Key Takeaways
- CCPA now applies to businesses with $26,625,000+ in annual gross revenue (inflation-adjusted for 2026, not a flat $25 million), or that handle 100,000 or more California consumers' or households' data a year, or that get 50%+ of revenue from selling or sharing personal information.
- Violations run up to $2,500 per unintentional violation and up to $7,500 per intentional one, both adjusted for inflation every two years by the California Privacy Protection Agency (CPPA).
- CPRA is not a future law anymore. It's been the current, enforceable version of CCPA since January 1, 2023, with enforcement starting July 1, 2023, and it added real obligations, like a separate "Limit the Use of My Sensitive Personal Information" link, that older checklists still miss.
- Your policy needs two distinct opt-out links, not one: "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information." They cover different data and different consumer rights.
- The CPPA, not just the Attorney General, now enforces CCPA. A compliance checklist that only mentions the AG is missing half of who can act against you.
If your business handles California residents' personal data and clears CCPA's applicability thresholds, your privacy policy has specific, checkable requirements, not just a general disclosure of what data you collect. Below: exactly who's in scope in 2026, what your policy has to say, and the two separate opt-out links CPRA requires that a lot of older checklists still get wrong.
Secure Privacy is a cookie and consent management platform that generates CCPA- and CPRA-compliant consent banners and privacy notices alongside GDPR, LGPD, and 55+ other privacy laws.
Does the CCPA Apply to Your Business?
CCPA (as amended by CPRA) applies to any for-profit business that does business in California and meets at least one of three thresholds: annual gross revenue over $26,625,000 (the original $25 million threshold, adjusted for inflation every two years since CPRA took effect), buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of annual revenue from selling or sharing consumers' personal information. That revenue threshold applies to global revenue, not just California-derived revenue.
A common and outdated mistake is citing the original CCPA's 50,000-consumer threshold. CPRA raised that number to 100,000 when it took effect, so a business that would have been in scope under the 2020 rules might be out of scope today, and vice versa if its data volume has grown.
What Are the Core Requirements of a CCPA-Compliant Privacy Policy?
Your privacy policy has to disclose, at or before the point of collection, the categories of personal information you collect and why. Beyond that, it has to give consumers a working way to exercise their actual rights: knowing what's been collected about them, accessing it, correcting it, deleting it, and opting out of its sale or sharing. It also has to state plainly that exercising these rights won't result in discriminatory treatment, like a different price or a degraded service.
Your privacy policy isn't the only disclosure CCPA requires, and it's worth keeping the two straight. A Notice at Collection is a short, point-of-collection disclosure, the kind that appears right where someone enters their email or fills out a form, covering just the categories collected and their purpose. Your privacy policy is the longer, comprehensive document this checklist covers. A compliant site needs both; the Notice at Collection isn't satisfied just because a full privacy policy exists somewhere else on the site.
What Do You Need to Disclose About the Data You Collect?
You have to list every category of personal information your business collected in the past 12 months, updated with each policy revision. CCPA's own categories are specific: identifiers (IP addresses, device IDs, cookies), protected classifications (like race or gender), commercial records, biometric data, geolocation, internet activity, and inferences drawn from profiling, among others. For each category, you also have to disclose where it came from, whether that's direct user input, public records, or cookies and web analytics, and why you collected it (identification, service delivery, personalization, marketing, legal compliance). Your policy also has to state how long you retain each category, or the criteria you use to decide, rather than leaving retention open-ended.
If you share categories of personal information with third parties for a business purpose, or sell or share categories of it, both have to be disclosed separately, including who you shared it with and why. CPRA also draws a real distinction worth reflecting in your disclosures: a service provider or contractor processes data on your behalf under a written contract restricting its use, while a third party is anyone else you disclose data to who can use it for its own purposes. Lumping all three into a generic "third parties" disclosure understates the difference in obligations between them. If your business genuinely doesn't sell or share personal information, your policy has to say that plainly rather than leave the question unanswered.
What Are the Two Separate Opt-Out Links You Actually Need?
This is where a lot of checklists get thin, because CPRA added a second, distinct link that the original CCPA never required. "Do Not Sell or Share My Personal Information" has to be clearly displayed, both in your privacy policy and in your website's footer, and lets consumers opt out of the sale or sharing of their data generally. "Limit the Use of My Sensitive Personal Information" is a separate, CPRA-specific link covering a narrower category: data like precise geolocation, racial or ethnic origin, health information, and financial account details. A business that only implements the first link and skips the second is missing a real, distinct CPRA obligation, not a redundant restatement of the same one.
Both links are unnecessary only if the underlying activity genuinely doesn't apply, that is, if you don't sell or share data at all, or don't process sensitive personal information beyond what's strictly necessary to provide the service requested.
What Rights Do Consumers Have, and How Fast Do You Have to Respond?
Consumers can know what's collected about them, access it, correct inaccuracies, delete it, opt out of sale/sharing, limit use of sensitive data, and exercise all of this without facing discriminatory treatment. Your policy has to explain, concretely, how to exercise each right, not just list them. You have 45 days to respond to a verified request, with one 45-day extension available when needed, and you have to offer at least two request methods, typically a toll-free number and a web form, or just an email address if your business operates exclusively online with a direct consumer relationship. Consumers can also submit a request through an authorized agent, someone they've designated in writing to act on their behalf; your policy should say how you verify an agent's authority rather than leaving that path undocumented.
CCPA also requires supporting Global Privacy Control or a similar browser-level opt-out signal, treating it as a valid, honored opt-out request the same as a manual one.
What Protections Apply to Children's Data?
Businesses need affirmative opt-in consent, not just a disclosed opt-out, before selling or sharing the personal information of a consumer known to be between 13 and 16 years old. For a consumer under 13, that consent has to come from a parent or guardian. This obligation applies whenever a business has actual knowledge of a user's age, not just when the business specifically targets children.
Who Actually Enforces This, and What Happens If You Don't Comply?
Two bodies can act on a CCPA/CPRA violation: the California Attorney General, and the California Privacy Protection Agency (CPPA), the dedicated enforcement agency CPRA created specifically for this law in 2023. A compliance checklist that only mentions the Attorney General is describing the pre-2023 enforcement landscape, not the current one.
Penalties run on a two-tier structure: up to $2,500 per unintentional violation, and up to $7,500 per intentional one, both adjusted for inflation every two years by the CPPA. For 2026, those figures work out to roughly $2,663 and $7,988. Given how "per violation" typically gets counted, that is, per affected consumer or per instance, these numbers scale quickly for any business processing meaningful volumes of California residents' data.
None of this is retroactive protection against enforcement trends. The 2026 CPPA regulatory amendments, covering automated decision-making technology, mandatory risk assessments, and cybersecurity audits, are a separate, ongoing compliance track beyond what a privacy policy document alone covers.
Keeping Your Policy Current
You have to update your privacy policy at least every 12 months, and each update needs a visible "last updated" date so consumers can see when it changed. Beyond the annual cycle, a policy needs a real update whenever your data practices actually change, not just on a fixed schedule; a policy that accurately described your practices a year ago but doesn't reflect what you collect today isn't compliant just because the calendar hasn't hit the 12-month mark yet.
Secure Privacy's privacy policy generator builds a CCPA- and CPRA-compliant notice from your actual scan results, so the categories and disclosures in your policy match what's genuinely running on your site rather than a template that drifts out of sync over time.
FAQ
Does the CCPA apply to my business if I'm not based in California?
Yes, if you do business in California and meet one of the three thresholds (revenue, consumer volume, or revenue-from-sale/share percentage), regardless of where your company is headquartered.
What's the difference between "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information"?
The first covers the general sale or sharing of personal information. The second, added by CPRA, is narrower and covers only sensitive categories like precise geolocation, health data, and financial account details. Most CCPA-covered businesses need both links unless the underlying activity genuinely doesn't apply.
How much can a CCPA violation actually cost?
Up to $2,500 per unintentional violation and up to $7,500 per intentional violation, both inflation-adjusted every two years by the CPPA. For 2026, that's roughly $2,663 and $7,988.
Who enforces CCPA and CPRA?
Both the California Attorney General and the California Privacy Protection Agency (CPPA), a dedicated enforcement agency CPRA created in 2023. Checklists that mention only the Attorney General are describing outdated enforcement.
How often do I need to update my privacy policy?
At least every 12 months, with a visible "last updated" date, and immediately whenever your actual data practices change, not just on the annual schedule.
Do I need parental consent to sell a minor's data?
For a consumer 13 to 16, you need the minor's own opt-in consent. For a consumer under 13, you need a parent or guardian's consent. This applies whenever your business has actual knowledge of the user's age.
Sources
- California Consumer Privacy Act, as amended by the CPRA, Cal. Civ. Code §§ 1798.100 et seq.
- California Privacy Protection Agency (CPPA), enforcement authority and inflation-adjusted penalty amounts




