Skip to content

CCPA / CPRA

Amended California · In force Jan 1, 2020 · next deadline Jan 1, 2027 (in 3 months)

Deadlines

DateWhat happens
Jan 1, 2020CCPA takes effect6.7 years ago
Jan 1, 2023CPRA amendments operative3.7 years ago
Jan 1, 2025CPI adjustment of thresholds and fines21 months ago
Sep 22, 2025ADMT, risk assessment and cybersecurity audit regulations approved12 months ago
Jan 1, 2026New CCPA regulations take effect9 months ago
Jan 1, 2027ADMT requirements compliance datein 3 months
Jan 1, 2027Browsers must support opt-out preference signal (AB 566)in 3 months
Dec 31, 2027Risk assessments for pre-existing processing duein 15 months
Apr 1, 2028First risk assessment submission to CPPAin 18 months
Apr 1, 2028Cybersecurity audit due: revenue over $100Min 18 months
Apr 1, 2029Cybersecurity audit due: revenue $50M-$100Min 2.5 years
Apr 1, 2030Cybersecurity audit due: revenue under $50Min 3.5 years

Summaries for reference, not legal advice. Check the official text.

What it does

Gives California residents (including employees and B2B contacts) rights to know, delete, correct, and opt out of sale/sharing of personal information and to limit use of sensitive personal information. CPPA regulations approved Sept 22, 2025 (effective Jan 1, 2026) add automated decisionmaking technology (ADMT) rights, mandatory risk assessments with submissions to the agency, and annual independent cybersecurity audits. AB 566 (2025) requires browsers to offer an opt-out preference signal from Jan 1, 2027.

Who it applies to
For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.
Penalties
Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).
Enforced by
California Privacy Protection Agency (CalPrivacy) and California Attorney General
Official name
California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11, 7000 et seq.)
Citation
Cal. Civ. Code 1798.100-1798.199.100 (AB 375, Stats. 2018 ch. 55; Proposition 24 (2020)); 11 CCR 7000 et seq.
Topics
privacy, ai, cybersecurity, children
Research notes

Monetary thresholds are CPI-adjusted every odd year; a January 2027 adjustment is expected but not yet published as of verification. CPPA rebranded as CalPrivacy. Additional 2025 bills (e.g. SB 361 data broker disclosures) and further CPPA rulemaking (reported for late 2026/2027 on notices and employee data) are not captured as deadlines. Risk assessment submission deadline is April 1, 2028 per 11 CCR 7157 (not April 21).

Related

Questions about CCPA / CPRA
What are the CCPA / CPRA compliance deadlines?
Jan 1, 2020: CCPA takes effect. Jan 1, 2023: CPRA amendments operative. Jan 1, 2025: CPI adjustment of thresholds and fines. Sep 22, 2025: ADMT, risk assessment and cybersecurity audit regulations approved. Jan 1, 2026: New CCPA regulations take effect. Jan 1, 2027: ADMT requirements compliance date. Jan 1, 2027: Browsers must support opt-out preference signal (AB 566). Dec 31, 2027: Risk assessments for pre-existing processing due. Apr 1, 2028: First risk assessment submission to CPPA. Apr 1, 2028: Cybersecurity audit due: revenue over $100M. Apr 1, 2029: Cybersecurity audit due: revenue $50M-$100M. Apr 1, 2030: Cybersecurity audit due: revenue under $50M.
When does CCPA / CPRA take effect?
CCPA / CPRA took effect on Jan 1, 2020. The next milestone is Jan 1, 2027: ADMT requirements compliance date.
Who does CCPA / CPRA apply to?
For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.
What are the penalties under CCPA / CPRA?
Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.