California's consumer privacy law, made operational.
The California Consumer Privacy Act, as amended by the CPRA, gives consumers rights over the personal information businesses collect, and requires notice at collection, opt-outs of sale and sharing, and limits on sensitive personal information.
Which businesses are covered
Thresholds
For-profit businesses that meet a revenue threshold, buy/sell/share large volumes of personal information, or derive significant revenue from selling it.
Consumers
California residents, with additional protections when the personal information relates to minors.
Service providers & contractors
Process on the business's behalf under contract terms that restrict further use.
Sale & sharing
"Sale" and "sharing" (for cross-context behavioural advertising) both trigger opt-out obligations.
What Californians can ask for
The categories and specific pieces of personal information collected, and the sources, purposes and recipients.
Request deletion of personal information, subject to statutory exceptions.
Request correction of inaccurate personal information (added by the CPRA).
Via a "Do Not Sell or Share My Personal Information" link and recognised opt-out signals.
Limit use and disclosure of sensitive personal information to specified purposes.
Not to be discriminated against for exercising these rights.
What a compliant business must do
Notice at collection
Disclose categories collected and the purposes, at or before the point of collection.
Opt-out mechanisms
Provide the "Do Not Sell or Share" link and honour Global Privacy Control signals.
Respond to requests
Verify and respond to consumer requests within statutory timelines.
Data minimisation
Collect and retain only what is reasonably necessary and proportionate.
Contracts
Impose CPRA terms on service providers, contractors and third parties.
Reasonable security
Maintain reasonable security procedures appropriate to the information.
Sensitive personal information
The CPRA created a category of sensitive personal information, government IDs, financial account details, precise geolocation, race or religion, health, and the contents of communications, and gave consumers the right to limit its use.
SSNs, driver's licence, financial account and payment details.
Location data that identifies a specific place.
Health, sex life, racial or ethnic origin, religious beliefs.
Who enforces, and how
| Mechanism | Detail |
|---|---|
| Regulator | California Privacy Protection Agency and the Attorney General investigate and enforce. |
| Administrative fines | Per-violation penalties, higher for violations involving minors. |
| Private right of action | Consumers may sue for statutory damages after certain data breaches. |
General information, not legal advice, applicability depends on your specific processing and revenue.
From notice-at-collection to verified requests
We build your notices, opt-out mechanisms, GPC handling, request workflows and vendor contracts, and prepare the evidence that shows they work.