Back to blog

What Is the CCPA? Key Points of the California Consumer Privacy Act

Shusaku Yosa

CCPAとは?カリフォルニア州消費者プライバシー法の要点

If you run a website aimed at overseas audiences, or use cookies and pixels for ad delivery, the CCPA is hard to avoid. It is a California state law, yet it can apply to companies based in Japan. This article covers what the CCPA is, who it applies to, the rights it grants consumers, the traps marketers most often fall into, and the key points of the amendments that took effect in January 2026.

What Is the CCPA?

The CCPA (California Consumer Privacy Act) was enacted in 2018 and took effect in January 2020, making it the first comprehensive consumer privacy law in the United States. It gives California consumers the right to know what personal information a business holds, to have it deleted, and to stop it from being sold — and it places corresponding disclosure and response obligations on businesses.

The CPRA Amendments and the CPPA Regulator

The CCPA was substantially amended by the CPRA (California Privacy Rights Act). The CPRA came into full effect in January 2023, adding new rights such as the right to correct and the right to limit the use of sensitive personal information, and establishing a dedicated regulator: the CPPA (California Privacy Protection Agency).

In practice, when people say "CCPA" today, they generally mean the full set of rules as amended by the CPRA. The CPRA is not a separate law standing alongside the CCPA — it is an amending statute that rewrote it. Holding that in mind avoids a lot of confusion.

Does It Apply to Companies Outside California?|Scope

The CCPA applies based on whether you handle the personal information of California consumers — not on where your company is located. A company headquartered in Japan can therefore fall in scope. Specifically, it applies to for-profit businesses meeting any one of the following.

  1. Revenue: Annual gross revenue above roughly USD 26.62 million (this threshold is adjusted for inflation and revised periodically).
  2. Data volume: Buying, selling, sharing, or processing the personal information of 100,000 or more California consumers or households per year.
  3. Revenue mix: Deriving 50% or more of annual revenue from selling or sharing personal information.

The 100,000 threshold is a lower bar than most people assume. If you run a website or app aimed at the US market and use tracking for advertising or analytics, you may already have crossed it without realizing.

The Main Rights Granted to Consumers

  • Right to know: Consumers can request disclosure of what personal information you collected, for what purpose, and who you disclosed it to. The 2026 amendments extended the lookback period for these disclosures back to January 2022.
  • Right to delete: Consumers can request deletion of the personal information collected about them. You must also pass the deletion request on to your service providers.
  • Right to correct: Consumers can request correction of inaccurate personal information (added by the CPRA).
  • Right to opt out of sale and sharing: Consumers can refuse the "sale" or "sharing" of their personal information. Businesses are required to provide a "Do Not Sell or Share My Personal Information" link.
  • Right to limit use of sensitive personal information: Consumers can require that data such as race, precise geolocation, and health information be used only as strictly necessary (added by the CPRA).
  • Right to non-discrimination: Consumers cannot be penalized on price or service quality for exercising their rights.

What Marketers Must Watch Most: "Sale" and "Sharing"

The most widely misunderstood term in the CCPA is "sale." A sale under the CCPA is not limited to exchanges of money. It covers transfers made for other valuable consideration too — which means passing data to an advertising platform can be treated as a sale.

The CPRA then added the concept of "sharing," which refers to disclosures made for cross-context behavioral advertising — the kind of targeting that follows a user from site to site. In other words, retargeting via third-party cookies and advertising pixels can qualify as "sharing" and be subject to opt-out, even where no consideration changes hands. This is the biggest gap between the CCPA and the intuitions most teams carry over from Japan's Act on the Protection of Personal Information.

Honoring GPC (Opt-Out Preference Signals)

GPC (Global Privacy Control) is a mechanism by which a browser or extension automatically transmits a user's intent to refuse the sale or sharing of their data. Under the CCPA, receiving this signal means you must treat it as a valid opt-out request. Ignoring GPC has been one of the regulator's key enforcement focuses in recent years. Don't assume a consent banner is enough — verify technically that the signal actually reaches your advertising tags.

Key Amendments That Took Effect in January 2026

Regulations finalized by the CPPA in September 2025 began applying in stages from January 1, 2026. The CCPA is shifting from a phase of "get your policies in order" to one of "prove your operations and controls."

  • Dark patterns banned, choices must be symmetrical: Inaction — closing a pop-up, clicking outside it, navigating away — does not count as consent. "Accept" and "Decline" buttons must be presented with equal prominence, including size and color.
  • Visible opt-out confirmation: Users must be able to see, in a visible form, that their opt-out has been received and honored.
  • Mandatory risk assessments: Processing that poses significant risk to consumers — selling or sharing personal information, handling sensitive information, profiling — now requires a documented risk assessment. Activities predating 2026 must be assessed by the end of 2027, with summaries submitted to the regulator by April 2028.
  • Rules for ADMT (automated decision-making technology): Where AI or similar technology automates significant decisions — employment, credit, education, housing — you must provide pre-use notice, an opt-out, and an explanation. Existing uses must be compliant by January 1, 2027.
  • Cybersecurity audits: Businesses above a certain size must undergo annual audits by an independent auditor and file certifications with the regulator. These phase in from 2028 through 2030 depending on revenue.

Key Differences from the GDPR

  • The consent model: The GDPR generally requires prior consent (opt-in). The CCPA is built around opt-out: you may use the data until the consumer says no (with an opt-in exception for those under 16).
  • Who is covered: The GDPR applies regardless of company size. The CCPA applies to for-profit businesses that cross thresholds for revenue, data volume, and the like.
  • How penalties work: The GDPR imposes large fines scaled to global revenue. The CCPA accumulates penalties on a per-violation basis.

Penalties for Non-Compliance

CCPA violations carry civil penalties assessed per violation, with higher amounts for intentional violations and those involving minors (the figures are adjusted for inflation). The per-violation amount may look modest, but it multiplies by the number of consumers affected — so totals escalate quickly.

Another defining feature of the CCPA is that consumers have a private right of action (and thus class action exposure) for certain data breaches. The CPPA has been sharpening its enforcement posture in recent years, including joint investigations with regulators in other states.

Steps Companies Should Take

  1. Determine whether you're in scope: Establish how much California resident data you actually handle. Don't move forward with this left vague.
  2. Take inventory of your data: What information do you collect, from where, into which tools, and shared with whom? Map every destination — ad tags, marketing automation, CDP, analytics.
  3. Get your notices and policy in order: Your notice at collection and privacy policy should state what you collect, why, how long you keep it, who you disclose it to, and how consumers exercise their rights.
  4. Implement the opt-out path: Add the opt-out link and make sure you can receive and honor GPC signals. Wire your consent management platform (CMP) to your tag manager, then verify that a refusal genuinely stops tags from firing.
  5. Build a workflow for rights requests: Set up an intake channel for access, deletion, and correction requests, and document the process end to end: identity verification, deadline tracking, and passing requests on to service providers.
  6. Keep records: From 2026, the question is whether you can prove you did the work. Retain risk assessments and request-handling records in a form that will withstand an audit.

Summary

The CCPA is the first comprehensive privacy law in the US, giving California consumers control over their personal information. The CPRA amendments expanded those rights, and the CPPA now enforces them. Companies based outside California, including in Japan, can fall in scope once they handle enough California resident data.

For marketing teams, two points matter most: data transfers for advertising can count as "sale or sharing" even with no money involved, and GPC signals must be honored at a technical level. The 2026 amendments moved the rules from "have your documents in order" to "be able to prove your operations." Start by taking inventory of how data flows through your stack, and checking what is actually being passed downstream of your advertising tags.

Note: This article is provided for general informational purposes only and does not constitute legal advice. Laws and regulations are subject to change. Always consult primary sources for the latest requirements and seek professional counsel regarding whether and how they apply to your business.

Back to blog