Skip to main content

What the CCPA and CPRA actually require of a business

California's privacy law reaches further than most companies assume, and the thresholds that trigger it are lower than the headlines suggest.

Technology Editor

· 2 min read

A data centre interior.
A data centre interior.Wikideas1 · CC0 · via Wikimedia Commons

Most companies encountering California privacy law assume it targets large platforms. It does not. The thresholds are disjunctive — meeting any one brings you in scope — and the definition of selling personal information is far broader than the ordinary meaning of the word.

The California Consumer Privacy Act took effect first; the California Privacy Rights Act amended and expanded it, adding a correction right, a category of sensitive personal information, and a dedicated enforcement agency.

Who is covered

A for-profit business doing business in California that meets any one of three tests: annual gross revenue above a statutory threshold; buying, selling or sharing the personal information of a threshold number of California consumers or households; or deriving a majority of annual revenue from selling or sharing personal information.

The second test catches companies that never thought of themselves as data businesses. A regional retailer with an email list and an advertising pixel can cross it without any deliberate data strategy.

The rights consumers have

  • **Know** what has been collected, where it came from, why, and who it was disclosed to.
  • **Access** a copy of that information.
  • **Delete** it, subject to exceptions such as completing a transaction or complying with a legal obligation.
  • **Correct** inaccurate personal information.
  • **Opt out** of the sale or sharing of personal information.
  • **Limit** the use of sensitive personal information.
  • **Non-discrimination** for exercising any of these.

Why "sale" is the trap

Sale is defined to include disclosing personal information to a third party for monetary *or other valuable consideration*. Passing identifiers to an advertising network so it can target and measure ads is generally treated as a sale or sharing, even though no invoice changes hands.

If you run behavioural advertising, assume you are sharing personal information and design accordingly.

That is why the Do Not Sell or Share link exists, and why a business that runs ads but takes no payment for data still typically needs one.

Global Privacy Control

A business must honour an opt-out preference signal transmitted by a browser or extension. This is not optional, and it is not satisfied by a cookie banner alone: the signal has to be detected and acted on for that browser automatically.

Practical minimum

  • A privacy notice describing categories collected, purposes, retention, and disclosure recipients.
  • A conspicuous opt-out mechanism, and detection of Global Privacy Control.
  • A verified process for access, deletion and correction requests, with a defined response window.
  • Contracts with service providers restricting what they may do with data you pass them.
  • A record of requests received and how they were handled.

The last one is easy to skip and is the first thing an enforcement enquiry asks for.

Related