Law / United States / California

California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24)

Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2020, effective 1 January 2023.

A comprehensive regime rule binding private bodies.

As of 23 August 2026.

What it requires

  • If your app is a for-profit business meeting the CCPA's revenue or data-volume threshold and it determines the purposes and means of processing a California consumer's personal information, honor the CCPA/CPRA's notice, opt-out, and non-discrimination duties before collecting, selling, or sharing that data.
  • Disclose at or before collection the categories of personal information you collect, your purpose for collecting it, and the retention period or the criteria you use to set it.
  • Limit your collection, use, retention, and sharing of a California consumer's personal information to what is reasonably necessary and proportionate to the purpose you disclosed.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Civ. Code section 1798.155(a): an administrative fine of not more than $2,500 for each violation, or $7,500 for each intentional violation or one involving the personal information of a consumer known to be under 16, as enacted, adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d). The Agency's most recent adjustment, effective 2025-01-01, raised the two figures to $2,663 and $7,988; the higher, intentional-violation figure is recorded as per_violation_amount, with the $2,663 base figure the lower tier for a non-intentional violation. The Attorney General holds a parallel civil-penalty power at the same as-enacted and adjusted amounts under section 1798.199.90(a).

Rule
Per violation only
As of
2 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
7,988

Statutory damages

Civ. Code section 1798.150(a)(1)(A): a consumer whose nonencrypted, nonredacted personal information is breached because a business violated its duty to maintain reasonable security may recover not less than $100 and not more than $750 per consumer per incident, or actual damages, whichever is greater, as enacted. The amount is adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d); its most recent adjustment, effective 2025-01-01, set the range at $107 to $799, recorded here as per_person_minimum and per_person_reckless respectively (the statute states a range rather than culpability tiers). Section 1798.150(b) allows a consumer to pursue statutory damages 'on an individual or class-wide basis,' so a class action is available.

As of
2 September 2026
Currency
USD
Per person minimum
107
Per person reckless
799
Class action available
Yes

Who enforces it

Enforcement body

California Privacy Protection Agency (administrative enforcement) and the California Attorney General (civil actions), sharing enforcement of the CCPA/CPRA.

Enforcement record

Count of distinct, dated CCPA enforcement announcements (a fine, order, or settlement against a named respondent) in the twelve months from 2025-09-02 to 2026-09-02, read from the California Privacy Protection Agency's own newsroom archive (CalPrivacy moved its announcements from cppa.ca.gov/announcements/ to privacy.ca.gov/about-us/newsroom/ on 2026-01-26; both archives were read to cover the full window): Tractor Supply Company, $1.35 million (2025-09-30); a marketing firm fined for selling audiences without data broker registration (2025-12-03); a round of data broker enforcement actions announced together (2026-01-08, individual count not itemized in the headline read); Youth Sports Media Company (PlayOn Sports), a $1.10 million fine (2026-03-03); Ford Motor Company, ordered to change practices and pay a fine (2026-03-05); a $12.75 million General Motors settlement led by the Attorney General, described by the agency as the largest CCPA penalty in California to date (2026-05-08); a data broker action brought under both the CCPA and the Delete Act, LocateSmarter (2026-08-11); a second data broker enforcement action the same week (2026-08-13); and an action against a Virginia data broker (2026-09-01). This counts public administrative and Attorney General actions only; no private CCPA filings are tallied by any register found. Enforcement advisories, the Data Broker Enforcement Strike Force launch, and the sectoral audit announcement are excluded as not themselves completed actions. fines_per_year is not recorded because not every action's dollar figure was confirmed from the register text itself; the confirmed figures above (Tractor Supply, PlayOn Sports, General Motors) are not totaled against the unconfirmed remainder. The newsroom is paginated: the 2026-05-08 to 2026-09-01 entries are on its first page, the Ford and PlayOn Sports decisions on its second, and the 2025 entries on the pages beyond and in the retired cppa.ca.gov/announcements/ index; only the first page is stored as the source snapshot for this count.

As of
2 September 2026
Trend
Rising
Source link
https://privacy.ca.gov/about-us/newsroom/
Actions per year
9

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Governs private-sector for-profit businesses that meet the CCPA's revenue or data-volume threshold and determine the purposes and means of processing a California consumer's personal information. Duties run on a notice-and-purpose-limitation model rather than a consent-gated lawful basis, and are allocated among four defined roles: business, service provider, contractor, and third party.

The original CCPA (AB 375) became operative January 1, 2020; the California Privacy Rights Act (Proposition 24) substantially expanded it, and the amended law now in force became operative January 1, 2023. AB 1008 (2024) separately expanded the personal-information definition to reach data held in AI systems capable of outputting it.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app