P freeprivacypolicy.app
Guide

CCPA complete guide: California Consumer Privacy Act

CCPA, CPRA, and the California Privacy Protection Agency — what they ask of every operator.

Generate CCPA-compliant policy Free · no signup · hosted public URL

What changed with CPRA

The California Privacy Rights Act (CPRA) amended CCPA effective 1 January 2023. The four main additions: (1) the new "sensitive personal information" category and the "Right to Limit" disclosure, (2) the "Do Not Sell or Share" terminology — sharing now covers cross-context behavioural advertising, (3) the California Privacy Protection Agency (CPPA) as a dedicated regulator, and (4) the 12-month look-back data inventory.

Who has to comply

For-profit entities doing business in California that meet at least one threshold: $25M+ annual gross revenue, buy/sell/share PI of 100,000+ consumers/households, or derive 50%+ revenue from selling/sharing PI. Non-profits and government bodies are exempt.

The eleven categories of personal information

  1. Identifiers (name, email, IP, device ID)
  2. Customer records (signed-up customers, contact info)
  3. Characteristics of protected classifications (race, religion, etc.)
  4. Commercial information (purchase history)
  5. Biometric information
  6. Internet or other electronic network activity
  7. Geolocation
  8. Sensory data (audio, electronic, thermal)
  9. Professional or employment-related information
  10. Education information
  11. Inferences drawn from the above

The seven consumer rights

  • Right to know what is collected, used, disclosed, sold, or shared
  • Right to delete
  • Right to correct inaccurate information
  • Right to opt out of sale or sharing
  • Right to limit use of sensitive personal information
  • Right to data portability
  • Right to non-discrimination for exercising rights

Fines

$2,500 per violation, $7,500 per intentional violation or violation involving a minor. The Sephora fine ($1.2M, August 2022) was the first under CCPA. CPPA enforcement actions accelerated through 2024–2025.

Ready to publish?

Answer six questions, get a hosted public URL the App Store, Google Play, and ad networks accept. No credit card.

Generate CCPA-compliant policy

Frequently asked questions

Is "sharing" the same as "selling"?
No. "Selling" means exchanging PI for money or other valuable consideration. "Sharing" specifically covers cross-context behavioural advertising, even when no money changes hands. Both trigger the same opt-out link.
What is "sensitive personal information"?
Government IDs, financial account info, precise geolocation, racial/ethnic origin, religious beliefs, union membership, mail/email/text contents, genetic data, biometric data for ID, health information, sexual orientation. The Right to Limit applies to use beyond what is necessary to provide the service.

Related reading