If your business handles data from people in California, the state’s privacy rules almost certainly apply to you, even if you have no office there. That surprises a lot of companies. California gives its residents some of the strongest privacy rights in the United States, and it backs them with real enforcement. In May 2026, General Motors settled a case for 12.75 million dollars over how it handled driving and location data. Fines like that are a clear signal that these rules have teeth.
CCPA Compliance is how you stay on the right side of them. It is not just a task for large tech firms. Any business that meets the thresholds and touches Californian data has duties to meet, from posting the right privacy notices to honouring consumer requests.
KewData helps UK and international businesses understand rules like these and build compliance that stands up to scrutiny. This guide walks through what the law says, how it has changed, and what your business needs to do.
Table of Contents
- What Is CCPA?
- What Is the California Consumer Privacy Act of 2018?
- California Consumer Privacy Act 2023
- Understanding CCPA Data Privacy
- What Is CCPA Privacy?
- What Is a CCPA Privacy Policy?
- Understanding California Consumer Privacy Act Regulations
- Why CCPA Compliance Matters for Businesses
- How Businesses Can Approach CCPA Compliance
- Conclusion
What Is CCPA?
The CCPA, short for the California Consumer Privacy Act, is a state law that gives California residents control over how businesses collect and use their personal information. It covers a wide range of data, from names and email addresses to browsing activity, location, and anything else that can be linked to a person or household.
CCPA California requirements do not apply to every business. The law targets for-profit companies that do business in California and meet at least one of three tests: they make more than 25 million dollars in annual gross revenue (a figure now adjusted for inflation to 26,625,000 dollars), they buy, sell, or share the personal information of 100,000 or more California consumers or households, or they make half or more of their revenue from selling or sharing personal information. Meet any one of these, and the law applies, wherever your business is based.
The reach is the part that catches people out. You do not need a Californian office or even a US presence. If you handle enough Californian data, CCPA California Consumer Privacy Act duties can land on you, which is why a clear privacy compliance review is a smart first move.
What Is the California Consumer Privacy Act of 2018?
The California Consumer Privacy Act of 2018 was the original law, signed in 2018 and brought into force on 1 January 2020. It was the first broad consumer privacy law of its kind in the United States, and it drew heavily on the ideas behind Europe’s GDPR.
Its purpose was to hand people real control over their own information. Under the 2018 Act, Californians gained the right to know what data a business collects about them, the right to ask for it to be deleted, the right to opt out of having it sold, and the right not to be treated unfairly for using any of these rights. For businesses, this set the foundation of CCPA Data Privacy: a duty to be open about what you collect, and to respect people’s choices about it. Meeting requests like these sits within your wider data protection responsibilities.
The 2018 law started the shift, but it was only the beginning. California soon strengthened it.
California Consumer Privacy Act 2023
The next big step came through the California Privacy Rights Act, often called the CPRA, which voters approved in 2020 and which took full effect on 1 January 2023. It did not replace the CCPA. It amended and expanded it, which is why people often talk about the California Consumer Privacy Act 2023 as the version most businesses follow today.
The 2023 changes added several things. They introduced a new category of “sensitive personal information,” covering data like precise location, health details, race, and financial account numbers, and gave people the right to limit how that data is used. They added a right to correct inaccurate information. They also changed the rules around data sharing, not just selling, and raised the consumer threshold to 100,000. On top of that, the changes created a dedicated regulator, the California Privacy Protection Agency, to write rules and enforce them.
For any business working towards CCPA Compliance, the practical message is simple. The 2023 framework is the current standard, so your privacy practices need to reflect the expanded rights and the tighter rules, not just the original 2018 version. A data protection impact assessment is a practical way to check high risk activities against them.
Understanding CCPA Data Privacy
CCPA Data Privacy is about giving people a clear view of, and a say in, what happens to their information. At its core sit a set of consumer rights that your business has to respect. Californians can ask to know what personal data you hold and how you use it. They can ask you to delete it. They can correct it if it is wrong. They can opt out of having it sold or shared. And they can limit how you use their sensitive information.
For an organisation, respecting these rights means real work behind the scenes. You need to know exactly what data you hold and where it lives, so you can answer a request properly. You need a way to receive and act on requests within the legal time limits. And you need to make sure someone cannot be penalised, for example with a worse price or service, simply for exercising a right.
This is where good data protection practices pay off. If you already map your data and handle access requests well, meeting CCPA duties becomes far more manageable.
What Is CCPA Privacy?
CCPA Privacy describes the overall approach the law expects a business to take towards personal information. It rests on two ideas: transparency and control. You have to be open about what you collect and why, and you have to give people genuine choices over it.
In practice, businesses can approach this by building privacy into how they operate rather than bolting it on afterwards. That means collecting only the data you actually need, being clear at the point of collection about how you will use it, and making it easy for people to opt out or make a request. A common requirement is a clear “Do Not Sell or Share My Personal Information” link on your website, so people can act on their choice without hunting for it.
The businesses that handle CCPA Privacy well treat it as part of good customer service. Being honest and straightforward about data builds trust, and it happens to keep you compliant at the same time.
What Is a CCPA Privacy Policy?
A CCPA Privacy Policy is the public document where you explain your data practices to consumers. It is not optional. The law requires covered businesses to give clear privacy information, and the privacy policy is the main place that information lives.
A proper policy tells people what categories of personal information you collect, where it comes from, why you collect it, and who you share or sell it to. It also has to spell out the rights Californians have and show them how to use those rights, including how to make a request or opt out. On top of that, the law expects you to keep it current, usually reviewing and updating it at least once a year.
Keeping this accurate over time is easier with proper privacy and data governance behind it. A vague or out-of-date policy is a common reason businesses fall foul of the rules. Clear, accurate privacy information protects your customers and protects you.
Understanding California Consumer Privacy Act Regulations
The California Consumer Privacy Act Regulations are the detailed rules that sit underneath the law itself. The California Privacy Protection Agency writes them, and they explain how businesses are actually expected to meet their duties in practice.
These regulations keep growing. A major new package took effect on 1 January 2026, adding requirements in three notable areas. It covers automated decision-making technology, meaning tools that make significant decisions about people, often using AI. It introduces mandatory risk assessments for certain high-risk data activities. And it requires annual cybersecurity audits for businesses whose processing poses a significant risk to consumers. If your business uses AI tools to process personal data, these newer rules deserve close attention.
The takeaway here is that CCPA Compliance is not a fixed target. The rules evolve, and staying compliant means keeping up with each new set of regulations as it lands.
Why CCPA Compliance Matters for Businesses
The clearest reason is the cost of getting it wrong. Penalties run to 2,500 dollars for each violation and 7,500 dollars for each intentional one or one involving a child’s data, and those figures are now adjusted for inflation. Because a violation is usually counted per affected consumer, the totals add up fast. Recent cases show the scale, from the 12.75 million dollar General Motors settlement to a string of six- and seven-figure fines against other well-known names.
Money is only part of it. Consumer privacy has become something people genuinely care about, and a business that mishandles data risks losing trust that is hard to win back. There is also the private right of action, which lets consumers sue directly if certain data is exposed in a breach, which makes strong data security a priority rather than an afterthought.
Handling compliance management well turns all of this from a threat into an advantage. A business that respects privacy and can prove it stands out to customers and partners who increasingly check before they commit.
How Businesses Can Approach CCPA Compliance
Getting to grips with CCPA Compliance is very doable when you break it into steps. A sensible approach looks like this:
- Check whether the law applies: Work out if you meet any of the thresholds and how much Californian data you actually handle.
- Review your current privacy practices: Map what data you collect, where it sits, why you hold it, and who you share it with. You cannot protect what you have not mapped.
- Set up processes for consumer rights: Put a clear system in place to receive and answer requests to know, delete, correct, and opt out, all within the legal deadlines.
- Update your privacy information: Make sure your CCPA Privacy Policy is accurate, complete, and easy to find, with a working opt-out link.
- Keep it going: Compliance is not a one-off. Review your practices regularly, train your team, and keep pace with new regulations.
That last point matters most. The rules change, your data changes, and your tools change. Setting up a reliable process to receive and answer these requests is where DSAR handling support helps, so you are not scrambling every time one comes in.
Conclusion
CCPA Compliance protects your customers and your business at the same time. California’s privacy rules reward companies that are open about data and honour people’s choices, and they come down hard on those that are not. With the law expanding through the 2023 changes and the new 2026 regulations, keeping up is an ongoing job rather than a one-off fix.
KewData helps businesses turn that job into a clear, managed process. Our team understands global privacy rules and builds practical compliance that fits how you actually work, backed by ongoing support as the requirements change. If you want to know where you stand with California’s rules and what to do next, our compliance services are a straightforward place to start.
Book your free consultation: https://kewdata.ai/contact-us/


