Chykalophia Docs
Compliance

CCPA & CPRA basics for businesses serving California

What California's consumer privacy law means for your website, who it applies to, and the practical steps we take to help you align with it.

Difficulty
Beginner

California has one consumer privacy law that you will see called by two names. The California Consumer Privacy Act (CCPA) gave California residents new rights over their data in 2020. The California Privacy Rights Act (CPRA) then amended the CCPA rather than replacing it, expanding those rights from 1 January 2023.

If you do business with California residents — or if California residents visit and use your website — this law may apply to you.

This is not legal advice

Chykalophia is a design and web agency, not a law firm. This article describes CCPA and CPRA concepts and best practices we follow in our work. It is not legal advice. Laws change, and your specific situation may have requirements beyond what we cover here. Please consult a qualified attorney for binding compliance decisions.

Quick summary

The CCPA, as amended by the CPRA, gives California residents rights over their personal data, including the right to know what data is collected, the right to opt out of its sale or sharing, and the right to delete it. It applies to for-profit businesses above certain size thresholds. Key steps include: publishing a clear privacy policy, adding a "Do Not Sell or Share My Personal Information" link, and honoring opt-out and deletion requests. We help implement the technical pieces when we build your site.

The two names, briefly explained

CCPA (California Consumer Privacy Act) — Signed into law in 2018, effective 2020. Gave California residents the right to know about, access, and delete the personal information businesses collect about them. Also created the right to opt out of the "sale" of personal data.

CPRA (California Privacy Rights Act) — A 2020 ballot measure that significantly expanded the CCPA. It added new rights (like the right to correct inaccurate data), created the California Privacy Protection Agency (CPPA) to enforce the law, and introduced tighter rules around "sensitive personal information."

In practice there is one set of rules to follow: the CCPA as amended by the CPRA. The California Attorney General's office puts it plainly — the CPRA "amends the CCPA; it does not create a separate, new law" — and refers to the result as the CCPA, or the CCPA as amended.

Does this apply to my business?

The CCPA/CPRA applies to for-profit businesses that meet at least one of these thresholds:

ThresholdDetails
RevenueGross annual revenue over $26,625,000 for the previous calendar year
Data volumeBuy, sell, or share the personal information of 100,000 or more California residents or households
Revenue from dataDerive 50% or more of annual revenue from selling or sharing consumers' personal information

The revenue figure moves

The law set that revenue threshold at $25 million, and requires it to be adjusted for inflation in every odd-numbered year. It rose to $26,625,000 on 1 January 2025. Check the California Privacy Protection Agency's threshold page for the current figure before you rely on it. And even if your business is under the thresholds today, building privacy-respecting practices early is always easier than retrofitting them later.

Nonprofit organizations and government agencies are generally outside the CCPA. If you are a healthcare provider subject to HIPAA or a financial institution subject to GLBA, different rules or exemptions may apply. Talk to a lawyer about your specific situation.

What California residents have the right to do

Under CCPA/CPRA, California residents can:

  • Know what personal information you collect, use, share, or sell
  • Access a copy of the personal information you hold about them
  • Delete their personal information (with some exceptions)
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of their personal information
  • Limit the use of their sensitive personal information
  • Not be discriminated against for exercising any of these rights

You must respond to verified requests within 45 days (with a possible 45-day extension if you notify the person).

What "selling" data means under CCPA

Under CCPA, "selling" data has a broader meaning than the everyday use of the word.

It includes disclosing or making available personal information to a third party in exchange for money or other valuable consideration. This can include:

  • Providing data to advertising networks in exchange for targeted ad access
  • Sharing behavioral data with data brokers
  • Certain data exchanges with business partners

The CPRA added a second, separate term: "sharing." That covers handing personal information to a third party for cross-context behavioural advertising — targeting someone based on their activity across other sites and apps — whether or not any money changes hands. Because it needs no payment, "sharing" can apply even when you are certain you never sold anything.

Neither term covers passing data to a service provider or contractor who processes it on your behalf (like your email platform or CRM), as long as they are contractually bound to use the data only for the services they provide.

Practical requirements for your website

Privacy policy updates

Your privacy policy must disclose:

  • The categories of personal information you collect
  • The purposes for collecting it
  • The categories of third parties you share it with
  • Whether you sell or share personal data, and to whom
  • The rights California residents have and how to exercise them
  • A dedicated privacy rights request contact (email or web form)

If your business sells or shares personal information as defined under CCPA, the law requires a clear and conspicuous link on your homepage titled "Do Not Sell or Share My Personal Information," leading to a page where someone can opt out. In practice this link usually sits in the footer, which appears on every page.

If you also use sensitive personal information beyond the purposes the law allows, you need a second link titled "Limit the Use of My Sensitive Personal Information." The law gives you two alternatives to running both:

  • Use one clearly labelled link that does both jobs, or
  • Skip the links entirely and instead honour an opt-out preference signal sent by the visitor's browser or extension, such as Global Privacy Control. If you take this route you have to actually act on the signal.

Which route fits you is a legal decision, so confirm it with your lawyer before we build it.

Many advertising and analytics tools effectively "share" data under CCPA's definition. A properly configured cookie consent tool — one that lets visitors opt out of tracking — is the standard technical approach.

See our guide on cookie consent law for how this works.

Data request process

You need a way for California residents to submit requests (to access, delete, or correct their data) and a process to handle them within the required timeframes.

What we do to help

When we build or maintain your website, we:

  • Implement a cookie consent tool that supports opt-out preferences
  • Add the required footer links if they apply to your business
  • Ensure your site uses SSL to protect data in transit
  • Help you keep tracking tool documentation current for your privacy policy

The legal side is yours

Determining whether CCPA/CPRA applies to your business, drafting compliant privacy policy language, and establishing your internal data request process are legal tasks. We handle the technical implementation — the law firm handles the legal obligations.

Common pitfalls

  • Thinking it only applies to California businesses. The law is about California residents, not where your business is. If someone in California visits your site, the law can apply.
  • Not updating your privacy policy. Adding a new analytics tool or ad platform without updating your privacy policy can create a compliance gap.
  • Ignoring the "sharing" definition. Many businesses assume they don't "sell" data because they don't receive direct payment. But sharing data with advertising networks for targeted ad access can count as "sharing" under CPRA.
  • No process for requests. You must be able to respond to data rights requests. A generic contact form is a starting point; a dedicated privacy request form is better.
  • Treating CCPA as separate from GDPR. If you need to comply with both, a properly configured consent tool can often handle both at once.

Common questions

Do I need to comply if I'm a small business?

If your gross annual revenue is under the CCPA's revenue threshold ($26,625,000 as of 1 January 2025, and adjusted for inflation in odd-numbered years), you don't buy, sell, or share the personal information of 100,000 or more California residents or households, and you don't earn 50% or more of your revenue from selling or sharing personal information, the formal thresholds don't technically apply. But privacy-aligned practices are still a good idea for trust and future readiness. Consult a lawyer to confirm your situation.

Does Google Analytics count as 'selling' data?

Using Google Analytics for your own site analytics generally doesn't constitute selling data. However, if you use Google Ads features or enable Google signals, data may be shared with Google's advertising network in ways that could count as "sharing" under CPRA. A privacy lawyer or your consent tool vendor can help you assess this.

What is 'sensitive personal information' under CPRA?

The CPRA introduced extra protection for a defined subset of personal information, and California has added to that list since. It includes government identifiers such as Social Security numbers; account log-ins and payment card numbers together with the security code or password; precise geolocation; the contents of mail, email, and text messages, unless your business is the intended recipient; genetic data; biometric information used to identify someone; information about health, sex life, or sexual orientation; and information about racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership. If your site collects any of these, you have additional obligations — talk to a lawyer.

How do I handle a deletion request?

When a California resident submits a verified deletion request, you must delete the personal information you hold about them (with some exceptions, such as data needed to complete a transaction or comply with a legal obligation). You also need to instruct your service providers to delete it. Document your process and keep records of requests.

Is CCPA the same as GDPR?

They overlap in spirit — both protect people's personal data — but they differ in scope, definitions, and requirements. GDPR is broader and more prescriptive; CCPA/CPRA is specifically focused on California residents. If you serve EU visitors as well, you may need to address both.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page