CCPA Compliance Explained for Business Owners Right Now

Business owner arranging compliance documents

If your business hits any one of three CCPA thresholds, revenue, data volume, or revenue from selling personal information, you have to provide specific notices, honor a defined set of consumer rights, and back it all up with real request-handling and technical controls. That’s the whole ballgame in one sentence. Everything else is detail.

You don’t need a law degree to get this right. You need to know where you stand and what to fix first.

Two things to check today:

  • Does your privacy policy list what personal information you collect, why, and who you share it with?
  • Do you have a working “Do Not Sell or Share My Personal Information” link on your homepage, or the newer combined opt-out link?

The thresholds that matter: as of January 1, 2025, the CCPA covers for-profit businesses doing business in California that hit gross annual revenue of $26.625 million or more, buy, sell, or share the personal information of 100,000 or more California residents or households, or pull 50% or more of annual revenue from selling or sharing that information. Cross any one of those lines and you’re in scope, whether you’re based in Sacramento or Ohio.

The California Privacy Protection Agency (CPPA) and the California Attorney General’s office both enforce this law. Knowing which one does what, and what they expect from your documentation, is where real compliance starts.

Key Takeaways

CCPA compliance requires meeting statutory notice, consumer-rights, and security obligations the moment your business crosses any one of three legal thresholds.

Point Details
Check your thresholds annually Revenue, data volume, and revenue-from-sale limits shift year to year and can trigger new obligations.
Post required opt-out links Conspicuous “Do Not Sell or Share” and sensitive-data limit links belong in your site footer.
Meet request timelines Acknowledge within 10 business days, respond substantively within 45 days, extendable once.
Fix vendor contracts Service provider agreements need specific use limitations and request-assistance clauses.
Build technical controls with Total Cyber Total Cyber’s managed cybersecurity and compliance consulting services operationalize data mapping, access controls, and audit-ready documentation.

Table of Contents

What Does CCPA Compliance Actually Cover?

The California Consumer Privacy Act, later expanded by the California Privacy Rights Act (CPRA), lives in California Civil Code sections 1798.100 through 1798.199.100. That’s the statute. The CPPA regulations layer on top of it, and those regulations get updated more often than most business owners would like.

Three thresholds decide whether you’re covered:

  • Gross annual revenue at or above a specified high millions-of-dollars threshold, which the CPPA adjusts periodically for inflation.
  • Buying, selling, or sharing personal information belonging to a large number of California residents or households in a year.
  • Deriving a substantial portion of annual revenue from selling or sharing personal information.

You only need to meet one. A ten-person consulting firm with $2 million in revenue can still trigger CCPA obligations if it buys and resells consumer data lists that touch 100,000 California households.

“Doing business in California” doesn’t require a physical office there. If you have customers, employees, or website visitors in the state and you meet a threshold, you’re generally in scope. The law also reaches entities that control or are controlled by a covered business and share the same branding, plus businesses that voluntarily certify to the CPPA that they comply, even if they wouldn’t otherwise meet the thresholds.

Close-up of California map with digital lock

Pro Tip: Check your thresholds every year, not just once. A good sales quarter or a new data partnership can push you past the $26.625 million or 100,000-household line without anyone in finance flagging it as a compliance event.

Revenue and data volume shift. What didn’t apply to you last year might apply this year, and the obligations kick in the moment you cross the line, not when you get around to noticing.

What Rights Do Consumers Have Under the CCPA?

California residents get six distinct rights under the CCPA, and the Attorney General’s office lays them out clearly: the right to know, delete, correct, opt-out, limit use of sensitive data, and non-discrimination. Each one carries its own operational burden.

  1. Right to know. Consumers can request the categories and specific pieces of personal information you’ve collected, the sources, the business purpose, and any third parties you’ve shared it with. You typically have to cover the prior 12 months, sometimes longer if the consumer’s account has been active that long.
  2. Right to delete. Consumers can ask you to delete personal information you’ve collected from them. Exceptions exist: information needed to complete a transaction, detect security incidents, comply with a legal obligation, or exercise free speech.
  3. Right to correct. If a consumer flags inaccurate personal information, you have to use commercially reasonable efforts to fix it. This means having an actual workflow, not just a promise in your privacy policy.
  4. Right to opt-out of sale or sharing. Consumers can tell you to stop selling or sharing their information, including through Global Privacy Control (GPC) signals your website must detect and honor automatically.
  5. Right to limit sensitive personal information and non-discrimination. Consumers can restrict how you use sensitive categories like precise geolocation or health data, and you can’t charge them more or give them worse service for exercising any of these rights.

Pro Tip: Build one internal intake process that routes every request type, know, delete, correct, opt-out, to the same review queue. Businesses that build five separate workflows almost always miss a deadline on the one nobody remembers to check.

What Must Your Privacy Notices Say and Where?

Your privacy policy is the document regulators read first when they’re deciding whether you take this seriously. The statute requires disclosures made at or before the point of collection, and it requires you to limit collection and retention to what’s reasonably necessary for the purposes you disclosed.

A compliant privacy policy needs to spell out:

  • The categories of personal information collected in the past 12 months, and the categories of sensitive personal information.
  • The sources of that information and the business or commercial purpose for collecting it.
  • Whether you sell or share personal information, and which categories.
  • The categories of third parties you disclose information to.
  • How consumers can exercise their rights and how long you retain each category of data.

A notice at collection is separate from your full privacy policy. It’s the short-form disclosure that appears right where you’re gathering data, on a signup form, a checkout page, a job application. It needs to tell the person what you’re collecting and why, before you collect it, in language a person can actually read without a law dictionary.

Placement rules matter as much as content. Businesses that sell or share personal information must post a clear, conspicuous opt-out link, commonly labeled “Do Not Sell or Share My Personal Information,” or a combined alternative link where the regulations permit it. If you process sensitive personal information for purposes beyond what’s necessary to provide the goods or service requested, you also need a “Limit the Use of My Sensitive Personal Information” link. Both links belong in your website footer, visible without scrolling through unrelated content, and your site must be built to detect and honor opt-out preference signals like GPC automatically.

Pro Tip: Test your opt-out link on mobile. A surprising number of businesses bury it in a hamburger menu that regulators, and consumers, never find. That’s the kind of “dark pattern” the CPPA has specifically called out as noncompliant.

How Fast Must You Respond to Consumer Requests?

The timelines are specific, and missing them is one of the easiest ways to draw regulatory attention.

  1. Acknowledge receipt within 10 business days. A short confirmation email counts, but it needs to go out fast.
  2. Deliver a substantive response within 45 calendar days. The Attorney General’s guidance treats this as the default clock, starting the day you receive the request.
  3. Extend once by another 45 days if needed, for a maximum of 90 days total, but only if you notify the consumer of the extension and the reason before the original 45-day window closes.
  4. Handle opt-out and limit requests faster. Comply as soon as feasible, and within 15 business days in most cases, since these requests don’t require the same identity verification depth as a delete or know request.

Verification should scale with sensitivity. A request to know your email address on file needs less proof than a request to delete your entire account history. Document why you chose a given verification level for each request type, because that documentation is exactly what an auditor or investigator will ask for first.

You’re also required to offer multiple designated request channels, including a toll-free phone number, and a web form if you operate primarily online (an email address can suffice for online-only businesses).

Who Counts as a Service Provider vs. a Third Party?

This distinction decides who’s legally on the hook when personal information moves outside your walls. A service provider processes data on your behalf under a written contract and can’t use it for its own purposes. A contractor is similar but typically receives data for its own business needs under contract limits. A third party is anyone else, and sharing with a third party without the right disclosures can count as a “sale” under the CCPA even if no money changes hands.

Your vendor contracts need specific language, not boilerplate. The statute requires written agreements that limit how service providers can use personal information and obligate them to assist with consumer requests. At minimum, your contracts should cover:

  • Purpose limitations restricting the vendor from using data for anything beyond the contracted service.
  • An obligation to assist you in responding to consumer requests within your statutory deadlines.
  • Required security measures matching the sensitivity of the data being processed.
  • Deletion obligations when the contract ends or a consumer exercises the right to delete.

Build a vendor inventory that maps every third party touching personal information, from your payroll processor to your marketing analytics platform, and review those contracts on a set schedule rather than only when a vendor renews. A policy compliance program that includes contract templates and periodic audits turns this from a one-time scramble into a repeatable process.

What Do the New ADMT and Risk Assessment Rules Require?

The CPPA finalized regulations covering automated decisionmaking technology, privacy risk assessments, and cybersecurity audits, and most provisions took effect January 1, 2026, with some compliance deadlines phased into 2027 and 2028. If your business uses algorithms to make decisions about hiring, lending, pricing, or similar significant outcomes, ADMT rules likely apply to you: pre-use notices, opt-out rights for certain uses, and additional disclosure obligations all come into play.

Hand connecting audit device to server rack

Privacy risk assessments document what data you process, why, and what could go wrong. Regulators expect to see the reasoning behind your data collection choices, not just a checkbox that says “assessment complete.” Cybersecurity audits, required for higher-risk processing, look for evidence of real controls, not policy documents that exist only on paper.

The technical side of compliance is where a lot of businesses stall out. It requires:

  • A current data map showing where personal information lives across every system, including SaaS tools and backups.
  • Access controls limiting who inside your organization can view or export personal information.
  • Encryption for data at rest and in transit, and logging that shows who accessed what and when.
  • Deletion workflows that actually remove data from backups and archives, not just the primary database.
  • Automated detection and handling of opt-out preference signals like GPC.

Pro Tip: Data mapping is the single most underestimated part of this whole process. You can’t honor a “right to know” request in 45 days if nobody can tell you which of your twelve SaaS tools has the data.

If your internal IT team doesn’t have bandwidth to build and maintain this, a managed cybersecurity provider can implement the access controls, monitoring, and audit documentation regulators expect, without pulling your team off their day jobs. You can start that conversation through Total Cyber’s MSP discovery form whenever you’re ready.

What Is a Realistic 30-60-90 Day Compliance Timeline?

You don’t need to fix everything simultaneously. You need to fix the highest-exposure items first.

  1. Days 1 to 30: Update your privacy policy with current data categories and disclosures. Post a conspicuous opt-out link. Set up your toll-free number, email, or web form for consumer requests.
  2. Days 30 to 90: Complete a data inventory across every system that touches personal information. Revise vendor contracts to include required service provider language. Build a verification workflow proportional to each request type, and train frontline staff to recognize and route a consumer request the moment it arrives, whether it comes by email, phone, or web form.
  3. Days 90 to 180: Conduct a formal privacy risk assessment. Build an ADMT inventory if you use automated decisionmaking anywhere in hiring, lending, or pricing. Schedule a cybersecurity audit and build a remediation plan for whatever it finds.

Pro Tip: Assign one named owner for this entire timeline. Compliance projects that get split across five departments with no single accountable person almost always stall at the 60-day mark, right when the data inventory gets hard.

Staff training deserves its own line item inside the 30 to 90-day window. The people answering your general support inbox need to recognize a CCPA request when it shows up disguised as a regular customer email, because a missed request is still a missed deadline.

How Does CCPA Enforcement Actually Work?

Two agencies can come after you: the CPPA through administrative enforcement, and the California Attorney General’s office. Penalties and remedial orders can follow findings of noncompliance, and the CPPA can also conduct audits proactively, not only in response to a complaint.

The CCPA’s private right of action is narrower than people assume. It applies specifically to certain data breaches involving nonencrypted, nonredacted personal information, where the business failed to maintain reasonable security procedures. That narrow scope doesn’t mean low risk. It means the risk concentrates exactly where weak security controls live, which is precisely where a breach is most likely to happen.

Investigations get triggered by consumer complaints, breach reports, and, increasingly, proactive audits based on public-facing gaps like a missing opt-out link or an inaccurate privacy policy. Businesses with a documented data map, a working request-handling log, and signed vendor contracts have a fundamentally different conversation with an investigator than businesses that don’t.

What CCPA Mistakes Show Up Most Often With Clients?

The same three problems come up again and again when businesses start taking CCPA seriously. Data mapping gaps top the list, most companies genuinely don’t know where all their customer data lives until someone forces the question. Dark patterns come second: opt-out links buried in menus, consent flows designed to confuse rather than clarify. Weak vendor clauses round it out, contracts that mention “compliance” in passing without the specific language the statute actually requires.

None of these are exotic problems. They’re the result of treating privacy as a document exercise instead of an operational one… If any of this sounds like your organization, a conversation through Total Cyber’s MSP discovery form is a reasonable next step before a regulator or a plaintiff’s attorney makes the point for you.

How Total Cyber Solutions Helps You Get Compliant

Total Cyber is the practical alternative to hiring outside counsel for every compliance question and hoping your internal IT team can also build enterprise-grade security controls on the side. Where a law firm can tell you what the regulation requires, Total Cyber builds the actual infrastructure, data mapping, access controls, deletion workflows, and audit logging, that makes those requirements achievable on your statutory deadlines.

Total Cyber

Total Cyber Solutions offers managed cybersecurity services that cover the technical backbone of CCPA compliance: monitoring, access controls, encryption, and incident response. Compliance consulting, including policy compliance support, helps you rebuild vendor contracts and privacy notices without guessing at legal language. A vCSO engagement gives you executive-level security leadership without a full-time hire, and cyber awareness training gets your staff recognizing consumer requests and phishing attempts before either one turns into a compliance failure.

If your business is anywhere near one of the CCPA thresholds, start with a risk and vulnerability assessment to see exactly where your gaps are. Request a consultation through the MSP discovery form and get a practical plan built around your actual data, not a generic template.

Where Can You Verify These CCPA Rules Yourself?

Frequently Asked Questions

Does the CCPA apply to businesses outside California?
Yes, if you do business in California and meet a revenue, data volume, or revenue-from-sale threshold, physical location doesn’t exempt you.

What’s the difference between CCPA and CPRA?
The CPRA amended and expanded the original CCPA, adding the sensitive personal information category, the right to correct, and creating the CPPA as a dedicated enforcement agency.

Do small businesses have to comply with CCPA?
Only if they meet one of the three thresholds. Revenue alone under $26.625 million doesn’t exempt a business if it meets the data-volume or revenue-from-sale threshold instead.

How long do businesses have to respond to a CCPA request?
Ten business days to acknowledge, 45 calendar days to substantively respond, with one possible 45-day extension if you notify the consumer in time.

What happens if a business ignores a consumer’s opt-out request?
It risks administrative enforcement from the CPPA or the Attorney General, and repeated violations involving inadequate security around a breach can expose the business to private lawsuits.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

Share this post!

Learn How We Can Secure Your Business