California Consumer Privacy Act, as amended by the California Privacy Rights Act
Tier 1 In forceThe CCPA (2018) as amended by the CPRA (Proposition 24, 2020) is a single, consolidated California statute — the CPRA did not replace the CCPA, it amended and expanded it, and most CPRA changes took effect 1 January 2023. It is enforced by two bodies: the California Privacy Protection Agency (CPPA), a dedicated regulator created by the CPRA, and the California Attorney General. The most overstated fact in US privacy writing is the private right of action: it is NOT a general right to sue for any CCPA violation — it is limited to specified data-breach scenarios involving certain non-encrypted, non-redacted personal information.
Identity
- Citation
- Cal. Civ. Code sec. 1798.100 et seq.
- Jurisdiction
- United States
- Sub-jurisdiction
- California
- Type
- comprehensive
- Structure
- Title 1.81.5 of the California Civil Code; implementing regulations in the California Code of Regulations.
- Royal assent
- 28 June 2018
- Main commencement
- 1 January 2020
CCPA effective 1 January 2020; CPRA amendments effective 1 January 2023 (with a lookback to January 2022 for some data). New CPPA regulations on cybersecurity audits, risk assessments and automated decision-making take effect on a staged basis from 1 January 2026.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | None found — checked | Applies to qualifying businesses handling California residents' personal information; no sub-state carve-out. It is a single state statute. |
| 2 | Commencement | Asymmetry found | Phased: core CCPA from 2020, CPRA amendments from 2023, and new CPPA regulations (cybersecurity audits, risk assessments, ADMT) phasing in from 2026 with audit deadlines staggered by revenue (first audits due 2028-2030 depending on revenue band). |
| 3 | Sunset / mandatory review | None found — checked | No sunset. The CPRA removed the CCPA's original 30-day cure period, so businesses are expected to be compliant at all times rather than curing after notice. |
| 4 | Criminal liability | None found — checked | None found — checked. The CCPA/CPRA creates administrative penalties and a narrow private right of action, not criminal offences. There is no custodial or criminal track under the statute itself. |
| 5 | Civil liability | Asymmetry found | A limited private right of action exists under Cal. Civ. Code sec. 1798.150. It is triggered ONLY where a consumer's non-encrypted and non-redacted personal information (defined narrowly: name plus SSN, driver's licence/government ID, financial account with access code, or medical/health-insurance information) is subject to unauthorised access and exfiltration, theft or disclosure as a result of the business's failure to maintain reasonable security. Statutory damages are $100-$750 per consumer per incident, or actual damages if greater. It does NOT extend to disclosure, deletion or other CCPA obligations — those are regulator-enforced only. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | Two enforcers. The California Attorney General and the CPPA can both pursue administrative penalties of up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a consumer under 16. The CPPA additionally has audit and rulemaking authority. Each affected consumer can count as a separate violation, so penalties scale steeply. |
| 7 | Personal / director liability | None found — checked | None found — checked. The statute targets "businesses"; no distinct director/officer personal liability provision was identified. |
| 8 | Public vs private sector split | None found — checked | One regime for covered for-profit businesses; extensive entity- and data-level exemptions (HIPAA, GLBA, FCRA, employment/B2B historically) rather than a public/private split. |
| 9 | Legal-person coverage | Asymmetry found | Protects "consumers" (California residents / natural persons). Employee and B2B contact data were temporarily exempt but that exemption expired on 1 January 2023 under the CPRA, so employees, job applicants and B2B contacts are now covered — a change over time worth noting. |
| 10 | Exemptions — with conditions | Asymmetry found | The regime's shape is deference to federal sectoral statutes rather than case-by-case balancing: data already regulated under HIPAA, GLBA, FCRA or the DPPA is carved out at data level, and non-profits and sub-threshold companies fall outside "business" entirely. Triggers are status-based — is this data set governed by the named federal law — not necessity or prejudice tests. The employee/B2B exemption was time-limited and sunset on 2023-01-01, a trap for summaries written before the CPRA took effect. |
Regulatory enforcement
- Penalty ceiling
- Administrative penalties up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a minor under 16. Private-action statutory damages $100-$750 per consumer per incident for qualifying breaches.
Exemptions
Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.
sec. 1798.145 — Entity- and data-level exemptions
Trigger
Applies where the data or entity falls within a listed federal regime (e.g. information collected under HIPAA, GLBA, FCRA, or the Driver's Privacy Protection Act). Availability turns on whether the specific data set is already regulated by the named federal law, assessed data set by data set.
The employee/B2B exemption sunset on 1 January 2023 and is no longer available.
Live issues
Sources
- Secondary What Is the CCPA? California Consumer Privacy Act Cyberhaven
- Secondary The CCPA/CPRA's Private Right of Action TermsFeed
- Secondary Changes in Statutory Penalties and Private Right of Action under the CPRA Clarip
Never independently verified — seeded from the prototype.