Updated on October 1st, 2026
Here's the short answer most guides bury: the CCPA and CPRA do not require opt-in consent before you set ordinary website cookies. You only need to tell visitors you're collecting their data and give them a way to opt out of its sale or sharing. That's a fundamentally different model from the GDPR's opt-in requirement, and conflating the two is the most common CCPA compliance mistake businesses make.
This guide covers what notice-at-collection actually requires, which businesses the law applies to under the current 2026 thresholds, the one real exception for minors' data, and how CCPA/CPRA cookie rules compare to the GDPR.
Does CCPA/CPRA require opt-in consent for cookies?
No. For ordinary, non-sensitive cookies, such as analytics or advertising cookies that don't involve selling or sharing personal information in a way that triggers the law's sale/share definition, you can load them without asking permission first. You still have to disclose that you use them.
The one thing you cannot skip is the notice at collection. It has to appear at or before the point where you start collecting data, typically via a cookie banner, and it has to tell visitors what you collect, why, and how to opt out if you sell or share their information.
If your business sells or shares personal information at all, your cookie banner also needs a clear "Do Not Sell or Share My Personal Information" link, and you must honor Global Privacy Control (GPC) signals as a valid opt-out request. California is currently the only US state that explicitly requires businesses to treat a browser-level GPC signal as an enforceable opt-out.
Who does the CCPA/CPRA apply to in 2026?
The CCPA applies to for-profit businesses that collect California residents' personal information and meet at least one of these thresholds, confirmed against the California Attorney General's current CCPA guidance and the California Privacy Protection Agency's (CPPA) FAQ:
| Threshold | Current figure (2026) | Note |
|---|---|---|
| Annual gross revenue | Over $26,625,000 | Adjusted for inflation from the original $25 million; the CPPA revises this figure every odd-numbered year |
| Consumer/household data volume | Buys, sells, or shares personal information of 100,000 or more California residents or households | The CPRA raised this from the original CCPA's 50,000 threshold and dropped "devices" from the count |
| Revenue from data sales | Derives 50% or more of annual revenue from selling or sharing personal information | Unchanged by the CPRA |
A large share of the CCPA content published online, including guides from compliance vendors that should know better, still cites the original $25 million and 50,000 figures as current. Both are stale. If your business doesn't meet any of the three thresholds, CCPA and CPRA don't apply to you, and you don't need a notice-at-collection banner for California visitors at all.
What the notice at collection must include
The CCPA's notice-at-collection regulations require the following elements, delivered before or at the moment you start collecting data:
- A list of the categories of personal information you collect
- The purposes for which you'll use that information
- Whether you sell or share personal information, and if so, a working "Do Not Sell or Share My Personal Information" link
- A link to the specific section of your privacy policy covering this information, not just the privacy policy's homepage
- A description of consumer rights: the right to know, the right to delete, the right to opt out, and the right to non-discrimination for exercising any of these
In practice, most businesses deliver this through a cookie banner that appears on first visit. Unlike a GDPR banner, a CCPA/CPRA notice-at-collection banner doesn't need an "Accept" button or any affirmative action from the visitor. Showing the notice is enough; the visitor doesn't have to click anything for your cookies to be compliant.
The minors' consent exception
There is exactly one case where CCPA/CPRA requires opt-in consent before you can sell or share personal information, including through cookies and similar tracking technology: when the person is a minor.
- Under 13: a parent or guardian must affirmatively opt in before you can sell or share the child's personal information.
- Ages 13 to 16: the minor can provide that opt-in consent themselves.
- 16 and older: the standard opt-out model applies, same as any adult consumer.
This exception applies even if the only data point you're collecting is a device identifier or IP address. If you knowingly operate a service aimed at or used by minors, don't rely on the general no-opt-in rule for your cookie setup. You need an affirmative, logged consent flow for that age group specifically.
Civil penalties for non-compliance
Both the Attorney General and the CPPA can bring enforcement actions. As of January 1, 2025, the statutory penalty amounts were adjusted for inflation and hold through 2026 (the next scheduled adjustment is 2027):
- $2,663 per violation for unintentional violations (up from the original $2,500 figure)
- $7,988 per violation for intentional violations, or any violation involving the personal information of a consumer the business knew was under 16 (up from the original $7,500 figure)
Because each affected consumer counts as a separate violation, these add up fast. Failing to honor opt-out requests from 1,000 California residents is 1,000 violations, not one. Separately, consumers have a private right of action for certain data breaches, with statutory damages currently in the $107 to $799 per-consumer range (also CPI-adjusted), or actual damages if higher.
How CCPA/CPRA cookie rules compare to GDPR
| CCPA/CPRA | GDPR | |
|---|---|---|
| Default for ordinary cookies | Notice only, no opt-in required | Opt-in required before setting non-essential cookies |
| Required banner action | None, just disclosure | Visitor must take a clear affirmative action |
| Core user control | Opt out of sale/sharing | Opt in before processing |
| Minors | Opt-in required only for sale/share of under-16 data | Parental consent generally required under the relevant member state's digital consent age (13 to 16 depending on the country) |
| Preference management | Needed only if you sell/share data or process minors' data | Needed for essential vs. non-essential cookie categories regardless |
Choose a GDPR-style opt-in banner if you have any EU traffic alongside California traffic. Rely on CCPA's lighter notice-only model if your audience is exclusively US-based and you don't sell or share personal information in a way that triggers opt-in obligations. Most multi-market businesses end up running the stricter GDPR-style flow everywhere, since it satisfies both laws at once; see our comparison of CCPA and other US state privacy laws if you operate in more than California.
For the fuller picture of what counts as a cookie, how categorization works, and why "essential vs. non-essential" matters across frameworks, see our guide to cookie compliance and our overview of what CCPA is and who it covers.
How Secure Privacy helps with CCPA/CPRA cookie compliance
Secure Privacy's consent management platform scans your website to identify and categorize the cookies you're actually running, then generates a notice-at-collection banner that includes the required categories, purposes, and opt-out link. The platform also detects and honors GPC signals automatically, logs consent records for any minors' data flow that needs affirmative opt-in, and lets you switch between a CCPA-style notice-only banner and a GDPR-style opt-in banner depending on where a visitor is located.
FAQ
Do I need to record CCPA cookie consent?
Not for general audiences. You only need to collect and log consent if you're knowingly processing a minor's personal information. For everyone else, showing the notice at collection satisfies the requirement; no logged consent record is needed.
Do I need a cookie consent manager to comply with CCPA/CPRA?
You need some mechanism to deliver the notice at collection and honor opt-out and GPC requests, which in practice means a cookie consent manager or equivalent banner tool. If you process minors' data, that same tool needs to support logging affirmative opt-in consent.
Does CCPA cookie compliance cover other US state privacy laws too?
No. Other states with their own privacy laws, including Colorado, Virginia, and Connecticut, have similar but not identical cookie and consent requirements. Treat each state's law separately rather than assuming CCPA/CPRA compliance covers them all.
What is Global Privacy Control, and do I have to honor it?
GPC is a browser-level signal that tells websites a visitor wants to opt out of the sale or sharing of their personal information. If your business is subject to CCPA/CPRA, yes, you must treat a GPC signal as a valid opt-out request. California is currently the only jurisdiction that explicitly requires this.
Is the $25 million revenue threshold still accurate?
No. The CPPA adjusts it for inflation every odd-numbered year. The current figure, effective since January 1, 2025, is $26,625,000, not $25 million.
Final thoughts
CCPA and CPRA cookie compliance is lighter than GDPR in one specific way: you don't need opt-in consent for ordinary cookies, just clear notice and a working opt-out. But the applicability thresholds have moved since the law launched, the penalty figures are higher than the oft-cited $2,500/$7,500, and the minors' exception is strict and easy to miss if your audience skews young. Get the notice-at-collection banner right, honor GPC signals, and treat the under-16 exception as a hard line rather than an edge case.


