TechKnowSurge
NIST NICE K0678 ISC2 CISSP 1.4 CompTIA Security+ 5.4 NIST NICE K0681 CompTIA SecurityX 1.4
VideoSecurityFree

California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA) is a state-level data privacy law modeled after GDPR that protects the personal information of California residents and imposes compliance requirements on qualifying for-profit businesses.

Complete this video to capture a CTF flag worth 1 point.

About this video

The California Consumer Privacy Act (CCPA) was signed into law in May 2018, just months after the European Union's GDPR went into effect. Designed specifically to protect California residents, CCPA applies to for-profit businesses operating in the state that meet at least one of three criteria: generating $25 million or more in annual revenue, buying, selling, or sharing the personal information of 100,000 or more California residents or households, or deriving at least 50% of annual revenue from selling California residents' personal data. Even businesses that fall under these thresholds but operate outside California should take note, as numerous other states are adopting comparable legislation modeled on the CCPA framework. Core provisions of the law include consumer opt-out rights, non-discrimination protections, breach notification requirements, expanded definitions of personal information, and defined enforcement mechanisms with associated penalties. CCPA and GDPR share a common foundation but differ in several important ways. GDPR applies to any organization collecting personal data on EU residents regardless of business size, while CCPA targets larger businesses or those actively engaging with California residents' data. GDPR operates on a consent model, meaning businesses must obtain explicit permission before collecting personal information, whereas CCPA uses an opt-out model that permits data collection by default but requires businesses to honor consumer requests to stop collecting or to delete existing data. CCPA also extends its scope beyond personal information to include device and household data. Penalty structures differ as well: CCPA imposes fines of $2,500 per unintentional violation and $7,500 per intentional violation, compared to GDPR's penalties of up to 4% of global annual revenue or 20 million euros, whichever is greater.

What you'll learn

What's covered

CCPA Overview

Aligned to

NIST NICE
K0678 Knowledge of privacy laws and regulations
K0678 Knowledge of privacy laws and regulations
K0681 Knowledge of privacy principles and practices
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
CompTIA Security+
5.4 Summarize elements of effective security compliance
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements

Key terms

California Consumer Privacy Act
CCPA
A California state law that grants consumers the right to know what personal data businesses collect about them, to request deletion, and to opt out of the sale of their personal information. It is one of the most comprehensive consumer privacy laws in the United States.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Personal Information
PI
Data that is personal to an individual, such as medical, financial, or school records, that a person would not want disclosed publicly.
Opt-Out Model
A consent approach used by CCPA in which businesses may collect consumer data by default, but consumers have the right to request deletion and halt future collection.
Consent Model
A privacy approach used by GDPR that requires businesses to obtain explicit permission from individuals before collecting their personal data.
Data Breach
An incident in which protected or sensitive data is accessed, stolen, or disclosed without authorization, typically triggering legal notification requirements.

Topics

Ccpa Gdpr Data Privacy Privacy Compliance Data Protection Regulatory Compliance

Transcript

Shortly after GDPR was put into place, then the California Consumer Privacy Act, or CCPA, was put into place.

The CCPA was put in place to protect California residents. It was put into place in May of 2018, which is just a few months after GDPR was put into place. It was modeled after GDPR, although there are a few key differences with CCPA.

Who Must Comply

So who must comply with CCPA? Any business that is a for-profit business doing business in the state of California and meets one of the following criteria. It could be that the business is making at least 25 million in revenue. Or maybe they're buying, selling or sharing the PI information of 100,000 or more California residents or their households. Or deriving more than, or at least, 50% of their annual revenue from selling California residents' PI information.

However, if your business falls in one of those criteria but is not doing business in the state of California, I still recommend at least giving some thought to the CCPA, because a lot of other states are putting into place similar programs or similar laws, and they're copying what California has done. So if your state hasn't done that already, it could be doing that soon, so you may want to give some consideration to applying CCPA compliance to your business.

Highlights of the CCPA

Some of the highlights of what CCPA is all about is protecting consumer rights, the idea that consumers have the right to opt out of having their information collected. There's some non-discrimination language in there. There's also notice requirements if there's any kind of breaches, and there's some data breach liability that comes with it. There's some expanded definitions of what personal information means, and talking about enforcement and how they're going to enforce the rules.

Key Differences From GDPR

Since the CCPA was modeled after the GDPR, there's a lot of similarities between the two. However, there are some key differences between the CCPA and the GDPR.

With the CCPA, it's really targeting bigger businesses, versus GDPR, it doesn't matter the size of the business. So with GDPR it just says if your business is collecting any Eastern European residents' information, personal information, then you fall under the category, versus CCPA targets larger businesses or businesses that are targeting California residents.

With the two there's a difference in what information is being collected as well. With GDPR it's any personal information, so protecting the consumer's personal information. CCPA goes beyond that and expands that and says if you're collecting information about their devices or about their household information, not just their personal information but beyond that, then you also have to follow the CCPA.

Another difference between the two is the model for opt out or consent. CCPA uses an opt out model. That means that they have the right to collect the information from you, but you can opt out and say I want you to delete the information and not collect any more information from me. Versus GDPR uses a consent model: before they can even collect information about you, you have to give them consent to collect that information.

And then the violation fees are different between the two as well. CCPA has 2500 per violation, or 7500 for intentional violations, versus the GDPR has 4% of the revenue or 2 million EUR.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →