Skip to main content
Explainer · Updated August 26, 2026

What Is CCPA? California Privacy Law for Data-Broker Questions

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents defined rights over personal information held by covered businesses. Rights, exemptions, request verification, response periods, and enforcement consequences depend on the statute and current regulations; the page below separates those rules from California\'s data-broker-specific Delete Act.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 26, 2026

At a glance

Full name
California Consumer Privacy Act, amended by CPRA
Effective dates
CCPA: Jan 2020 · CPRA: Jan 2023
Covers
CA residents’ personal info held by businesses meeting thresholds
Response timing
10-business-day receipt confirmation; 45-day response for delete/correct/know requests; up to 15 business days for opt-out/limit requests
Enforcement
California Privacy Protection Agency + AG
Current adjusted fines
Up to $2,663 per violation · $7,988 for an intentional violation or a violation involving a consumer known to be under 16, as specified by law

Who does the CCPA apply to?

A business is covered if it collects California residents’ personal information and meets any one of these thresholds:

  • Has annual gross revenue of at least $26.625 million under the current CPPA-adjusted threshold
  • Buys, sells, or shares the personal information of 100,000+ California residents or households annually
  • Derives 50% or more of annual revenue from selling or sharing personal information

An out-of-state business may be covered when the statutory definition and threshold are met, but location alone does not decide coverage. The CPPA also describes additional categories and exceptions; check the current statute and regulations rather than treating the three bullets as a complete applicability test.

What rights does the CCPA give you?

Right to know

What categories and specific pieces of personal information a business has collected about you, sources, purposes, and third parties it shares with.

Right to delete

Request deletion of personal information collected from you, subject to verification and statutory exceptions. Covered requests generally have a 45-day substantive response period.

Right to correct

Demand inaccurate personal information be corrected. Added by CPRA (effective 2023).

Right to opt out of sale or sharing

Direct a covered business to stop selling or sharing personal information where the CCPA applies. Use the business's designated method or an applicable opt-out preference signal.

Right to limit use of sensitive personal info

Restrict use of SSN, precise geolocation, biometric data, contents of non-business communications, and other sensitive categories.

Right to non-discrimination

Businesses generally cannot deny service, charge different prices, or provide different quality of service because you exercised a CCPA right, subject to statutory financial-incentive and data-value exceptions.

Right to data portability

Receive personal information in a portable, usable format to transfer to another business.

Certain ADMT-related rights

For certain significant decisions involving automated decisionmaking technology, current CPPA materials describe notice, access to meaningful information, and an opt-out where applicable. A human-review appeal can be relevant when a business relies on that exception; compliance dates and other exceptions are phased.

How do you exercise your CCPA rights?

  1. 1

    Identify the business that holds your data (or use OfflistMe, which pre-targets 1000+ known brokers).

  2. 2

    Submit a verifiable consumer request through the business's designated method or methods. The available channels depend on how the business interacts with consumers, so follow its current privacy policy or request page rather than assuming a particular channel.

  3. 3

    For requests to delete, correct, or know, the business generally must confirm receipt within 10 business days and respond within 45 calendar days; it may extend once to 90 days with notice. Opt-out-of-sale-or-sharing and sensitive-personal-information limit requests must be handled as soon as feasibly possible, up to 15 business days.

  4. 4

    If the business denies or ignores your request, ask for the reason and preserve the request, response, and dates. Use any request-specific appeal route required by current rules—for example, an ADMT appeal where a business relies on a human-review exception—then submit a complaint to the California Privacy Protection Agency or another appropriate authority when warranted.

How to Use CCPA to Opt Out of Data Brokers

Data brokers may collect and sell personal information about consumers with whom they do not have a direct relationship. California\'s data-broker definition and deletion mechanism come from the separate Delete Act, while the CCPA supplies a different framework for covered businesses and consumer requests. Check which statute, definition, and exception fits the provider and request.

Here is how to use your CCPA deletion rights against data brokers:

  • Use the applicable request: If the CCPA applies, identify whether you are asking to know, delete, correct, opt out of sale or sharing, or limit sensitive-information use.
  • State the scope: Ask for deletion under § 1798.105 only when that right and the request facts fit. A provider may apply verification and statutory exceptions, so a request is not proof of a required outcome.
  • Separate providers and outcomes: A request to one provider does not automatically change a source record, another broker\'s copy, or a search-engine result. Keep the request and response, then verify the specific provider route separately.

CCPA Delete Act (SB 362) + DROP Platform

California’s Data Broker Delete Act (SB 362) is separate from the general CCPA rights framework. The CPPA says DROP lets a California consumer submit one verifiable request directing every data broker that maintains related personal information held by the broker, its service provider, or contractor to delete it, subject to legal exceptions. Beginning August 1, 2026, data brokers must access the mechanism at least once every 45 days and process requests as required by the law; the CPPA says a broker must report the status of each request in DROP within 45 days after retrieving it. SB 361 (2025, Chapter 466) expands data-broker registration disclosures, including whether brokers collect specified sensitive-data categories and whether they shared or sold data to specified recipients.

Generate requests in under 60 seconds

Generate CCPA-aware deletion request drafts for $9 one-time

OfflistMe prepares user-reviewed deletion request drafts for 1000+ catalog profiles. Review the route and wording, then send from your own inbox; a draft is not a legal determination, provider acceptance, or deletion outcome.

Illustrative CCPA Rights & Fine-Limit Tools

Compare recorded rights fields against selected state privacy regimes and explore illustrative CCPA fine-limit inputs. These tools cannot decide coverage, verification, an exemption, a violation, or an actual penalty in a specific matter.

Primary sources and update boundary

Check the CPPA consumer FAQ, current CCPA statute, current monetary-threshold table, California Civil Code § 1798.130, and CPPA data-broker guidance, Delete Act regulations announcement, and CPPA complaint portal, CPPA CCPA and ADMT updates, and chaptered SB 361 text for current scope, timing, exceptions, enforcement, and DROP requirements. Reviewed August 26, 2026. This page is general information, not legal advice or a determination that CCPA applies to a particular request.

Does CCPA apply to your profession or state?

CCPA rights are tied to California residency and the statute\'s coverage rules. A provider may voluntarily offer a broader route, but do not treat a CCPA citation as a universal right for every state. Your profession and state may also affect whether separate safety or privacy statutes apply.

Frequently Asked Questions

What does CCPA stand for?

+

CCPA stands for the California Consumer Privacy Act of 2018, codified at California Civil Code § 1798.100 et seq. It was substantially amended by the California Privacy Rights Act (CPRA, Proposition 24, 2020), which took effect January 2023. The combined current-state citation is "CCPA/CPRA."

Who does CCPA apply to?

+

CCPA coverage depends on the statutory definition of a covered business and other applicable categories or exceptions. The CPPA currently describes thresholds including annual gross revenue of at least $26.625 million (effective January 1, 2025), buying, selling, or sharing personal information of 100,000 or more California residents or households, or deriving at least 50% of annual revenue from selling or sharing California residents' personal information. The law also covers some controlled entities, joint ventures, and voluntarily certified entities. A business outside California is not covered merely because its website is accessible there; the statutory scope and facts matter.

What rights does CCPA grant?

+

CCPA grants California residents: the right to know what personal information a business has collected; the right to delete that information; the right to correct inaccurate information (added by CPRA); the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; the right to non-discrimination for exercising CCPA rights, subject to statutory financial-incentive and related exceptions; and the right to data portability. Current CPPA materials also describe notice, access-to-meaningful-information, and, where applicable, opt-out rights for certain significant decisions involving automated decisionmaking technology (ADMT); those requirements have phased compliance dates and exceptions.

How long does a business have to respond to a CCPA request?

+

For requests to know, delete, or correct, the CPPA says a business must confirm receipt within 10 business days and substantively respond within 45 calendar days. One additional 45-day extension may be available with notice. Opt-out-of-sale-or-sharing and sensitive-personal-information limit requests must be handled as soon as feasibly possible, up to 15 business days.

What are CCPA penalties?

+

The CPPA's current monetary-threshold page lists administrative fines of up to $2,663 per violation and $7,988 for each intentional violation or for violations involving personal information of consumers the violator actually knows are under 16, effective January 1, 2025. A separate private right of action can apply to certain data breaches under § 1798.150; the current adjusted statutory-damages range is $107–$799 per consumer per incident or actual damages, whichever is greater. These are upper statutory figures, not an automatic award or penalty in every dispute.

What is the difference between CCPA and CPRA?

+

CPRA (Proposition 24, 2020) is an amendment to CCPA whose operative provisions took effect January 2023. It added the right to correct, the right to limit use of sensitive personal information, made opt-out rights expressly cover sale and sharing (including sharing for cross-context behavioral advertising), and created the California Privacy Protection Agency as an enforcement body. It also changed definitions, notices, exemptions, and other rules; the current statute and regulations control rather than a short historical summary.

Do CCPA rights apply outside California?

+

The CCPA rights described here are for California residents when the statutory requirements are met. A provider may voluntarily offer a broader process, but a non-California resident should not assume that citing the CCPA creates the same legal right. Use the law and request route that apply to your location and relationship with the provider.

How do I file a CCPA complaint?

+

You can submit a privacy complaint through the California Privacy Protection Agency's current complaint portal. The CPPA says it enforces the CCPA and its regulations; the California Attorney General also provides consumer-privacy information and complaint options. Preserve the request, provider response, dates, and supporting evidence before escalating.

Which state laws are modeled on CCPA?

CCPA was the first comprehensive US state privacy law. Later state privacy statutes often overlap with it, but each has its own rules for scope, rights, cure periods, and enforcement.

Related concepts & guides