Home Blog The CCPA Explained

Jump to Section

Quick Facts — Privacy Policy Lawyers

What Is the CCPA?

The CCPA, more officially known as the California Consumer Privacy Act or AB 375, is a state-wide data privacy law in California. It is the first law of its kind in the U.S.

ContractsCounsel CCPA

Image via Unsplash by rupixen

The CCPA regulates how businesses worldwide can handle personal information, or PI, of California residents. Though the CCPA was passed by the California state legislature in 2018, it first came into effect on January 1, 2020. The law became enforceable on July 1, 2020.

Who Does the CCPA Affect?

The CCPA is similar to the General Data Protection Regulation, or GDPR, in the European Union. As with the GDPR, the CCPA deals with consumers' data privacy rights. The law forces many organizations to protect the privacy rights of their consumers.

The CCPA specifically covers consumers who are California residents. However, businesses around the world must comply with CCPA regulations if they have consumers from California. Businesses do not need to be based in California to fall under the law. Companies do not even need to have a physical presence in California or in the United States to fall under this law if they meet certain requirements.

Requirements for Businesses

Not all businesses must comply with the regulations in the CCPA. The CCPA applies if a company fits in one or more of the following categories:

  • The business buys, sells, or receives personal information of 50,000 or more devices, consumers, or households.
  • The business derives half or more of its revenue from selling personal information of consumers.
  • The business has a gross annual revenue that exceeds $25 million.

Under the CCPA, businesses that handle personal information for more than four million consumers have additional obligations as well.

Exemptions










Volume 0%























A later amendment exempts insurance institutions, agents, and organizations that already fall under similar regulation of the Insurance Information and Privacy Protection Act, or IIPPA, in California.

Additionally, the following businesses are exempt from the CCPA as they are covered under federal data security laws already:

Protections for Consumers

The CCPA allows any California consumer to:

  • Demand to see all information a company has saved about them.
  • Demand to see a full list of all third parties a company shares their data with.
  • Sue companies in cases when privacy guidelines are violated, and consumers can sue companies even if no breach occurs.

California residents, or consumers, have the right to:

  • Opt out of having data sold to third parties.
  • Request disclosure of data that has already been collected.
  • Request that data collected be deleted.
  • Be notified and receive equal prices and services — companies cannot discriminate against consumers based on a consumer's choice to exercise these rights.

What Happens When a Company Is Not in Compliance With the CCPA?

Once regulators notify a business of a violation, the company has 30 days to comply with the law. If the issue is not resolved in that time, businesses are subject to a fine per record.

Fines may be between $100 and $750 per consumer per alleged violation, or the actual damages — whichever amount is greater.

Consumers also have the right to sue businesses if they believe their privacy rights were violated. The CCPA allows for class action lawsuits as well.

Data the CCPA Covers

The CCPA covers personal information. Examples of what the law considers personal information includes:

  • Biometric information.
  • Geolocation data.
  • Characteristics of protected classifications under federal or California law.
  • Identifiers, including:
    • Driver's license number
    • Social Security number
    • Passport number
    • Account name
    • Postal address
    • Email address
    • Online identifier IP address
    • Real name
    • Alias
  • Commercial information, including:
    • Products purchased, obtained, or considered
    • Services purchased, obtained, or considered
    • Records of personal property
  • Purchasing/consuming histories/tendencies.
  • Internet/electronic network activity such as:
    • Browsing history
    • Search history
    • Information about the consumer's interaction with applications, advertisements, or websites
  • Education information, as defined in the Family Education Rights and Privacy Act (FERPA) as not publicly available PII, or personally identifiable information.
  • Audio, electronic, olfactory, thermal, visual, or similar information.

The CCPA also covers inferences drawn from the above information to create a consumer profile reflecting things such as a consumer's:

  • Abilities
  • Aptitudes
  • Attitudes
  • Behavior
  • Characteristics
  • Intelligence
  • Predispositions
  • Preferences
  • Psychological trends

Key Provisions of the CCPA

The CCPA stipulates that companies covered by the law must allow consumers to choose not to have data shared with third parties. In practical terms, that means companies now must be able to separate data they collect following their users' privacy choices.

Companies are not required to report breaches under this law. Additionally, before fines are possible, a consumer must file a complaint.

Enforcement of the CCPA

In addition to granting Californians the right to sue businesses that do not take reasonable precautions to prevent data breaches, the CCPA can be enforced. The Office of the Attorney General of California has the power to enforce the CCPA. However, the state has limited enforcement capabilities, as there are not enough resources to ensure that all companies comply with the law at the same time that they manage non-compliance cases.

What Must a Business Do to Be In Compliance With the CCPA?

If your business falls under the CCPA, you are required to:

  • Allow consumers to deal with their personal data in the business's storage in the following ways:
    • Choosing to opt-out
    • Choosing to read the data
    • Choosing to delete the data
  • Disclose financial incentives for your business to sell or retain a consumer's personal data as well as how you value the data.
  • Respond to requests from consumers within specific timeframes.
  • Verify the identity of any consumer who requests to read/delete their information; this is the case even if the consumer has a password-protected account.
  • Keep records of access requests and how your business responded for 24 months.

You must ensure that your company's website:

  • Includes a "Do Not Sell My Personal Information" link so that users may opt out of third-party data sales.
  • Informs users about categories of personal information collected (and for what purposes) at or before the point of data collection.
  • Obtains opt-in/consent before selling or disclosing personal information of minors under the age of 16; parents or legal guardians must opt in for minors under 13.
  • Updates its privacy policy to include:
    • A description of consumer's rights
    • An explanation of how to exercise rights
    • A list, updated annually, of personal information categories the company collects/sells/discloses
  • Shows consumer privacy settings that signal the choice to opt out.

If your company gets a verifiable request from a consumer requesting disclosure of personal information your business has collected, you must provide records of personal information that have been collected in the past 12 months. You must do this free of charge. These records include:

  • Categories of third parties that have received the records
  • Commercial purposes
  • Sources

Your company must not discriminate based on a consumer's decision to exercise the right to:

  • Opt out
  • Request disclosure
  • Request deletion

The CCPA laws are now in effect, and will change the way businesses deal with data across the country. As almost all bigger businesses have some customers based in California, the CCPA has tremendous implications for data privacy laws. For more help with privacy policies and contracts, contact us .


ContractsCounsel is not a law firm, and this post should not be considered and does not contain legal advice. To ensure the information and advice in this post are correct, sufficient, and appropriate for your situation, please consult a licensed attorney. Also, using or accessing ContractsCounsel's site does not create an attorney-client relationship between you and ContractsCounsel.


Need help with a Privacy Policy?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,648 reviews

Meet some of our Lawyers

Chaz G. on ContractsCounsel
View Chaz
5.0 (2)
Member Since:
April 15, 2026

Chaz G.

Business Lawyer
Free Consultation
Dallas, TX
13 Yrs Experience
Licensed in NY, TX
American University - Washington College of Law

As a former corporate attorney at one of the world's premier global law firms and former in-house counsel at Texas Instruments, a Fortune 500 technology leader, I bring big-firm expertise and corporate-level sophistication to entrepreneurs, startups, and small business owners who deserve the same quality legal support as the largest companies in the world. As a lawyer and startup founder with products currently being sold in national retail chains, I've spent my career at the intersection of complex business transactions, corporate law, and policy. I know how deals get done, where contracts go wrong, and how to protect businesses before problems arise. Now, I put that experience to work for founders and business owners who need practical, straightforward legal guidance without the intimidating price tag of a major law firm. Whether you're signing your first vendor contract, structuring a partnership, protecting your intellectual property, or navigating a business dispute, I translate the law into plain language so you can make confident decisions and focus on growing your business. What I bring to the table: - Complex commercial transactions experience at an AmLaw 100 firm - 7+ years as in-house counsel at a Fortune 500 company - Deep understanding of how businesses actually operate day-to-day - Flat-fee, transparent pricing with no billing surprises - Fast turnaround and direct communication If you're building something, I want to help you protect it.

Recent  ContractsCounsel Client  Review:
5.0

"Chaz was extremely helpful, thorough, and professional. I hired him for a cease and desist letter involving an unauthorized use of my company’s business identity, EIN, and credit. He took the time to review the documents carefully, explain the legal issues in plain English, and help me understand the strengths and challenges of my situation. What stood out most was how organized he was. He prepared a legal analysis memo before our call, walked me through the authority issues, and adjusted his approach after reviewing additional company documents. He was patient, clear, and never made me feel rushed, even though the situation involved several complicated details. The final work product was strong, detailed, and tailored to my specific facts rather than feeling like a generic template. I would definitely recommend Chaz to anyone who needs a knowledgeable attorney who communicates clearly and takes the time to understand the full picture."

Rhea d. on ContractsCounsel
View Rhea
5.0 (78)
Member Since:
April 12, 2023

Rhea d.

Attorney
Free Consultation
San Francisco Bay Area, California
29 Yrs Experience
Licensed in CA, DC
University of Utah

Rhea de Aenlle is a business-savvy attorney with extensive experience in Privacy & Data Security (CIPP/US, CIPP/E), GDPR, CCPA, HIPAA, FERPA, Intellectual Property, and Commercial Contracts. She has over 25 years of legal experience as an in-house counsel, AM Law 100 firm associate, and a solo practice attorney. Rhea works with start-up and midsize technology companies.

Recent  ContractsCounsel Client  Review:
5.0

"Excellent communication and delivered a very thorough privacy policy."

Terence B. on ContractsCounsel
View Terence
5.0 (45)
Member Since:
August 23, 2020

Terence B.

Partner
Free Consultation
Orlando, FL and New York, NY
15 Yrs Experience
Licensed in FL, NY
Georgetown University Law Center

Terry Brennan is an experienced corporate, intellectual property and emerging company transactions attorney who has been a partner at two national Wall Street law firms and a trusted corporate counsel. He focuses on providing practical, cost-efficient and creative legal advice to entrepreneurs, established enterprises and investors for business, corporate finance, intellectual property and technology transactions. As a partner at prominent law firms, Terry's work centered around financing, mergers and acquisitions, joint ventures, securities transactions, outsourcing and structuring of business entities to protect, license, finance and commercialize technology, manufacturing, digital media, intellectual property, entertainment and financial assets. As the General Counsel of IBAX Healthcare Systems, Terry was responsible for all legal and related business matters including health information systems licensing agreements, merger and acquisitions, product development and regulatory issues, contract administr

Recent  ContractsCounsel Client  Review:
5.0

"Working with Terence was quick and easy, we would highly recommend him."

Kennedy W. on ContractsCounsel
View Kennedy
Member Since:
July 11, 2023

Kennedy W.

Attorney
Free Consultation
Holton, KS
7 Yrs Experience
Licensed in KS
Washburn University School of Law

Graduated from Washburn University School of Law with certificates in Tax Law and Business Transactions. Served as a specialized tax advisor and business consultant to clients across the nation over the last 8 years. I have practiced law since 2019, specializing in entity formations, contract drafting, contract review, contract disputes, business transactions, demand letters, legal research, and general business consulting.

Matt T. on ContractsCounsel
View Matt
Member Since:
July 31, 2023

Matt T.

Attorney
Free Consultation
Dallas, TX
4 Yrs Experience
Licensed in TX
Samford University's Cumberland School of Law

Matt is a licensed attorney based out of Dallas, Texas. Despite having recently graduated, Matt has been immersed in the world of Corporate law throughout law school and beyond. As a result, he has benefitted from the unique and advantageous position of experiencing and working on a wide array of matters, such as reviewing, drafting and negotiating contracts, overseeing regulatory compliance, business formation, risk management, and much more. Contact Matt today for a free consultation!

Penny R. on ContractsCounsel
View Penny
Member Since:
July 14, 2023

Penny R.

Founder/Owner
Free Consultation
Dallas, Texas
39 Yrs Experience
Licensed in TX
Southern Methodist University

I have practiced law for more than 35 years in the State of Texas. I am proud of the relationships I have formed with my clients and the high level of legal advice I have provided over these many years. I am responsive and will promptly address your particular situation. For 35 years I have counseled individuals, partnerships and corporations with regard to business formation, real estate transactions and issues, employer/employee relationships, contracts, estate planning and asset protection. I am licensed to practice law in all state courts in Texas and all federal courts. I have represented plaintiffs and defendants throughout the state in cases ranging from contract disputes to injury claims. I have worked with every type of business you can imagine from individuals to "mom and pop" businesses and businesses with assets of more than $10,000,000. My clients' businesses range from large construction contractors, investment companies, oil and gas companies, and commercial landlords, to name a few.

Find the best lawyer for your project

Browse Lawyers Now

See Real Privacy Policy Projects

California Privacy Policy Drafting
  • California
  • 2 lawyer bids
  • $250 - $2,000
View Details
Washington Create Privacy Policy and User Agreement for new Readathon Platform Drafting
  • Washington
  • 10 lawyer bids
  • $875 - $3,000
View Details
California Draft Privacy Policy for VR application Drafting
  • California
  • 10 lawyer bids
  • $249 - $1,800
View Details
Pennsylvania Create Privacy Policy Drafting
  • Pennsylvania
  • 14 lawyer bids
  • $795 - $2,000
View Details
Texas Local-IL Drafting
  • Texas
  • 10 lawyer bids
  • $300 - $1,999
View Details
Wyoming MHMDA + GDPR Privacy Policy Review — iOS Health App (Flat Fee) Review
  • Wyoming
  • 7 lawyer bids
  • $249 - $1,750
View Details

See all Privacy Policy projects

Quick, user friendly and one of the better ways I've come across to get ahold of lawyers willing to take new clients.

View Trustpilot Review

Need help with a Privacy Policy?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,648 reviews
CONTRACT LAWYERS BY TOP CITIES
See All Privacy Lawyers
CCPA LAWYERS BY CITY
See All CCPA Lawyers

Contracts Counsel was incredibly helpful and easy to use. I submitted a project for a lawyer's help within a day I had received over 6 proposals from qualified lawyers. I submitted a bid that works best for my business and we went forward with the project.

View Trustpilot Review

I never knew how difficult it was to obtain representation or a lawyer, and ContractsCounsel was EXACTLY the type of service I was hoping for when I was in a pinch. Working with their service was efficient, effective and made me feel in control. Thank you so much and should I ever need attorney services down the road, I'll certainly be a repeat customer.

View Trustpilot Review

I got 5 bids within 24h of posting my project. I choose the person who provided the most detailed and relevant intro letter, highlighting their experience relevant to my project. I am very satisfied with the outcome and quality of the two agreements that were produced, they actually far exceed my expectations.

View Trustpilot Review

Need help with a Privacy Policy?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,648 reviews

Want to speak to someone?

Get in touch below and we will schedule a time to connect!

Request a call

Find lawyers and attorneys by city