CCPA Compliance
Requirements, penalties, and how to check your website against California Consumer Privacy Act.
Test your website for CCPA compliance for free
Enter your domain to start a free scan and open an account - no integration required.
Does CCPA apply to my business?
Answer a few questions for an instant, plain-English read on whether California Consumer Privacy Act likely applies to you.
Answer a few questions to see whether the California Consumer Privacy Act (CCPA), as amended by the CPRA, is likely to apply to your business.
This tool offers general guidance, not legal advice. Applicability can turn on details specific to your business - confirm with qualified counsel.
Who CCPA applies to
- The CCPA applies to for-profit businesses that do business in California and collect California residents’ personal information.
- A business must also meet at least one threshold: annual gross revenue over $25 million; buying, selling, or sharing the personal information of 100,000+ California consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing personal information.
- Jurisdiction depends on the location of the consumer, not the business - a company anywhere in the world can be covered if it handles Californians’ data.
- Most non-profit organizations are outside the CCPA’s scope, with limited exceptions.
Common questions
- Does the CCPA apply to businesses outside California?
- Yes. The CCPA follows the location of the consumer, not the business. A company based anywhere can be covered if it collects personal information from California residents and meets one of the thresholds.
- Does the CCPA apply to small businesses?
- Only if they meet a threshold. A small business under $25 million in revenue that does not sell/share data on 100,000+ Californians and does not derive 50%+ of revenue from selling data is generally not covered - though thresholds are easy to cross as you grow.
- Does the CCPA apply to non-profits?
- Generally no. The CCPA applies to for-profit businesses. A non-profit can be pulled in if it is controlled by, or shares branding with, a covered for-profit, or otherwise operates for another entity’s profit.
- What are the CCPA revenue and data thresholds?
- A covered business meets at least one of: over $25 million in annual gross revenue; buying, selling, or sharing personal information of 100,000+ California consumers or households per year; or 50%+ of annual revenue from selling or sharing personal information.
Overview
The California Consumer Privacy Act (CCPA) is a state statute that enhances privacy rights and consumer protection for residents of California. It applies to businesses that collect personal information from California residents and meet certain thresholds.
Penalties
$2,500 per unintentional violation, $7,500 per intentional violation
What Complyy checks
6 automated tests — 3 passive, 3 active
Passive (instant scan)
"Do Not Sell or Share My Personal Information" link present
Cal. Civ. Code §1798.135 requires a clear and conspicuous "Do Not Sell or Share My Personal Information" link on the homepage when the business sells or shares data. Missing link is the single most-cited CCPA violation by the CA AG.
Privacy policy includes CCPA-required disclosures
§1798.130 requires a privacy policy listing categories collected, sources, purposes, third parties, retention, and consumer rights. The policy must be updated at least every 12 months.
Categories of personal data collected are disclosed
§1798.110 requires disclosure of the specific categories of personal information collected in the past 12 months. Generic statements like "we collect information about you" are non-compliant.
Active (synthetic identity tests)
Opt-out of sale/sharing request honored within 15 days(waits up to 15d for response)
Once a consumer opts out of sale/sharing, the business must comply within 15 business days (CCPA Regs §7026). Continued targeted ads after opt-out is a documented enforcement priority.
Right to delete fulfilled within 45 days(waits up to 45d for response)
§1798.105 requires deletion within 45 days, with exceptions documented. Partial deletion or "soft delete" that leaves marketing profiles intact is a finding.
Right to know fulfilled within 45 days(waits up to 45d for response)
§1798.130 requires fulfilling right-to-know requests within 45 days (extendable to 90). Slow or incomplete responses trigger AG enforcement and the private right of action under CPRA.
Learn More About California Consumer Privacy Act
What is CCPA compliance?
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most far-reaching consumer privacy law in the United States. CCPA compliance means giving California residents control over the personal information your website collects about them, and being able to prove - technically and operationally - that your site honors those rights. In practice that is a set of concrete obligations: telling people what you collect, letting them opt out of the sale or sharing of their data, deleting their data on request, and responding to those requests within legal deadlines.
A privacy policy alone does not make a site compliant. The requirement is that the mechanisms on your live site actually work - the "Do Not Sell or Share" link genuinely stops the data flow, the deletion request is answered in time, and the opt-out signal from a browser is respected. A misconfigured tag or a broken opt-out link is a violation even when the page looks correct.
Who must comply with the CCPA?
A common misconception is that the CCPA only applies to companies based in California. It does not. Jurisdiction follows the location of the consumer, not the business. The CCPA applies to any for-profit business that does business in California, collects personal information from California residents, and meets at least one of these thresholds:
Has annual gross revenue over $25 million.
Buys, sells, or shares the personal information of 100,000 or more California consumers or households per year. The CPRA raised this from the original 50,000 and added "sharing" to the test.
Derives 50% or more of its annual revenue from selling or sharing consumers' personal information.
"Doing business in California" is read broadly and does not require a physical office. If you market to California residents or get meaningful website traffic from the state, you are likely in scope. This pulls in a large share of e-commerce sites, SaaS platforms, and digital publishers.
Does the CCPA apply to non-profits?
The CCPA applies to for-profit businesses, so most non-profit organizations are not directly covered. There are important exceptions: a non-profit can fall in scope if it is controlled by, or shares branding with, a covered for-profit business, or if it otherwise operates for the profit of another entity. Non-profits should also note that other privacy obligations may still apply even when the CCPA does not.
What personal information does the CCPA cover?
The definition of personal information is deliberately expansive. It covers far more than names and email addresses. Under Cal. Civ. Code section 1798.140 it includes online identifiers, IP addresses, geolocation data, browsing and search history, and inferences drawn from that data to build a profile of a consumer. This means a business that never collects a name or an email can still be processing personal information through cookies, analytics trackers, and advertising pixels - which is enough to trigger CCPA obligations.
Consumer rights under the CCPA
The law grants California residents a set of rights that a compliant business must be able to honor within the legal timeline:
The right to know what personal information is collected, where it comes from, why it is collected, and who it is shared with.
The right to delete personal information the business has collected, subject to statutory exceptions. Requests must be honored within 45 days, with one 45-day extension when reasonably necessary.
The right to opt out of the sale or sharing of personal information. Businesses that sell or share data must post a clear "Do Not Sell or Share My Personal Information" link.
The right to correct inaccurate personal information, added by the CPRA.
The right to limit the use of sensitive personal information, such as precise geolocation, requiring a "Limit the Use of My Sensitive Personal Information" link where applicable.
The right to non-discrimination for exercising any of these rights.
A critical technical requirement is honoring opt-out preference signals such as the Global Privacy Control (GPC). CPRA regulations require businesses to treat a GPC signal as a valid request to opt out of sale or sharing. This has to be automated - the site must detect the signal and suppress the relevant advertising and analytics data flows for that visitor.
CCPA fines and penalties
Enforcement is handled by the California Privacy Protection Agency (CPPA) and, for data breaches, by consumers directly. The penalties are structured per violation, which is what makes them add up:
Up to $2,500 per unintentional violation. A single broken opt-out link on a high-traffic site can be counted as one violation per affected consumer - potentially thousands of them.
Up to $7,500 per intentional violation, or per violation involving the personal information of a minor.
A private right of action for data breaches of unencrypted personal information caused by unreasonable security, with statutory damages of $100 to $750 per consumer, per incident, or actual damages if greater.
The CPRA also removed the guaranteed 30-day right to cure. Regulators may still allow time to fix a problem, but it is no longer an automatic safe harbor, which raises the value of continuous, proactive compliance.
CCPA vs CPRA: what changed
The CPRA did not replace the CCPA - it amended and strengthened it, and took full effect for enforcement in 2023. The most important changes: it added the rights to correct and to limit sensitive personal information, introduced the concept of "sharing" for cross-context behavioral advertising, raised the consumer threshold to 100,000, created the CPPA as a dedicated enforcement agency, and removed the guaranteed cure period. When people say "CCPA" today, they generally mean the CCPA as amended by the CPRA.
How to check if your website is CCPA compliant
Because modern websites change constantly, a one-time audit is not enough. A routine deployment, a new marketing pixel, or a misconfigured tag manager rule can quietly break a mechanism that was compliant last week. A reliable check has to test the actual behavior of the site, not just the presence of a policy:
Confirm the "Do Not Sell or Share" link exists and actually stops advertising and analytics data flows on later visits, not just returns a success page.
Confirm deletion and access requests are answered within the 45-day deadline.
Confirm the site detects and honors the Global Privacy Control signal.
Confirm the privacy notice discloses the categories collected, the purposes, and the sharing practices, and that it is updated at least every 12 months.
Complyy checks all of this continuously from the outside, the same way a regulator would, and captures timestamped evidence for every finding. Enter your domain above to run a free CCPA compliance check on your site.
Frequently asked questions
Who does the CCPA apply to?
The CCPA applies to for-profit businesses that operate in California and meet certain thresholds like revenue over $25 million or buy/sell data of 50,000+ California consumers annually.
What are the penalties for not complying with CCPA?
Non-compliance can result in fees of $2,500 per violation or $7,500 per intentional violation, with no caps on overall fines.
Does CCPA apply to small businesses?
It depends. CCPA applies if a small business makes over $25 million in revenue, handles data of 50,000+ consumers, or makes more than 50% of its revenue selling data.
What is the deadline to respond to a request under CCPA?
Businesses have 45 days to respond to a verified consumer request, extendable by another 45 days if necessary, with a notification to the consumer.
Are non-profits subject to CCPA?
No, non-profit organizations are generally excluded from CCPA requirements unless they are controlled by or share branding with a for-profit entity subject to CCPA.
Is data from non-Californians covered by CCPA?
No, CCPA specifically applies to the personal information of California residents.
How does CCPA handle data breaches?
Consumers can file a lawsuit over data breaches, seeking statutory or actual damages, with penalties ranging from $100 to $750 per incident.
When does the CPRA amendment take effect?
The new CPRA regulations came into effect on January 1, 2023, further extending CCPA's provisions.
Recently Scanned Websites
Live compliance reports from Complyy's public directory.
Related CCPA articles
Insights and analysis from Complyy on CCPA compliance.

How To Test The Right To Be Forgotten: Proactive GDPR & CCPA Right to Erasure Tests
Learn how to rigorously test Right to Erasure requests under GDPR and CCPA. Discover methods for validating deletion processes and ensuring timely compliance to prevent legal exposure.

The Opt-Out Mistake That Just Cost a Company $116,490
California just issued its first fine under the Delete Act. The most useful lesson for everyone else isn't about data brokers - it's that you can be penalized for making it too hard to opt out.

The Privacy Policy Was Perfect. The Website Fired 86 Trackers Before Consent
A children's brand with a textbook privacy policy scored 54/100 - because its live website fired 86 tracking cookies before consent, with no banner in sight. Here's the gap between what a policy promises and what a website does, and how to test your own.
The Platform
How Complyy enforces CCPA compliance
Complyy continuously tests your site against California Consumer Privacy Act using synthetic identities that behave exactly like regulators — and your customers.
Discover
We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.
Scan & Test
Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.
Score & Evidence
Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.
Why Complyy
The only platform that tests compliance the way regulators do
Real synthetic identities
We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.
Active + passive tests
Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.
Court-admissible artifacts
Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.
4
Regulations monitored
19
Compliance tests
∞
Agentic identities
3 min
Avg. first evidence artifact
Is your company CCPA-compliant?
Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.