California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
A practical compliance guide for website owners. Learn what California's privacy law requires and how to implement it on your site.
Who Must Comply
Annual gross revenue over $25M, OR buys/sells personal information of 100K+ consumers/households, OR derives 50%+ revenue from selling/sharing personal information
What Your Website Must Do
| Requirement | Status |
|---|---|
| Cookie consent banner | Recommended |
| Do Not Sell link | Required |
| Do Not Share link | Required |
| Honor GPC browser signals | Required |
| Universal opt-out mechanism | Required |
| Sensitive data opt-in consent | Not required |
Checked against the CCPA/CPRA on August 29, 2026. Read the source This is a summary, not legal advice.
Required Links & Notices
The CCPA/CPRA requires the following links or notices to be visible on your website:
- 1Do Not Sell or Share My Personal Information
- 2Limit the Use of My Sensitive Personal Information
- 3Privacy Policy
Enforcement & Penalties
Key Things to Know
The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) has applied in California since January 1, 2020.
Who it covers: Annual gross revenue over $25M, OR buys/sells personal information of 100K+ consumers/households, OR derives 50%+ revenue from selling/sharing personal information.
California is the only one of these laws with a dedicated regulator, the California Privacy Protection Agency, and the only one that treats sensitive information as a right to limit use rather than something you must ask permission for.
Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. CCPA/CPRA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Information”, and you may not degrade the service of someone who exercises it.
Global Privacy Control: CCPA/CPRA requires you to honour a universal opt-out mechanism sent by the visitor’s browser. A GPC signal has to be treated as the opt-out itself — not as a request to show someone a banner — and it applies to that browser without any further action from the person.
Cookie banner: CCPA/CPRA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data needs notice and a way to opt out rather than prior consent.
Enforcement: $2,500 per unintentional violation, $7,500 per intentional violation. Private right of action for data breaches: $100-$750 per consumer per incident. Enforced by the California Attorney General + California Privacy Protection Agency (CPPA).
How to Configure LegalBanner for CCPA/CPRA
- 1
Create your site
Sign up for free and add your website domain in the dashboard.
- 2
Set consent mode to "Opt-out"
In Settings, select the consent mode that matches California's requirements.
- 3
Install the snippet
Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.
- 4
Generate your Privacy Policy
Use the built-in policy wizard to generate a CCPA/CPRA-compliant privacy policy.
Set up CCPA/CPRA compliance in 5 minutes
LegalBanner handles California privacy requirements automatically — cookie banner, opt-out links, and GPC support included.
Frequently Asked Questions
Does California require a cookie consent banner?
California does not require opt-in cookie consent like GDPR. However, you must provide a clear 'Do Not Sell or Share My Personal Information' link and honor opt-out requests. A cookie preference center that allows users to opt out of sale/sharing categories is strongly recommended.
What is the difference between CCPA and CPRA?
The CPRA (effective January 2023) expanded the CCPA with new rights including data correction, opt-out of automated decision-making, and limits on sensitive personal information use. It also created the California Privacy Protection Agency (CPPA) for dedicated enforcement.
Do I need to honor Global Privacy Control (GPC) signals?
Yes. California law requires businesses to treat GPC browser signals as a valid opt-out of sale/sharing of personal information. LegalBanner automatically detects and honors GPC signals.
What are the penalties for CCPA/CPRA violations?
$2,500 per unintentional violation and $7,500 per intentional violation. Consumers also have a private right of action for data breaches, with statutory damages of $100-$750 per consumer per incident.
Does the CCPA apply to my small business?
The CCPA applies if your business has annual gross revenue over $25 million, buys/sells/shares personal information of 100,000+ consumers or households, or derives 50%+ of annual revenue from selling/sharing personal information. If none apply, you are generally exempt.
What is 'sensitive personal information' under CPRA?
Sensitive personal information includes Social Security numbers, financial account information, precise geolocation, racial/ethnic origin, religious beliefs, genetic data, biometric data, health information, sex life/sexual orientation data, and contents of mail, email, and text messages.