Skip to main content
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state-level privacy law in the United States. Effective since January 2020 and significantly strengthened in 2023, CCPA gives California residents substantial rights over their personal information and imposes obligations on businesses that collect or process that data.

Who CCPA applies to

CCPA applies to for-profit businesses that collect California consumers’ personal information and meet any of the following thresholds:
CCPA applies based on where the consumer resides, not where your business is located. A company in New York with California customers must comply if it meets the thresholds.

Who is a “consumer”?

Under CCPA, a “consumer” is any California resident—defined as a natural person who is in California for other than a temporary or transitory purpose, or who is domiciled in California but currently outside the state temporarily.

Key definitions

CCPA uses specific terminology that differs from GDPR and other privacy frameworks:
The “sale” definition is broader than cash transactions. Sharing data with an advertising partner in exchange for services can constitute a sale under CCPA.

Consumer rights

CCPA grants California consumers specific rights over their personal information:

Right to know

Consumers can request that a business disclose:
  • The categories of personal information collected
  • The sources from which information was collected
  • The business or commercial purpose for collection or sale
  • The categories of third parties with whom information is shared
  • The specific pieces of personal information collected about them

Right to delete

Consumers can request deletion of their personal information, with limited exceptions for legal obligations, completing transactions, security purposes, and certain internal uses.

Right to correct

Added by CPRA, consumers can request correction of inaccurate personal information that a business maintains about them.

Right to opt-out of sale/sharing

Consumers can direct businesses not to sell or share their personal information. Businesses must provide a clear “Do Not Sell or Share My Personal Information” link on their website.

Right to limit use of sensitive personal information

Added by CPRA, consumers can limit a business’s use of sensitive personal information (such as Social Security numbers, financial accounts, precise geolocation, or racial/ethnic origin) to purposes necessary for providing the requested goods or services.

Right to non-discrimination

Businesses cannot discriminate against consumers who exercise their CCPA rights through:
  • Denying goods or services
  • Charging different prices
  • Providing different quality of goods or services
  • Suggesting that exercising rights will result in any of the above

Business obligations

Businesses subject to CCPA must fulfill several requirements:

Privacy notices

Provide a privacy policy that discloses:
  • Categories of personal information collected in the past 12 months
  • Purposes for each category
  • Categories of sources and third parties
  • Consumer rights and how to exercise them
  • Whether information is sold or shared, with opt-out instructions

Responding to consumer requests

  • Provide at least two methods for submitting requests (for online businesses, this must include a web form)
  • Verify the identity of consumers making requests
  • Respond within 45 days (extendable by an additional 45 days with notice)
  • Provide information free of charge for up to two requests per year

Service provider contracts

Maintain written contracts with service providers and contractors that:
  • Specify the business purposes for processing
  • Prohibit selling or sharing the information
  • Require the same level of privacy protection as required by CCPA
  • Grant the business rights to monitor compliance

Training

Ensure that personnel handling consumer inquiries about privacy practices are informed of CCPA requirements.

Record keeping

Businesses processing personal information of 10 million or more consumers must maintain records of requests and responses for 24 months.

Sensitive personal information

CPRA created a special category of “sensitive personal information” with additional protections:
  • Social Security, driver’s license, state ID, or passport numbers
  • Account log-in credentials (username with password or security questions)
  • Financial account, debit card, or credit card numbers with access codes
  • Precise geolocation
  • Racial or ethnic origin, religious or philosophical beliefs, union membership
  • Contents of mail, email, or text messages (unless the business is the intended recipient)
  • Genetic data
  • Biometric information for identification purposes
  • Health information
  • Sex life or sexual orientation information
Consumers can limit the use of sensitive personal information to what is necessary to perform the services or provide the goods reasonably expected.

Enforcement and penalties

CCPA is enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General:
Penalties are assessed per violation, meaning each affected consumer or each instance of non-compliance can be a separate violation. This can result in substantial aggregate penalties for widespread issues.
Unlike GDPR, CCPA provides a limited private right of action allowing consumers to sue directly—but only for data breaches involving non-encrypted or non-redacted personal information due to a business’s failure to maintain reasonable security procedures.

CCPA vs. GDPR

While both laws protect consumer privacy, they differ in significant ways:

Managing Data Subject Requests

Submit opt-out and deletion requests in Narrative

GDPR

Compare with the EU’s privacy regulation

Data Pseudonymization

Privacy-preserving data collaboration techniques

Security Model

How Narrative protects data throughout the platform