Law / United States /
California
CCPA/CPRA Enforcement: California Privacy Protection Agency and Private Right of Action
Cal. Civ. Code sections 1798.150, 1798.155, 1798.199.10, 1798.199.90
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 July 2023.
An enforcement supervision rule binding private bodies.
As of 23 August 2026.
What it requires
- Expect administrative enforcement from the California Privacy Protection Agency and the Attorney General, with civil penalties up to $7,988 for an intentional violation or one involving a consumer under 16 (the 2025 inflation-adjusted amount).
- Maintain reasonable security procedures for a California consumer's unencrypted, unredacted personal information; a breach caused by their absence exposes your business to a private lawsuit for $100 to $750 in statutory damages per consumer per incident, which cannot be cured by improving security after the fact.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Civ. Code section 1798.155(a): an administrative fine of not more than $2,500 for each violation, or $7,500 for each intentional violation or one involving the personal information of a consumer known to be under 16, as enacted, adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d). The Agency's most recent adjustment, effective 2025-01-01, raised the two figures to $2,663 and $7,988 (the higher figure is recorded as per_violation_amount). Section 1798.199.90(a) gives the Attorney General a parallel civil-penalty power at the same as-enacted and adjusted amounts, assessed and recovered in a civil action brought in the name of the People.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 7,988
Statutory damages
Civ. Code section 1798.150(a)(1)(A): a consumer whose nonencrypted, nonredacted personal information is breached because a business violated its duty to maintain reasonable security may recover not less than $100 and not more than $750 per consumer per incident, or actual damages, whichever is greater, as enacted, adjusted for inflation by the California Privacy Protection Agency under section 1798.199.95(d) to $107 and $799 effective 2025-01-01 (recorded here as per_person_minimum and per_person_reckless; the statute states a range rather than culpability tiers). Section 1798.150(b) allows a consumer to pursue statutory damages 'on an individual or class-wide basis,' so a class action is available.
- As of
- 2 September 2026
- Currency
- USD
- Per person minimum
- 107
- Per person reckless
- 799
- Class action available
- Yes
Who enforces it
Enforcement body
California Privacy Protection Agency (administrative enforcement) and the California Attorney General (civil actions), sharing enforcement of the CCPA/CPRA.
Enforcement record
Count of distinct, dated CCPA enforcement announcements (a fine, order, or settlement against a named respondent) in the twelve months from 2025-09-02 to 2026-09-02, read from the California Privacy Protection Agency's own newsroom archive (CalPrivacy moved its announcements from cppa.ca.gov/announcements/ to privacy.ca.gov/about-us/newsroom/ on 2026-01-26; both archives were read to cover the full window): Tractor Supply Company, $1.35 million (2025-09-30); a marketing firm fined for selling audiences without data broker registration (2025-12-03); a round of data broker enforcement actions announced together (2026-01-08, individual count not itemized in the headline read); Youth Sports Media Company (PlayOn Sports), a $1.10 million fine (2026-03-03); Ford Motor Company, ordered to change practices and pay a fine (2026-03-05); a $12.75 million General Motors settlement led by the Attorney General, described by the agency as the largest CCPA penalty in California to date (2026-05-08); a data broker action brought under both the CCPA and the Delete Act, LocateSmarter (2026-08-11); a second data broker enforcement action the same week (2026-08-13); and an action against a Virginia data broker (2026-09-01). This counts public administrative and Attorney General actions only; no private CCPA filings are tallied by any register found. Enforcement advisories, the Data Broker Enforcement Strike Force launch, and the sectoral audit announcement are excluded as not themselves completed actions. fines_per_year is not recorded because not every action's dollar figure was confirmed from the register text itself; the confirmed figures above (Tractor Supply, PlayOn Sports, General Motors) are not totaled against the unconfirmed remainder. The newsroom is paginated: the 2026-05-08 to 2026-09-01 entries are on its first page, the Ford and PlayOn Sports decisions on its second, and the 2025 entries on the pages beyond and in the retired cppa.ca.gov/announcements/ index; only the first page is stored as the source snapshot for this count.
- As of
- 2 September 2026
- Trend
- Rising
- Source link
- https://privacy.ca.gov/about-us/newsroom/
- Actions per year
- 9
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The California Privacy Protection Agency, which assumed enforcement authority July 1, 2023, and the Attorney General share administrative enforcement of the CCPA/CPRA, with civil penalties currently up to $2,663 per violation or $7,988 per intentional violation or one involving a consumer known to be under 16, inflation-adjusted for 2025 under a streamlined adjustment mechanism AB 3286 (2024) put in place.
There is no general private right of action for a CCPA violation; a narrow one exists only under section 1798.150 for a business's failure to maintain reasonable security resulting in a breach of unencrypted, unredacted personal information, carrying statutory damages of $100 to $750 per consumer per incident and a 30-day cure notice that does not excuse a breach already suffered.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)
California Attorney General (oag.ca.gov); California Privacy Protection Agency (cppa.ca.gov)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.