CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)

A California state statute (2018, effective 2020) granting state residents specific data rights, since substantially expanded by a 2020 ballot-measure amendment, the CPRA. It applies to any for-profit business meeting at least one threshold: over $25 million in annual gross revenue, buying/receiving/selling the personal information of 100,000 or more consumers or households, or earning more than half its revenue from selling personal information — thresholds that catch most mid-size-and-larger consumer-facing sites regardless of where the business itself is based.

It applies to any for-profit business meeting at least one threshold: over $25 million in annual gross revenue, buying/receiving/selling the personal information of 100,000 or more consumers or households, or earning more than half its revenue from selling personal information — thresholds that catch most mid-size-and-larger consumer-facing sites regardless of where the business itself is based.

Support the consumer rights the law grants

The interface has to give a California resident a real way to exercise each right:

  • Know what personal data is held and why.
  • Access a copy of it.
  • Delete it.
  • Opt out of its sale or (per the CPRA) “sharing” for cross-context advertising.
  • Correct inaccurate data (added by the CPRA).
  • Limit use of sensitive personal information such as precise geolocation or government ID numbers (also added by the CPRA).

None of these can come at a cost to the customer — the law separately prohibits discriminating against anyone for exercising them.

None of these can come at a cost to the customer — the law separately prohibits discriminating against anyone for exercising them.

A business selling or sharing personal information must post a clearly labeled link on its homepage — historically “Do Not Sell My Personal Information,” now commonly consolidated into “Your Privacy Choices” alongside a recognizable toggle icon now that the CPRA’s “sharing” opt-out folds in alongside the original sale opt-out — that lets a visitor exercise that choice without first creating an account or contacting support directly. The CPRA also requires honoring a browser- or device-level opt-out preference signal (e.g., Global Privacy Control) as a valid opt-out in itself, so a compliant site can’t require a visitor to additionally click through its own link if that signal is already present.

A business selling or sharing personal information must post a clearly labeled link on its homepage — historically “Do Not Sell My Personal Information,” now commonly consolidated into “Your Privacy Choices” alongside a recognizable toggle icon now that the CPRA’s “sharing” opt-out folds in alongside the original sale opt-out — that lets a visitor exercise that choice without first creating an account or contacting support directly.

Respond to requests within a fixed window

Verified consumer requests generally need a response within 45 days, extendable once by another 45 days with notice to the requester — a concrete deadline for whatever request-handling flow (see Account Management and Fair Information Practices‘s access principle) processes know/delete/correct requests.

Patterns

Principles

Standards

Sources

California Consumer Privacy Act (Wikipedia) provided the applicability thresholds, the consumer-rights list (know/access/delete/opt-out/correct/limit), the homepage opt-out link and Global Privacy Control requirement, and the 45-day (extendable) response window.

Source Links

Created Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Updated Fri Aug 21 2026 00:00:00 GMT+0000 (Coordinated Universal Time)