Privacy
CCPA
Also called California Consumer Privacy Act.
CCPA is the California Consumer Privacy Act, the state law that gives residents rights over personal information held by larger businesses. Those rights include knowing what is held, deleting it, and opting out of its sale or sharing.
How it is measured
Coverage is a test, not a label. A for-profit business that does business in California is in scope if it clears one of three bars: annual revenue above an inflation-adjusted figure near 25 million dollars, personal information of 100,000 or more consumers or households, or half its revenue from selling or sharing that information.
You confirm compliance by walking the consumer requests: a request to know, to delete, and to opt out. Each has a response clock of 45 days, extendable once. Count how many you received and how many you closed inside the window.
Worked example
A regional outdoor-gear retailer ships to 130,000 California addresses a year, so it is in scope on the consumer count alone. A customer emails asking for deletion on March 3. The retailer finds the order history, the email list entry, and an ad-audience upload, and confirms deletion on April 11, day 39.
The same week, a visitor with a Global Privacy Control signal loads the site. The retailer's ad pixel should treat that signal as an opt-out of sale or sharing, with no banner click needed.
How it differs
CCPA is a California law about consumer rights and business duties. CPRA is the later amendment that added sensitive-data limits, a correction right, and a dedicated agency. The original sets the base rights; the amendment adds to them and does not replace them.
Common errors
Assuming a US company outside California is out of scope. Treating CCPA as a copy of GDPR, when it is mainly opt-out and has no lawful-basis requirement. Forgetting that "sharing" for cross-context advertising counts, not only sales for money. Ignoring browser opt-out signals. Posting a policy with no working request channel.
In practice
This week, count whether you clear a threshold, then test your request path end to end with a dummy deletion. Check that a Global Privacy Control signal stops ad tags on your site. Keep a log of request dates so you can show the 45-day clock.