The California Consumer Privacy Act (CCPA) is a state-level data privacy law modeled after GDPR that protects the personal information of California residents and imposes compliance requirements on qualifying for-profit businesses.
CCPA Overview
Shortly after GDPR was put into place, then the California Consumer Privacy Act, or CCPA, was put into place.
The CCPA was put in place to protect California residents. It was put into place in May of 2018, which is just a few months after GDPR was put into place. It was modeled after GDPR, although there are a few key differences with CCPA.
So who must comply with CCPA? Any business that is a for-profit business doing business in the state of California and meets one of the following criteria. It could be that the business is making at least 25 million in revenue. Or maybe they're buying, selling or sharing the PI information of 100,000 or more California residents or their households. Or deriving more than, or at least, 50% of their annual revenue from selling California residents' PI information.
However, if your business falls in one of those criteria but is not doing business in the state of California, I still recommend at least giving some thought to the CCPA, because a lot of other states are putting into place similar programs or similar laws, and they're copying what California has done. So if your state hasn't done that already, it could be doing that soon, so you may want to give some consideration to applying CCPA compliance to your business.
Some of the highlights of what CCPA is all about is protecting consumer rights, the idea that consumers have the right to opt out of having their information collected. There's some non-discrimination language in there. There's also notice requirements if there's any kind of breaches, and there's some data breach liability that comes with it. There's some expanded definitions of what personal information means, and talking about enforcement and how they're going to enforce the rules.
Since the CCPA was modeled after the GDPR, there's a lot of similarities between the two. However, there are some key differences between the CCPA and the GDPR.
With the CCPA, it's really targeting bigger businesses, versus GDPR, it doesn't matter the size of the business. So with GDPR it just says if your business is collecting any Eastern European residents' information, personal information, then you fall under the category, versus CCPA targets larger businesses or businesses that are targeting California residents.
With the two there's a difference in what information is being collected as well. With GDPR it's any personal information, so protecting the consumer's personal information. CCPA goes beyond that and expands that and says if you're collecting information about their devices or about their household information, not just their personal information but beyond that, then you also have to follow the CCPA.
Another difference between the two is the model for opt out or consent. CCPA uses an opt out model. That means that they have the right to collect the information from you, but you can opt out and say I want you to delete the information and not collect any more information from me. Versus GDPR uses a consent model: before they can even collect information about you, you have to give them consent to collect that information.
And then the violation fees are different between the two as well. CCPA has 2500 per violation, or 7500 for intentional violations, versus the GDPR has 4% of the revenue or 2 million EUR.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →