Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · CCPA / CPRA
Reference · LeakTrace Intelligence Team

CCPA / CPRA.

California Consumer Privacy Act (as amended by California Privacy Rights Act)
At a glance
Jurisdiction
California
Breach reporting deadline
Notification to Attorney General for 500+ residents; individual notification "in the most expedient time possible"
Applies to
AllConsumer-Facing Businesses
Authoritative source
https://oag.ca.gov/privacy/ccpa
Last updated
August 5, 2026
## What it is The California Consumer Privacy Act (CCPA), effective January 1, 2020, is the first comprehensive US state consumer privacy law. Amended by the California Privacy Rights Act (CPRA) with substantive provisions effective January 1, 2023, it is now enforced by the California Privacy Protection Agency (CPPA) alongside the California Attorney General. ## Who it applies to For-profit businesses that do business in California, collect California consumers' personal information, and meet at least one of: - Annual gross revenues exceeding USD $25 million (2023 threshold; adjusted for inflation) — [VERIFY current threshold] - Buy, sell, or share the personal information of 100,000 or more consumers or households - Derive 50 percent or more of annual revenue from selling or sharing consumers' personal information ## Consumer rights - **Right to know** what personal information is collected, used, shared, or sold - **Right to delete** personal information held by businesses (with exceptions) - **Right to correct** inaccurate personal information (added by CPRA) - **Right to opt out** of the sale or sharing of personal information - **Right to limit** use and disclosure of sensitive personal information (added by CPRA) - **Right to non-discrimination** for exercising CCPA rights - **Right to portability** — receive personal information in a portable, machine-readable format ## Key business obligations - Provide a clear "Do Not Sell or Share My Personal Information" link on the homepage - Honour Global Privacy Control (GPC) signals as opt-out requests - Update privacy policies annually with specific CCPA disclosures - Execute contracts with service providers and contractors specifying processing limits - Conduct annual cybersecurity audits and risk assessments (CPRA — regulations still being finalized by CPPA) ## Breach notification and private right of action CCPA does not create a general breach reporting deadline of its own; California's separate breach notification statute (Cal. Civ. Code § 1798.82) applies. However, CCPA § 1798.150 creates a **private right of action** allowing consumers to sue for statutory damages of USD $100 to $750 per consumer per incident, or actual damages (whichever is greater), when nonencrypted and nonredacted personal information is exposed due to a business's failure to implement and maintain reasonable security procedures. Attorney General notification is required for breaches affecting more than 500 California residents. ## Penalties Civil penalties up to USD $2,500 per unintentional violation and USD $7,500 per intentional violation or violation involving a minor's information. Enforcement by the CPPA (administrative) and Attorney General (civil). The 30-day cure period was eliminated by CPRA for most violations (with some CPPA discretion). ## How LeakTrace aligns LeakTrace's monitoring focuses on the reasonable-security exposures that trigger CCPA § 1798.150 private actions — credential leaks, misconfigured public infrastructure, unencrypted data exposure. Evidence documentation supports both breach notification obligations and defence of "reasonable security" claims.
Key provisions
Cal. Civ. Code § 1798.100 — Right to know
Consumers can request the categories and specific pieces of personal information a business has collected about them.
Cal. Civ. Code § 1798.105 — Right to delete
Consumers can request deletion of personal information collected from them, subject to enumerated exceptions.
Cal. Civ. Code § 1798.120 — Right to opt out of sale/sharing
Businesses must provide a clear opt-out mechanism and honour Global Privacy Control signals.
Cal. Civ. Code § 1798.121 — Right to limit sensitive PI
CPRA-added right to limit use of sensitive personal information to what is necessary to perform services.
Cal. Civ. Code § 1798.150 — Private right of action
Statutory damages of USD $100 to $750 per consumer per incident for breaches caused by failure to maintain reasonable security.
Cal. Civ. Code § 1798.155 — Administrative penalties
Up to USD $7,500 per intentional violation or violation involving a minor's information.
Recent amendments & guidance
2023-01-01
CPRA substantive provisions in force — CPPA established, sensitive PI category, right to correct, right to limit added.
2023-07-01
CPRA enforcement began — CPPA and Attorney General empowered to enforce.
2025-01-14
CPPA finalized regulations on CCPA enforcement priorities including risk assessments and cybersecurity audits. [VERIFY current CCPA regulation status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs