# Automated CCPA Compliance Software

> For the complete site index, see [llms.txt](/llms.txt). Every page is also available as Markdown: replace the trailing slash with `.md` (`/pricing/` becomes `/pricing.md`), or send `Accept: text/markdown` to the page URL itself.

> Does your website have an opt-out banner and &#x27;Do not sell/share&#x27; link for CCPA/CPRA? Get compliant in no time, with our #1 consent management platform!

**Source:** https://www.cookieyes.com/ccpa-compliance/

---

# CCPA Compliance Software to Secure Your Business

Implement all your CCPA compliance requirements under one roof. Display opt-out notice, 'Do not sell' link and generate privacy disclosures.

[Become CCPA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=CYM_CCPA_Hero)

14-day free trial Cancel anytime

![CCPA Compliance Software to Secure Your Business](https://assets.cookieyes.com/ccpa_hero_2d25bc8184.svg)

## The #1 cookie consent solution, trusted by 1.5 Million+ websites

![Decathlon](https://assets.cookieyes.com/decathlon_a23456d440.svg)

![KFC](https://assets.cookieyes.com/kfc_73dc90db22.svg)

![Dominos](https://assets.cookieyes.com/dominos_9ce9dc7569.svg)

![Heineken](https://assets.cookieyes.com/heineken_f0fca7d239.svg)

![Forbes](https://assets.cookieyes.com/forbes_b76200d4a5.svg)

![Toyota](https://assets.cookieyes.com/toyota_71a8106b6a.svg)

![Renault](https://assets.cookieyes.com/renault_d254f28337.svg)

## What is CCPA?

The California Consumer Privacy Act (CCPA) is data privacy legislation that applies to businesses that process the personal data of California residents. Effective January 1, 2020, CCPA provides individuals control over the personal data that businesses collect about them.

From January 01, 2023, the [California Privacy Rights Act (CPRA)](https://www.cookieyes.com/cpra-compliance/) amends the existing CCPA.

## Who does CCPA apply to?

The CCPA applies to for-profit businesses that collect, share, or sell the personal information of California residents and fit any of the criteria.

$25M

Has annual gross revenues over $25 million

50K

Processes personal information of 50,000 or more consumers, households, or devices

50%

Earns more than 50% of annual revenue from the sale of personal information

## CCPA Compliance Checklist for Websites

- Display CCPA opt-out notice to respect the user's right to opt-out
- Add a clear and conspicuous "Do Not Sell My Personal Information" link
- Include an up-to-date and accessible privacy policy and cookie policy

## Comply with CCPA using CookieYes compliance software

### Implement ‘Do not sell’ opt-out notice

The CCPA requires businesses to respect the consumer’s right to opt-out of the sale of their personal information to third parties. This includes data collected through cookies. With CookieYes you can

- Scan your website for cookies and trackers
- Pre-select cookie categories to block cookies when the user opts out
- Display a CCPA opt-out notice or simply add a ‘Do Not Sell My Personal Information’ link on the website footer

![Implement ‘Do not sell’ opt-out notice](https://assets.cookieyes.com/ccpa_cookie_banner_beea3c0463.svg)

### Comply with GDPR and CCPA regulations

If your website has visitors from both US and the EU, then it is important to comply with both laws. Businesses are required to display an opt-out notice for CCPA and a cookie consent banner for GDPR. With CookieYes, you can

- Show CCPA and GDPR cookie notices for website visitors
- Geotarget the CCPA opt-out notice for California/US visitors
- Geotarget the GDPR cookie banner for visitors from the EU & UK

![Comply with GDPR and CCPA regulations](https://assets.cookieyes.com/ccpa_cookie_consent_bb11d9756a.svg)

### Add a privacy policy

Under CCPA, businesses should include an up-to-date privacy policy on their website. It should describe what personal information is collected, the data processors, the purpose of collection and description of consumer rights. With our privacy policy generator, you can

- Answer a simple data privacy questionnaire
- Generate your privacy policy instantly
- Copy-paste the privacy policy to your website

![Add a privacy policy](https://assets.cookieyes.com/ccpa_pp_23da08bfbb.svg)

### Create a cookie policy

Under the CCPA, businesses must include a disclosure about their use of cookies in their policies. It can either be included within the privacy policy or added as a separate disclosure. With our cookie policy generator, you can

- Edit or customize the preset cookie policy template
- Generate a cookie policy with a complete cookie list
- Auto-update your policy with each website scan

![Create a cookie policy](https://assets.cookieyes.com/ccpa_cp_6a5e2b5c82.svg)

## Comply with CCPA and ever-evolving privacy laws in the US

[Become CCPA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=CYM_CCPA_cta1)

14-day free trial

Cancel anytime

## What are consumer rights under CCPA?

![Right to notice](https://assets.cookieyes.com/icon_info_33ae4f8847.svg)

Right to notice

The right to know about the personal information a business collects about them and how it is used and shared.

![Right to deletion](https://assets.cookieyes.com/icon_delete_ba1643b859.svg)

Right to deletion

The right to delete personal information that a business has collected from them.

![Right to opt-out](https://assets.cookieyes.com/icon_optout_ee96d6bad1.svg)

Right to opt-out

The right to opt-out of the sale of their personal information by a business.

![Right to non-discrimination](https://assets.cookieyes.com/icon_complain_b6a5620bca.svg)

Right to non-discrimination

The right to not be discriminated against for exercising their consumer rights under CCPA.

![CCPA Penalty](https://assets.cookieyes.com/ccpa_penalties_53207ff99a.svg)

## What are the penalties for non-compliance with the CCPA?

Businesses can get civil penalties of up to $7500 for each intentional violation while each unintentional can amount to a fine of up to $2500. Businesses will have a 30-day cure period to rectify violations before the California Attorney General takes action.

CCPA provides a private right of action to consumers under limited circumstances if they suffer a data breach due to negligence from a business. Consumers can sue for the amount equal to the monetary damages they actually suffered from the breach or "statutory damages" of up to $750 per incident.

To avoid these penalties, follow this guide on [how to comply with CCPA](https://www.cookieyes.com/blog/how-to-comply-with-ccpa/).

## FAQ on CCPA Compliance

**What is CCPA compliance?**

The California Consumer Privacy Act (CCPA) is a state-wide privacy regulation enacted in 2018. CCPA compliance applies to any for-profit entity doing business in California that collects, shares, or sells the personal information of California residents.

To be CCPA compliant, companies are required to meet certain standards for data collection and processing of any personal data that can be linked, associated, or related to Californians.

Help guide: [How to use CookieYes for CCPA Compliance](https://www.cookieyes.com/documentation/cookieyes-for-us-state-laws-cookie-compliance/)

**Does CPRA replace CCPA?**

No, the California Privacy Rights Act (CPRA) does not replace the CCPA but amends it. The CPRA is an expansion of the CCPA, as it modifies existing provisions and introduces additional requirements for businesses operating in California. The CPRA came into effect on January 1, 2023.

**What is personal information under CCPA?**

Under CCPA, personal information is any information relating to an identified or identifiable individual. It is any data that can directly or indirectly lead to the identification of a specific consumer or household. CCPA maintains a broad definition of personal information but excludes de-identified/anonymized information from it.

Personal information can be identifiers such as name, identification number, IP addresses, biometric information or characteristics such as race, ancestry, religion, age, sex, sexual orientation, gender, medical condition etc.

**Are cookies personal information under CCPA?**

Cookies and similar tracking technologies are classified as unique identifiers and can be considered personal information under CCPA. A unique identifier could directly or indirectly identify an individual consumer, family, or device over time and across services.

These identifiers can include IP addresses, cookies, beacons, pixel tags, mobile ad identifiers, customer numbers, unique pseudonyms, user aliases, and telephone numbers.

CCPA requires that users be able to opt out of the sale of personal information. This means the website should give users the choice to opt out of the use of cookies that are not strictly necessary, especially third-party cookies such as tracking cookies used for advertising.

**What is the CCPA privacy policy?**

CCPA requires businesses to disclose how they collect, use and retain personal information about California residents. Businesses are therefore required to maintain a CCPA-specific privacy policy that is available to the consumers.

A CCPA privacy policy should disclose what personal information is being collected about consumers, how it is being used, and with whom it is being shared. It should also detail the consumer's rights as per CCPA and how they can exercise these rights.

**Does CCPA apply to all states in the US?**

CCPA applies to all for-profit organizations that process the information of California residents to offer goods or services. The law does not require the business to have a physical presence in California — any business that deals with the personal data of California residents must be CCPA compliant.

**Does CCPA require opt-out?**

The CCPA law provides consumers with the right to opt out, i.e. the right to ask a business to stop selling their personal information. A CCPA-compliant opt-out mechanism should be accessible and transparent and should not require consumers to search through a privacy policy to perform an opt-out request.

**What is 'sale' under CCPA?**

Under the CCPA, the sale of personal information occurs when a business transfers consumers' information to another business or third party for financial gain. The definition includes any disclosure involving selling, renting, releasing, disclosing, disseminating, making available, or transferring personal information.

**Is CCPA the same as GDPR?**

The GDPR and CCPA/CPRA are two comprehensive data privacy regulations that aim to protect individuals' data and impose regulations on how businesses process user data. While the two regulations have similar goals, they have different scopes and requirements.

GDPR is a data protection law that applies to all organizations that collect, use, or share personal data of individuals in the European Union. CCPA/CPRA, on the other hand, is a California state law that applies to for-profit companies that meet specific requirements and collect personal data of California residents.

**Is the CCPA applicable only in California?**

No, the CCPA (California Consumer Privacy Act) and its amendment, the California Privacy Rights Act (CPRA) can be applicable outside California. While CCPA/CPRA is a state-level legislation in California, it has extraterritorial reach and can apply to businesses outside of the state that 'do business' in California (i.e. cater to California consumers) and meet the applicability thresholds.

**What are the rules of CCPA?**

CCPA/CPRA imposes certain obligations on businesses that are considered "covered entities". Some of the key CPRA/CCPA guidelines are:

- **CCPA notice requirements:** Businesses must inform consumers at or before the point of collection about the categories of personal information to be collected and the purposes for which the information will be used.
- **Privacy policy:** Maintain a comprehensive privacy policy that discloses the categories of personal information you collect, the purposes for which it will be used, and whether it will be sold or shared with third parties.
- **Right to opt out:** If you sell/share personal information, you must provide a clear and conspicuous "Do Not Sell/Share My Personal Information" link on their website and respect consumer opt-out requests.
- **Consumer rights:** CCPA/CPRA provides more consumer rights such as the right to know, request deletion, the right to correct data, and protection against discrimination for exercising these rights. Businesses are required to inform consumers of their rights under the CCPA/CPRA and how to exercise them.
- **Limitation on sensitive personal information:** The CCPA/CPRA requires businesses to restrict the use of sensitive personal information. Businesses must provide an additional notice specifying the categories of sensitive information collected and the purposes for which it will be used.

**What does CCPA compliance mean?**

CCPA compliance involves your organization's responsibilities and obligations outlined in the CCPA. Some key requirements for CCPA/CPRA compliance include:

- Conduct data mapping to identify and review all personal information being collected or processed.
- Review third-party vendor contracts to ensure continued compliance.
- Update your privacy policy to reflect CCPA/CPRA requirements.
- Provide notice to consumers about what personal information is collected and for what purposes.
- Implement a method for consumers to exercise their right to opt out of the sale or sharing of their personal information.
- Accept universal opt-out signals such as Global Privacy Control.
- Fulfil consumer requests to access, delete, or correct their personal information.
- Implement reasonable security measures to protect personal information.
- Train employees on privacy policies and procedures.

**What is the biggest difference between GDPR and CCPA?**

**Applicability:** GDPR applies to any organization (regardless of whether it's for-profit or non-profit) that processes the personal data of individuals in the European Union, regardless of their citizenship. On the other hand, CCPA/CPRA applies to for-profit organizations collecting personal data about California residents.

**Data covered:** GDPR has a broader scope in terms of the types of data covered and includes all personal data, while CCPA/CPRA focuses on personal information that is not publicly available. CCPA also does not apply to data that is already made available and exempts data covered under the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA) etc.

**Opt-in requirement:** GDPR also requires users to opt-in for data processing and requires obtaining explicit and affirmative consent (opt-in) from individuals before processing their data. CCPA/CPRA does not have strict opt-in requirements. Instead, it requires businesses to provide consumers with the right to opt out of the sale/sharing of their data.

**Where can I find additional resources on CCPA?**

You can find additional resources on CCPA at:

- [Guide to CCPA](https://www.cookieyes.com/blog/what-is-ccpa/)
- [CCPA vs GDPR overview](https://www.cookieyes.com/blog/ccpa-vs-gdpr/)
- [Guide to CPRA](https://www.cookieyes.com/blog/cpra-californias-new-privacy-law/)

## Fast-track your CCPA compliance in minutes

Set up a cookie consent banner in 3 simple steps and automate your compliance.

[Become CCPA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=CYM_CCPA_cta2)

14-day free trial

Cancel anytime