CyberGlossary

Compliance & Frameworks

CCPA

Also known as: California Consumer Privacy Act, CPRA

Definition

The California Consumer Privacy Act, a U.S. state privacy law granting California residents rights over their personal information held by businesses.

The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CPRA) in 2020 and enforced since 2023 by the California Privacy Protection Agency (CPPA), is the leading U.S. state-level privacy law. It applies to for-profit businesses that collect personal information about California residents and meet thresholds for revenue, data volume, or sales of personal information. The law grants consumers rights to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. Businesses must publish a privacy notice, provide opt-out mechanisms, and contractually bind service providers and contractors.

Examples

  • A large U.S. retailer publishing a "Do Not Sell or Share My Personal Information" link on its website.
  • A SaaS company executing a CCPA service-provider addendum with its data processors.

Related terms