The CCPA (California Consumer Privacy Act) is a state privacy law that grants California residents the right to know, delete, correct, and opt out of the sale or sharing of their personal information. Enacted in 2018 and effective January 1, 2020, it applies to for-profit businesses that meet revenue or data-volume thresholds and imposes penalties of up to $7,500 per intentional violation.
If any part of your marketing stack touches California residents' data — email lists, ad pixels, analytics, CRM — CCPA sets the rules. Ignoring it costs money in fines and lawsuits. Handling it well earns customer trust and keeps you off the Attorney General's public enforcement list.
What is the CCPA?
The California Consumer Privacy Act is a state statute passed in June 2018 (AB-375) and effective January 1, 2020. It was significantly expanded by the California Privacy Rights Act (CPRA), which took effect January 1, 2023 and created the California Privacy Protection Agency (CPPA) — the first US regulator dedicated solely to privacy enforcement.
CCPA gives California residents ("consumers") six core rights:
- Right to know — what personal information is collected, used, shared, or sold
- Right to delete — personal information collected from them
- Right to correct — inaccurate personal information (added by CPRA)
- Right to opt out — of the sale or sharing of personal information
- Right to limit — the use of sensitive personal information (added by CPRA)
- Right to non-discrimination — for exercising CCPA rights
CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds: (1) annual gross revenue over $25 million, (2) buy, receive, sell, or share personal information of 100,000+ California consumers or households annually, or (3) derive 50%+ of annual revenue from selling or sharing personal information.
Why the CCPA matters for marketers
CCPA reshapes how marketing teams collect, store, and share customer data. Three reasons it's a boardroom-level issue:
- Direct financial exposure. Fines run up to $2,500 per unintentional violation and $7,500 per intentional violation — multiplied by the number of affected consumers. A single 100,000-record incident can exceed $250 million.
- Private right of action. Consumers can sue for $100 to $750 per incident (or actual damages, whichever is greater) for certain data breaches. Class actions are common.
- Downstream vendor risk. If your ad platform, CDP, or email tool mishandles California data, the responsibility often flows back to you as the business owner of that data.
How CCPA compliance works in practice
Compliance rests on three operational systems: disclosure, consumer request handling, and opt-out mechanics.
1. Privacy notice at collection
Before or at the point of collection you must disclose the categories of personal information being collected and the purposes of use. This lives in a privacy policy plus contextual notices on forms.
2. Consumer request workflow
You need at least two channels for requests (usually a toll-free number and a web form). Businesses must respond within 45 days, extendable by another 45 days with notice. Identity must be verified before serving a request.
3. "Do Not Sell or Share My Personal Information" link
A visible link in the site footer that lets a consumer opt out of the sale or sharing of their data. Sharing here means "cross-context behavioural advertising" — which captures most retargeting pixels.
CCPA vs GDPR vs other privacy laws
| Law | Jurisdiction | Consent model | Max fine | Enforcer |
|---|---|---|---|---|
| CCPA / CPRA | California residents | Opt-out (sale/sharing) | $7,500 per intentional violation | CPPA + AG |
| GDPR | EU/EEA residents | Opt-in (explicit consent) | 4% of global revenue or 20M EUR | DPAs per member state |
| VCDPA | Virginia residents | Opt-out (sale/targeted ads) | $7,500 per violation | Virginia AG |
| CPA | Colorado residents | Opt-out (sale/profiling) | $20,000 per violation | Colorado AG |
| LGPD | Brazil residents | Opt-in (10 legal bases) | 2% of Brazil revenue | ANPD |
Real CCPA examples marketers face
Three situations where CCPA changes day-to-day marketing operations.
1. Meta Pixel on a California-facing checkout
The Meta Pixel sending event data (purchase amount, product IDs) to Facebook counts as "sharing" for cross-context behavioural advertising. You need a Global Privacy Control (GPC) handler that disables the pixel firing when a California visitor has opted out.
2. Right-to-delete request on an active CRM contact
A California customer emails asking you to delete their record. You have 45 days to (a) verify identity, (b) delete or de-identify the record in your CRM, ESP, CDP, and any third-party audience where you exported it, and (c) confirm completion in writing.
3. Lookalike audiences built from a California email list
Uploading a hashed email list to Meta or Google to build a lookalike audience is "sharing" under CPRA. You need documented opt-out honouring plus a data processing agreement with the ad platform.
CCPA vs GDPR — which framework applies
Marketers targeting global audiences usually need both. The difference is jurisdiction and the default consent state.
CCPA applies when
- Any of your users are California residents
- You meet the $25M revenue or 100k consumer threshold
- You sell or share personal information
- Default is opt-in; user must actively opt out
- Focus is on transparency and control
GDPR applies when
- Any of your users are in the EU/EEA
- Regardless of company size or revenue
- You process any personal data (broader scope)
- Default is opt-out; user must actively consent
- Focus is on lawful basis for processing
6 best practices for CCPA compliance
- Map every data flow. Document each source (form, pixel, integration), each destination (CRM, ESP, CDP, ad platform), and the legal basis for each transfer. If it isn't documented, it isn't defensible.
- Honour the Global Privacy Control signal. The CPPA requires businesses to treat the browser-level GPC header as an opt-out request. Enforcement actions against Sephora ($1.2M in 2022) turned on this exact failure.
- Publish a Do Not Sell or Share link in the footer. Not buried in a policy. Direct, one-click, always visible on California-facing pages.
- Build a 45-day request workflow. One inbox, one owner, one verification step, one deletion checklist that covers every downstream system.
- Update vendor contracts. Data Processing Agreements with every service provider that receives California data — with contractual restrictions on further sale or sharing.
- Retrain marketing quarterly. Rules change. Enforcement targets change. What was permissible in 2023 may not be in 2026.
Marketers often assume "sharing" only means selling data for cash. Under CPRA, sharing includes cross-context behavioural advertising — every retargeting pixel, every audience export to Meta or Google. If you retarget California visitors and don't offer a working opt-out, you're likely non-compliant.
Common CCPA mistakes to avoid
- Ignoring GPC signals — the CPPA has confirmed enforcement priority
- Charging a fee for CCPA rights — the non-discrimination clause prohibits this
- Verifying identity with excessive data — you must use minimum necessary information
- Missing the 45-day response window — with no notification of extension
- Applying CCPA only to logged-in users — anonymous cookie data is often personal information under CCPA
- Skipping vendor data processing agreements — service providers need contractual limits
How theStacc helps with CCPA-safe marketing
theStacc's content and local SEO automation only uses first-party data your business explicitly owns — no third-party data purchases, no consumer profiling. Every content asset published through theStacc is served without third-party tracking pixels by default, which sidesteps a large class of CCPA "sharing" obligations. The audit report flags any downstream integrations (like GBP posts or citations) that touch consumer data so your privacy team knows exactly where compliance checks apply.
Frequently asked questions
The CCPA is California's consumer privacy law that gives residents the right to know what personal data a business collects, request its deletion, correct it, and opt out of its sale or sharing. It applies to for-profit businesses meeting certain revenue or data thresholds.
For-profit businesses that do business in California and meet one of three thresholds: annual gross revenue over $25 million, buy/sell/share personal info of 100,000+ California consumers or households, or derive 50%+ of annual revenue from selling or sharing personal information.
GDPR is an opt-in framework covering all EU residents; CCPA is an opt-out framework covering California residents. GDPR fines reach 4% of global revenue; CCPA fines cap at $7,500 per intentional violation, plus statutory damages of $100–$750 per record for data breaches.
The California Privacy Protection Agency can levy fines of up to $2,500 per unintentional violation and $7,500 per intentional violation. Consumers can also sue for $100 to $750 per incident for certain unauthorised data breaches — often as class actions.
Yes. Email lists, ad-targeting cookies, CRM records, and analytics data on California residents all fall within CCPA scope. Sharing this data with third parties for cross-context behavioural advertising counts as "sharing" and requires an opt-out mechanism.
