Cybersecurity 101back-iconWhat is the California Consumer Privacy Act (CCPA)?

What is the California Consumer Privacy Act (CCPA)?

The California Consumer Privacy Act (CCPA) is a privacy law that gives California residents greater control over how businesses collect, use, share, and sell their personal information. Enacted in 2018 and effective from January 1, 2020, the CCPA established consumer privacy rights and imposed data-handling obligations on qualifying for-profit businesses that do business in California.

The CCPA is a major U.S. state privacy law that shaped privacy compliance obligations for many organizations handling California residents’ personal information.

What rights does the CCPA provide?

The CCPA grants consumers several rights regarding their personal information.

Consumer Right  Description 
Right to know  Request information about collected personal data 
Right to access  Obtain details about personal information held by a business 
Right to delete  Request deletion of certain personal information 
Right to correct*  Request correction of inaccurate personal information 
Right to opt out  Prevent the sale or sharing of personal information 
Right to non-discrimination  Receive equal service regardless of privacy requests 

*The right to correct was introduced through the California Privacy Rights Act (CPRA), which amended and expanded the CCPA.

These rights are designed to increase transparency and consumer control over personal data.

Who must comply with the CCPA?

The CCPA applies to for-profit businesses that collect personal information from California residents and meet specific eligibility thresholds.

Common thresholds include:

  • Annual gross revenues over $25 million.
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households.
  • Deriving 50% or more annual revenue from selling or sharing California consumers’ personal information.

Organizations that fall within the law’s scope must implement processes for handling consumer privacy requests and protecting personal information.

What information is covered by the CCPA?

The CCPA defines personal information broadly and covers many categories of consumer data.

Covered Data Examples

  • Names and addresses
  • Email addresses
  • Device identifiers
  • IP addresses
  • Geolocation data
  • Internet activity information
  • Commercial transaction records
  • Employment-related information (subject to applicable provisions)

Because the definition is broad, organizations must understand where they collect, store, process, and share personal information.

How Hexnode supports privacy and compliance initiatives

Privacy compliance requires visibility into the devices that access, store, and process business data.

Hexnode UEM helps organizations manage and secure endpoints through centralized device management, compliance monitoring, security policies, application management, device restrictions, encryption management, and remote management capabilities. By helping IT teams maintain device visibility, enforce security controls, and reduce unauthorized data exposure risks, Hexnode can support broader privacy and compliance initiatives, including those related to CCPA requirements.

CCPA vs CPRA

The California Privacy Rights Act (CPRA) expanded the original CCPA framework and introduced additional privacy protections.

CCPA  CPRA 
Established core consumer privacy rights  Expanded privacy protections 
Focused on personal information  Added protections for sensitive personal information 
Introduced opt-out rights  Expanded consumer control and enforcement 
Initially enforced by the California Attorney General  Created the California Privacy Protection Agency (CPPA), while enforcement authority is also retained by the Attorney General

Today, organizations often refer to CCPA compliance while incorporating the additional requirements introduced by CPRA.

Key takeaways

The California Consumer Privacy Act (CCPA) is a privacy law that gives California residents greater control over their personal information and requires qualifying businesses to provide transparency and consumer rights. Organizations subject to the law must implement appropriate privacy, security, and governance practices to support compliance and protect consumer data.

FAQs

No. Businesses outside California may still be subject to the CCPA if they collect or process personal information from California residents and meet applicable thresholds.