CCPA / CPRA
Amended California · In force Jan 1, 2020 · next deadline Jan 1, 2027 (in 3 months)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Gives California residents (including employees and B2B contacts) rights to know, delete, correct, and opt out of sale/sharing of personal information and to limit use of sensitive personal information. CPPA regulations approved Sept 22, 2025 (effective Jan 1, 2026) add automated decisionmaking technology (ADMT) rights, mandatory risk assessments with submissions to the agency, and annual independent cybersecurity audits. AB 566 (2025) requires browsers to offer an opt-out preference signal from Jan 1, 2027.
- Who it applies to
- For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.
- Penalties
- Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).
- Enforced by
- California Privacy Protection Agency (CalPrivacy) and California Attorney General
- Official name
- California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11, 7000 et seq.)
- Citation
- Cal. Civ. Code 1798.100-1798.199.100 (AB 375, Stats. 2018 ch. 55; Proposition 24 (2020)); 11 CCR 7000 et seq.
- Topics
- privacy, ai, cybersecurity, children
Research notes
Monetary thresholds are CPI-adjusted every odd year; a January 2027 adjustment is expected but not yet published as of verification. CPPA rebranded as CalPrivacy. Additional 2025 bills (e.g. SB 361 data broker disclosures) and further CPPA rulemaking (reported for late 2026/2027 on notices and employee data) are not captured as deadlines. Risk assessment submission deadline is April 1, 2028 per 11 CCR 7157 (not April 21).
Related
Questions about CCPA / CPRA
- What are the CCPA / CPRA compliance deadlines?
- Jan 1, 2020: CCPA takes effect. Jan 1, 2023: CPRA amendments operative. Jan 1, 2025: CPI adjustment of thresholds and fines. Sep 22, 2025: ADMT, risk assessment and cybersecurity audit regulations approved. Jan 1, 2026: New CCPA regulations take effect. Jan 1, 2027: ADMT requirements compliance date. Jan 1, 2027: Browsers must support opt-out preference signal (AB 566). Dec 31, 2027: Risk assessments for pre-existing processing due. Apr 1, 2028: First risk assessment submission to CPPA. Apr 1, 2028: Cybersecurity audit due: revenue over $100M. Apr 1, 2029: Cybersecurity audit due: revenue $50M-$100M. Apr 1, 2030: Cybersecurity audit due: revenue under $50M.
- When does CCPA / CPRA take effect?
- CCPA / CPRA took effect on Jan 1, 2020. The next milestone is Jan 1, 2027: ADMT requirements compliance date.
- Who does CCPA / CPRA apply to?
- For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.
- What are the penalties under CCPA / CPRA?
- Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).