Artifact GuideUSFAQ

US CCPA FAQ

Start with the right or business activity involved, then use the focused pages for the controlling rule, exceptions, implementation steps, and evidence.

The current CPPA regulations took effect January 1, 2026. Some cybersecurity-audit, risk-assessment, and automated-decisionmaking compliance dates are phased later.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
13

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The (CCPA), as amended by the California Privacy Rights Act, gives California residents rights over personal information and regulates covered for-profit businesses. This hub explains the main scope test, consumer rights, notices, opt-outs, request handling, and specialized rules. A specific outcome still depends on the entity, data, purpose, recipient, contract, consumer relationship, and statutory exceptions.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items40
Focused FAQ modules
13
Showing 13 of 13
FAQ module

California Data Brokers: CCPA, Registration, and DROP Duties

Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.

3 items
FAQ module

CCPA Dark Patterns: Rules, Examples, and Review Checklist

Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.

3 items
FAQ module

CCPA Do Not Sell or Share: Scope and Implementation

Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.

3 items
FAQ module

CCPA Financial Incentives: Notice, Consent, and Data Value

Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.

3 items
FAQ module

CCPA Global Privacy Control (GPC): team obligations and technical implementation

Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.

3 items
FAQ module

CCPA Minors: Opt-In Rules for Consumers Under 16

Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.

4 items
FAQ module

CCPA Notice at Collection: Timing, Content, and Examples

Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.

3 items
FAQ module

CCPA Personal and Sensitive Information Categories

Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.

3 items
FAQ module

Does the CCPA apply to my business? Threshold guide

Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.

3 items
FAQ module

What must a CCPA privacy policy include?

A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.

3 items
FAQ module

What must CCPA service-provider contracts include?

Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.

3 items
FAQ module

What should teams do about consumer request verification under the CCPA?

Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.

3 items
FAQ module

When does the CCPA require risk assessments or cyber audits?

CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.

3 items
Question 1

Does the CCPA apply and what does it require?

The core business definition covers a for-profit legal entity that does business in California, determines the purposes and means of processing, and meets at least one statutory threshold. Effective January 1, 2025, the adjusted gross-revenue threshold is more than $26,625,000 in the preceding calendar year. The alternatives are buying, selling, or sharing personal information of at least 100,000 consumers or households in a year, or deriving at least 50 percent of annual revenue from selling or sharing consumers' personal information. Related entities, joint ventures, partnerships, and voluntary certification can be covered under additional conditions.

Covered businesses must give required notices, respond to applicable rights requests, avoid discrimination for exercising rights, honor sale and sharing opt-outs and qualifying preference signals, limit collection, use, and retention to disclosed and compatible purposes, secure personal information reasonably, and use compliant contracts and downstream controls. Exemptions can be data-specific or activity-specific rather than an exemption for the whole entity.

  • Confirm the legal entity, California activity, threshold year, adjusted revenue threshold, and consumer or household count.
  • Map the entity as a business, service provider, contractor, third party, or a combination by processing activity.
  • Identify applicable data and activity exemptions before removing a system or data set from scope.
  • Assign each notice, right, opt-out, contract, retention, security, and assessment control to an owner and evidence record.
Question 2

Which focused answer should you use?

Choose the page that matches the immediate decision. Several pages may apply to one flow: an advertising sign-up can involve notice at collection, personal-information categories, sale or sharing, GPC, minors, a financial incentive, and dark-pattern review.

  • Collection point: use Notice at Collection before collecting and disclose categories, purposes, retention, sale or sharing, and required links.
  • Data inventory: classify personal and sensitive personal information, including conditional categories and statutory exclusions.
  • Advertising or other transfers: decide whether the activity is sale or sharing and implement the opt-out and Global Privacy Control.
  • User interface: test consent and rights flows for dark patterns, plain language, and symmetrical choices.
  • Special populations or programs: apply the under-16 opt-in rules and financial-incentive notice, consent, withdrawal, and value analysis.
  • Rights operations: use proportionate verification for know, delete, correct, access, and ADMT appeal requests, but not for sale-or-sharing, sensitive-information, or ADMT opt-out requests.
  • Indirect-data business: test whether the entity is a data broker and track registration, public metrics, DROP, vendor, and audit duties.
Question 3

What evidence should a CCPA program keep?

Keep evidence that connects the legal trigger to actual product and operational behavior. A policy is one record, not proof that notices appeared on time, requests reached every system, vendor roles were classified correctly, or retention rules ran.

Update the record when the entity, threshold, data category, purpose, interface, recipient, contract, consumer relationship, or system behavior changes.

  • Entity and threshold analysis with calculation period, inputs, assumptions, exemptions, and approval.
  • Data and transfer inventory with collection points, categories, purposes, recipients, roles, contracts, retention, and sale or sharing status.
  • Versioned notices and interfaces with screenshots, accessibility checks, release dates, and dark-pattern review.
  • Rights and signal logs with intake, verification where required, response, propagation, exception, and completion evidence.
  • Vendor contracts, instructions, monitoring, incidents, remediation, owners, and scheduled reassessment.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding consumer rights, business duties, exceptions, enforcement, and private-action provisions.
Related guides

Explore more topics

CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.