Who Must Comply with CCPA? A Guide to the California Consumer Privacy Act
The California Consumer Privacy Act establishes the regulatory framework for businesses that buy, sell, or manage leads and phone calls – something everyone should keep in mind before they start generating, distributing, or acquiring consumer data.
The CCPA requires businesses to implement comprehensive data protection measures, regularly update their privacy policies, and put in place clear procedures for responding to consumer requests.
And now, with the California Privacy Rights Act (CPRA) amending and expanding the original CCPA standards, compliance obligations have increased – so there are many more things to know and take care of before rolling out your marketing campaigns.
Read on to learn everything you need to know about CCPA compliance and how ValidRecord can help you stay compliant in 2026.
What Is CCPA & What Does It Do?
CCPA is intended to strengthen privacy rights for California consumers, with CCPA compliance coming down to following the statutory rules governing how a business handles the collection, management, and sharing of California residents’ personal data.
The CCPA offers individuals a number of comprehensive consumer rights:
- The right to know: Consumers can ask a business to provide the categories of personal information it collects, where it gets that data, the business purposes for collecting data, and what specific pieces of information it has collected.
- The right to delete personal data: Consumers can request the deletion of personal information a business has collected from them, subject to certain exceptions.
- The right to opt-out: Consumers have the right to direct a business to stop selling or sharing their personal information.
- The right to correct: Added under CPRA compliance, consumers can request corrections to inaccurate personal information.
- The right to restrict information: Consumers may request that sensitive personal information not be used for any purpose other than what is necessary.
- The right to non-discrimination: consumers who exercise their privacy rights can’t be discriminated against, for example, by being charged different rates or denied services.
The CCPA’s definition of “personal information” is expansive. “Personal Information” means information that identifies, connects to, describes, or could fairly be linked to a particular consumer or household. This includes real names, email addresses, IP addresses, geolocation data, biometric information, and even inferences drawn to create a consumer profile.
Who Must Comply with CCPA?
Many companies mistakenly assume that the law only applies to businesses physically located in California. In reality, the CCPA scope of application extends globally.
The CCPA applies to for-profit businesses that “do business” in California, that set the purposes and means of processing consumers’ personal information, and that fulfill at least one of the following CCPA thresholds:
- Gross annual revenue: A business with annual gross revenue exceeding $25 million.
- Data volume: A business that annually buys, receives, sells, or shares the personal information of 100,000 or more California consumers, households, or devices.
- Revenue from data sales: A business that derives 50% or more of its annual revenue from selling or sharing California consumers’ personal information.
Therefore, the CCPA applies to any out-of-state or international company that processes data of California residents and meets one of the mentioned thresholds. Even a small e-commerce website based in Europe must comply if it handles data of 100,000 Californians.
Who Is Exempt from the CCPA?
The CCPA typically does not apply to non-profit organizations or government agencies and exempts certain types of information already regulated by other federal laws, such as medical information governed by HIPAA and consumer credit reporting information governed by the Fair Credit Reporting Act (FCRA) and the Gramm-Leach-Bliley Act (GLBA).
How to Be CCPA Compliant: A Practical Checklist
If you find that your business meets the CCPA’s applicability criteria, you’ll need a systematic CCPA compliance strategy:
- Data inventory and classification: Before you can protect consumer data, you must understand it. For this, companies must map their data to know what types of personal information they collect, where they store it, and with whom they share it.
- Update your company’s privacy policy: Compliance with privacy policies is a key obligation. Three things must be clearly stated in any CCPA-compliant privacy policy: which categories of information are collected, why they are collected, and which consumer rights apply. A “notice at collection” must also be in place at or before the point at which personal data is collected.
- CCPA cookie compliance and opt-out mechanisms: If your company sells or distributes data (even for targeted behavioral advertising), you will need to have a clearly visible link on your website stating “do not sell or share my personal information”. You must also consider user-enabled global privacy controls (GPC signals) as acceptable opt-out requests. CCPA cookie compliance involves disclosing tracking cookies that collect personal information and providing the user with an opt-out option.
- Create consumer request procedures: Consumer requests must be responded to within 45 days, and at least 2 specific ways for consumers to submit requests must be included, such as a toll-free number or interactive web form.
- Manage third parties and service providers: Personal information shared with a service provider has to be covered by a formal contract. That contract needs to state that the data may be used only for defined business purposes and may not be sold or shared further.
- CCPA compliance training: Managing privacy inquiries and consumer rights requests requires a solid grasp of CCPA regulations. Everyone in that role needs to understand the requirements well enough to help customers exercise their rights without hesitation.
- Implement CCPA compliance tools: Managing these obligations manually is challenging for large companies. Consumer request intake and vendor contract reviews become easier to manage with CCPA compliance tools, data mapping platforms, and CCPA compliance services in the mix. The right CCPA compliance solutions are also what keep companies from missing the strict 45-day deadline.
CCPA & GDPR Compliance: What’s the Difference?
Managing CCPA and GDPR compliance is a challenge for multinational businesses. The two frameworks are both serious about privacy, but their differences have significant implications for putting together a compliance plan.
| CCPA | GDPR | |
| Who it protects | California residents | Individuals in the EU |
| Consent model | Opt-out model | Opt-in model |
| Penalties | Levied per violation | Up to 4% of global annual revenue or €20 million |
Penalties for Non-Compliance with CCPA
The implications of not being CCPA-compliant are substantial. The penalties for non-compliance can be financially significant if the California Attorney General or California Privacy Protection Agency concludes that a business has violated the CCPA.
Administrative fines can reach up to $2,500 for each unintentional violation and up to $7,500 for each intentional violation, or for violations involving minors’ data. Because these fines are calculated per violation (or per user), they may result in substantial financial exposure.
Can Consumers Sue a Company for Breach of Privacy?
Consumers cannot sue a business simply for selling their data under the CCPA, but they have the statutory right to force them to stop.
That said, they can sue a company for a data breach. The CCPA provides consumers with a limited private right of action for data breaches in which the consumer’s non-encrypted, non-redacted personal information is stolen due to a business’s failure to establish reasonable security practices.
In certain circumstances, customers can claim statutory damages of $100 to $750 per consumer per event, or actual damages, whichever is greater.
Streamlining CCPA Compliance with ValidRecord
ValidRecord is a software solution that enables businesses to efficiently handle consumer consent and validate lead data, offering two core solutions for consent collection and fraud protection: iClaim and iClear.
iClaim: Verifiable Proof of Consumer Consent
iClaim can help you by recording and maintaining a verifiable record of consumer consent. As a user fills out a lead-generating form on your site, iClaim’s tracking code collects the user’s session and form activity, including the exact consent language displayed to the user.
iClear: Lead Screening & Proactive Data Validation
iClear is a lead screening and fraud protection solution that validates lead data in real time before the consumer is accepted for distribution, sold, or bought. iClear allows you to evaluate data points such as phone numbers, so you can automatically accept high-quality, compliant leads and reject those with mismatched or incorrect information.
This proactive screening maintains data accuracy, minimizes compliance risks, and gives you granular control over your lead distribution channels. With ValidRecord, your company can help manage data protection compliance requirements and optimize your client acquisition efforts.
Frequently Asked Questions
Does CCPA apply to me if my business is not in California?
Yes. The California Consumer Privacy Act applicability is not based on physical location. If your for-profit business collects the personal information of California residents, targets California consumers, and meets the revenue or data volume thresholds (such as handling the data of 100,000+ Californians or exceeding $25 million in gross revenue), the CCPA applies to you regardless of where your business is located.
Can I sue a company for a data breach under the CCPA?
Yes, in some instances. The CCPA provides a private right of action for California customers to sue a company when their personal information is stolen or exfiltrated in a data breach, provided that the personal information is nonencrypted and nonredacted. This rule applies if the breach happened due to the business’s failure to exercise adequate security standards. Consumers may pursue statutory damages of $100 to $750 per event.
What’s the difference between CCPA and CPRA compliance?
The first data privacy law passed in 2018 was the California Consumer Privacy Act (CCPA). In 2020, California passed the California Privacy Rights Act (CPRA), a ballot measure that updated and enhanced the CCPA. The CPRA introduced new consumer rights, including the ability to correct data and limit the use of sensitive personal information. CPRA compliance means staying aligned with all of that. The CPRA did not replace the CCPA. It strengthened it.
How to stop companies from selling your personal information?
California residents have the right to opt out of the sale or sharing of their personal information under the CCPA. You can do this by locating and clicking the link “do not sell or share my personal information” that covered businesses are required to prominently display on their homepages. You may also use a user-enabled Global Privacy Control (GPC) signal on your web browser, which automatically signals to the websites you visit that you want to opt out.