Everything you need to know about CCPA / CPRA compliance, data security requirements, and secure data disposal.
The California Consumer Privacy Act (CCPA) is the law that kicked off the modern wave of US state-level privacy legislation. Effective January 1, 2020, it gave California residents a set of enforceable rights over their personal information and forced businesses across the country to rethink how they collect, use, and disclose consumer data — because California's size means CCPA effectively sets a national baseline for many companies.
Background
CCPA was signed into law in 2018 after a ballot initiative gathered enough signatures to force the state legislature's hand. Lawmakers passed a modified version of the bill to keep it off the ballot, and it took effect in 2020. In 2020, California voters approved the California Privacy Rights Act (CPRA), a ballot measure that expanded and amended CCPA, adding new rights and creating a dedicated enforcement agency, the California Privacy Protection Agency (CPPA). CPRA amendments became operative January 1, 2023.
Who Must Comply
CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds:
- Annual gross revenue over $25 million, or
- Buy, sell, or share the personal information of 100,000 or more California consumers or households annually, or
- Derive 50% or more of annual revenue from selling or sharing consumers' personal information
Consumer Rights Under CCPA
CCPA grants California residents several rights regarding their personal information:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information collected from them, with certain exceptions
- Right to opt out of the sale or sharing of personal information
- Right to correct inaccurate personal information
- Right to limit use and disclosure of sensitive personal information
- Right to non-discrimination for exercising any of these rights
What Counts as "Personal Information"
CCPA defines personal information broadly — far beyond just names and email addresses. It includes identifiers, commercial information, biometric data, internet and network activity, geolocation data, employment-related information, education information, and inferences drawn from any of this data to create a profile of a consumer.
Business Obligations
To comply, businesses generally need to:
- Provide a clear, accessible privacy notice describing data practices
- Offer a "Do Not Sell or Share My Personal Information" mechanism, often via a homepage link
- Honor consumer rights requests within statutory timeframes (typically 45 days, extendable once)
- Implement reasonable security procedures and practices
- Maintain records of consumer requests and how they were handled
- Enter into specific contractual terms with service providers and third parties
Enforcement and Penalties
The California Privacy Protection Agency and the California Attorney General share enforcement authority. Civil penalties can reach:
- Up to $2,663 per unintentional violation (adjusted periodically for inflation)
- Up to $7,988 per intentional violation
- Statutory damages for consumers in the event of certain data breaches involving unencrypted, unredacted personal information, ranging from $100 to $750 per consumer per incident, or actual damages if greater
Data Deletion as a Compliance Obligation
CCPA's right to delete places a direct operational burden on businesses: when a consumer requests deletion, personal information must be permanently removed not just from primary databases, but from backups, archives, and any devices where it may reside — including decommissioned hardware. Because standard deletion leaves data forensically recoverable, businesses handling retired drives, laptops, or mobile devices need a verifiable, standards-based erasure process to demonstrate that deletion requests were genuinely fulfilled, not just logically marked as complete.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
CCPA, as amended by CPRA, has become a template that other US states have drawn from when drafting their own privacy laws. For any business handling California consumer data — regardless of where the business itself is headquartered — CCPA compliance requires clear consumer-facing rights mechanisms, strong internal data governance, and defensible data disposal practices at the end of the data lifecycle.
No comments yet. Be the first to comment.