Direct Answer: The California Consumer Privacy Act (CCPA) is a state law that gives California residents the right to know what personal data companies collect about them, request its deletion, and opt out of its sale. It applies to for-profit businesses meeting specific revenue or data-processing thresholds and as of 2026, enforcement has gotten significantly tougher.
CCPA explained simple that’s what most people are searching for after hearing the term thrown around in privacy policies they never read. Maybe a website just asked you to accept cookies and mentioned “California privacy rights,” or you got an email about a data breach and wondered what protections actually exist. The California Consumer Privacy Act is one of the strongest consumer privacy laws in the United States, and it affects far more people and companies than most realize. Understanding what rights you have when a data breach happens is a good place to start.
The Short Version
- The CCPA gives California residents six major privacy rights, including the right to know, delete, and opt out of the sale of personal data.
- It applies to for-profit businesses with over $26.625 million in annual revenue, those processing data of 50,000+ consumers, or those earning 50%+ of revenue from data sales.
- As of January 2026, new regulations added requirements around automated decision-making technology (ADMT), risk assessments, and cybersecurity audits.
- Enforcement is ramping up fast California regulators issued over $18 million in CCPA fines in early 2026 alone, including a record $12.75 million penalty against General Motors.
What CCPA Explained Simple Really Means Under the Law
The California Consumer Privacy Act was signed into law in 2018 and took effect on January 1, 2020. In November 2020, California voters approved Proposition 24, which introduced the California Privacy Rights Act (CPRA) an amendment that expanded and strengthened the original CCPA. The CPRA changes generally took effect on January 1, 2023.
Here’s what matters in plain English: the CCPA gives California residents control over their personal information. Under the law, “personal information” means anything that identifies, relates to, or could reasonably be linked to a specific person or household. That includes names, email addresses, browsing history, purchase records, geolocation data, and much more.
Who does it apply to? The CCPA covers for-profit businesses that do business in California and meet at least one of these thresholds:
- Annual gross revenue exceeding $26.625 million (adjusted for inflation as of January 2025)
- Buying, selling, or sharing the personal information of 50,000 or more California consumers, households, or devices per year
- Deriving 50% or more of annual revenue from selling or sharing consumers’ personal information
A business does not need to be physically located in California to fall under the CCPA. Any company doing business with California residents that meets these thresholds is covered.
The Six Rights Under CCPA
Under the CCPA, as amended by the CPRA, California residents generally have these six rights:
Right to Know Individuals can request that a business disclose what personal information it has collected, where it came from, and who it was shared with.
Right to Delete Individuals can request deletion of their personal information. Businesses must also direct service providers to delete that data, with some exceptions (like legal obligations).
Right to Opt Out of Sale or Sharing Individuals can direct a business to stop selling or sharing their data. Businesses must provide a “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control (GPC) browser signals.
Right to Correct Individuals can request fixes to inaccurate personal information.
Right to Limit Individuals can restrict how businesses use sensitive personal information like Social Security numbers, financial accounts, and precise geolocation.
Right to Non-Discrimination Businesses cannot penalize consumers for exercising their CCPA rights.
What Changed in 2026
New CCPA regulations took effect on January 1, 2026. Data of consumers under 16 is now automatically classified as sensitive personal information. Businesses must show visible confirmation when an opt-out request is processed, and consent obtained through inaction like closing a pop-up no longer counts. California also launched the Delete Request and Opt-Out Platform (DROP), letting consumers send a single deletion request to all registered data brokers at once. New risk assessment and cybersecurity audit requirements began phasing in, with ADMT obligations starting January 2027.
Real-World Examples
The Disney Case (February 2026): California Attorney General Rob Bonta announced a $2.75 million settlement with Disney the largest CCPA fine at the time after an investigation found that Disney’s opt-out toggle only applied to the specific streaming service and device a consumer was using. If someone opted out on Disney+ on their tablet, their data could still be sold through other Disney services or devices. The settlement required Disney to honor opt-out requests across all services linked to a consumer’s account.
General Motors (May 2026): GM agreed to pay $12.75 million the largest CCPA penalty to date in a joint action by the Attorney General, the CPPA, and local district attorneys over the sale of driving and location data. Regulators called it California’s first data-minimization enforcement action.
Tractor Supply Company (September 2025): The rural lifestyle retailer paid $1.35 million after the CPPA found violations in how it handled consumer data.
These cases show regulators are targeting companies across industries not just tech giants.

What People in This Situation Typically Do
For California residents who want to exercise their CCPA rights, the process is more practical than most people expect.
- Check the company’s privacy policy. Look for a link at the bottom of the website labeled “Privacy” or “California Privacy Rights.” This should explain how to submit requests.
- Submit a request to know or delete. Most companies offer a web form, email address, or toll-free number. The business must confirm receipt within 10 business days and respond within 45 calendar days (extendable to 90 days in some cases).
- Opt out of data sales. Click the “Do Not Sell or Share My Personal Information” link on any website that has one. Alternatively, install a browser that sends Global Privacy Control signals businesses are legally required to honor them.
- Use the DROP platform. Since January 2026, California’s Delete Request and Opt-Out Platform lets consumers send a single request to every registered data broker in the state at once. The platform sends ongoing deletion requests every 45 days.
- File a complaint if a business ignores your request. The California Privacy Protection Agency (CPPA) accepts complaints through its online portal. The Attorney General’s office also investigates violations.
- Consult a lawyer if your data was breached. Under Section 1798.150, individuals can file a private lawsuit if their unencrypted personal information was exposed due to a company’s failure to maintain reasonable security practices. Statutory damages range from $100 to $750 per consumer per incident and class actions can add up to millions.
Tools That Can Help
DeleteMe A paid service that submits opt-out and deletion requests to data brokers on your behalf. For anyone who doesn’t want to track down dozens of brokers individually, DeleteMe handles the repetitive work of keeping your information off data broker sites. Plans start at around $129 per year for individuals.
Global Privacy Control (GPC) A free browser setting available in Firefox, Brave, and DuckDuckGo. Once enabled, it automatically sends an opt-out signal to every website you visit. Under the CCPA, businesses must honor GPC signals as valid opt-out requests.
CPPA’s DROP Platform California’s official, free tool for sending deletion requests to all registered data brokers at once. Available at privacy.ca.gov.
Related Articles
- Can Your Boss Watch You Work from Home? If you’re wondering what privacy rights extend to the workplace, this article breaks down federal and state monitoring laws.
- When a Company Has a Data Breach Your Rights Learn what companies are required to do after a breach and how the CCPA’s private right of action works.
- Can Companies Legally Sell Your Personal Data? A broader look at how data selling works across US federal and state law.
Frequently Asked Questions
Does CCPA only protect California residents?
Yes. The CCPA applies exclusively to California residents people in California for other than a temporary purpose. However, the businesses it covers can be located anywhere. A company in Texas or New York must still comply if it meets the thresholds and handles California consumers’ data.
How is CCPA different from GDPR?
The GDPR applies to all EU residents regardless of a business’s size and requires a legal basis before collecting data. The CCPA only covers for-profit businesses meeting certain thresholds and focuses on opt-out rights rather than upfront consent. GDPR fines can reach €20 million or 4% of global revenue as a single penalty. CCPA fines are smaller per violation ($7,988 max) but stack across every affected consumer reaching $12.75 million in one case.
Can I sue a company under CCPA?
Only in limited situations. The CCPA’s private right of action (Section 1798.150) allows lawsuits when unencrypted personal information is exposed through a data breach caused by inadequate security. A 30-day written notice must be sent first. Statutory damages range from $100 to $750 per consumer per incident. For other violations like ignored deletion requests enforcement is handled by the Attorney General and the CPPA, not private lawsuits.
What businesses must comply with CCPA?
Any for-profit business doing business in California that meets at least one threshold: over $26.625 million in annual revenue, processing data of 50,000+ consumers annually, or earning 50%+ of revenue from selling personal information. No California headquarters or physical presence is required.
Wrapping Up
The CCPA is not just another privacy policy checkbox it’s a law with real teeth and growing enforcement muscle. Whether someone is dealing with unwanted data collection, a breach notification, or a company that refuses to stop selling personal information, having CCPA explained simple makes it possible to actually act on those rights. California set the standard for state-level privacy law in the United States, and as of 2026, the penalties for ignoring it are higher than ever.
This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.
Sources & Further Reading
- California Consumer Privacy Act (CCPA) California Attorney General Official overview of CCPA rights and how to exercise them
- California Privacy Protection Agency Regulations Full text of CCPA regulations effective January 1, 2026
- CCPA Frequently Asked Questions CPPA Official FAQ on consumer rights, business obligations, and enforcement
- California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100–1798.199) Full statutory text of the CCPA

