Effective January 1, 2020

California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)

A practical compliance guide for website owners. Learn what California's privacy law requires and how to implement it on your site.

Who Must Comply

Annual gross revenue over $25M, OR buys/sells personal information of 100K+ consumers/households, OR derives 50%+ revenue from selling/sharing personal information

Consent model: Opt-outGPC Required

What Your Website Must Do

RequirementStatus
Cookie consent bannerRecommended
Do Not Sell linkRequired
Do Not Share linkRequired
Honor GPC browser signalsRequired
Universal opt-out mechanismRequired
Sensitive data opt-in consentNot required

Checked against the CCPA/CPRA on August 29, 2026. Read the source This is a summary, not legal advice.

Required Links & Notices

The CCPA/CPRA requires the following links or notices to be visible on your website:

  • 1Do Not Sell or Share My Personal Information
  • 2Limit the Use of My Sensitive Personal Information
  • 3Privacy Policy

Enforcement & Penalties

Enforcement Body
California Attorney General + California Privacy Protection Agency (CPPA)
Maximum Penalty
$2,500 per unintentional violation, $7,500 per intentional violation. Private right of action for data breaches: $100-$750 per consumer per incident.

Key Things to Know

The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) has applied in California since January 1, 2020.

Who it covers: Annual gross revenue over $25M, OR buys/sells personal information of 100K+ consumers/households, OR derives 50%+ revenue from selling/sharing personal information.

California is the only one of these laws with a dedicated regulator, the California Privacy Protection Agency, and the only one that treats sensitive information as a right to limit use rather than something you must ask permission for.

Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. CCPA/CPRA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Information”, and you may not degrade the service of someone who exercises it.

Global Privacy Control: CCPA/CPRA requires you to honour a universal opt-out mechanism sent by the visitor’s browser. A GPC signal has to be treated as the opt-out itself — not as a request to show someone a banner — and it applies to that browser without any further action from the person.

Cookie banner: CCPA/CPRA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data needs notice and a way to opt out rather than prior consent.

Enforcement: $2,500 per unintentional violation, $7,500 per intentional violation. Private right of action for data breaches: $100-$750 per consumer per incident. Enforced by the California Attorney General + California Privacy Protection Agency (CPPA).

How to Configure LegalBanner for CCPA/CPRA

  1. 1

    Create your site

    Sign up for free and add your website domain in the dashboard.

  2. 2

    Set consent mode to "Opt-out"

    In Settings, select the consent mode that matches California's requirements.

  3. 3

    Install the snippet

    Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.

  4. 4

    Generate your Privacy Policy

    Use the built-in policy wizard to generate a CCPA/CPRA-compliant privacy policy.

Set up CCPA/CPRA compliance in 5 minutes

LegalBanner handles California privacy requirements automatically — cookie banner, opt-out links, and GPC support included.

Frequently Asked Questions

Does California require a cookie consent banner?

California does not require opt-in cookie consent like GDPR. However, you must provide a clear 'Do Not Sell or Share My Personal Information' link and honor opt-out requests. A cookie preference center that allows users to opt out of sale/sharing categories is strongly recommended.

What is the difference between CCPA and CPRA?

The CPRA (effective January 2023) expanded the CCPA with new rights including data correction, opt-out of automated decision-making, and limits on sensitive personal information use. It also created the California Privacy Protection Agency (CPPA) for dedicated enforcement.

Do I need to honor Global Privacy Control (GPC) signals?

Yes. California law requires businesses to treat GPC browser signals as a valid opt-out of sale/sharing of personal information. LegalBanner automatically detects and honors GPC signals.

What are the penalties for CCPA/CPRA violations?

$2,500 per unintentional violation and $7,500 per intentional violation. Consumers also have a private right of action for data breaches, with statutory damages of $100-$750 per consumer per incident.

Does the CCPA apply to my small business?

The CCPA applies if your business has annual gross revenue over $25 million, buys/sells/shares personal information of 100,000+ consumers or households, or derives 50%+ of annual revenue from selling/sharing personal information. If none apply, you are generally exempt.

What is 'sensitive personal information' under CPRA?

Sensitive personal information includes Social Security numbers, financial account information, precise geolocation, racial/ethnic origin, religious beliefs, genetic data, biometric data, health information, sex life/sexual orientation data, and contents of mail, email, and text messages.

Disclaimer: This page provides practical implementation guidance only. It does not constitute legal advice. The information is current as of the most recent review date but privacy laws change frequently. Consult a qualified attorney for legal advice specific to your situation. LegalBanner provides compliance tools, not legal counsel.