The California Consumer Privacy Act is a state privacy law that gives California residents specific rights over how businesses collect, use, share, and sell their personal information. It can apply to a business anywhere in the country, or the world, if that business handles data from California residents and meets certain thresholds.
The law has changed substantially since it first took effect on January 1, 2020. The California Privacy Rights Act amended it in 2023, and a new set of California Privacy Protection Agency regulations on cybersecurity audits, risk assessments, and automated decision-making took effect on January 1, 2026.
This guide explains what the CCPA covers today, who has to comply, what changed most recently, and how businesses typically approach compliance. It is for general information only and is not legal advice.
What is the California Consumer Privacy Act?
The California Consumer Privacy Act, or CCPA, is a state law that gives California residents the right to know, delete, correct, and limit how businesses use their personal information.
Personal information under the law means data that identifies, relates to, or could reasonably be linked to a specific consumer or household, including names, contact details, online identifiers, geolocation data, and internet browsing activity. The CCPA also creates matching duties for businesses, including posting clear privacy notices, responding to consumer requests within set timelines, and offering opt-out mechanisms for the sale or sharing of data.
What changed under the 2026 CCPA regulations?
The most significant 2026 change is a new regulatory package covering automated decision-making technology, mandatory cybersecurity audits, and formal risk assessments, finalized by the California Privacy Protection Agency in late 2025.
These rules phase in over several years rather than all at once:
- Automated decision-making technology (ADMT).
Businesses using ADMT to make significant decisions about consumers, such as in hiring or lending, must comply with notice and opt-out requirements starting January 1, 2027.
- Risk assessments.
Businesses engaged in higher-risk processing, such as selling personal information or using sensitive personal information, must complete risk assessments by December 31, 2027, with the first summary reports due to the CPPA by April 1, 2028.
- Cybersecurity audits.
Businesses whose data processing presents a significant security risk must complete independent annual audits, phased in by company size between 2028 and 2030.
For most other businesses, the practical takeaway is that CCPA compliance is now an ongoing governance program, not a checklist to complete once and file away.
Who needs to comply with the CCPA?
A business generally needs to comply with the CCPA if it does business in California, collects personal information from California residents, and meets at least one of three legal thresholds.
As of the 2025 inflation adjustment, those thresholds are:
| Threshold | Current amount |
|---|---|
| Annual gross revenue | Over $26,625,000 |
| Data volume | Buys, sells, or shares personal information of 100,000 or more consumers or households annually |
| Revenue from data sales | 50% or more of annual revenue comes from selling or sharing personal information |
The revenue threshold applies to total global revenue, not just revenue earned in California, and it adjusts every two years for inflation. This makes it easy for a growing business to cross into CCPA coverage without realizing it, especially SaaS companies, research platforms, and ecommerce brands running large-scale customer data integration projects.
Who is protected under the CCPA?
The CCPA protects natural persons who are California residents, whether they are physically in the state or temporarily traveling or living elsewhere.
This means the law can apply in both B2C and B2B contexts, covering customers, employees, prospects, website visitors, and survey respondents alike. A business does not need a physical presence in California to be covered. Conducting online transactions with California residents, tracking their activity through cookies, or employing remote workers in the state can all establish coverage.
What consumer rights does the CCPA guarantee?
The CCPA guarantees six main consumer rights: the right to know, delete, correct, opt out of sale or sharing, limit sensitive personal information, and be free from discrimination for exercising these rights.
Right to know and right to delete
Consumers can request the categories and specific pieces of personal information a business has collected, along with its sources and purposes. They can also request deletion, though a business may retain certain data needed to complete a transaction, detect security incidents, or meet a legal obligation.
Right to correct and right to opt out
Consumers can ask a business to fix inaccurate personal information, a right added through the CPRA amendments. They can also opt out of the sale or sharing of their data, typically through a clearly posted link or a recognized opt-out preference signal.
Right to limit sensitive data and right to non-discrimination
Consumers can ask certain businesses to limit use of sensitive personal information, such as precise geolocation, health data, or government identifiers. Businesses cannot deny service, charge more, or provide a lower quality of service simply because a consumer exercised any of these rights.
What are the main CCPA requirements for businesses?
CCPA requirements generally include publishing a clear privacy notice, offering functioning request and opt-out mechanisms, and maintaining reasonable data security.
Common obligations include:
- Publishing a privacy notice describing what data is collected and why
- Providing at least two methods for consumers to submit requests
- Responding to verified requests within the legally required timeline
- Offering a working opt-out option for the sale or sharing of data
- Training employees who handle privacy requests
- Reviewing contracts with service providers and contractors
- Avoiding retention of personal information beyond what is reasonably necessary, supported by routine data quality reviews
Companies collecting survey, research, or experience data must focus on key compliance areas. They should pay particular attention to clear consent language and defined retention policies. Additionally, organizations need reliable processes to respond quickly to access or deletion requests. Strong data governance practices make most of these obligations easier to sustain over time.
How is the CCPA different from GDPR?
The CCPA and GDPR both protect personal data. The CCPA centers primarily on consumer disclosure and opt-out rights. In contrast, the GDPR requires a specific legal basis before processing any personal data.
Businesses that already run a GDPR compliant survey platform often benefit from existing operational habits. Practices like documenting data flows and honoring deletion requests transfer directly to CCPA compliance.
| Area | GDPR | CCPA |
|---|---|---|
| Scope | The EU and processing involving people in the EU | California residents and covered businesses |
| Legal basis | Requires a lawful basis before processing | Focuses on disclosure and consumer opt-out rights |
| Default | Processing is restricted unless justified | Processing is generally allowed unless a consumer opts out |
| Enforcement | EU data protection authorities | California Privacy Protection Agency and Attorney General |
A business serving both US and EU customers typically needs coordinated, not identical, privacy programs for each law.
What happens if a business violates the CCPA?
Violating the CCPA can lead to regulatory fines, and in limited cases, private lawsuits from affected consumers.
As of the 2025 inflation adjustment, the California Privacy Protection Agency can pursue administrative fines up to $2,663 per violation, or $7,988 for intentional violations and those involving a minor’s data. These amounts adjust every two years. Consumers also have a limited private right of action for certain data breaches, with statutory damages generally between $107 and $799 per person per incident. Most day-to-day CCPA issues, however, are resolved through regulatory enforcement rather than consumer lawsuits.
What common mistakes put businesses at CCPA risk?
The most common mistake is treating CCPA compliance as a one-time 2020 project instead of an ongoing program that needs review as the law and regulations change.
Other frequent mistakes include:
- Posting a privacy notice that no longer matches actual data practices
- Failing to test the opt-out link or request form to confirm it actually works
- Assuming a business is too small to qualify, without checking the current revenue and data volume thresholds
- Overlooking employee and B2B contact data, which can also fall under CCPA protection
- Not updating vendor and service provider contracts after data practices change
QuestionPro supports CCPA-related efforts through strong data protection practices. They provide clear customer-facing documentation and help users responsibly manage their collected feedback data.
As a survey software provider, QuestionPro maintains internal privacy and security standards. They also support workflows for customer data subject requests.
However, businesses using research platforms remain accountable for their own CCPA obligations. This includes handling privacy notices, consent language, and consumer requests. A vendor can assist with this work, but they cannot assume legal responsibility for it.
Treat CCPA compliance as an ongoing program
The California Consumer Privacy Act gives California residents real control over their personal information. These business obligations have grown increasingly detailed since 2020.
The 2026 regulatory package introduces a new compliance layer. It focuses on cybersecurity audits, risk assessments, and automated decision-making that will unfold over several years.
Businesses should treat CCPA compliance as a living program. Regularly reviewing policies against current thresholds leaves organizations far better prepared than relying on a static policy.
Frequently Asked Questions (FAQs)
Yes. A business does not need a physical presence in California to be covered. Conducting online transactions with California residents, tracking their activity through cookies, or employing remote California workers can all establish that a business is doing business in the state.
Only if they meet one of the three legal thresholds: annual gross revenue over $26,625,000, buying or selling data from 100,000 or more consumers, or deriving half or more of their revenue from selling personal data. Many small businesses fall outside these thresholds entirely.
The CPRA is not a separate law. It amended the CCPA in 2023, adding rights like correction and limiting the use of sensitive personal information, and created the California Privacy Protection Agency to enforce the combined law.
No. The ADMT rules take effect on January 1, 2027, risk assessments are due by the end of 2027, and cybersecurity audits phase in between 2028 and 2030 based on company size. Only businesses that meet specific risk or revenue criteria are affected by each rule.
Only in limited cases involving certain types of data breaches, where consumers have a private right of action with statutory damages. Most other CCPA violations are handled through enforcement by the California Privacy Protection Agency or the Attorney General, not private lawsuits.



