- Official statutory text for the limited private right of action, enforcement caps, inflation adjustment, and bar on double penalties for the same violation.
"A consumer whose nonencrypted and nonredacted personal information"
Use this guide to resolve penalties and fines under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.
Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains the CPRA enforcement framework that can lead to fines and penalties: the California Privacy Protection Agency can enforce the CCPA regulations and the Attorney General can seek civil penalties, while a separate private right of action is available for certain data breaches. It then maps the issue to the trigger, responsible role, deadline, evidence record, and review path that product, legal, privacy, security, and compliance teams can apply.
The statute sets base caps of $2,500 per violation and $7,500 per intentional violation or violation involving personal information of a consumer known to be under 16, and requires inflation adjustments. The CPPA's 2025 adjustment notice lists current administrative-fine and civil-penalty caps of $2,663 and $7,988. Confirm the published amount applicable when the violation occurred. The same violation cannot receive both an administrative fine and a civil penalty.
The private right of action is narrower: it covers specified unauthorized access and exfiltration, theft, or disclosure caused by a failure to maintain reasonable security, not every CCPA violation. The statute provides actual damages or base statutory damages of $100 to $750 per consumer per incident, whichever is greater, subject to statutory conditions, inflation adjustment, and the 30-day notice procedure for a statutory-damages claim.
Ownership should sit with the team that can change notices, rights intake, consent/opt-out interfaces, data sharing, retention, vendor terms, or security evidence, with privacy counsel reviewing edge cases.
Keep the penalties and fines decision, source, affected data and systems, implementation record, owner approval, exception rationale, and dated test or review evidence together.
The main risk is applying a general California privacy answer without checking the facts that control this penalties and fines decision: entity scope, data category and purpose, consumer context, recipient role, applicable exception, and current regulatory text.
Reassess before a material change to the data, purpose, interface, vendor, recipient role, system logic, or source text.
Use a CPRA workflow that captures threshold status, data categories, consumer rights, opt-out signals, vendor role, retention logic, risk/cyber/ADMT trigger, owner, and review date.
The output should be a threshold memo, notice update, DSAR workflow, opt-out/GPC implementation record, vendor clause map, risk-assessment intake, or audit evidence pack.
This US CPRA guide turns penalties and fines into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn penalties and fines into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"A consumer whose nonencrypted and nonredacted personal information"
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency's regulations and filed"
"(ii) Does not make use of any dark patterns"
"Civil penalty amounts Not more than $2,663 for each violation or $7,988 for each intentional violation"
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"