JaxSuite AI logoJaxSuite AI

What Is the CCPA?

TL;DR

The CCPA, or California Consumer Privacy Act, is a state law giving California residents the right to know what personal information a business holds about them, to have it deleted or corrected, and to opt out of its sale or sharing. A business has 45 days to answer a verified request.

Who has to comply with the CCPA?

The law reaches for-profit businesses that do business in California and meet any one of three thresholds: annual gross revenue above 25 million dollars, buying selling or sharing the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Where the company is headquartered does not decide it.

Business contact data is in scope. The exemption that once covered B2B contacts and employee data expired on 1 January 2023, so a work email address belonging to a California resident is now treated like any other personal information. Reading thresholds against your own revenue and record counts is a question for counsel, and this page defines the term rather than answering it for you.

What rights does the CCPA give a person?

Five rights, plus a protection. A resident can request what personal information is held and how it is used, ask for deletion, ask for correction of inaccurate data, opt out of the sale or sharing of their data, and limit the use of sensitive personal information. A business may not retaliate against someone for exercising any of them.

The clock is 45 calendar days from a verified request. It can be extended by a further 45 days, for a total of 90, provided the person is told. That is a shorter window than the one month plus two months GDPR allows, which matters if one workflow is meant to serve both regimes.

How is the CCPA enforced?

Enforcement runs through the California Attorney General and the California Privacy Protection Agency. Penalties are set per violation rather than per incident: up to 2,500 dollars for a violation, and up to 7,500 dollars for an intentional violation or one involving the personal information of a consumer the business knows to be under 16. Because a violation is counted per affected consumer, the arithmetic scales with list size.

A separate private right of action exists, but only for certain data breaches of unencrypted personal information, where a consumer may recover statutory damages capped at 750 dollars per incident or actual damages if those are higher. Ordinary CCPA failures are not privately actionable, which is why the regulators are the practical audience for a compliance programme.

FAQ

Frequently asked questions

  • Yes. The temporary exemption for business contact information lapsed on 1 January 2023, so a work email address, job title or work phone number belonging to a California resident is personal information under the CCPA and carries the same access, deletion and opt-out rights as consumer data.