California has set the most influential privacy standard in the United States. The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give California residents enforceable rights over their personal information and put real obligations on the businesses that collect it.
Many small and mid-sized businesses assume these laws apply only to big tech. In practice, CCPA/CPRA reaches professional services firms, healthcare-adjacent vendors, e-commerce brands, SaaS applications, financial services, and marketing agencies - including companies outside California that handle California residents' data.
This guide breaks down what the laws cover, what compliance requires, and how to prepare your business - in plain English.
The California Consumer Privacy Act is a state privacy law that gives California consumers rights over their personal information and imposes duties on the businesses that collect, store, use, and share it. It was enacted in 2018 as AB 375 and took effect January 1, 2020, and it is widely regarded as the first comprehensive state privacy law in the United States (California Attorney General).
The California Privacy Rights Act amends and expands the CCPA, closing loopholes and moving California's model closer to the EU's GDPR. California voters approved it as Proposition 24 in November 2020, and its amendments took effect January 1, 2023 (California Attorney General).
The CPRA:
Together, these laws form one of the most comprehensive privacy regimes in the United States.
CCPA/CPRA applies to for-profit organizations that do business in California, handle California residents' personal information, and meet any one of three thresholds (California Attorney General):
Service providers and contractors are not covered "businesses" under the thresholds - they are separately defined roles with their own duties. The law requires covered businesses to bind their vendors by contract: restricted data use, required security, and help with consumer rights requests.
This is the big one for SMBs. If your customers must comply, meeting their contractual compliance requirements becomes a condition of keeping them.
The CCPA defines personal information (PI) broadly - nearly anything that identifies or can reasonably be linked to a person or household.
Examples of PI:
The CPRA adds sensitive personal information (SPI), including:
SPI triggers higher security obligations and stricter processing limits.
The law requires businesses to provide working mechanisms for consumers to:
1. Know: what personal information is collected, for what purposes, and who it is shared with. 2. Access: receive a copy of their personal information on request. 3. Correct: fix inaccurate information. The CPRA added this right. 4. Delete: have their information deleted, with limited exceptions. 5. Opt out: of the sale of their data, of sharing for cross-context behavioral advertising, and of certain uses of automated decisionmaking technology (ADMT). The ADMT regulations were finalized in 2025, with compliance required beginning January 1, 2027. 6. Limit: the use and disclosure of sensitive personal information. 7. Not face discrimination: consumers cannot be penalized for exercising any of these rights.
CCPA/CPRA is California law, but it does not exist in isolation.
The GDPR parallel. The CPRA moves California's model closer to the EU's GDPR: sensitive data categories, minimization, and expanded individual rights. Work done for one covers much of the other.
Other state privacy laws. Colorado (CPA), Virginia (CDPA), Connecticut (CTDPA), Utah (UCPA), New Jersey, and a growing list of states have followed California's lead. Building to CCPA/CPRA gives you a foundation those laws largely share - preparing now avoids costly fire drills later.
Overlapping data categories. Biometric SPI overlaps with Illinois's BIPA. Health data outside healthcare is SPI here, while HIPAA governs it inside covered entities. Children's data intersects with COPPA, and the CCPA/CPRA penalty tier for consumers under 16 raises those stakes.
Privacy management standards. ISO/IEC 27701 provides a certifiable structure for operationalizing these obligations across every privacy law you face.
Many SMBs think privacy laws just mean updating the privacy policy. In reality, compliance requires real changes to technology, cybersecurity, and data management operations. Here is what the law expects to be in place:
1. Strong access controls. Only authorized individuals may access PI or SPI. That means role-based access controls (RBAC), enforced MFA, least-privilege permissions, and logging with audit trails.
2. Encryption at rest and in transit. The statute does not name encryption as a mandate. But the private right of action reaches breaches of nonencrypted, nonredacted personal information caused by a failure to maintain reasonable security (Civ. Code §1798.150) - which makes encryption one of the strongest mitigating controls available to you.
3. Data minimization. The CPRA limits collection to what disclosed purposes require. Stop collecting unnecessary data, stop retaining data longer than needed, and document your purpose limitations.
4. Data retention schedules. The CPRA requires disclosure of how long data is retained, why it is retained, and when it will be deleted. This is newer than most SMB documentation - many businesses have never written it down.
5. Vendor and contractor management. The law requires contracts holding your service providers to CPRA standards: restricted data use, no selling or sharing, security obligations, and assistance with consumer rights requests. You can remain accountable when a vendor mishandles data - the law expects contracts and due diligence, so vendor oversight is part of your compliance program, not someone else's.
6. Consumer rights workflows. Access, deletion, correction, opt-out, and SPI limitation requests all need to be fulfilled quickly and securely. That takes ticketing or case tracking, identity verification, and system integrations that can actually locate the data.
7. Incident response and breach notification. A documented incident response plan, trained staff, tabletop exercises, and prompt notification of affected consumers after a breach. Mishandled SPI raises breach exposure under the CPRA.
8. Cybersecurity audits and risk assessments. The CPPA finalized its cybersecurity audit, risk assessment, and ADMT regulations in September 2025; they took effect January 1, 2026. Annual audit certifications phase in by revenue: April 1, 2028 for businesses over $100 million, April 1, 2029 for $50 to $100 million, and April 1, 2030 below $50 million. Risk assessment obligations began January 1, 2026, with the first attestations due April 1, 2028 (CPPA regulations).
CCPA/CPRA carries some of the strictest privacy enforcement in the United States.
Civil penalties. Regulators can seek up to $2,663 per violation, and up to $7,988 per intentional violation or per violation involving consumers under 16. Those are the statutory $2,500 and $7,500 figures, CPI-adjusted effective January 1, 2025. Penalties count per violation, so totals climb fast.
The private right of action - consumers can sue you. When nonencrypted, nonredacted personal information is breached because a business failed to maintain reasonable security, consumers can sue directly (Civ. Code §1798.150). Statutory damages run $107 to $799 per consumer per incident, or actual damages, whichever is greater - the statutory $100 to $750 range, as adjusted January 1, 2025.
Do the math on a small incident: 2,000 affected consumers at the $799 cap is $1,598,000 in potential statutory damages. That is before any civil penalties, legal fees, or reputational cost.
Note where the line sits: the private right of action reaches only nonencrypted, nonredacted data. Encryption and reasonable security are not just good practice - they are what keeps a breach from becoming a class action.
Treat CCPA/CPRA as a program, not a project. The obligations now arrive on a schedule - ADMT compliance beginning January 1, 2027, phased audit certifications from 2028 - and enforcement belongs to a dedicated agency with rulemaking authority.
That is exactly what a Governance, Risk & Compliance program manages: tracking which deadlines apply to you, keeping documentation current, and assigning ownership. Cyber Risk Management keeps the underlying controls real, and Third-Party Assessments validate them independently - the same evidence your privacy compliance rests on.
The CPPA remains active on retention guidance, SPI processing limits, and enforcement. Businesses that build the program now, with strong controls, documented data practices, and privacy built into operations, stay compliant and become safer, more trustworthy, and more resilient in the process.
Here is the part many SMB owners miss: the overwhelming majority of compliance requirements are the basic protections every business should run anyway.
MFA. Encryption. Access controls. Logging. Data minimization. Vendor oversight. Incident response.
These are not "compliance tasks" - they are core security fundamentals that protect your business, your customers, and your reputation. Compliance simply formalizes them, and CCPA/CPRA turns them into documented, provable practice. Privacy is not just a regulation - it is a responsibility, and with the right approach it becomes an advantage.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps your data inventory and controls against the CCPA/CPRA thresholds, the CPPA's audit and risk assessment rules, and the reasonable-security bar behind the private right of action.
Build the data inventory: systems, data types, data flows, and every vendor who receives data. You cannot protect or disclose what you have not mapped.
Sensitive personal information requires stricter controls and minimized processing. Classification decides which obligations attach to which systems.
The essentials: MFA everywhere, endpoint protection, email security, encryption, logging, SIEM or monitoring, regular backups, and a tested incident response plan.
It needs to disclose the categories of PI collected, purposes of use, retention periods, sales and sharing practices, SPI handling, and how consumers exercise their rights.
Web forms for intake, identity verification, internal ticketing, and automated data lookup where possible. Requests need to be answered quickly and securely.
Service provider and contractor terms are required: restrict data use, require compliance, and prevent selling or sharing. Vendor oversight is part of your program.
Everyone who handles personal data should understand privacy rights, data handling principles, SPI restrictions, and security basics.
Annually at minimum - more often when handling SPI at scale. If the CPPA's formal risk assessment regulations apply to you, obligations began January 1, 2026, with first attestations due April 1, 2028.
It applies if you are a for-profit business handling California residents' personal information and you cross any one threshold: revenue over $26,625,000, personal information of 100,000 or more consumers or households, or 50% of revenue from selling or sharing personal information. Below the thresholds, you can still be bound by contract when your customers are covered - their compliance obligations flow down to you.
Civil penalties run up to $2,663 per violation and $7,988 per intentional violation or violation involving consumers under 16 (CPI-adjusted figures, effective January 1, 2025). Separately, consumers can sue after a breach of nonencrypted, nonredacted personal information - statutory damages of $107 to $799 per consumer per incident, no proof of loss required.
It depends on how much of the foundation exists. The assessment that scopes it runs two to four weeks; most SMBs then close core gaps - data inventory, policy updates, rights workflows, vendor contracts - over the following months. Deadline-driven items like ADMT (January 1, 2027) and phased audits (2028-2030) get scheduled into the roadmap.
It depends on your data footprint and how much of the security foundation you already have. We publish no price list; you get a firm quote after the assessment, and the conversation costs nothing.
Probably - CCPA/CPRA is a legal-and-governance program, not just an IT task. Our co-managed approach adds the compliance structure, documentation, and risk oversight alongside what your provider already does well. No turf wars, no duplication.
GDPR is EU law with broad extraterritorial reach and fines up to 4% of worldwide turnover; CCPA/CPRA is California law with revenue and volume thresholds, CPI-adjusted penalties, and a breach-triggered private right of action. The underlying controls overlap heavily - data inventory, minimization, rights workflows, vendor contracts - so building for one covers much of the other.
Some businesses can, with the right structure. Our DIY-with-support tier gives you the gap analysis and executive decision support while your team does the work - scoped and quoted after your assessment.
Start by finding out where you actually stand. Our Cyber Risk & Compliance Gap Assessment inventories your personal data, tests your controls against the law's expectations, and hands you a prioritized roadmap.
Official source: California Privacy Protection Agency
Secondary source: California Legislative Information - Civ. Code §1798.100 et seq.
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25