CCPA

CCPA (California Consumer Privacy Act) gives California residents rights over the personal information businesses collect about them, including the right to know what's collected, request deletion, and opt out of its sale or sharing. The CPRA later expanded these rights and created a dedicated enforcement agency.

Before most US privacy laws existed, California passed one that became the template for a dozen more. Any company serving California residents, including through an AI-powered support experience, operates under its rules.

What is CCPA?

The California Consumer Privacy Act, effective 2020, gives California residents specific rights over the personal information that businesses collect about them: the right to know what's been collected, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the sale or sharing of their data.

The California Privacy Rights Act (CPRA), which took effect in 2023, expanded these rights further, added a new category for "sensitive personal information" with extra protections, and created the California Privacy Protection Agency (CPPA) as a dedicated enforcement body. In practice, "CCPA" is now generally used to mean the law as amended by CPRA.

Why CCPA Matters

CCPA was the first comprehensive consumer privacy law in the US, and it directly shaped privacy legislation later passed in states including Virginia, Colorado, and Connecticut. For companies operating nationally, it's often the strictest state-level bar to clear.

  • Broad applicability: covers any for-profit business doing business in California that meets revenue or data-volume thresholds, not just California-headquartered companies
  • Opt-out model: unlike GDPR's consent-first approach, CCPA generally lets processing continue until a consumer actively opts out of sale or sharing
  • Defined roles: the law distinguishes a "business" (which determines why and how data is processed) from a "service provider" (a vendor processing data on a business's behalf, contractually barred from using it for its own purposes)

How CCPA Works

  1. The business identifies what personal information it collects and why, and discloses this in a privacy policy
  2. It classifies vendors as service providers, contractors, or third parties, based on how they may use the data
  3. Consumers can submit verifiable requests to know, delete, or correct their information, or to opt out of sale/sharing
  4. The business must respond to verified requests within statutory timelines, generally 45 days, extendable once
  5. Businesses that sell or share personal information must post a "Do Not Sell or Share My Personal Information" link where required

CCPA vs GDPR

CCPA and GDPR share a broad goal, giving individuals more control over their data, but differ in mechanism: CCPA is opt-out by default and scoped to California, while GDPR requires a lawful basis before processing begins and applies across the EU regardless of company location. A company operating in both regions typically needs separate, though overlapping, compliance programs for each.

Frequently Asked Questions

Does CCPA apply to business-to-business data?

Yes, since the CPRA amendments took effect. Earlier exemptions for employee and B2B contact data have phased out, bringing that data under the same consumer rights framework.

What's the difference between a "business" and a "service provider" under CCPA?

A business determines the purposes and means of processing personal information and bears the primary compliance obligations. A service provider, such as a software vendor, processes data only on the business's behalf and is contractually restricted from using it for its own purposes.

Related Terms

The #1 AI Agent for all your customer service