California Consumer Privacy Act, as amended by the CPRA
Cal. Civ. Code §1798.100 et seq. (CCPA, as amended by the CPRA)Who it applies to
Businesses that do business in California and either have gross annual revenue over $25M, buy, sell, or share personal information of 100,000+ California consumers or households a year, or derive 50%+ of annual revenue from selling or sharing personal information.
What it requires
- A “Do Not Sell or Share My Personal Information” link, plus recognition of the Global Privacy Control (GPC) opt-out signal
- Honoring opt-out requests within 15 business days
- A privacy policy disclosing categories of data collected, sold, or shared, and consumer rights
- Signed data processing agreements with every third party or service provider that receives personal information
What's changed recently
The California Privacy Protection Agency fined Tractor Supply Co. $1.35M in September 2025 for an opt-out link that did not actually stop data sharing, and for ignoring Global Privacy Control signals until mid-2024. Todd Snyder was fined $345K in May 2025 for mishandled opt-out requests. Both cases involved a cookie banner that looked compliant but did not function correctly behind it.
Informational summary, not legal advice. Reviewed for accuracy as of August 2026; laws and enforcement priorities change, so verify current requirements against the official regulator text before relying on this page.