CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)
A California state statute (2018, effective 2020) granting state residents specific data rights, since substantially expanded by a 2020 ballot-measure amendment, the CPRA. It applies to any for-profit business meeting at least one threshold: over $25 million in annual gross revenue, buying/receiving/selling the personal information of 100,000 or more consumers or households, or earning more than half its revenue from selling personal information — thresholds that catch most mid-size-and-larger consumer-facing sites regardless of where the business itself is based.
It applies to any for-profit business meeting at least one threshold: over $25 million in annual gross revenue, buying/receiving/selling the personal information of 100,000 or more consumers or households, or earning more than half its revenue from selling personal information — thresholds that catch most mid-size-and-larger consumer-facing sites regardless of where the business itself is based.
Support the consumer rights the law grants
The interface has to give a California resident a real way to exercise each right:
- Know what personal data is held and why.
- Access a copy of it.
- Delete it.
- Opt out of its sale or (per the CPRA) “sharing” for cross-context advertising.
- Correct inaccurate data (added by the CPRA).
- Limit use of sensitive personal information such as precise geolocation or government ID numbers (also added by the CPRA).
None of these can come at a cost to the customer — the law separately prohibits discriminating against anyone for exercising them.
None of these can come at a cost to the customer — the law separately prohibits discriminating against anyone for exercising them.
Provide a homepage opt-out link
A business selling or sharing personal information must post a clearly labeled link on its homepage — historically “Do Not Sell My Personal Information,” now commonly consolidated into “Your Privacy Choices” alongside a recognizable toggle icon now that the CPRA’s “sharing” opt-out folds in alongside the original sale opt-out — that lets a visitor exercise that choice without first creating an account or contacting support directly. The CPRA also requires honoring a browser- or device-level opt-out preference signal (e.g., Global Privacy Control) as a valid opt-out in itself, so a compliant site can’t require a visitor to additionally click through its own link if that signal is already present.
A business selling or sharing personal information must post a clearly labeled link on its homepage — historically “Do Not Sell My Personal Information,” now commonly consolidated into “Your Privacy Choices” alongside a recognizable toggle icon now that the CPRA’s “sharing” opt-out folds in alongside the original sale opt-out — that lets a visitor exercise that choice without first creating an account or contacting support directly.
Respond to requests within a fixed window
Verified consumer requests generally need a response within 45 days, extendable once by another 45 days with notice to the requester — a concrete deadline for whatever request-handling flow (see Account Management and Fair Information Practices‘s access principle) processes know/delete/correct requests.
Related Concepts
Patterns
Principles
Standards
Sources
California Consumer Privacy Act (Wikipedia) provided the applicability thresholds, the consumer-rights list (know/access/delete/opt-out/correct/limit), the homepage opt-out link and Global Privacy Control requirement, and the 45-day (extendable) response window.