Artifact GuideUSPenalties and Fines

US CCPA Penalties and Fines

The current public-enforcement caps are $2,663 per violation and $7,988 for an intentional violation or a violation involving personal information of a consumer the violator actually knows is under 16.

The limited security-breach private action currently allows $107-$799 per consumer per incident or actual damages, whichever is greater. Do not estimate a total until the enforcement path and unit of violation are established.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

CCPA monetary exposure depends on who is enforcing, what provision was violated, whether the violation was intentional or involved a known consumer under 16, and how many legally distinct violations or qualifying security incidents occurred. The California Privacy Protection Agency published the amounts below for January 1, 2025. The statute requires adjustments every odd-numbered year, so check the current CPPA threshold before using them in a live matter.

Section 1

What are the current CCPA fine and penalty amounts?

For CPPA administrative enforcement, the current cap is $2,663 for each violation. The current higher cap is $7,988 for each intentional violation or violation involving personal information of a consumer the violator actually knows is under 16. The Attorney General's civil-penalty caps are the same, and an Attorney General action can also seek an injunction.

These are maximum amounts, not automatic charges. The Agency or court determines the amount from the facts and governing law. The statute requires consideration of good-faith cooperation, and the Attorney General penalty provision expressly lets the court consider good-faith cooperation.

Are the $2,663 and $7,988 CCPA amounts automatic?

No. They are current for public enforcement, not fixed charges. The violation, enforcement route, facts, intent, age knowledge, and legally supported violation count still have to be established. Good-faith cooperation must be considered when setting the amount.

  • CPPA administrative fine: up to $2,663 for each violation.
  • Higher CPPA administrative fine: up to $7,988 for each intentional violation or violation involving personal information of a consumer the violator actually knows is under 16.
  • Attorney General civil penalty: up to $2,663 for each violation, or $7,988 for each intentional violation or violation involving personal information of a consumer the violator actually knows is under 16.
  • Public remedies may also include a cease-and-desist order or injunction.
Section 2

What damages can a consumer seek for a qualifying security incident?

The current statutory-damages range is $107-$799 per consumer per incident, or actual damages if greater. A court may also grant injunctive or declaratory relief and any other relief it considers proper. The action is limited to the data and event conditions in Civil Code section 1798.150; it does not apply to every CCPA violation or every security event.

For , the court considers circumstances including the nature and seriousness of the misconduct, number of violations, persistence, duration, willfulness, and the defendant's assets, liabilities, and net worth. Those factors guide an award within the range; they do not create a mechanical exposure formula.

Does every data breach qualify for CCPA ?

No. Section 1798.150 requires specified personal information, a qualifying unauthorized access and exfiltration, theft, or disclosure, and a causal connection to the business's failure to maintain . A different security incident may create duties or claims under other laws without meeting this CCPA private-action test.

  • Covered event: unauthorized access and exfiltration, theft, or disclosure caused by a failure to maintain .
  • Covered data: the specified nonencrypted and nonredacted personal information, or an email address combined with account-access credentials described in section 1798.150.
  • Available monetary relief: $107-$799 per consumer per incident or actual damages, whichever is greater.
  • Notice: a consumer seeking must give 30 days' written notice before filing; an individual action seeking only actual pecuniary damages does not require that notice.
Section 3

How do cure, cooperation, and overlapping enforcement affect exposure?

Cure rules differ by path. In a section 1798.150 claim for , a consumer must give 30 days' written notice. If a cure is possible, an actual cure plus the required written assurance can bar statutory damages for the noticed violation. Implementing after a breach does not cure that breach. In public enforcement, the CPPA may allow time to cure, but no automatic cure period applies.

Cooperation enters the amount analysis but does not erase a violation. California Civil Code section 1798.199.100 requires the Agency or court to consider good-faith cooperation and prevents a business from being required to pay both a CPPA administrative fine and an Attorney General civil penalty for the same violation. A private section 1798.150 claim remains a separate path.

  • Do not confuse the private-action 30-day notice with the CPPA's 30-day probable-cause notice; they serve different purposes.
  • Document what was corrected, when, how the correction was tested, and whether the original harm can be cured.
  • Keep proof of prompt cooperation, preservation, investigation, remediation, and accurate regulator communications.
  • Identify whether two public demands concern the same violation before applying the rule against duplicate administrative and civil monetary penalties.
Section 4

How should a team estimate CCPA exposure?

Estimate a range. First identify the enforcement path and the exact provision or security-incident test. Then determine the relevant acts, consumers, incidents, dates, systems, and responsible entities. Apply an amount only after counsel has a supported basis for the unit of violation or incident.

Keep the adjusted amount and the statutory base amount separate in the record. The CCPA requires inflation adjustments on January 1 of every odd-numbered year, so the amount can change even when the underlying violation rule does not.

  • Step 1: classify CPPA administrative enforcement, Attorney General civil enforcement, section 1798.150 private action, or more than one path.
  • Step 2: identify the exact violated provision or qualifying security incident and the period it continued.
  • Step 3: document facts relevant to intent, actual knowledge of age, , cure, cooperation, and actual damages.
  • Step 4: define the proposed violation or incident count and record the legal basis; do not assume one count per consumer, record, day, or data field.
  • Step 5: apply the current adjusted amount, show low and high scenarios, and keep nonmonetary remedies separate.
  • Step 6: update the estimate when the facts, claims, enforcement route, or CPPA monetary threshold changes.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding source for administrative fines, civil penalties, private security-breach damages, award factors, cure rules, cooperation, and monetary adjustments.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.