law. It is a 2023 amendment that expanded consumer rights under CCPA and tightened several existing obligations. The original CCPA gave consumers a set of rights, and several more were added when the CPRA was passed.

Additionally, the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/), or CalPrivacy, was introduced with the CPRA as well.

**Consumer Right****CCPA****CCPA + CPRA**Right of access✅✅Right to opt out of sale✅✅Right to deletion (with exceptions)✅✅Right to non-discrimination for exercising rights✅✅Right to correction✅Right to data portability✅Right to restrict sensitive personal data collection and use✅Right to request or access information about automated decision-making✅Right to opt out of automated decision-making technology✅Enforcement bodyCalifornia Attorney GeneralCalifornia Attorney General and California Privacy Protection Agency (CPPA/CalPrivacy)

If your privacy compliance approach predates 2023, it is worth revisiting. Check out our full CCPA vs CPRA comparison for more details.

## CCPA Compliance Support Checklist: 7 Steps

These seven steps map to the legal requirements above and cover what most SMBs need to put in place. No legal background is required to work through them, though a privacy attorney should review your final setup.

### Step 1: Audit What Personal Data You Collect

Start by identifying every category of personal data your website collects, where it comes from, and who it is shared with. For most SMBs, cookies and tracking pixels are the primary collection mechanism, quietly gathering identifiers, browsing behavior, and device data on every page load. You cannot comply with a law covering data you have not accounted for, so this audit is the foundation everything else depends on.

While the CCPA does not require prior consent for most data collection and use, it is increasingly a best practice to obtain consent (and promptly honor opt-outs) for all data processing. We will cover some of the reasons for that later in this article.

## Find Out What's Running on Your Site

Not sure what cookies and trackers are active on your website? Scan it for free with Cookiebot™.

[Start free scan](https://www.cookiebot.com/en/cookie-checker/)

### Step 2: Update Your Privacy Policy

Your privacy policy needs to disclose several types of information, including:

- Categories of personal information you collect
- Purposes for collecting and use of personal information
- If and how you share personal information with third parties
- What rights consumers have, and how they can exercise them

Keep the policy itself in plain language rather than dense legal drafting. The goal is a document consumers can actually read and understand, not just one that satisfies a checklist.

An outdated privacy policy is also a common thread in recent enforcement actions, so treat it as a living document, not a one-time task. It should be updated at least every 12 months, but ideally every time there’s a notable change to business operations, technologies in use, and/or regulatory requirements.

Cookiebot™ provides a [Privacy Policy Generator](https://usercentrics.com/privacy-policy-generator/) so you can create a customized privacy policy for CCPA/CPRA requirements (and other regulations) in minutes. Additionally, Cookiebot CMP enables automated updates to your privacy notice and consent banners when the regular cookie and tracker scans are run.

See our guide to CCPA privacy policy requirements for the full disclosure list.

### Step 3: Add a "Do Not Sell or Share" Link and Honor GPC

Covered businesses must display a "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link prominently on their homepage and within their privacy policy, and the exact wording matters — it’s stipulated in the regulation itself.

Businesses must also respond to requests to not sell or share that personal information across their organization, regardless of where the business collected that personal information.

If your organization collects and processes sensitive categories of personal information, you must also clearly and accessibly display a “[Limit the Use of My Sensitive Personal Information](https://usercentrics.com/guides/website-disclaimers/limit-the-use-of-my-sensitive-personal-information/)” link. That specific wording is also required.

Consumers must also be able to exercise their opt-out right through the [Global Privacy Control (GPC)](/en/global-privacy-control/), a browser signal that California law requires businesses to honor as a valid opt-out.

Handling GPC correctly is a technical requirement. If an individual has the GPC signal set in their browser, your site must honor it — your consent banner should not be displayed at all — and, as of January 1, 2026, you are required to visibly confirm that the signal was processed. The CPPA's own regulatory example is displaying "Opt-Out Request Honored," though other compliant wording is permitted.

In September 2025, [CalPrivacy announced a joint investigative privacy sweep](https://cppa.ca.gov/announcements/2025/20250909.html) in conjunction with Colorado and Connecticut. The investigations centered around businesses not honoring consumers’ opt-out right for sale of their personal information via GPC signal. This sweep is one of the [Consortium of Privacy Regulators](https://cppa.ca.gov/announcements/2025/20250416.html)’ stated priorities (the group includes six other states), along with data broker registration, children's data, and dark patterns.

Cookiebot CMP detects and honors GPC signals automatically, so an opt-out registered in a consumer's browser is recognized without a business having to build that detection logic itself.

### Step 4: Enable Script Blocking Before Consent

The CCPA's opt-out model technically permits scripts to run before a consumer opts out. In practice, blocking data-sharing scripts until a consumer's preference is recorded is the more defensible approach, demonstrates a privacy-first approach, and can support prevention of CIPA claims and other litigation based on tracking practices.

Manually managing which scripts fire before and after an opt-out signal is error-prone at any scale beyond a handful of tags. Auto-blocking through a consent management platform, such as Cookiebot™ CMP, is the practical way most SMBs handle this without an engineering team dedicated to tag governance.

After a Cookiebot scan detects all the cookies and trackers in use on your site, you can enable auto-blocking of all of them until you obtain active user consent.

### Step 5: Set Up a Consumer Rights Request Process

Consumers can submit verifiable requests to access personal data held about them, and/or to request that it be deleted or corrected, to limit certain uses of it, or opt out of certain uses of it, including sale, sharing, targeted advertising, or automated decision-making.

Businesses must respond to consumer requests within 45 calendar days of receipt, extendable once by another 45 days (90 days total) under certain circumstances if the consumer is notified of the delay.

At minimum, organizations need a request intake method, such as a form or dedicated email inbox, an identity verification step, and a documented workflow for fulfilling each request type. Responses must be free of charge and provided in a format consumers can use elsewhere without hindrance.

For a closer look at building this workflow, see our guide to data subject access requests (DSARs).

### Step 6: Review Third-Party and Service Provider Contracts

The CCPA requires[ data processing agreements](/en/what-is-a-data-processing-agreement-dpa/) with any third party that handles personal information on your behalf. Start with the vendors most SMBs already use: analytics providers, ad platforms, and email marketing tools. These contracts should restrict third parties from using the data you share for their own independent purposes, not just for the service they provide to you. Sub-processors need to be covered as well.

### Step 7: Set Up Ongoing Compliance Monitoring and Maintenance

CCPA compliance is not a one-time setup. Regulations continue to evolve, and your website's cookie and tracking profile changes as you add tools, run campaigns, or redesign pages. An ongoing approach typically includes:

- Monthly automated scans to catch new cookies and trackers as they appear
- Regular privacy policy reviews to reflect current data practices
- Data processing audits to review:
    - What data you’re processing
    - Processing purposes
    - Where data is stored and how
    - Who has access to what data
    - How you’re handling data retention
- Monitoring for regulatory updates from the CPPA
- Regular training for staff that’s customized to roles and business activities

[New CCPA regulations that were effective January 1, 2026](https://usercentrics.com/knowledge-hub/cppa-enforcement-is-escalating/#3-a-wave-of-new-compliance-obligations-took-effect-january-1-2026-4) introduced cybersecurity audit and risk assessment requirements for larger or higher-risk businesses, with certification deadlines phased in through 2030 based on revenue. Many SMBs will not meet these thresholds today, but it is worth tracking as your business grows.

## CCPA Fines and Enforcement: What's at Stake

Administrative fines currently top out at USD 2,500 per violation, rising to USD 7,500 (also periodically adjusted for inflation) for intentional violations or those involving a known minor, with no overall cap on the total.

In March 2026, the California Privacy Protection Agency fined youth sports media platform [PlayOn Sports](https://privacy.ca.gov/2026/03/youth-sports-media-company-to-pay-1-1-million-fine-change-practices-over-privacy-violations/) USD 1.1 million after finding it sold and shared personal information, including that of students, without an effective, compliant opt-out mechanism. The largest CCPA settlement to date, for USD 12.75 million, came [in May 2026 against General Motors](https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general) for illegal data sales to data brokers, along with injunctive terms.

Consumers also have a limited private right of action for data breaches: statutory damages of USD 100 to USD 750 (also periodically adjusted for inflation) per consumer per incident, or actual damages, whichever is greater, where a breach results from a failure to maintain reasonable security.

Learn more about escalating CCPA enforcement.

## A Note on CIPA, VPPA, and ECPA: Risks CCPA Compliance Doesn't Cover

Everything above addresses CCPA compliance. It's worth being clear that CCPA compliance, on its own, does not protect a business against potential violations of the [California Invasion of Privacy Act (CIPA)](https://usercentrics.com/us/knowledge-hub/california-invasion-of-privacy-act-cipa/), the federal [Video Privacy Protection Act (VPPA)](https://usercentrics.com/us/knowledge-hub/video-privacy-protection-act-vppa/), or the federal [Electronic Communications Privacy Act (ECPA)](https://usercentrics.com/us/knowledge-hub/electronic-communications-privacy-act-ecpa/).

All three rest on different legal theories, unauthorized interception, unauthorized disclosure of video viewing history, and wiretapping, rather than CCPA's notice-and-opt-out model, and each carries its own private right of action and statutory damages.

CIPA claims — typically over chat tools, tracking pixels, or session replay software — allege unauthorized interception of a communication. As of this writing, a bill ([SB 690](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB690)) that would narrow CIPA's reach has advanced further than in prior sessions. An Assembly committee approved an amended version on July 1, 2026 that would remove the private right of action under CIPA's pen register and trap-and-trace provisions.

That amendment does not touch Sections 631 and 632, the wiretap and eavesdropping provisions behind many CIPA demand letters, and the bill still has to clear Appropriations and a full floor vote before the August 31, 2026 deadline. The absolute earliest that this legislation could come into effect is January 1, 2027. Meanwhile, CIPA demand letters creating urgency for settlement continue to be sent to companies around the United States.

Cookiebot's consent management and auto-blocking capabilities can help reduce this exposure by preventing tracking scripts, pixels, and video embeds from firing before a visitor has made a choice, but they don't eliminate CIPA, VPPA, or ECPA risk on their own.

A qualified privacy attorney should review any chat, pixel, video, or session replay tools against these statutes specifically, independent of your CCPA program.

## Automate CCPA Compliance Functions with Cookiebot CMP

CCPA compliance is achievable for organizations of any size. It requires some education, commitment to maintenance, and the right tooling. Cookiebot CMP is built to support that layer, so you can focus on running your business rather than manually tracking every script and signal:

1. Automatic cookie scanning and categorization, detecting tracking technologies across your site
2. GPC signal detection and handling, so California opt-out signals are recognized and acted on
3. Consent log generation, giving you audit-ready records of consumer preferences

## Automate CCPA consent handling and GPC opt-outs

See how Cookiebot CMP handles California privacy signals and requirements automatically. Set up in minutes, try it free for 14 days.

[Start free trial](https://www.cookiebot.com/en/cookie-consent-solution/)

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)
- [Cookiebot vs CookieYes](https://www.cookiebot.com/us/cookiebot-best-cookieyes-alternative/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject Requests

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)