ConsentPixel – Privacy · Verified

CCPA · CPRA · 2026 Requirements

CCPA Compliance: Requirements & Checklist

A clear, current guide to what CCPA compliance actually requires in 2026 — who it applies to, every obligation (including California's new January 2026 rules that most guides haven't caught up to), the penalties, a practical checklist, and how to comply without drowning in legal jargon.

By ConsentPixel TeamUpdated August 202614 min readInformation, not legal advice
$2,663 / $7,988
CCPA fine per violation in 2026 — unintentional / intentional (CPI-adjusted)
$12.75M
Largest CCPA penalty ever — General Motors, May 2026
No cure period
The 30-day "fix-it" window is gone — fines can attach immediately
What is CCPA compliance?

CCPA compliance means meeting the obligations of the California Consumer Privacy Act — as amended by the California Privacy Rights Act (CPRA) — for any business that handles the personal information of California residents. In practice it comes down to a handful of things: tell people what you collect and why, let them access, delete, correct, and opt out of the sale or sharing of their data, honor those choices technically (including the Global Privacy Control browser signal), and keep the records that prove you did.

As of January 1, 2026, California added new rules on top — automated decision-making, risk assessments, and stricter, more testable consent behavior — and removed the grace period businesses used to rely on. This is general information, not legal advice.

If you run a website that California residents can use, CCPA compliance probably applies to you — and the bar moved in 2026. California didn't just raise its fines; it changed what it fines for and removed the window businesses used to fix problems quietly. This guide walks through every requirement in plain language, flags exactly what changed this year, and points you to the deeper resources for your specific situation.

What CCPA compliance actually means

The California Consumer Privacy Act (CCPA) is the most far-reaching consumer privacy law in the United States, giving California residents rights over their personal information and imposing matching obligations on the businesses that collect it. "CCPA compliance" is simply meeting those obligations — but the phrase hides how much of it is operational rather than paperwork.

It helps to separate the CCPA compliance meaning into three layers:

  • Disclosure — telling consumers, before or at the point of collection, what personal information you collect, why, and who you share it with (your privacy policy and collection notices).
  • Rights — giving consumers working mechanisms to access, delete, correct, opt out of sale/sharing, and limit the use of sensitive data — and responding within the deadlines.
  • Proof — actually honoring those choices at a technical level (including automated browser signals) and keeping records that show you did.

The third layer is where most businesses fall short, and it's where 2026 enforcement is concentrated. A privacy policy that says the right things but sits above a website that keeps sharing data after someone opts out isn't compliant — it's a documented gap. Regulators in 2026 are testing behavior, not reading policies.

Who CCPA applies to

CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds. You do not need a physical presence in California — if California residents can access and transact with your site, you're "doing business" there. Non-profits, government agencies, and purely B2B companies with no California consumer data generally fall outside its scope.

You're covered if you meet any one of these:

ThresholdThe number (2026)What it means in practice
Gross annual revenue~$26.625M (CPI-adjusted from $25M)Worldwide revenue, not just California — a common surprise for national businesses.
Consumers / households100,000+ per yearWhose personal information you buy, sell, or share. Analytics and ad pixels count every unique visitor — easy to hit with moderate traffic.
Revenue from data50%+ of annual revenueFrom selling or sharing consumers' personal information — the ad-tech and data-broker trigger.
The 100,000-visitor threshold is easier to hit than it looks

"Sharing" under CCPA includes routing data to advertising and analytics platforms — even when no money changes hands. A site running Google Analytics or the Meta Pixel with moderate traffic can pass 100,000 California individuals a year on identifiers alone (IP addresses, device IDs, browsing behavior). You may already qualify without ever having "sold" anything.

If you don't meet any threshold, CCPA doesn't legally compel action — but building privacy-first practices now is far cheaper than retrofitting them after a complaint, and several other US state laws use lower thresholds. If you want the step-by-step version for a smaller operation, our plain-English CCPA checklist for small businesses walks through each task in order.

CCPA vs CPRA: what's the difference?

People often ask about CPRA compliance as if it were a separate law. It isn't, anymore. The California Privacy Rights Act (CPRA) was a 2020 ballot measure that amended and expanded the CCPA; it took full effect on January 1, 2023, with enforcement from July 1, 2023. Today the two operate as a single framework — when people say "CCPA," they almost always mean CCPA-as-amended-by-CPRA. So what is CPRA compliance? It's simply CCPA compliance that reflects CPRA's additions — the CPRA requirements layered on top of the original CCPA:

  • A new "sensitive personal information" category with its own right to limit use.
  • A right to correct inaccurate personal information.
  • Mandatory data-retention disclosures — you must state how long you keep each category, or the criteria you use.
  • A dedicated enforcement agency — the California Privacy Protection Agency (now branded CalPrivacy) — with independent rulemaking and audit power.
  • A distinct concept of "sharing" for cross-context behavioral advertising, so ad-targeting is covered even without a sale.

For a side-by-side of how California's regime compares to the EU's GDPR and to California's own wiretapping law, see our comparison of CIPA vs GDPR vs CCPA.

The 7 core CCPA requirements

Strip away the legalese and CCPA compliance requirements come down to seven things every covered business must do — covering everything from your CCPA privacy policy requirements to how you handle CCPA data compliance day to day. Think of these as the pillars; the operational checklist later in this guide turns them into concrete tasks.

📄

1. A compliant privacy policy

Disclose the categories of personal information you collect, the purpose for each, who you share it with, retention periods, and how to exercise rights. Update it at least every 12 months. Vague language ("we collect certain information") doesn't satisfy the law.

🔔

2. Notice at collection

At or before the point you collect data, tell consumers what you're collecting and why — not buried in a policy they have to hunt for, but at the moment of collection.

3. The consumer rights process

Provide working mechanisms to access, delete, correct, opt out of sale/sharing, and limit sensitive-data use — with at least two request methods, identity verification, and responses within 45 days (extendable to 90).

🚫

4. "Do Not Sell or Share" + opt-out

If you sell or share personal information, display a clear "Do Not Sell or Share My Personal Information" link and honor opt-outs — including the Global Privacy Control (GPC) browser signal, automatically.

🔒

5. Sensitive-data limits

Let consumers limit how you use sensitive personal information (precise geolocation, health, financial credentials, race, private communications, and more) beyond the narrow purposes CPRA permits.

🤝

6. Vendor / service-provider contracts

Put CCPA-specific terms in contracts with vendors that touch personal data, restricting them from using it for their own purposes. Without that language, sharing data with them can count as a "sale."

🗂️

7. Records & non-discrimination

Keep a log of requests and consent decisions, maintain a data inventory, and never penalize consumers — with worse prices or service — for exercising their rights.

The consumer rights, at a glance

CCPA (as amended) grants Californians the rights to know, delete, correct, opt out of sale/sharing, limit sensitive-data use, opt in for minors, data portability, and non-discrimination. Each needs a real intake channel and a tracked response. Our small-business guide breaks down all eight rights with response windows in a single table.

What's new in 2026 (the part most guides miss)

This is where a lot of CCPA content is now out of date. On September 23, 2025, CalPrivacy finalized a major package of regulations that took effect January 1, 2026 — the biggest expansion of California privacy rules since the law began. Two things make it matter for every covered business, not just enterprises:

New obligations phased in from 2026

  • Automated Decision-Making Technology (ADMT). If you use ADMT to make "significant decisions" about consumers (lending, housing, employment, essential services), you'll owe pre-use notices, access rights, and an opt-out. ADMT notices and opt-outs begin January 1, 2027.
  • Risk assessments. Processing that presents "significant risk" — including selling/sharing data and using ADMT — requires a documented risk assessment, with the first ones due by December 31, 2027.
  • Cybersecurity audits. The new CCPA audit requirements mean larger businesses must complete annual cybersecurity audits, phased in on a staggered timeline running 2027–2030 by business size.

Near-term, website-facing changes (already in effect)

Several 2026 changes are public-facing and required now — they touch your live site, not a future roadmap:

  • Show that you processed a GPC opt-out. When a business receives a Global Privacy Control signal, it must now display that it has processed the opt-out — visible confirmation, not silent handling.
  • Symmetry in choice / no dark patterns. Opting out can't be harder than opting in; reject controls must be as easy and prominent as accept controls. Asymmetric banners are an explicit enforcement target.
  • Cookie-banner consent rules. The rules tightened how consent interfaces must behave, reinforcing that a banner has to reflect real, symmetric choice.
  • Privacy-policy disclosure updates. Additional disclosures about your data practices and, where relevant, ADMT.
The 30-day cure period is gone

Earlier versions of the law gave businesses a 30-day window to fix a violation before a fine could attach. That grace period was removed. In 2026, a regulator that finds a broken banner or an ignored opt-out can act without giving you a guaranteed chance to fix it first — which makes continuous, provable compliance far more important than a one-time setup.

CCPA cookie requirements: banners, consent & GPC

A common question is CCPA cookie compliance — where CCPA differs from Europe. CCPA is an opt-out regime: unlike GDPR, it doesn't require affirmative consent before you set most cookies. But it does require clear disclosure and a working way to opt out of the sale or sharing of data — which, for a typical site running ad and analytics tools, is exactly what cookies trigger.

So the practical CCPA consent requirements and cookie banner requirements look like this:

  • Disclose the categories of data your cookies and trackers collect, and the purposes, at first visit.
  • Offer a real opt-out from sale and sharing — and make rejecting as easy as accepting (symmetry).
  • Honor GPC automatically — if a visitor's browser sends the Global Privacy Control signal, treat it as a valid opt-out without requiring them to click anything, and now show that you've processed it.
  • Actually block the sharing — the banner has to change what the site does, not just display text.
Opt-in (GDPR) vs opt-out (CCPA) — two different cookie models GDPR — opt-IN Non-essential cookies BLOCKED until the visitor clicks "Accept." ✓ No consent = no tracking Default is OFF CCPA — opt-OUT Collection allowed WITH notice, but opt-out must actually work. ✓ Honor GPC automatically ✓ Reject as easy as accept Default is ON, opt-out available
CCPA doesn't require opt-in like GDPR — but it does require a functioning opt-out, GPC honoring, and symmetric choice. A banner that only displays text isn't enough.
Running one banner for both GDPR and CCPA?

Many businesses serve EU and California visitors from one site. A good consent tool applies the right model by region — opt-in for the EU, opt-out for California — from a single deployment, rather than forcing you to pick one. The key requirement both share: the banner must technically block or stop the trackers, not just show a notice.

See your actual exposure first

Which trackers fire before consent on your site?

Every CCPA cookie obligation starts with knowing what's actually running. Scan your site free to see every third-party tracker that loads — and whether any keep firing after an opt-out. It's the same behavior California's technical investigations look for, in about 10 seconds.

No account needed for the scan · no credit card · information, not legal advice

Penalties & enforcement in 2026

CCPA penalties rose in 2026, and the enforcement pattern shifted. The headline numbers, inflation-adjusted for 2026:

  • $2,663 per unintentional violation and $7,988 per intentional violation (or one involving a minor) — the CPI-adjusted figures, up from the $2,500 / $7,500 statutory base.
  • A limited private right of action for data breaches: consumers can recover $107–$799 per consumer per incident, or actual damages if higher.
  • Violations are counted per consumer, so a single misconfiguration across a large audience multiplies fast.

The enforcement record tells the real story. Two agencies now enforce — the California Attorney General and CalPrivacy — and 2026 brought the largest action yet:

Action (2025–2026)AmountWhat it was for
General Motors / OnStar (May 2026)$12.75MThe largest CCPA penalty ever — and the first data-minimization & purpose-limitation action. GM allegedly sold drivers' geolocation and driving-behavior data to data brokers without adequate notice or consent.
Disney / ABC (Feb 2026)$2.75MOpt-outs that didn't propagate across linked services; GPC signals not fully honored.
Tractor Supply (2025)$1.35MTracking-technology and opt-out failures.
Honda (Mar 2025) · Ford (Mar 2026)$632,500 · $375,703Connected-vehicle opt-out violations — hard-to-use opt-outs, signals not honored.
Todd Snyder (2025)$345KA consent banner that malfunctioned for 40 days unnoticed; over-collection during opt-out.

The pattern is unmistakable: California isn't fining businesses for lacking a privacy policy — it's fining technical failures in how consent and opt-outs actually behave, and now data-minimization too. The GM case matters for everyone because it establishes that collecting more than you need, or repurposing data beyond what you disclosed, is itself an enforcement priority. And in the Disney case, California rejected the "our vendor's tool failed" defense outright: third-party tools don't transfer your legal accountability.

Why "installed" isn't "compliant"

Todd Snyder's banner was installed — it just quietly broke for 40 days, and nobody noticed. With no cure period, that's now an expensive gap. The lesson driving 2026 compliance: your consent setup has to be monitored and provable, not set-and-forget. If you're choosing tools, our CCPA compliance software buyer guide maps each capability to the specific failure it prevents.

CCPA compliance checklist

Here's a condensed CCPA compliance checklist organized by the seven requirement pillars — a fast way to see where you stand. For the full, printable, task-by-task version built for smaller teams, use our small-business CCPA checklist; this one is the pillar-level overview.

Applicability & disclosure
Confirm whether a threshold applies ~$26.625M revenue, 100k+ consumers/households, or 50%+ revenue from data.
Publish a compliant privacy policy Categories, purposes, third parties, retention periods; refreshed every 12 months.
Give notice at collection Tell people what you collect and why, at the moment of collection.
Rights & opt-out
Stand up a consumer-rights process Two request methods, verification, 45-day response, a request log.
Add a working "Do Not Sell or Share" link It must actually stop sharing — not just log a request.
Honor GPC automatically — and show it Treat the signal as a valid opt-out; display that you processed it (2026 rule).
Offer a sensitive-data limit Where you use sensitive PI beyond permitted purposes.
Technical & records
Deploy a consent tool that blocks, not just notifies Trackers must stop on opt-out; reject as easy as accept (no dark patterns).
Audit every tracker on your site Find the pixels and scripts marketing added over the years — you can't control what you can't see.
Fix service-provider contracts CCPA terms restricting vendors from using your data for their own purposes.
Keep consent & request logs Timestamped proof — the evidence that matters now the cure period is gone.
2026 & forward
Map any automated decision-making (ADMT) Prepare pre-use notices and opt-outs ahead of the Jan 1, 2027 date.
Plan risk assessments & audits Risk assessments (by end 2027) and staggered cybersecurity audits (2027–2030) if in scope.
Practice data minimization Collect only what you need; don't repurpose data beyond what you disclosed — the GM lesson.

The gap most CCPA guides miss: CIPA

Here's what almost no competitor's CCPA guide tells you. If you have California visitors, CCPA is not your only California exposure. The California Invasion of Privacy Act (CIPA) — a separate, older wiretapping law — is currently the more aggressively litigated risk, and it works completely differently from CCPA.

Where CCPA is enforced by regulators through fines, CIPA carries a private right of action with statutory damages — meaning individual plaintiffs and their firms can sue directly. Its theory targets sites running session-replay tools (Hotjar, Microsoft Clarity, FullStory) and tracking pixels on California visitors before consent, and it has driven thousands of demand letters and class actions.

You can be CCPA-compliant and still get a CIPA letter

Because CCPA is an opt-out regime, a tool tuned only for CCPA may leave session-replay and pixels firing on page load — which can satisfy CCPA while leaving the CIPA door wide open. If you serve California traffic, "does it block trackers before consent?" belongs on your checklist right next to the CCPA questions. We cover why in CCPA-compliant but still got a CIPA letter.

This is the core of the prevention-first approach: closing the CCPA gap with a working opt-out is necessary, but stopping there leaves the more-litigated California risk untouched. The businesses in the best position handle both from one layer — and when you're evaluating CCPA compliance solutions, that dual coverage is the capability to look for: block the trackers plaintiff firms scan for before consent, and honor CCPA opt-out and GPC on top. (Our software buyer guide compares the tool categories in depth.)

How to comply with CCPA, practically

Pulling it together, here's the practical order of operations — the short answer to how to comply with CCPA:

  1. See what's actually firing. Scan your site to inventory every tracker, pixel, and cookie — including the ones nobody documented. You can't disclose, control, or opt out of what you can't see.
  2. Deploy a consent layer that blocks, not just notifies. It must stop non-essential trackers on opt-out, honor GPC automatically (and show it), and keep reject as easy as accept.
  3. Fix the disclosures. Update your privacy policy (categories, purposes, third parties, retention) and add notice at collection plus a working "Do Not Sell or Share" link.
  4. Stand up the rights process. Two intake methods, verification, a 45-day clock, and a request log.
  5. Prove it, continuously. Log consent and opt-out decisions, monitor that the banner still works, and keep the records — because there's no cure period to fall back on.
  6. Close the CIPA gap. Make sure session-replay and pixels don't fire before consent for California visitors.

That's the posture ConsentPixel — Privacy · Verified is built to deliver from a single pixel: it blocks third-party trackers at the browser level until the right consent/opt-out state, honors GPC, logs every decision as evidence, monitors itself, and closes the CIPA gap at the same time. It's a prevention-first consent layer — not legal advice, and not a substitute for counsel on your specific obligations.

Key takeaways

  • CCPA compliance = disclose, honor rights, and prove it — for any business meeting one of three thresholds and handling Californians' data.
  • CPRA isn't a separate law — it's the amendment that expanded CCPA (sensitive data, correction, retention, CalPrivacy). "CCPA" today means CCPA-as-amended.
  • 2026 changed the bar: new ADMT, risk-assessment, and audit rules phase in through 2030; GPC-processed display and no-dark-pattern rules apply now; the 30-day cure period is gone.
  • Enforcement targets behavior, not paperwork — broken banners, opt-outs that don't propagate, ignored GPC, and now data minimization (GM, $12.75M).
  • CCPA cookies are opt-out, not opt-in — but the opt-out must actually work and honor GPC, not just display a notice.
  • Don't stop at CCPA — CIPA is the more-litigated California risk, and a CCPA-only setup can leave it wide open.

The bottom line

CCPA compliance in 2026 is less about having the right documents and more about your website actually behaving the way your privacy notices promise — every visit, provably, with no grace period to fall back on. The requirements are stable and knowable: know your thresholds, disclose clearly, give working rights and opt-outs, honor GPC, keep the proof, and don't over-collect.

The reassuring part is that most of it flows from one technical foundation — knowing and controlling what fires on your site. Get that right and the rest of the checklist has something solid to build on. And if you handle California traffic, closing the CIPA gap in the same move turns a compliance chore into genuine risk reduction.

The cheapest first step is simply to look at what's running on your pages today.

See where your site stands on CCPA — in ~10 seconds

Scan your site free to see every third-party tracker that fires before consent — and whether any keep running after opt-out. Then close the CCPA and CIPA gaps with a single prevention-first pixel that blocks trackers, honors GPC, and logs the proof.

Scan your site free →
No account needed · then a 14-day free trial, no credit card, from $8.99/mo · or read the full CCPA reference · information, not legal advice
CP
The ConsentPixel Team

ConsentPixel — Privacy · Verified helps website owners and agencies reduce exposure to CCPA, CPRA, CIPA, GDPR, and US state privacy laws from a single pixel — blocking trackers until the right consent state, honoring opt-out and GPC signals, and logging each decision as evidence. We translate evolving requirements into practical, verifiable steps. This article is educational and not legal advice; consult a qualified privacy professional about your specific obligations. ConsentPixel is not a law firm.

Frequently asked questions

What is CCPA compliance?

CCPA compliance means meeting the obligations of the California Consumer Privacy Act (as amended by the CPRA) for any business that handles the personal information of California residents. In practice: disclose what you collect and why; give consumers working rights to access, delete, correct, and opt out of the sale or sharing of their data; honor those choices technically, including the Global Privacy Control browser signal; and keep records proving you did. As of January 1, 2026, California also added rules on automated decision-making, risk assessments, and stricter, testable consent behavior. This is general information, not legal advice.

Who has to comply with CCPA?

For-profit businesses doing business in California that meet at least one of three thresholds: gross annual revenue over roughly $26.625 million (the 2026 CPI-adjusted figure); buying, selling, or sharing the personal information of 100,000 or more consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing personal information. You don't need a physical presence in California — if California residents can use your site, you likely qualify as doing business there. The 100,000 threshold is easy to reach because analytics and ad pixels count every unique visitor.

What is the difference between CCPA and CPRA compliance?

They're the same framework. The CPRA (California Privacy Rights Act) was a 2020 measure that amended and expanded the CCPA; it took full effect on January 1, 2023, with enforcement from July 1, 2023. CPRA added a "sensitive personal information" category with its own limit-use right, a right to correct data, mandatory data-retention disclosures, a dedicated enforcement agency (now CalPrivacy), and a distinct concept of "sharing" for behavioral advertising. So "CPRA compliance" is just CCPA compliance that reflects those additions — today the two operate as a single law.

Does CCPA require a cookie consent banner?

CCPA is an opt-out regime, so unlike GDPR it doesn't require affirmative opt-in consent before you set most cookies. But it does require clear disclosure of what your cookies and trackers collect, a working opt-out from the sale or sharing of data, automatic honoring of the Global Privacy Control (GPC) signal, and — as of 2026 — a display that you've processed a GPC opt-out, with reject made as easy as accept. For a typical site running ad and analytics tools, that means you effectively need a consent banner that technically blocks or stops sharing on opt-out, not just one that displays a notice.

What are the CCPA penalties in 2026?

The CPI-adjusted administrative fines for 2026 are up to $2,663 per unintentional violation and $7,988 per intentional violation or one involving a minor (up from the $2,500 and $7,500 statutory base). Consumers also have a limited private right of action for data breaches, with statutory damages of $107 to $799 per consumer per incident, or actual damages if higher. Violations are counted per consumer, so a single misconfiguration across a large audience adds up quickly. The 30-day cure period that once let businesses fix issues before a fine was removed, so fines can attach without a guaranteed window to remediate first.

What changed for CCPA compliance in 2026?

A major regulation package finalized in September 2025 took effect January 1, 2026. Phased-in obligations include automated decision-making technology (ADMT) notices and opt-outs (from January 1, 2027), documented risk assessments (first ones due by end of 2027), and staggered cybersecurity audits (2027–2030). Several changes apply now and are website-facing: businesses must display that they've processed a GPC opt-out, opt-out must be as easy as opt-in (no dark patterns), cookie-consent interfaces must reflect symmetric choice, and privacy-policy disclosures expanded. The removal of the 30-day cure period also means continuous, provable compliance matters more than a one-time setup.

How do I comply with CCPA if I already have a privacy policy?

A privacy policy is necessary but not sufficient — 2026 enforcement targets behavior, not documents. Start by scanning your site to inventory every tracker and pixel, then deploy a consent layer that actually blocks or stops non-essential trackers on opt-out, honors GPC automatically, and keeps reject as easy as accept. Confirm your "Do Not Sell or Share" link genuinely stops sharing, stand up a consumer-rights request process with a 45-day clock and a log, fix service-provider contracts, and keep timestamped consent records. If you serve California visitors, also make sure session-replay and pixels don't fire before consent, to avoid CIPA exposure. This is general information, not legal advice.

Is CCPA compliance the same as being protected from CIPA?

No. CCPA and CIPA are separate California laws. CCPA is enforced by regulators (the Attorney General and CalPrivacy) through fines and is an opt-out regime. CIPA is a wiretapping law with a private right of action, letting plaintiffs sue directly, and it targets trackers and session-replay tools that fire before consent. A setup tuned only for CCPA's opt-out model can leave scripts firing on page load — satisfying CCPA while leaving CIPA exposure open. If you have California traffic, you need to block trackers before consent as well as honor CCPA opt-out. This is general information, not legal advice.

Not legal advice. This article is general educational information about the California Consumer Privacy Act (as amended by the CPRA) and does not constitute legal advice or create an attorney–client relationship. Requirements, penalty amounts, and effective dates are stated as of August 2026 based on the sources referenced (including CalPrivacy/CPPA regulations effective January 1, 2026 and 2026 enforcement actions) and may change; verify current requirements and how they apply to your business with qualified counsel. Penalty figures reflect the CPI-adjusted 2026 amounts. ConsentPixel — Privacy · Verified is not a law firm.
Scroll to Top