One-Line Definition
The California Consumer Privacy Act (CCPA) is a state-level data privacy law that grants California residents the right to know what personal information a business collects about them, request its deletion, opt out of its sale, and hold businesses accountable for mishandling it — with real teeth in the form of statutory fines and a private right of action after a data breach.
For any DTC brand, marketplace seller, or cross-border e-commerce operator with customers in California, the CCPA (as amended by the California Privacy Rights Act, or CPRA, effective January 1, 2023) is not optional reading. It is the operational baseline for how you collect, store, share, and monetize customer data.
Real-Life Analogy
Imagine you walk into a physical store. Before you can browse, the greeter hands you a clipboard listing every piece of information the store plans to collect — your name, address, purchase history, browsing patterns — and asks you to sign. You can say no. Later, you can call the store and ask, "What exactly do you have on me?" They must answer. You can also say, "Delete it," and they must comply. And critically, you can say, "Stop selling my information to other companies," and the store cannot punish you for it by charging you more or refusing service.
That is essentially the CCPA in physical-world terms. The law turns data collection from a silent, one-sided transaction into a disclosed, negotiable, and revocable one — at least for California residents.
Core Formula
Think of CCPA compliance as a simple equation:
CCPA Exposure = (Applicability Threshold) × (Consumer Rights Obligations) × (Penalty Risk)
Breaking it down:
- Applicability Threshold: You are subject to CCPA if you do business in California AND meet at least one of these criteria:
- Annual gross revenue exceeding $25 million (adjusted periodically for inflation; the CPRA raised the threshold from the original $25M to approximately $26.625 million as of 2023).
- Buying, selling, or sharing personal information of 100,000 or more California consumers or households annually.
- Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.
- Consumer Rights Obligations: Four core rights — the right to know, the right to delete, the right to opt out of sale/sharing, and the right to non-discrimination.
- Penalty Risk: Up to $2,500 per violation for unintentional violations and up to $7,500 per intentional violation or violation involving minors' data. Data breaches affecting unencrypted personal information can trigger statutory damages of $100 to $750 per consumer per incident through a private right of action.
The formula matters because it tells you where your exposure is highest: if you sell data and serve minors, your per-violation cost multiplies by three.
Comparison with Related Terms
| Term | Jurisdiction | Key Difference from CCPA | Who It Affects Most |
|---|---|---|---|
| **GDPR** | EU/EEA | Broader lawful-basis framework; requires consent *before* collection; 72-hour breach notification; fines up to 4% of global revenue | Any business with EU customers |
| **CPRA** | California | Amends and expands CCPA; adds right to correct, limits use of sensitive data, creates the California Privacy Protection Agency (CPPA) | Same as CCPA, but with stricter enforcement |
| **VCDPA** | Virginia | No private right of action; applies to businesses meeting different thresholds; narrower definition of "sale" | Businesses operating in Virginia |
| **PIPEDA** | Canada | Consent-based; applies to private-sector organizations; no "opt-out of sale" concept because sale of data is less common | Canadian e-commerce and SaaS |
| **CalOPPA** | California | Older law; requires privacy policy disclosure but no deletion or opt-out rights | Websites collecting any personal data from Californians |
The practical takeaway: CCPA is the most enforcement-active U.S. state privacy law, and unlike GDPR, it does not require opt-in consent for most data collection — it requires disclosure and opt-out. That distinction trips up many international sellers.
Use Cases
1. DTC Shopify brand selling to California customers.
You collect emails, shipping addresses, and browsing behavior. You use a Facebook pixel and a Klaviyo integration. Under CCPA, you must:
- Post a privacy policy with a "Do Not Sell or Share My Personal Information" link.
- Honor opt-out requests within 15 business days.
- Disclose the categories of third parties receiving data (e.g., "advertising partners").
2. Cross-border Amazon FBA seller.
You may not think of yourself as a "data business," but if you run retargeting ads or use Amazon's customer data for email marketing, you are collecting and potentially sharing personal information. If you meet the thresholds, CCPA applies — even if your company is incorporated in Hong Kong or Shenzhen.
3. Subscription box service with a loyalty program.
You track purchase frequency, preferences, and referral behavior. If you sell that aggregated data to a market research firm, that is a "sale" under CCPA. You must offer an opt-out and cannot retaliate by downgrading the customer's loyalty tier.
4. SaaS tool with a California user base.
Even B2B companies are covered if they collect personal information of California residents (e.g., employee emails, login IPs). The "business-to-business" exemption expired under CPRA, so B2B data is now fully in scope.
Misconceptions
Misconception 1: "CCPA only applies to companies headquartered in California."
False. It applies to any for-profit entity doing business in California that meets the thresholds. A Shenzhen-based brand selling via Shopify to California customers is covered.
Misconception 2: "If I don't sell data, CCPA doesn't apply to me."
False. The right to know and right to delete apply regardless of whether you sell data. You still need a compliant privacy policy and a process for handling requests.
Misconception 3: "I can charge customers who opt out."
False. CCPA's non-discrimination clause prohibits charging different prices or providing different quality of service to consumers who exercise their privacy rights — unless the difference is reasonably related to the value of the data.
Misconception 4: "A cookie banner is enough."
False. A banner is only one piece. You need backend processes to verify identity, fulfill deletion requests, and log opt-outs. The California Privacy Protection Agency has signaled it will audit enforcement, not just respond to complaints.
Misconception 5: "CCPA is just GDPR with a different name."
False. GDPR requires a lawful basis for *all* processing and defaults to opt-in. CCPA defaults to opt-out for sale/sharing and does not require consent for most collection. The compliance workflows are fundamentally different.
Related Terms
- CPRA (California Privacy Rights Act): The 2020 ballot initiative that amended CCPA, effective 2023. Adds rights to correct, limit use of sensitive data, and creates the CPPA.
- CPPA (California Privacy Protection Agency): The enforcement body for CCPA/CPRA. Has subpoena power and can fine businesses directly.
- Do Not Sell or Share My Personal Information: The required link for opt-out requests. "Share" includes cross-context behavioral advertising, even if no money changes hands.
- Sensitive Personal Information (SPI): Under CPRA, includes SSN, driver's license, precise geolocation, racial/ethnic origin, health data, and sexual orientation. Consumers can limit its use.
- Service Provider vs. Third Party: A service provider processes data on your behalf under contract; a third party is anyone else. Selling to a third party triggers opt-out rights.
- Private Right of Action: CCPA's unique feature — consumers can sue directly after a data breach, with statutory damages of $100–$750 per person.
- Data Broker: A business that buys and sells personal information. California's Delete Act (2023) adds further registration and deletion requirements for data brokers.
Bottom line for DTC and cross-border operators: CCPA is not a checkbox. It is an operating system for customer data. If you serve California customers, you need a privacy policy that reflects reality, a functioning opt-out mechanism, a deletion workflow, and a vendor map showing where data flows. The fines are per violation, and the CPPA is funded and active. Treat it like sales tax compliance — boring, mandatory, and expensive to ignore.