CCPA (California Consumer Privacy Act)

The California Consumer Privacy Act (CCPA) is a data privacy law enacted in California that gives residents enhanced rights and control over their personal data. Enforced since January 1, 2020, it mandates that businesses disclose how they collect, use, share, and sell personal information — and empowers consumers with the right to access, delete, and opt out of data sharing or sales.

CCPA is a landmark regulation that inspired similar privacy laws across the U.S. and beyond, and it affects companies worldwide — not just those based in California.


What Is the CCPA?

The California Consumer Privacy Act (CCPA) is the first comprehensive data protection law in the U.S., designed to protect the privacy of California residents. It gives consumers rights to:

  • 📜 Know what data is collected
  • ❌ Opt out of the sale or sharing of their data
  • 📥 Request access to their data
  • 🗑 Request deletion of their data
  • 🛑 Prevent discrimination for exercising privacy rights

CCPA applies to both online and offline data and introduces transparency obligations similar to the EU’s GDPR, but with differences in scope, legal basis, and enforcement.


Who Does the CCPA Apply To?

CCPA applies to any for-profit business that:

✅ Collects personal information of California residents, and
✅ Meets one or more of the following thresholds:

ThresholdDescription
💵 RevenueAnnual gross revenue over $25 million
🧑‍💻 Data VolumeBuys, receives, or sells personal data of 100,000+ individuals or households annually
💰 Revenue from dataDerives 50%+ of revenue from selling or sharing personal data

This means even non-California companies — like SaaS platforms, analytics providers, or B2B lead tools — must comply if they collect California user data.


What Is Considered Personal Information Under CCPA?

CCPA defines personal information (PI) as any data that identifies, relates to, or could be linked to a person or household, including:

  • 👤 Name, email, phone number
  • 🌍 IP address, geolocation
  • 📱 Device identifiers
  • 📊 Browsing and search history
  • 📦 Purchase history
  • 🧠 Inferred data like preferences and behavior
  • 🎙 Voice recordings, biometric data

Unlike GDPR, CCPA includes household-level data and is more focused on sale and sharing activities than processing purpose.


Key Consumer Rights Under CCPA

RightDescription
Right to KnowConsumers can request what personal data is collected, why, and with whom it is shared
Right to DeleteConsumers can ask a business to delete their personal data
Right to Opt Out of Sale/ShareConsumers can opt out of the sale or sharing of their data (especially to advertisers)
Right to Non-DiscriminationBusinesses can’t punish users for exercising their privacy rights
Right to Correct (via CPRA)As of 2023, users may correct inaccurate data

What Is “Selling” Data Under CCPA?

Sale under CCPA means exchanging personal data for value, not just monetary. That includes:

  • Sharing data with ad networks
  • Using retargeting cookies
  • Partnering with data brokers or enrichment tools
  • Using profiling platforms that personalize experiences

If you “sell” data, you must display a clear “Do Not Sell or Share My Personal Information” link on your website.


CCPA for B2B Businesses

Initially, CCPA included a temporary exemption for B2B personal data, but that expired on January 1, 2023. Now:

  • CCPA applies fully to business contacts, including work emails
  • B2B platforms must support access, deletion, opt-out, and privacy notices
  • Even lead enrichment and CRM syncing activities must follow CCPA

CUFinder, for example, processes publicly available B2B data and offers compliance options like data access and opt-out mechanisms.


Differences Between CCPA and GDPR

FeatureCCPAGDPR
RegionCaliforniaEuropean Union
ScopeFor-profit businesses onlyAll entities (profit or not)
Legal BasisNot requiredRequires one of six legal bases
FocusData sale/sharingData processing and control
Consumer RightsAccess, delete, opt outAccess, delete, correct, restrict, portability, object
FinesUp to $7,500 per violationUp to €20M or 4% of global revenue
Consent RequirementNot required (opt-out model)Often required (opt-in model)

CCPA Compliance Checklist

✅ Update your privacy policy with CCPA rights and disclosures
✅ Add a “Do Not Sell or Share My Info” link if applicable
✅ Maintain a data inventory of personal data and processors
✅ Implement a DSAR (Data Subject Access Request) workflow
✅ Provide methods for access and deletion requests (webform, email, toll-free number)
✅ Document and train your team on compliance procedures
✅ Honor opt-out signals from Global Privacy Control (GPC)
✅ Sign Data Processing Agreements (DPAs) with vendors


How CUFinder Supports CCPA Compliance

CUFinder enables clients to meet CCPA obligations by:

  • ✅ Processing business contact data responsibly
  • ✅ Offering opt-out and data access request options
  • ✅ Maintaining transparent privacy policies
  • ✅ Providing signed DPAs for enterprise clients
  • ✅ Ensuring data minimization and lawful usage of enrichment tools

Enforcement and Penalties

The California Attorney General and California Privacy Protection Agency (CPPA) enforce the law.

Violation TypeFine
UnintentionalUp to $2,500 per violation
IntentionalUp to $7,500 per violation
Children’s dataEven stricter enforcement (explicit opt-in)

Private lawsuits may also arise in case of data breaches, even without proving financial loss.


Cited Sources


Related Terms


FAQ

What is the CCPA?

The California Consumer Privacy Act is a U.S. state law that gives California residents control over how their personal data is collected, used, and shared, especially by businesses that profit from user information.

Does CCPA apply to B2B companies?

Yes. As of 2023, CCPA applies to B2B contact data, meaning work emails, job titles, and CRM records are regulated if the data relates to California residents.

What are my obligations under CCPA?

You must publish a privacy policy, provide access/deletion/opt-out options, and maintain compliance with user requests and disclosures.

What is “selling” data under CCPA?

It includes any transfer of data for value — including targeted advertising, lead brokering, or sharing with enrichment vendors.

How can I comply if I use CUFinder?

CUFinder provides a DPA, supports opt-out workflows, and offers publicly sourced data to help clients operate legally under CCPA.