Analytics and Tracking

CCPA and CPRA

Also called California Consumer Privacy Act, California Privacy Rights Act

California's privacy laws, built on an opt-out model rather than the up-front permission Europe requires.

Quick facts: CCPA and CPRA

Category
Analytics and Tracking
Also called
California Consumer Privacy Act, California Privacy Rights Act
Level
Intermediate
Affects
Remarketing setup, privacy notice wording, data subject requests
Where to see it
Ad platform data restriction settings, consent platform regional rules, privacy notice
In this article4
  1. How CCPA and CPRA work
  2. Why CCPA and CPRA matter
  3. Where CCPA and CPRA go wrong
  4. How to act on it

How CCPA and CPRA work

The California Consumer Privacy Act gave residents of the state rights over the personal information businesses hold about them. The California Privacy Rights Act amended and extended it, adding a category for sensitive personal information, a right to correct records, and a dedicated agency to write rules and enforce them. They are usually discussed as one regime because that is how they now operate.

Coverage is not universal. The laws reach businesses above a certain size, businesses handling personal information at scale, or businesses that make most of their revenue from selling it. Where they apply, residents can ask what you hold, ask you to delete or correct it, opt out of the sale or sharing of it, and limit how sensitive information is used. The definitions of “sale” and “sharing” are broad: passing identifiers to an advertising platform for cross-context behavioural advertising can count even when no money changes hands.

Why CCPA and CPRA matter

The default runs the opposite way to Europe. You are generally allowed to collect first, but you must offer a clear, working exit and honour it promptly. Businesses that built their setup around a European-style banner often have the mechanics of blocking and none of the mechanics of opting out.

The part that catches marketers is the browser signal. California requires businesses to respect an automated opt-out preference sent by the visitor’s browser, so a person can decline once and have it apply everywhere without touching your interface at all. If your tags ignore that signal, your consent design is irrelevant.

Where CCPA and CPRA go wrong

The most common mistake is stating “we do not sell data” while running remarketing pixels that hand identifiers to advertising platforms. Under these definitions that is often sharing, and the declaration becomes a false statement in your own privacy notice.

The second is an opt-out link that exists but leads to a form demanding a great deal of identification before it will act. Verification has limits, and an obstacle course is treated as a refusal to comply. The third is forgetting that requests can arrive by any reasonable route — an email to your general address counts, whether or not it uses the wording on your website.

How to act on it

Decide honestly whether your advertising tags amount to sharing; for most sites running remarketing, they do. Then publish the opt-out route where a visitor can find it, wire it to the data restriction settings your ad platforms provide, and confirm the browser preference signal is detected and acted on rather than logged and ignored.

After that, keep a record of requests and how quickly you answered them, and make sure your privacy notice describes the categories you collect and who receives them. A quick review of what your tags actually transmit — the same ground a tracking audit covers — usually tells you more than a legal template will.

Do and do not

Do

  • Offer a visible route to opt out of sharing
  • Respect the browser's automated opt-out preference signal
  • List the categories you collect and who receives them

Do not

  • Claim you never sell data while running remarketing pixels
  • Demand excessive identification before honouring a request
  • Ignore requests that arrive outside your official form

Questions people ask about this

Do these laws apply to a business outside the United States?

They can, because the test is whether you do business in California and meet one of the size or activity thresholds, not where your office is. A small consultancy with occasional California clients is usually below them. An online shop selling steadily into the state, or a site collecting large volumes of visitor data, should take proper advice rather than assume.

Do I need a cookie banner for California?

Not in the European sense. California is built on opting out, so what matters is a clear route to decline the sale or sharing of personal information, respect for the automated browser preference signal, and a privacy notice that describes what you collect and who receives it. Many sites run one banner that handles both regimes by detecting the visitor's region.

Does running remarketing count as selling data?

Often it counts as sharing, which carries the same opt-out obligation. Handing an identifier to an advertising platform so it can show your ads to that person elsewhere is exactly the activity the definition was written for, and no payment needs to flow for it to apply. Check what each of your tags transmits before claiming otherwise in a notice.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.