ConsentPixel – Privacy · Verified

CCPA · CPRA · 2026 Rights Guide

California Consumer Privacy Rights, Explained

If you live in California, you have the strongest data-privacy rights in the United States — the right to know what companies collect, delete it, correct it, and stop them selling or sharing it. This is a plain-English guide to every California consumer right under the CCPA and CPRA in 2026, how to actually use each one, and — if you run a website — exactly what you have to do to honor them.

By ConsentPixel TeamUpdated August 202613 min readInformation, not legal advice
9 rights
Distinct privacy rights California residents hold under the CCPA/CPRA in 2026
$26.625M
Revenue threshold that can make a business subject to these rights — the lowest in the US
Aug 1, 2026
The date one deletion request (DROP) can reach every registered California data broker
The short version

California consumer rights come from the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). If you're a California resident, they give you the right to know what personal information a business collects, access it, delete it, correct it, opt out of its sale or sharing, limit the use of your sensitive information, and be free from discrimination for exercising any of them — plus new 2026 protections around automated decisions and data brokers.

For businesses, each right is a matching obligation with real deadlines and, since the cure period was removed, real penalties for getting it wrong. This is general information, not legal advice.

Californians got the strongest privacy rights in the country, and in 2026 they got stronger still — new rules on automated decisions took effect, and a single deletion request can now reach every registered data broker in the state. Whether you're a resident who wants to use these rights or a business that has to honor them, this guide covers all of them: what each one is, the statute behind it, and what it means in practice on both sides.

Where California consumer rights come from

California's privacy rights live in one law with two names. The California Consumer Privacy Act (CCPA), passed in 2018, was significantly expanded by the California Privacy Rights Act (CPRA) — a 2020 ballot measure (Proposition 24) that took full effect on January 1, 2023. People sometimes talk about "CPRA rights" as if they're separate, but the CPRA amended the CCPA rather than replacing it. Today they operate as a single framework, codified at California Civil Code §§ 1798.100–1798.199.100.

What makes California's consumer laws exceptional isn't just that they exist — most comparable US states now have privacy laws — but their depth. California grants more rights than any other state, sets the lowest business-size threshold in the country, is the only state with a dedicated privacy enforcement agency, and is the only one that lets consumers sue directly over certain data breaches. When people call California's regime the strongest in the US, this is why.

CCPA vs CPRA, in one line

The CCPA is the original 2018 law; the CPRA is the 2020 amendment that added the rights to correct and to limit sensitive data, created the enforcement agency (now branded CalPrivacy), and expanded opt-out to cover "sharing" for targeted advertising. "CCPA" today means CCPA-as-amended-by-CPRA.

Who has these rights — and who must honor them

The rights belong to California residents (the law calls them "consumers"). You don't have to be a customer of a business to have them — if a company has your personal information and does business in California, the rights apply to you.

The obligations fall on for-profit businesses that do business in California and meet at least one of three thresholds. Critically, a business does not need to be located in California — if it handles Californians' data and crosses a threshold, it's covered no matter where it's headquartered.

A business is covered if it…Threshold (2026)
Has high gross revenueOver ~$26.625 million/year (CPI-adjusted; the lowest bar in the US)
Handles data at scaleBuys, sells, or shares the personal information of 100,000+ consumers or households/year
Makes money from dataDerives 50%+ of annual revenue from selling or sharing personal information

The 100,000 threshold catches more websites than people expect: analytics and advertising trackers "share" data on every unique visitor, so a moderately trafficked site can cross it without ever "selling" anything. If you want the full compliance-requirements view for businesses, our CCPA compliance requirements and checklist covers the obligations end to end; this guide focuses on the rights themselves.

The 9 California consumer rights, one by one

Here's every right, with the statute behind it, what it means for you as a resident, and what a business must do to honor it. Together these are the heart of California's consumer rights regime.

1
Right to know / access§§ 1798.100, .110, .115
What it means for you

You can ask a business what categories and specific pieces of personal information it has collected about you, where it got them, why, and who it disclosed them to — going back to January 2022 under the 2026 rules.

What a business must do

Maintain a data inventory, verify the requester's identity, and provide the information (usually free) within 45 days, extendable to 90.

2
Right to delete§ 1798.105
What it means for you

You can ask a business to delete the personal information it collected from you, and to tell its service providers to do the same — subject to exceptions (e.g. data it's legally required to keep).

What a business must do

Verify the request, delete the data, direct downstream vendors to delete it, and confirm what it did — within the same 45-day window.

3
Right to correct§ 1798.106
What it means for you

You can ask a business to fix inaccurate personal information it holds about you — a right the CPRA added in 2023.

What a business must do

Use commercially reasonable efforts to correct the data once the request is verified, and instruct service providers accordingly.

4
Right to opt out of sale or sharing§ 1798.120
What it means for you

You can tell a business to stop selling or sharing your personal information — "sharing" covers cross-context behavioral advertising, so this reaches ad targeting even when no money changes hands.

What a business must do

Post a clear "Do Not Sell or Share My Personal Information" link, honor opt-outs (including the automatic GPC signal), and stop the sale/sharing — a working control, not just a notice.

5
Right to limit use of sensitive PI§ 1798.121
What it means for you

You can limit how a business uses your sensitive personal information — precise geolocation, health, financial credentials, race, religion, private communications, and (since 2024's SB 1223) neural data — to only the purposes the law permits.

What a business must do

Offer a "Limit the Use of My Sensitive Personal Information" control where it uses sensitive PI beyond permitted purposes, and respect it.

6
Right to non-discrimination§ 1798.125
What it means for you

A business can't punish you for using your rights — no worse prices, no degraded service, no denial of goods — just because you opted out or asked to delete.

What a business must do

Treat rights-exercisers the same as everyone else. (Certain genuine, disclosed loyalty-program value exchanges are narrowly allowed.)

7
Right to data portability§ 1798.100
What it means for you

When you make an access request, you can get your data in a portable, readily usable format you can move to another service where technically feasible.

What a business must do

Provide the data in a structured, commonly used, machine-readable format on request.

8
Rights for minors (opt-in to sell/share)§ 1798.120(c)
What it means for you

Businesses can't sell or share the personal information of consumers under 16 without opt-in consent — from the teen (13–15) or a parent (under 13).

What a business must do

Obtain affirmative opt-in before selling/sharing a known minor's data, and default to not selling/sharing otherwise.

9
Right to opt out of automated decisionsADMT regs (2026)
What it means for you

New in 2026: where a business uses automated decision-making technology (ADMT) for significant decisions — lending, housing, employment, essential services — you'll be able to get notice, access, and an opt-out.

What a business must do

Provide pre-use notices and opt-outs for qualifying ADMT, with compliance deadlines phasing in from January 1, 2027.

Plus a right to sue — but only for breaches

Beyond the nine above, Californians have a limited private right of action: if a business's failure to use reasonable security leads to a data breach of certain unencrypted personal information, you can sue for statutory damages of $107–$799 per consumer per incident (or actual damages, if higher). For most other CCPA violations, enforcement runs through the regulators, not private lawsuits.

The opt-out that works automatically: GPC

The single most practical of these rights is the opt-out of sale and sharing — and in California it can happen without you clicking anything. The Global Privacy Control (GPC) is a browser signal that broadcasts your opt-out automatically to every site you visit. California law treats a GPC signal as a valid opt-out request that businesses must honor, and as of 2026 businesses also have to display that they've processed it.

How the Global Privacy Control (GPC) opt-out works Your browser GPC toggle: ON (set once) signal Site A → opt-out ✓ Site B → opt-out ✓ Site C → opt-out ✓ No manual clicks Every site must honor it (2026)
GPC turns one browser setting into an automatic opt-out that every business must respect — no per-site banner clicking required. For businesses, honoring it isn't optional.

For a business, this is a hard requirement, not a nice-to-have: if your site can't detect and act on a GPC signal, you're failing to honor a valid opt-out on every visit from a GPC user — exactly the kind of gap California has been fining companies for.

For businesses honoring these rights

Is your site actually honoring opt-outs?

The opt-out rights only mean something if your site technically stops the trackers. Scan your site free to see which trackers fire before consent — and whether any keep firing after a visitor opts out or sends a GPC signal. About 10 seconds, no account.

No account needed for the scan · no credit card · information, not legal advice

What's new for California consumer rights in 2026

2026 is the biggest expansion of these rights since the CPRA. Three changes stand out:

  • The Delete Act and DROP. California's Delete Request and Opt-out Platform (DROP) launched January 1, 2026, and from August 1, 2026 a California resident can submit a single deletion request that reaches every registered data broker in the state at once — a genuinely new, powerful right that no other state offers.
  • Automated decision-making rights. The new ADMT rules give residents notice and opt-out rights over significant automated decisions, phasing in from 2027 — the ninth right in the list above.
  • Rights reaching into AI. A 2024 amendment (AB 1008) confirmed that personal information embedded in AI systems is covered by the CCPA, and SB 1223 added neural data to the sensitive-information category — extending these rights to technologies that didn't exist when the law was written.
The safety net under all of this: no more cure period

California removed the 30-day "cure period" that once let businesses fix a violation before a penalty could attach. Combined with fines up to $7,988 per intentional violation (2026, CPI-adjusted) and enforcement by both the Attorney General and CalPrivacy, that means honoring these rights has to be continuous and provable — not a one-time setup. California regulators secured over $19 million in privacy settlements between 2022 and 2026, including a record $12.75M from General Motors.

How to exercise your California consumer rights

If you're a resident who wants to use these rights, the process is more approachable than it sounds:

  1. Find the business's privacy tools. Look for a "Privacy" or "Do Not Sell or Share My Personal Information" link (usually in the footer) and a privacy policy describing how to submit requests — businesses must offer at least two methods.
  2. Turn on Global Privacy Control. Enable GPC in a supported browser or extension and your opt-out is sent automatically to every site — the least-effort way to exercise the opt-out right everywhere at once.
  3. Submit a specific request. To know, delete, or correct, use the business's request method; you'll typically verify your identity, and they must respond within 45 days (extendable to 90).
  4. Use DROP for data brokers. From August 1, 2026, a single DROP submission handles deletion across every registered California data broker at once.
  5. Escalate if ignored. If a business won't comply, you can file a complaint with the California Attorney General or CalPrivacy.

You can also authorize an agent to exercise these rights on your behalf, and many companies now extend CCPA-style rights to all US customers because maintaining separate policies by state is harder than applying one.

What businesses must do to honor them

If you run a website that reaches Californians, each right above is an obligation. In practical terms, honoring California's consumer laws comes down to a handful of capabilities:

  • Disclose clearly — a privacy policy stating what you collect, why, who you share it with, and how to exercise rights, refreshed at least annually.
  • Offer working request channels — at least two methods to know/delete/correct, identity verification, and a tracked 45-day response.
  • Honor opt-outs technically — a "Do Not Sell or Share" link and automatic GPC honoring that actually stops the trackers, with reject as easy as accept (no dark patterns).
  • Keep the proof — timestamped records of consent and opt-out decisions, since there's no cure period to fall back on.

That last point is where a consent banner alone falls short. A banner that displays the right notice but sits above a site still firing trackers isn't honoring the opt-out right — it's documenting a gap. A "legal banner" only protects you if it technically blocks what it promises to block. For the full operational picture, see our CCPA requirements and checklist, and for choosing tooling, our CCPA compliance software guide. (These are distinct from website accessibility obligations — if you're researching "what is ADA compliance for websites," that's a separate accessibility law, not a privacy right.)

A note on "regulatory compliance services"

Many businesses reach for outside regulatory compliance services or consultants for CCPA. That can help with policy and process — but the technical half (what actually fires on your site, and whether opt-outs stop it) is measurable in seconds and is where the enforcement risk concentrates. Confirm the behavior, not just the paperwork. And if your reach extends to the EU, remember these California rights are distinct from EU rules like the GDPR and the EU AI Act — different frameworks, different obligations.

The California privacy right that isn't in the CCPA

Here's what most guides to California consumer rights miss entirely. The CCPA is the rights law — but it's not the law generating the most lawsuits against websites right now. That's the California Invasion of Privacy Act (CIPA), a separate wiretapping statute — and for businesses, it changes the risk calculus completely.

The difference matters. CCPA violations are mostly enforced by regulators; CIPA carries a private right of action with statutory damages of $5,000 per violation under Penal Code §637.2, so any affected individual can sue. Its theory targets sites running session-replay tools (Hotjar, Microsoft Clarity, FullStory) and tracking pixels on California visitors before consent — and it's driven thousands of demand letters and class actions, tracked in our CIPA lawsuit tracker.

You can honor every CCPA right and still get a CIPA letter

Because CCPA is an opt-out regime, a site can post its "Do Not Sell" link, respect deletion requests, and still have session-replay and pixels firing on page load — leaving the exact fact pattern CIPA plaintiffs target wide open. For a Californian, CIPA is effectively a privacy protection too; for a business, it's the risk that a CCPA-only setup doesn't cover.

This is the core of the prevention-first approach: honoring the CCPA's opt-out rights is necessary, but if trackers still fire before consent, the more-litigated California risk remains. The strongest position handles both — block the trackers before consent and honor CCPA opt-out and GPC. That's what ConsentPixel — Privacy · Verified is built to do from a single pixel: block third-party trackers until the right consent state, honor GPC, log each decision as evidence, and close the CIPA gap alongside CCPA and GDPR. It's not legal advice, and not a substitute for counsel on your obligations.

Key takeaways

  • California residents hold nine privacy rights under the CCPA/CPRA: know, delete, correct, opt out of sale/sharing, limit sensitive data, non-discrimination, portability, minor opt-in, and (new) automated-decision opt-out.
  • The rights apply regardless of where a business is based — if it handles Californians' data and crosses one of three thresholds (as low as ~$26.625M revenue), it must comply.
  • GPC makes the opt-out automatic — one browser signal every business must honor and, in 2026, must show it processed.
  • 2026 expanded the rights — the DROP data-broker deletion platform (single request from Aug 1, 2026), automated-decision opt-outs, and coverage reaching AI systems and neural data.
  • No cure period means honoring these rights must be continuous and provable, with fines up to $7,988 per intentional violation.
  • The CCPA isn't the only California privacy law — CIPA lets individuals sue directly, and a CCPA-only setup can leave that risk open.

The bottom line

California gave its residents a real, usable set of privacy rights — and in 2026 made them broader and easier to exercise, from a single browser signal that opts you out everywhere to a single request that clears you from every data broker. If you're a Californian, they're worth knowing and using.

If you're a business, every one of those rights is an obligation with a deadline and, now, no grace period. The reassuring part is that most of it flows from one technical foundation: knowing what fires on your site and making sure opt-outs actually stop it. Get that right and the rest of honoring these rights has something solid to stand on — and closing the CIPA gap in the same move turns a compliance chore into genuine risk reduction.

The fastest way to see where you stand is to look at what's running on your own pages today.

See whether your site honors these rights — in ~10 seconds

Scan your site free to see every third-party tracker that fires before consent — and whether any keep running after a visitor opts out or sends GPC. Then close the CCPA and CIPA gaps with a single prevention-first pixel that blocks trackers, honors GPC, and logs the proof.

Scan your site free →
No account for the scan · then a 14-day free trial, no credit card, from $8.99/mo · or read the full CCPA reference · information, not legal advice
CP
The ConsentPixel Team

ConsentPixel — Privacy · Verified helps website owners and agencies honor CCPA, CPRA, CIPA, GDPR, and US state privacy rights from a single pixel — blocking trackers until the right consent state, honoring opt-out and GPC signals, and logging each decision as evidence. This article is educational and not legal advice; it describes California consumer rights as of August 2026 based on the sources cited, and the law changes — verify current rights and obligations with qualified counsel. ConsentPixel is not a law firm.

Frequently asked questions

What are my California consumer privacy rights?

As a California resident, the CCPA (as amended by the CPRA) gives you the right to know what personal information a business collects about you and to access it, delete it, correct inaccuracies, opt out of its sale or sharing, limit the use of your sensitive personal information, and be free from discrimination for exercising these rights. You also have data portability, opt-in protections for minors under 16, and — new in 2026 — the right to opt out of certain automated decisions. Separately, you have a limited right to sue businesses over data breaches caused by unreasonable security. This is general information, not legal advice.

Who has to follow California's consumer privacy laws?

For-profit businesses that do business in California and meet at least one of three thresholds: annual gross revenue over roughly $26.625 million (CPI-adjusted, the lowest bar in the US); buying, selling, or sharing the personal information of 100,000 or more consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing personal information. A business does not have to be located in California — if it handles California residents' data and crosses a threshold, it must comply regardless of where it is headquartered. The 100,000 threshold is easy to reach because analytics and advertising trackers share data on every unique visitor.

How do I exercise my CCPA rights?

Look for a business's "Privacy" or "Do Not Sell or Share My Personal Information" link, usually in the website footer, and its privacy policy, which must describe at least two ways to submit requests. To opt out of sale and sharing everywhere at once, turn on Global Privacy Control (GPC) in a supported browser — California treats that signal as a valid opt-out businesses must honor. To know, delete, or correct your data, submit a request through the business's method; you'll typically verify your identity, and the business must respond within 45 days (extendable to 90). From August 1, 2026, you can also use California's DROP platform to send one deletion request to every registered data broker. If a business ignores you, file a complaint with the California Attorney General or CalPrivacy.

What is the difference between the CCPA and the CPRA?

They're the same law. The CCPA is the original 2018 California Consumer Privacy Act; the CPRA (California Privacy Rights Act) was a 2020 ballot measure that amended and expanded it, taking full effect on January 1, 2023. The CPRA added the rights to correct data and to limit the use of sensitive personal information, created the state's dedicated enforcement agency (now branded CalPrivacy), expanded opt-out to cover "sharing" for cross-context behavioral advertising, and introduced risk-assessment and cybersecurity-audit requirements. So when people say "CCPA," they generally mean the CCPA as amended by the CPRA — a single framework, not two separate laws.

Do California privacy rights apply to businesses outside California?

Yes. The rights belong to California residents, and the obligations apply to any for-profit business that does business in California and meets one of the thresholds — regardless of where the business is headquartered. A company in another state or country can be subject to the CCPA if it handles California residents' personal information and crosses a threshold. Because maintaining separate policies by state is cumbersome, many businesses extend CCPA-style rights to all US customers. Non-California residents may have similar rights under their own state laws, such as Virginia's VCDPA, Colorado's CPA, or Connecticut's CTDPA.

What changed for California consumer rights in 2026?

Several things. California's Delete Request and Opt-out Platform (DROP) launched January 1, 2026, and from August 1, 2026 a single deletion request can reach every registered California data broker at once. New automated decision-making (ADMT) rules give residents notice and opt-out rights over significant automated decisions, phasing in from 2027. A 2024 amendment (AB 1008) confirmed the CCPA covers personal information embedded in AI systems, and SB 1223 added neural data to the sensitive-information category. The 30-day cure period was also removed, so businesses can be penalized without a guaranteed window to fix a violation first.

Is following the CCPA enough to avoid a California privacy lawsuit?

Not necessarily. The CCPA is enforced mainly by regulators, but a separate California law — the California Invasion of Privacy Act (CIPA) — gives individuals a private right of action with statutory damages of $5,000 per violation under Penal Code §637.2. CIPA targets websites that run session-replay tools and tracking pixels on California visitors before consent. Because the CCPA is an opt-out regime, a site can honor CCPA rights — posting a "Do Not Sell" link and respecting deletion requests — while still firing trackers on page load, leaving CIPA exposure open. To reduce both risks, a business needs to block non-essential trackers before consent as well as honor CCPA opt-outs. This is general information, not legal advice.

Not legal advice. This article is general educational information about California consumer privacy rights under the CCPA, as amended by the CPRA, and does not constitute legal advice or create an attorney–client relationship. Rights, thresholds, penalty amounts, and effective dates are stated as of August 2026 based on the sources cited (including the California Attorney General's office, the CalPrivacy/CPPA statute effective January 1, 2026, and related reporting) and may change; verify current rights and how they apply with qualified counsel. Penalty figures reflect CPI-adjusted 2026 amounts, and the $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. ConsentPixel — Privacy · Verified is not a law firm.
Scroll to Top