Now available: 🔀 Free OneTrust migration trial
CCPA AND CPRA COMPLIANCE GUIDE

CCPA compliance: consumer rights, business duties and 2026 requirements

Understand when the California Consumer Privacy Act applies, the rights it gives California residents, and the operational controls businesses need under the CCPA, CPRA and current regulations.
CCPA COMPLIANCE WITH TRUSTWORKS

Turn California privacy obligations into measurable, repeatable workflows

Map California consumer data

Identify where personal information is collected, used, disclosed, sold or shared across systems, vendors and business processes.

Keep notices and data practices aligned

Connect data categories, purposes, retention, sensitive information and third-party disclosures to current operational records.

Run risk assessments and governance reviews

Assess processing that presents significant privacy risk and maintain evidence, approvals and remediation in one workflow.

Fulfil consumer requests on time

Centralise requests to know, delete, correct, opt out and limit sensitive personal information with tracked deadlines and verification.
On this page

What is the CCPA?

The California Consumer Privacy Act, commonly called the CCPA, is California's comprehensive consumer privacy law. The California Privacy Rights Act, or CPRA, amended and expanded it. Together, these rules give California residents control over personal information and require covered businesses to explain, govern and secure their data practices.

The CCPA is not limited to website cookies or marketing. It can affect customer, employee, applicant, supplier and business-contact information, as well as data used across product, analytics, advertising, security, human resources and vendor operations.

Who does the CCPA apply to?

The CCPA generally applies to a for-profit entity doing business in California that determines why and how personal information is processed and meets at least one statutory threshold. From 1 January 2025, the revenue threshold is $26.625 million in annual gross revenue for the preceding calendar year. The law can also apply where a business buys, sells or shares the personal information of 100,000 or more California residents or households, or earns 50% or more of annual revenue from selling or sharing California residents' personal information.

Some controlled entities, joint ventures and partnerships may also be covered. Service providers, contractors and third parties have separate contractual and use restrictions. Nonprofits and government agencies are generally outside the definition of a business, although other privacy laws may still apply.

Personal and sensitive personal information

Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household. It can include identifiers, online activity, geolocation, purchasing history, employment information, profiles and inferences.

Sensitive personal information includes categories such as government identifiers, precise geolocation, account credentials, certain communications, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric information used for identification, health information and information about sex life or sexual orientation. Certain uses and disclosures may trigger a consumer's right to limit.

California consumer privacy rights

Depending on the circumstances and applicable exceptions, California consumers may have the right to:

  • know the categories and specific pieces of personal information a business has collected;
  • know the sources, purposes and categories of recipients involved;
  • delete personal information;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information;
  • limit certain uses and disclosures of sensitive personal information;
  • receive portable information where required; and
  • receive equal service and pricing when exercising privacy rights.

Businesses must also recognise valid opt-out preference signals, such as Global Privacy Control, where the regulations require them to do so.

Key obligations for businesses

Provide notice at or before collection

A notice at collection should explain the categories of personal information collected, the purposes for which they are used, whether they are sold or shared, applicable retention information and where consumers can find the full privacy policy. Notices and policies should reflect actual data practices rather than generic assumptions.

Apply purpose limitation and data minimisation

Collection, use, retention and sharing should be reasonably necessary and proportionate to disclosed purposes. A business should document why data is needed, limit access and retention, and perform the required analysis before using information for an unrelated or incompatible purpose.

Offer effective opt-out and limitation methods

Where a business sells or shares personal information, it must provide the required opt-out mechanism and process recognised preference signals. Where the right to limit applies, the business must provide a clear method for exercising it. Dark patterns and unnecessary identity verification must not obstruct these choices.

Maintain appropriate contracts

Contracts with service providers, contractors and third parties should contain the required restrictions, specify permitted purposes and support compliance with consumer requests. Businesses should also perform reasonable oversight and address unauthorised use.

Use reasonable security

The CCPA includes a private right of action for certain security breaches involving specified personal information. Security controls should reflect the nature and sensitivity of the data and may include access management, encryption, secure configuration, monitoring, testing, incident response and vendor oversight.

Consumer request deadlines

Businesses generally confirm receipt of a request to know, delete or correct within 10 business days and provide a substantive response within 45 calendar days. The response period may be extended by another 45 days when reasonably necessary and when the consumer is notified during the initial period.

Requests to opt out of sale or sharing and requests to limit the use or disclosure of sensitive personal information should be processed as soon as feasibly possible and no later than 15 business days. Identity verification should be proportionate to the request and should not be required for an opt-out request.

Requirements effective from 2026

California regulations effective 1 January 2026 introduced or clarified obligations concerning risk assessments, annual cybersecurity audits and automated decision-making technology, commonly called ADMT.

  • Risk assessments: covered processing that presents significant risk to consumers' privacy requires an assessment that weighs benefits against negative impacts and documents safeguards. Compliance began in 2026, with summary and attestation submissions phased in.
  • Cybersecurity audits: businesses meeting the regulatory thresholds must complete annual independent audits. Certification deadlines are phased from 2028 to 2030 according to annual revenue.
  • ADMT: businesses using automated decision-making technology for significant decisions must prepare for notices, access information and opt-out requirements that begin in 2027.

These obligations are targeted and depend on the business, processing activity and regulatory thresholds. Organisations should document their applicability analysis.

Enforcement and penalties

The California Privacy Protection Agency and the California Attorney General can investigate and enforce the CCPA. Current administrative fines can reach $2,663 per violation or $7,988 for an intentional violation and certain violations involving consumers known to be under 16.

For eligible security breaches, consumers may seek statutory damages of $107 to $799 per consumer per incident or actual damages, whichever is greater. Enforcement can also result in corrective orders, operational changes and reputational damage.

A practical CCPA compliance checklist

  • Confirm whether each relevant entity meets a CCPA threshold.
  • Map personal information, sensitive information, systems, vendors and disclosures.
  • Document purposes, retention periods and whether activities constitute a sale or sharing.
  • Align notices at collection, privacy policies and internal records.
  • Implement opt-out, limitation and preference-signal workflows.
  • Maintain secure intake, verification, fulfilment and deadline tracking for consumer requests.
  • Review service-provider, contractor and third-party contracts.
  • Screen processing for risk-assessment, cybersecurity-audit and ADMT obligations.
  • Apply reasonable security and maintain tested incident-response procedures.
  • Train relevant teams and preserve evidence of decisions, requests and remediation.

How TrustWorks supports CCPA operations

TrustWorks helps privacy teams turn CCPA requirements into connected operational workflows rather than disconnected spreadsheets, inboxes and policy documents.

  • Data mapping: identify systems, vendors, personal-information categories and data flows.
  • Consumer requests: centralise intake, identity checks, deadlines, decisions and fulfilment.
  • Preference governance: connect opt-out and limitation choices to systems and responsible teams.
  • Risk assessments: use structured questionnaires, risk analysis, approvals and remediation tracking.
  • Vendor oversight: maintain contracts, roles, purposes and evidence across the vendor lifecycle.
  • Audit readiness: assign owners and preserve an accountable history of actions and decisions.
TrustWorks supports CCPA compliance operations. It does not provide legal advice, and organisations should assess their specific obligations with qualified counsel and current CPPA guidance.

Operationalise CCPA compliance across every team

See how TrustWorks connects consumer requests, data mapping, preferences, risk assessments and vendor governance in one collaborative platform.

Frequently asked questions about the CCPA

What is the CCPA?
Who must comply with the CCPA?
What rights do California consumers have?
How quickly must consumer requests be answered?
What is the difference between selling and sharing personal information?
What changed under the regulations effective in 2026?
What are the maximum CCPA penalties?
How does TrustWorks support CCPA compliance?
Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.