The CCPA, or California Consumer Privacy Act, is a state law that gives California residents control over their personal information. It lets them see what data a business collects, delete it, and opt out of its sale or sharing.
People now use the name loosely. Voters amended the original 2018 law in November 2020 through the CPRA, the California Privacy Rights Act. So when someone says CCPA today, they almost always mean the combined, amended law.
I have spent the last seven years cleaning and enriching B2B contact databases. Honestly, no US law has changed that work more than this one. In this guide I cover the thresholds, the consumer rights, the GDPR differences, and the sales outreach impact. One note first: I build data processes, not legal defenses. Treat this page as an operator’s guide, not legal advice.
What Does the CCPA Actually Mean?
The CCPA means personal information about a California resident belongs, in practice, to that resident. A business holding that data is closer to a borrower than an owner. Everything else in the law flows from that single idea.
In practice, the law creates three duties for any covered business:
- Transparency. Tell people what you collect, why you collect it, and how long you keep it.
- Responsiveness. Accept rights requests through at least two channels and answer them on fixed deadlines.
- Restraint. Stop selling or sharing someone’s data the moment they opt out, and keep it stopped.
For data teams, this rewires data governance from the ground up. Every record needs a known source, a documented purpose, and a working deletion path. Spreadsheets with mystery columns stop being a quirk and start being a liability. IBM’s overview of CCPA compliance is a good plain-language companion if you want a second walkthrough.
📌 Example: A revenue team I supported in 2021 kept 14 export copies of the same contact list across three shared drives. One deletion request meant hunting through every copy by hand. Their fix was boring and effective: one system of record, plus a 90-day purge rule for exports.
What Counts as Personal Information Under the CCPA?
Personal information is anything that identifies, relates to, or could reasonably be linked with a resident or household. That definition reaches far beyond names and emails, and the household part surprises almost everyone.
| Category | Everyday examples |
|---|---|
| Identifiers | Name, email, phone number, IP address, account handles |
| Commercial information | Purchase history, products viewed, subscription records |
| Internet activity | Browsing history, search history, ad interactions |
| Geolocation | Device location trails, store visit data |
| Professional information | Employer, job title, work email, employment history |
| Inferences | Profiles predicting preferences, behavior, or intent |
| Sensitive personal information | SSN, precise geolocation, health data, login credentials |
Notice the professional row. A work email with a job title is personal information, which is exactly why sales databases are in scope. Notice the inferences row too. Even a lead score you calculated yourself counts as data about the person.
The sensitive category arrived with the CPRA and carries its own right. Consumers can tell you to limit its use to core service delivery only. Most B2B teams hold little sensitive data, but login credentials and precise location sneak in through product analytics.
Where Did the CCPA Come From?
The CCPA began as a citizen ballot initiative backed by real estate developer Alastair Mactaggart. To keep that initiative off the ballot, California’s legislature passed AB 375 in a single week in June 2018. That unusual origin explains both the law’s speed and its rough edges. California often previews where US regulation goes next, which makes the story worth knowing even outside the state.
The law took effect on January 1, 2020, with Attorney General enforcement starting that July. Its full backstory, including the last-minute negotiation drama, is well documented on Wikipedia’s CCPA page.
Then voters strengthened it. In November 2020, Proposition 24 passed and enacted the CPRA. The amendment added the right to correct and the right to limit sensitive data use. Sharing data for cross-context advertising got stricter rules too. It also created the California Privacy Protection Agency, the first US regulator dedicated purely to privacy.
Most CPRA provisions became operative on January 1, 2023. That date matters enormously for B2B teams, because two temporary exemptions died the same day. We will get to that shortly.
Who Must Comply With the CCPA?
You must comply if you are a for-profit business handling California residents’ data and you cross one of three thresholds. Location does not save you. A SaaS company in Berlin or Toronto is covered once it does business in California and meets a threshold.
Here are the thresholds, straight from the Attorney General’s CCPA page:
- Revenue. Annual gross revenue above $25 million. Regulators adjust this figure for inflation every two years.
- Volume. Buying, selling, or sharing personal information of 100,000 or more California residents or households per year.
- Business model. Earning 50 percent or more of annual revenue from selling or sharing personal information.
Meeting any single test is enough. Nonprofits and government agencies sit outside the law entirely. Data already governed by sector rules, such as HIPAA medical records, is partly carved out as well.
Publicly available information gets a carve-out too. Data lawfully drawn from government records, or made public by the person, is not personal information here. That line gets fuzzy fast, though, so treat scraped profiles with real care.
In my experience, the volume test catches more mid-market companies than the revenue test. Californians make up roughly one in eight Americans. As a result, national contact databases hit 100,000 California records faster than anyone expects.
💡 Pro Tip: Do not guess your California exposure. Filter your database by state, count residents and households, and rerun that count quarterly. I watched a 60,000-contact list cross the 100,000 threshold in one funding-fueled year, and nobody noticed until an audit.
What Rights Does the CCPA Give Consumers?
The CCPA grants six rights: know, delete, correct, opt out of sale or sharing, limit sensitive data, and non-discrimination. Each right comes with a deadline, and the deadlines are where operations teams actually feel the law.
| Right | What the consumer can demand | Your deadline |
|---|---|---|
| Know | The categories and specific pieces of data you hold | 45 days, extendable once |
| Delete | Removal from your systems and your service providers | 45 days, extendable once |
| Correct | Fixes to inaccurate personal information | 45 days, extendable once |
| Opt out of sale or sharing | An end to data sales and cross-context ad sharing | 15 business days |
| Limit sensitive data | Use of sensitive data for core services only | 15 business days |
| Non-discrimination | Equal price and service after exercising any right | Ongoing |
Two operational details matter here. First, you must verify identity for know, delete, and correct requests, but you cannot demand verification for opt-outs. Second, requests can arrive through an authorized agent, and certain browser signals count as valid opt-outs.
That last point is the Global Privacy Control, or GPC. When a browser sends the GPC signal, California treats it as a formal opt-out request. Ignoring it has already cost companies real money, as the enforcement section will show.
One scope note before we move on. The right to know reaches back at least 12 months. For data collected after January 2022, a request can reach further when honoring it is not impossible or disproportionately hard.
How Is the CCPA Different From GDPR?
The core difference is the consent model. GDPR requires a lawful basis before any processing starts, while the CCPA allows processing until the consumer opts out. One is a locked door, and the other is an open door with a clearly marked exit.
| Aspect | GDPR | CCPA (as amended) |
|---|---|---|
| Consent model | Opt-in: lawful basis required before processing | Opt-out: processing allowed until the consumer objects |
| Who it protects | People located in the EU and EEA | California residents and households |
| Who must comply | Organizations of any size or type | For-profit businesses above thresholds |
| Maximum fines | Up to 20 million euros or 4% of global turnover | $2,500 per violation, $7,500 if intentional |
| Private lawsuits | Broad individual rights of action | Data breach cases only |
| Privacy officer | DPO mandatory for many organizations | No DPO requirement |
| B2B contact data | Covered from day one | Fully covered since January 2023 |
The fine structures look wildly different until you do the math. GDPR headlines with percentage-of-revenue penalties, which the European Commission’s data protection framework describes in detail. CCPA fines apply per violation, and regulators count each affected consumer. Multiply $2,500 by a mishandled database and the number stops feeling small.
There is also a philosophical split around de-identification. GDPR formally encourages pseudonymization, where identifiers are replaced but re-identification stays possible under controls. The CCPA prefers full de-identification backed by a public promise never to re-identify.
One more difference matters for American teams: the CCPA started a wave. A long list of states has since passed comprehensive privacy laws, tracked well by the IAPP’s state legislation tracker. California remains the strictest and the most actively enforced of them.
If you already comply with GDPR, you are perhaps 70 percent of the way there in spirit. Still, do not assume equivalence. The opt-out link, GPC handling, and the sale definition have no GDPR twin, and each one has produced fines.
What Does the CCPA Mean for B2B Data and Sales Outreach?
Since January 1, 2023, the CCPA fully covers business contact data. A prospect‘s work email now carries the same rights as a shopper’s home address. This is the part of the law most sales teams still get wrong.
The history explains the confusion. Early versions carved out B2B communications data and employee data through temporary exemptions. Lawmakers extended those carve-outs twice, and many teams assumed the extensions would continue forever. Instead, the CPRA let both exemptions expire on January 1, 2023.
So what changes day to day? Records used in B2B sales and B2B lead generation sit inside the law whenever the person is a California resident. A prospect can ask what you know, demand deletion, and opt out of any sale or sharing of their profile.
Cold email itself is not banned. The CCPA regulates how you collect, hold, and disclose data, not whether you may send a message. Your cold outreach program mainly inherits three duties: source transparency, opt-out plumbing, and deletion that actually works.
Suppression lists deserve special care in that plumbing. An opt-out is permanent until the person changes their mind, so deleting the suppression record is itself a failure. I keep a separate, minimal suppression table holding just enough data to honor the request. Good email teams already run unsubscribes this way.
Data vendors add another layer. California’s Delete Act requires data brokers to register on a public data broker registry run by the CPPA. A one-stop deletion mechanism is phasing in on top of it. If you buy lists, you inherit whatever obligations your source ignored.
Enrichment sits in the same frame. Teams that use B2B data enrichment to refresh CRM records should ask every provider two questions. Where does each field come from, and how do opt-outs propagate? We built CUFinder’s enrichment around documented sourcing partly for this reason. Still, I will be blunt. No tool rescues you if consumer requests die unanswered in your inbox.
🔍 Field Note: In February 2023 I audited a 90,000-record outbound database, three weeks after the B2B exemption expired. Roughly 11,000 rows were California contacts, and the team had no opt-out workflow for any of them. Building the request pipeline took three more weeks. Skipping it would have made every mishandled request a separate potential violation.
Service Provider vs Third Party: Why the Difference Matters
A service provider may process personal information only on your documented instructions. By contrast, a third party can use the data for its own purposes. That one distinction decides whether handing data to a vendor counts as a sale.
Start with the definition of selling, because it surprises people. A sale is any disclosure of personal information for money or other valuable consideration. No invoice is required. Swapping customer lists with a partner, or feeding a data cooperative, can qualify.
DoorDash learned this in 2024 and paid $375,000 to settle. The company had contributed customer data to a marketing cooperative in exchange for advertising opportunities. Regulators called that trade a sale, made without notice or an opt-out.
Contracts are what separate the categories. A vendor bound by CCPA-mandated contract terms can act as your service provider, so the disclosure is not a sale. The same vendor without those terms defaults to a third party.
| Question | Service provider | Third party |
|---|---|---|
| Can it use the data for its own purposes? | No, your instructions only | Yes |
| Does disclosure count as a sale or sharing? | No, when contract terms are met | Often yes |
| What paperwork is required? | A contract with CCPA-mandated clauses | Notice at collection plus an opt-out path |
| Typical examples | Email platform, hosting, analytics processor | Ad networks, data cooperatives, list buyers |
De-identified and aggregate data sit outside the law when handled properly. Techniques such as data masking help, but California sets a high bar. You must strip identifiers, publicly commit never to re-identify, and push that promise into downstream contracts.
How Is the CCPA Enforced? Real Cases and Real Fines
Two regulators enforce the CCPA, the California Attorney General and the CPPA, and both have moved from warnings to money. Penalties reach $2,500 per violation and $7,500 per intentional violation or violations involving minors. Each affected consumer can count as a separate violation.
The public enforcement record tells you exactly what regulators care about:
- Sephora, 2022. Paid $1.2 million for selling customer data without disclosure and ignoring Global Privacy Control signals.
- Honda, 2025. Paid $632,500 to the CPPA for demanding excessive verification from people trying to opt out.
- Healthline, 2025. Paid $1.55 million, the largest CCPA settlement to date, over ad trackers that shared health-related browsing data.
A breach adds private lawsuits on top. Consumers can seek statutory damages between $100 and $750 per person, per incident, when weak security exposes their data. Class action math turns that range into board-level numbers quickly.
Notice what connects the public cases. None of them involved a hack. Every company simply failed at opt-out mechanics, verification design, or honest disclosure. Those are process failures, and process is fixable in advance. One more pattern is worth knowing. The Honda case grew out of a CPPA sweep of connected vehicle makers, and more sweeps are coming.
🧠 Worth Remembering: The CPRA removed the automatic 30-day cure period in 2023. Regulators may still let you fix a violation before fining you, but that is now discretion, not your right. Build the process before the letter arrives, because the letter no longer comes with a grace period.
How Do You Build a CCPA Compliance Program?
Start with a data map, because every CCPA duty depends on knowing what you hold and where it lives. Here is the working checklist I run with revenue teams:
- Map your data. List every system that holds personal information, including marketing tools, spreadsheets, and forgotten exports.
- Rewrite the privacy notice. Disclose the categories you collect, your purposes, retention periods, and every consumer right, in plain language.
- Add the opt-out link. Post a “Do Not Sell or Share My Personal Information” link and honor GPC signals automatically.
- Build the request workflow. Log every request, verify identity where allowed, and answer within 45 days.
- Fix vendor contracts. Add service provider clauses so routine disclosures do not quietly become sales.
- Clean as you go. Fold data cleansing into the routine so duplicates and dead records stop multiplying your exposure.
- Train the humans. Reps and marketers must recognize a rights request even when it arrives as an angry reply.
The quiet benefit of all this is data quality. Mapped, deduplicated, well-sourced records make a deletion request a ten-minute task instead of a forensic project. Compliance work and revenue work point in the same direction more often than people expect.
📌 Checkpoint: Run one drill per quarter. Submit a test deletion request against your own stack and time it end to end. Anything over two weeks means your data map has holes. I have never seen a first drill finish on time without uncovering at least one surprise system.
How Do You Handle a CCPA Rights Request Step by Step?
Handle every request through the same six-step lane: intake, log, verify, search, act, and respond. A repeatable lane is what keeps a legal deadline from turning into a fire drill.
- Intake. Offer at least two request channels, such as a web form and a toll-free number, and watch them daily.
- Log. Record the date immediately, because the 45-day clock starts at receipt, not at your first reply.
- Verify. Match two or three data points for know and delete requests. Opt-outs need no verification at all.
- Search. Query every system on your data map, including the service providers holding copies.
- Act. Delete, compile, or correct as requested, then instruct vendors to do the same with their copies.
- Respond. Reply in plain language, explain what you did, and keep the records for at least 24 months.
Volume stays low for most B2B companies, often a handful of requests per month. Even so, the lane must exist before the first request lands. When a spike does come, it usually follows a news story or a breach headline. Regulators judge the quality of your response, never the size of your request queue.
What Are the Most Common CCPA Mistakes?
The most common mistakes are assuming B2B data is still exempt, treating a cookie banner as compliance, and forgetting vendors. I have watched each of these happen to otherwise careful teams.
The B2B assumption is everywhere. Sales leaders remember the old exemption and never heard about its expiry. In 2024 I reviewed an outbound program whose privacy notice still cited the lapsed exemption as its legal position. Their counsel’s reaction was a lesson in itself.
Cookie banners create false comfort. A consent pop-up does not satisfy the opt-out link requirement, and it rarely honors GPC. Compliance lives in your data handling, not in one overlay bought from a plugin store.
Vendor amnesia is the expensive one. Teams secure their own site, then pipe the same data into a dozen tools with no contract language behind them. Remember the DoorDash case: the data left through a partnership, not a breach.
And then there is the missed deadline, the quiet killer. One client’s deletion request sat in a shared inbox for five weeks in 2024 because nobody owned it. We beat the 45-day window by two days, purely on luck. Ownership, not software, was the fix.
Frequently Asked Questions
What is the CCPA in simple terms?
The CCPA is a California law that lets residents control the personal data businesses hold about them. They can see it, delete it, correct it, and stop its sale or sharing. Covered businesses must honor those requests on fixed deadlines or face fines.
Who needs to comply with the CCPA?
Any for-profit business that handles California residents’ data and crosses one of three thresholds. The thresholds: $25 million in revenue, data on 100,000 residents or households, or half of revenue from data sales. Nonprofits and government agencies are exempt, and company location makes no difference.
What is the difference between GDPR and CCPA?
GDPR requires a legal basis before processing personal data, while the CCPA permits processing until someone opts out. Scope also differs: GDPR covers organizations of any size, whereas the CCPA covers for-profit businesses above thresholds. Fines differ too: GDPR scales with global revenue, and the CCPA charges per violation.
What is the CCPA now called?
It is still called the CCPA. The CPRA of 2020 amended the law rather than replacing it, so lawyers often write CCPA, as amended. You will also see the shorthand CCPA/CPRA, which refers to the same combined law.
Does the CCPA apply to B2B data?
Yes. The temporary exemption for business-to-business contact data expired on January 1, 2023. Work emails, job titles, and prospect profiles of Californians now carry full CCPA rights, including deletion and opt-out.
Does the CCPA require opt-in consent?
No, the CCPA uses an opt-out model for most processing. Businesses may collect and use data until the consumer objects. The main exception is minors. Children under 16 must opt in to any sale or sharing, and kids under 13 need parental consent.
What happens if you violate the CCPA?
Regulators can fine you up to $2,500 per violation, or $7,500 when the violation is intentional or involves minors. Each affected consumer can count separately, which is how Sephora reached $1.2 million and Healthline $1.55 million. Data breaches also expose you to private lawsuits seeking $100 to $750 per person.
Does the CCPA apply to companies outside California?
Yes, whenever they do business in California and meet a threshold. A New York startup or a German SaaS firm holding enough California records must comply fully. The law follows the residents’ data, not the company’s address.
So that is the CCPA: an opt-out privacy law with real teeth and its own dedicated regulator. It has covered your B2B pipeline fully since 2023. Map what you hold, honor requests on time, and put contracts behind every vendor. Do that, and America’s strictest privacy law becomes a process you run rather than a risk you carry.