Artifact GuideUSEnforcement and Penalties

US CCPA Enforcement and Penalties

Separate CPPA administrative enforcement, Attorney General civil enforcement, and the narrow consumer action for qualifying security incidents.

Most CCPA violations do not give consumers a private CCPA lawsuit. They can still lead to an investigation, audit, order, injunction, fine, civil penalty, or settlement.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A CCPA enforcement issue can follow three paths. The California Privacy Protection Agency (CPPA) investigates, audits, and brings administrative actions. The California Attorney General may seek injunctions and civil penalties in court. A consumer may sue under the CCPA only for the security incidents defined in Civil Code section 1798.150, not for an ordinary notice, request, opt-out, or contract violation.

Section 1

Who enforces the CCPA, and what can each enforcer do?

The CPPA may investigate a business, service provider, contractor, or other person after a sworn complaint or on its own initiative. Its regulations also permit investigations based on referrals and nonsworn or anonymous complaints. The Agency may audit compliance with any CCPA provision, and an audit may be announced or unannounced. If an administrative hearing finds a violation, the Agency may order the violator to cease and desist and pay an .

The Attorney General may bring a civil action in the name of the people of California for an injunction and civil penalties. If the Attorney General asks, the CPPA must stay its administrative investigation or action while the Attorney General proceeds. The statute also prevents the Attorney General from filing a civil action for the same violation after the Agency has issued the specified decision or order.

Can an anonymous complaint lead to a CPPA investigation?

Yes. The regulations state that the CPPA may investigate on its own initiative and may use nonsworn or anonymous complaints, government referrals, or private-organization referrals. A sworn complaint has specific filing and attestation requirements, but it is not the only source of an investigation.

Can the CPPA audit without first finding a violation?

Yes. The CPPA may audit to investigate possible violations, but it may also select a subject because its processing presents significant privacy or security risk or because it has a history of noncompliance with privacy law. The regulations allow announced and unannounced audits.

  • CPPA investigation: can begin from a complaint, referral, anonymous information, or the Agency's own initiative.
  • CPPA audit: can examine any CCPA provision and may be announced or unannounced; failure to cooperate can lead to a subpoena, warrant request, or other enforcement step.
  • CPPA administrative order: can require the violator to cease and desist and can impose an after the statutory probable-cause and hearing process.
  • Attorney General civil action: can seek an injunction and civil penalties in court.
  • Consumer action: is limited to the security incidents and conditions in section 1798.150.
Section 2

What process applies before a CPPA administrative fine?

An investigation does not itself establish a violation. At least 30 days before the Agency considers , it must notify the alleged violator, provide a summary of the evidence, and explain the right to appear with counsel. A probable-cause proceeding is private unless the alleged violator requests a public proceeding. If the Agency finds probable cause, it holds an Administrative Procedure Act hearing to determine whether a violation occurred.

The CPPA may decline to investigate or give time to cure, considering lack of intent and voluntary cure efforts made before Agency notice. That discretion is not an automatic cure period. A stipulated order can resolve a matter without an administrative hearing, but the Board must approve it; the final order is public and has the force of a Board order.

Does the CCPA guarantee a 30-day cure period before public enforcement?

No. The CPPA may give a business time to cure and may consider voluntary cure efforts made before Agency notice, but the statute makes that discretionary. The separate 30-day probable-cause notice is procedural notice before the Agency considers ; it is not a guaranteed right to cure.

  • Preserve the alleged practice, affected period, systems, data, consumers, roles, notices, interfaces, contracts, request logs, and decision history.
  • Separate confirmed facts from legal conclusions and unresolved questions; do not alter or discard relevant records after a complaint, inquiry, subpoena, audit notice, or litigation hold.
  • Identify who can stop the practice, who owns regulator communications, and who can approve remediation or a stipulated resolution.
  • Track response dates from the actual notice, subpoena, audit request, probable-cause notice, or court filing rather than using a generic CCPA deadline.
Section 3

What penalties and remedies can follow?

The statutory base amounts are adjusted for inflation. The amounts effective January 1, 2025 are not more than $2,663 for each violation and $7,988 for each intentional violation or violation involving personal information of a consumer the violator actually knows is under 16. Those adjusted amounts apply to CPPA administrative fines and Attorney General civil penalties. The statute requires another adjustment on January 1 of each odd-numbered year, so confirm the CPPA's current monetary-threshold page before estimating exposure.

Public remedies also include a cease-and-desist order or injunction. Good-faith cooperation must be considered when setting an or civil penalty. A business cannot be required to pay both an administrative fine and a civil penalty for the same violation.

  • Do not multiply a headline amount by consumers, requests, days, or data fields without identifying what legally counts as each violation.
  • Check whether the higher amount rests on intent or on actual knowledge that the affected consumer was under 16.
  • Remedial work does not prove that the Agency will decline enforcement; preserve the facts and legal basis for the response.
  • Keep administrative fines, Attorney General civil penalties, and private security-breach damages in separate exposure calculations.
Section 4

When can a consumer sue under the CCPA?

Civil Code section 1798.150 creates a private action only when specified personal information is subject to unauthorized access and exfiltration, theft, or disclosure because the business violated its duty to use reasonable security. The covered information includes nonencrypted and nonredacted information defined in section 1798.81.5(d)(1)(A), and an email address combined with a password or security question and answer that permits account access. Other CCPA violations do not create a private action under this section.

For statutory damages, a consumer must give 30 days' written notice before filing. If a cure is possible and the business actually cures within that period and gives the required written statement, statutory damages cannot proceed on that noticed violation. Adding reasonable security after a breach does not cure that breach. No pre-suit notice is required for an individual action seeking only actual pecuniary damages.

Can a consumer sue under the CCPA because a business ignored an opt-out request?

Not under the CCPA's . Section 1798.150 limits that action to specified security incidents caused by a failure to maintain reasonable security. An ignored opt-out may still be investigated or enforced by the CPPA or Attorney General, and other law may create separate claims.

  • Classify the event against the exact data categories and unauthorized-access, exfiltration, theft, or disclosure language in section 1798.150.
  • Determine whether the alleged incident resulted from a failure to maintain reasonable security procedures and practices appropriate to the information.
  • Separate a demand for statutory damages from an action seeking only actual pecuniary damages because the pre-suit notice rule differs.
  • Preserve the incident facts, security controls, affected data, consumer count, notices, remediation, and any section 1798.150 written notice.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official current amounts effective January 1, 2025: $2,663 and $7,988 for administrative fines and civil penalties, with the higher amount covering intentional violations and specified violations involving consumers under 16.
cppa.ca.gov
Referenced sections
  • Official current source for the statute and CCPA regulations effective January 1, 2026, including investigation, probable-cause, stipulated-order, and audit rules.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.