Artifact GuideUSpenalties and fines

US CPRA penalties and fines

The CCPA allows administrative fines and civil penalties per violation, while consumers have a narrower damages claim for specified security breaches.

Use the amount in effect when the violation occurred and separate Agency enforcement, Attorney General actions, and private claims.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

For violations occurring from January 1, 2025 through 2026, the current caps are $2,663 per violation and $7,988 for the enhanced tier. The enhanced tier covers intentional violations and violations involving personal information of consumers the violator actually knows are under 16. The Attorney General civil-penalty provision covers intentional violations and violations involving personal information of minor consumers. These are maximum amounts, not automatic awards. A separate private action applies only to specified security breaches and currently allows $107 to $799 per consumer per incident or actual damages, whichever is greater.

Section 1

What amounts can apply?

Civil Code Sections 1798.155 and 1798.199.90 state base maximums of $2,500 per violation and $7,500 for the enhanced tier. For administrative fines, that tier covers intentional violations and violations involving personal information of consumers the violator actually knows are under 16. For Attorney General civil penalties, it covers intentional violations and violations involving personal information of minor consumers. The Agency adjusts the amounts every odd-numbered year. The adjustment effective January 1, 2025 raised both sets of caps to $2,663 and $7,988. These remain the posted current amounts in 2026; check the Agency's current thresholds for the date of the alleged violation.

A per-violation cap does not determine how many violations occurred or the final amount. The Agency or court must apply the statute to the facts. Good-faith cooperation must be considered when setting an or civil penalty, and a business cannot be required to pay both for the same violation.

The adjusted private statutory-damages range effective January 1, 2025 is $107 to $799 per consumer per incident or actual damages, whichever is greater. That range belongs to the limited security-breach action in Section 1798.150; it is not available for every CCPA violation.

  • Administrative enforcement: up to $2,663 per violation, or $7,988 for an intentional violation or one involving personal information of a consumer the violator actually knows is under 16.
  • Attorney General civil action: up to $2,663 per violation, or $7,988 for an intentional violation or one involving personal information of a minor consumer, plus possible injunctive relief.
  • : $107 to $799 per consumer per incident or actual damages, whichever is greater.
  • Amount selection: preserve the violation date, affected consumers, conduct, intent evidence, minor-age knowledge, cooperation, and any claimed loss.
Section 2

Who can enforce the CCPA?

The California Privacy Protection Agency can investigate and bring an administrative enforcement action against a business, service provider, contractor, or other person that violates the CCPA. After the statutory hearing process, the Agency may order the person to cease and desist and pay an .

The Attorney General may bring a civil action in the name of the people of California for an injunction and civil penalties. If the Attorney General asks, the Agency must stay its administrative action or investigation so the Attorney General can proceed. The Attorney General cannot file a civil action for the same violation after the Agency has issued the specified decision or order.

The statute does not provide a blanket 30-day right to cure before government enforcement. The separate 30-day notice provision in Section 1798.150 applies to a consumer seeking private statutory damages for a qualifying security breach.

  • Agency matter: preserve complaint, investigation, probable-cause, hearing, audit, stipulation, and remediation records.
  • Attorney General matter: preserve the alleged violation record, cooperation history, requested relief, and any overlap with an Agency proceeding.
  • Do not describe a proposed settlement, staff allegation, or complaint as a final finding unless the official record says it is final.
  • Route legal-hold, response, privilege, and regulator-communication decisions to qualified counsel.
Section 3

When can a consumer bring the private security-breach action?

The in Section 1798.150 is limited to a breach involving either nonencrypted and nonredacted personal information within the categories cross-referenced from Civil Code Section 1798.81.5(d)(1)(A), or an email address combined with a password or security question and answer that would permit account access. The information must have been subject to the specified unauthorized access and exfiltration, theft, or disclosure because the business failed to implement and maintain reasonable security procedures and practices appropriate to the information.

The consumer may seek the adjusted statutory-damages range or actual damages, whichever is greater, as well as injunctive or declaratory relief and other relief the court considers proper. The court selects statutory damages after considering circumstances such as the seriousness, number and persistence of violations, duration, willfulness, and the defendant's financial position.

Before filing for individual or class-wide statutory damages, the consumer must give 30 days' written notice identifying the specific CCPA provisions alleged to have been violated. If a cure is possible and the business actually cures within that period and gives the required written statement, the statutory-damages action may be barred. Adding reasonable security after a breach does not cure that breach. No pre-suit notice is required for an action seeking only actual pecuniary damages.

This private action cannot be based on another CCPA section. Other causes of action may exist under other law, but this page does not determine them.

  • Data gate: confirm the compromised data falls within Section 1798.150's covered categories.
  • Event gate: document the access, exfiltration, theft, or disclosure and the affected consumers and incidents.
  • Security gate: preserve the controls in place before and during the event and evidence relevant to reasonable security.
  • Claim gate: distinguish statutory damages, actual pecuniary damages, injunctive relief, and the notice or cure rules that apply to each.
Section 4

What evidence should the response team preserve?

Build the record around the alleged provision and event, not a generic penalty estimate. Preserve the version of the law, regulation, notice, interface, contract, request workflow, security control, and system behavior in effect at the relevant time. Record the number of consumers and events only from supported evidence; do not multiply a cap by an assumed violation count.

For a rights-handling allegation, retain request timestamps, identity-verification steps where permitted, opt-out signals, response and extension notices, decisions, downstream instructions, and testing records. For a security incident, retain forensic evidence, affected-data analysis, control design and operation, incident chronology, notices, remediation, and any Section 1798.150 demand.

Document cooperation and corrective action without calling them a guaranteed cure or penalty reduction. The statute requires consideration of good-faith cooperation, but the authority or court determines the final effect.

  • Identify the exact provision, regulated role, date range, affected processing, and alleged conduct.
  • Separate confirmed facts, allegations, estimates, legal conclusions, and privileged advice.
  • Preserve evidence before changing the affected system or workflow; record the remediation date and validation result.
  • Recheck the Agency's monetary-threshold page for the amount effective on the violation date.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Sections 1798.150, 1798.155, 1798.199.90, and 1798.199.100 identify the facts that affect private damages, administrative fines, civil penalties, and consideration of cooperation.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.