Get fresh insights, pro tips, and thought starters–only the best of posts for you.
The California Consumer Privacy Act (CCPA) is a privacy law that gives California residents greater control over how businesses collect, use, share, and sell their personal information. Enacted in 2018 and effective from January 1, 2020, the CCPA established consumer privacy rights and imposed data-handling obligations on qualifying for-profit businesses that do business in California.
The CCPA is a major U.S. state privacy law that shaped privacy compliance obligations for many organizations handling California residents’ personal information.
The CCPA grants consumers several rights regarding their personal information.
| Consumer Right | Description |
| Right to know | Request information about collected personal data |
| Right to access | Obtain details about personal information held by a business |
| Right to delete | Request deletion of certain personal information |
| Right to correct* | Request correction of inaccurate personal information |
| Right to opt out | Prevent the sale or sharing of personal information |
| Right to non-discrimination | Receive equal service regardless of privacy requests |
*The right to correct was introduced through the California Privacy Rights Act (CPRA), which amended and expanded the CCPA.
These rights are designed to increase transparency and consumer control over personal data.
The CCPA applies to for-profit businesses that collect personal information from California residents and meet specific eligibility thresholds.
Common thresholds include:
Organizations that fall within the law’s scope must implement processes for handling consumer privacy requests and protecting personal information.
The CCPA defines personal information broadly and covers many categories of consumer data.
Because the definition is broad, organizations must understand where they collect, store, process, and share personal information.
Privacy compliance requires visibility into the devices that access, store, and process business data.
Hexnode UEM helps organizations manage and secure endpoints through centralized device management, compliance monitoring, security policies, application management, device restrictions, encryption management, and remote management capabilities. By helping IT teams maintain device visibility, enforce security controls, and reduce unauthorized data exposure risks, Hexnode can support broader privacy and compliance initiatives, including those related to CCPA requirements.
The California Privacy Rights Act (CPRA) expanded the original CCPA framework and introduced additional privacy protections.
| CCPA | CPRA |
| Established core consumer privacy rights | Expanded privacy protections |
| Focused on personal information | Added protections for sensitive personal information |
| Introduced opt-out rights | Expanded consumer control and enforcement |
| Initially enforced by the California Attorney General | Created the California Privacy Protection Agency (CPPA), while enforcement authority is also retained by the Attorney General |
Today, organizations often refer to CCPA compliance while incorporating the additional requirements introduced by CPRA.
The California Consumer Privacy Act (CCPA) is a privacy law that gives California residents greater control over their personal information and requires qualifying businesses to provide transparency and consumer rights. Organizations subject to the law must implement appropriate privacy, security, and governance practices to support compliance and protect consumer data.
No. Businesses outside California may still be subject to the CCPA if they collect or process personal information from California residents and meet applicable thresholds.