Law / United States /
California
California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24)
Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2020, effective 1 January 2023.
A comprehensive regime rule binding private bodies.
As of 23 August 2026.
What it requires
- If your app is a for-profit business meeting the CCPA's revenue or data-volume threshold and it determines the purposes and means of processing a California consumer's personal information, honor the CCPA/CPRA's notice, opt-out, and non-discrimination duties before collecting, selling, or sharing that data.
- Disclose at or before collection the categories of personal information you collect, your purpose for collecting it, and the retention period or the criteria you use to set it.
- Limit your collection, use, retention, and sharing of a California consumer's personal information to what is reasonably necessary and proportionate to the purpose you disclosed.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Civ. Code section 1798.155(a): an administrative fine of not more than $2,500 for each violation, or $7,500 for each intentional violation or one involving the personal information of a consumer known to be under 16, as enacted, adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d). The Agency's most recent adjustment, effective 2025-01-01, raised the two figures to $2,663 and $7,988; the higher, intentional-violation figure is recorded as per_violation_amount, with the $2,663 base figure the lower tier for a non-intentional violation. The Attorney General holds a parallel civil-penalty power at the same as-enacted and adjusted amounts under section 1798.199.90(a).
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 7,988
Statutory damages
Civ. Code section 1798.150(a)(1)(A): a consumer whose nonencrypted, nonredacted personal information is breached because a business violated its duty to maintain reasonable security may recover not less than $100 and not more than $750 per consumer per incident, or actual damages, whichever is greater, as enacted. The amount is adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d); its most recent adjustment, effective 2025-01-01, set the range at $107 to $799, recorded here as per_person_minimum and per_person_reckless respectively (the statute states a range rather than culpability tiers). Section 1798.150(b) allows a consumer to pursue statutory damages 'on an individual or class-wide basis,' so a class action is available.
- As of
- 2 September 2026
- Currency
- USD
- Per person minimum
- 107
- Per person reckless
- 799
- Class action available
- Yes
Who enforces it
Enforcement body
California Privacy Protection Agency (administrative enforcement) and the California Attorney General (civil actions), sharing enforcement of the CCPA/CPRA.
Enforcement record
Count of distinct, dated CCPA enforcement announcements (a fine, order, or settlement against a named respondent) in the twelve months from 2025-09-02 to 2026-09-02, read from the California Privacy Protection Agency's own newsroom archive (CalPrivacy moved its announcements from cppa.ca.gov/announcements/ to privacy.ca.gov/about-us/newsroom/ on 2026-01-26; both archives were read to cover the full window): Tractor Supply Company, $1.35 million (2025-09-30); a marketing firm fined for selling audiences without data broker registration (2025-12-03); a round of data broker enforcement actions announced together (2026-01-08, individual count not itemized in the headline read); Youth Sports Media Company (PlayOn Sports), a $1.10 million fine (2026-03-03); Ford Motor Company, ordered to change practices and pay a fine (2026-03-05); a $12.75 million General Motors settlement led by the Attorney General, described by the agency as the largest CCPA penalty in California to date (2026-05-08); a data broker action brought under both the CCPA and the Delete Act, LocateSmarter (2026-08-11); a second data broker enforcement action the same week (2026-08-13); and an action against a Virginia data broker (2026-09-01). This counts public administrative and Attorney General actions only; no private CCPA filings are tallied by any register found. Enforcement advisories, the Data Broker Enforcement Strike Force launch, and the sectoral audit announcement are excluded as not themselves completed actions. fines_per_year is not recorded because not every action's dollar figure was confirmed from the register text itself; the confirmed figures above (Tractor Supply, PlayOn Sports, General Motors) are not totaled against the unconfirmed remainder. The newsroom is paginated: the 2026-05-08 to 2026-09-01 entries are on its first page, the Ford and PlayOn Sports decisions on its second, and the 2025 entries on the pages beyond and in the retired cppa.ca.gov/announcements/ index; only the first page is stored as the source snapshot for this count.
- As of
- 2 September 2026
- Trend
- Rising
- Source link
- https://privacy.ca.gov/about-us/newsroom/
- Actions per year
- 9
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Security, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Governs private-sector for-profit businesses that meet the CCPA's revenue or data-volume threshold and determine the purposes and means of processing a California consumer's personal information. Duties run on a notice-and-purpose-limitation model rather than a consent-gated lawful basis, and are allocated among four defined roles: business, service provider, contractor, and third party.
The original CCPA (AB 375) became operative January 1, 2020; the California Privacy Rights Act (Proposition 24) substantially expanded it, and the amended law now in force became operative January 1, 2023. AB 1008 (2024) separately expanded the personal-information definition to reach data held in AI systems capable of outputting it.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.