CCPA and US Privacy Laws Overview

About this module

US privacy compliance is no longer only a California issue. This lesson covers CCPA, the CPRA update, and the growing set of state privacy laws. Learners see who CCPA applies to, how its opt-out model differs from GDPR consent, and what consumers can request: to know, delete, opt out of sale or sharing, correct inaccurate data, and limit sensitive data use. It also covers website notices, privacy policy updates, request workflows, response deadlines, and breach reporting. The practical takeaway is clear: collect only for disclosed purposes and route privacy requests fast.

Key takeaways

  • CCPA gives California residents rights over how businesses collect, use, sell, and share personal information
  • CPRA added rights to correct data and limit sensitive personal information use
  • CCPA uses opt-out rights, while GDPR often requires opt-in consent before processing
  • Privacy notices, request workflows, and response deadlines need clear ownership

Full Transcript

Welcome to CS04-03. This module covers the California Consumer Privacy Act and the growing patchwork of US state privacy laws — what they require, who they apply to, and what your organization must do to stay compliant.

The California Consumer Privacy Act — CCPA — took effect in January 2020. It was the first comprehensive consumer privacy law in the United States, giving California residents new rights over how businesses collect, use, and sell their personal information.

It was later strengthened by the California Privacy Rights Act, or CPRA, in 2023. As of 2024, roughly one in five Americans lives in a state with a comprehensive privacy law.

California led the way, but Virginia, Colorado, Connecticut, Texas, and others have followed. That number is rising — making US privacy compliance a national issue, not just a California concern.

CCPA uses an opt-out model — businesses can collect and share data by default, but consumers have the right to say stop. It applies to for-profit companies meeting certain size or revenue thresholds that serve California residents.

GDPR requires opt-in consent before processing personal data. Businesses must obtain explicit permission, and can face much larger penalties.

Understanding both frameworks is essential if your organization operates globally.

CCPA applies to for-profit businesses doing business in California that meet at least one of three thresholds: annual gross revenue over $25 million; buying, selling, or sharing the personal data of 100,000 or more consumers per year; or deriving 50 percent or more of annual revenue from selling or sharing personal information.

Many mid-size companies are surprised to find they qualify. First: the Right to Know.

Consumers can ask exactly what personal information you have collected about them, why it was collected, and whether it has been sold or disclosed to third parties. Second: the Right to Delete.

Consumers can request that you erase their personal information. Businesses must comply unless an exception applies — such as completing a transaction or meeting a legal obligation.

Third: the Right to Opt-Out. Consumers can tell you to stop selling or sharing their personal information.

Your website must display a clear 'Do Not Sell or Share My Personal Information' link — and you must honor it promptly. These three rights form the foundation of CCPA compliance.

In 2023, the California Privacy Rights Act significantly expanded CCPA. CPRA adds new consumer rights — including the right to correct inaccurate data and the right to limit how sensitive personal information is used.

It also created a dedicated enforcement agency, the California Privacy Protection Agency, and tightened rules around sensitive data categories like health information, racial origin, and precise geolocation. If your organization was already CCPA-compliant, a CPRA gap analysis is now essential.

One of the most serious CCPA violations is selling or sharing consumer data without proper disclosure. If your business transfers personal information to third parties for commercial purposes without telling consumers and offering an opt-out, you are in violation.

Each intentional violation can carry a civil penalty of up to seventy-five hundred dollars — and a single data-sharing campaign can generate thousands of violations. To comply with CCPA, organizations must deliver five key obligations.

A privacy notice at the point of collection — telling consumers what data you collect, why, and who gets it. A publicly available privacy policy updated at least once a year.

A Do Not Sell or Share link if you transfer data to third parties. A clear process for consumers to submit rights requests.

And a response to those requests within 45 days. California is no longer alone.

Virginia, Colorado, Connecticut, and Texas have all enacted comprehensive privacy laws. Each has slightly different thresholds, rights, and exceptions.

Organizations operating across state lines must map their data flows and build compliance programs flexible enough to handle all of them. The financial stakes are real.

CCPA allows the California Attorney General to seek civil penalties of up to seventy-five hundred dollars per intentional violation — and fifteen hundred dollars per unintentional violation. CPRA additionally allows consumers to sue directly for certain data breaches.

For large-scale data operations, non-compliance can quickly become multi-million-dollar exposure. Every employee plays a role in US privacy compliance.

Collect only the personal data required for a specific, disclosed purpose. If a consumer contacts you to exercise their rights, route the request to your Privacy or Legal team right away.

Never share personal data with vendors without proper legal grounds. Report any suspected data breach within 24 hours per your incident response policy.

And complete your annual privacy training to stay current as laws evolve. US privacy law is no longer a future concern — it is here, and expanding.

By understanding CCPA, CPRA, and the growing state-law landscape, you help protect the consumers your organization serves and reduce the legal and reputational risk your company faces. Stay informed, follow the compliance checklist, and complete your assessment.

Thank you. Know the law.