CCPAEnacted, in effectDelete ActIn force since Aug 1, 2026
Who this affects: This page tracks California’s data-privacy regulations, including the CCPA, CPRA, and California Delete Act (DROP).
Content on this page is not legal advice
This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
CCPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.
Must
Honor verifiable requests to know, delete, and correct personal information within 45 days via designated request methods.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.130“Disclose and deliver the required information to a consumer free of charge, correct inaccurate personal information, or delete a consumer’s personal information, based on the consumer’s request, within 45 days of receiving a verifiable consumer request from the consumer.”Read the statute ↗·Official PDF ↗CA-1798.130“Make available to consumers two or more designated methods for submitting requests for information required to be disclosed pursuant to Sections 1798.110 and 1798.115, or requests for deletion or correction pursuant to Sections 1798.105 and 1798.106, respectively, including, at a minimum, a toll-free telephone number. A business that operates exclusively online and has a direct relationship with a consumer from whom it collects personal information shall only be
required to provide an email address for submitting requests for information required to be disclosed pursuant to Sections 1798.110 and 1798.115, or for requests for deletion or correction pursuant to Sections 1798.105 and 1798.106, respectively.”Read the statute ↗·Official PDF ↗
Conduct and document a risk assessment before initiating identified processing, and review it at least every three years.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.11 CCR § 7155 (CPPA regulations)“A business must conduct and document a risk assessment in accordance with the
requirements of this Article before initiating any processing activity identified in
section 7150, subsection (b).
(2)
At least once every three years, a business must review, and update as necessary, its
risk assessments to ensure that they remain accurate in accordance with the
requirements of this Article.”Read the regulation ↗
If you sell or share, honor opt-out preference signals, such as GPC, to opt consumers out of sale and sharing.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.11 CCR § 7025 (CPPA regulations)“A business that sells or shares personal information shall process any opt-out preference signal that meets the following requirements as a valid request to opt-out of sale/sharing”Read the regulation ↗
Can't
Sell or share a consumer's personal information after receiving their opt-out direction, unless they later provide consent.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.120“shall be prohibited, pursuant to paragraph (4) of subdivision (c) of Section 1798.135, from
selling or sharing the consumer’s personal information after its receipt of the consumer’s direction, unless the consumer subsequently provides consent”Read the statute ↗·Official PDF ↗CA-1798.120“A consumer shall have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer’s personal information. This right may be referred to as the right to opt out of sale or sharing.”Read the statute ↗·Official PDF ↗
Sell or share a known under-16's data unless they (if 13 or older) or a parent or guardian (if under 13) affirmatively authorize.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.120“a business shall not sell or share the personal information of consumers if the business has actual knowledge that the consumer is less than 16 years of age, unless the consumer, in the case of consumers at least 13 years of age and less than 16 years of age, or the consumer’s parent or guardian, in the case of consumers who are less than 13 years of age, has affirmatively authorized the sale or sharing of the consumer’s personal information. A business that willfully disregards the consumer’s age shall be deemed to have had
actual knowledge of the consumer’s age.”Read the statute ↗·Official PDF ↗
Use or disclose sensitive personal information beyond the purposes the law still permits after a consumer's limit direction.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.121“shall be prohibited, pursuant to paragraph (4) of subdivision (c) of Section 1798.135, from using or disclosing the consumer’s sensitive personal information for any other purpose after its receipt of the consumer’s direction unless the consumer subsequently
provides consent”Read the statute ↗·Official PDF ↗CA-1798.121“A consumer shall have the right, at any time, to direct a business that collects sensitive personal information about the consumer to limit its use of the consumer’s sensitive personal information”Read the statute ↗·Official PDF ↗
Should
Set a retention period for each disclosed purpose and purge personal information once no longer reasonably necessary for it.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.100“a business shall not retain a consumer’s personal information or
sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose”Read the statute ↗·Official PDF ↗
Build request and opt-out flows that never force account creation or ask for more information than an opt-out needs.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.130“shall not require the consumer to create an account with the business in order to make a verifiable consumer request provided that if the consumer, has an account with the business, the business may require the consumer to use that account to submit a verifiable consumer request.”Read the statute ↗·Official PDF ↗CA-1798.135“Not require a consumer to create an account or provide additional information beyond what is necessary in order to direct the business not to sell or share the consumer’s personal information or to limit use or disclosure of the consumer’s sensitive personal information.”Read the statute ↗·Official PDF ↗
When a request needs more than 45 days, tell the consumer of the extension and the reasons within 45 days of receipt.DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text.CA-1798.145“The business shall inform the consumer of any such extension within 45 days of receipt of the request, together with the reasons for the delay.”Read the statute ↗·Official PDF ↗
These are the highlights we judge most important, not everything CCPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.
The comprehensive law
California Consumer Privacy Act (as amended by CPRA)
CCPA (AB 375) is California’s comprehensive privacy law, separate from Delete Act above. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.
Status
Enacted, in effect
Archived excerpt — the text we read1798.198.
(a) Subject to limitation provided in subdivision (b), and in Section 1798.199, this title shall be operative January 1, 2020.
(b) This title shall become operative only if initiative measure No. 17-0039, The Consumer Right to Privacy Act of 2018, is withdrawn from the ballot pursuant to Section 9604 of the Elections Code.
(Amended (as added …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Effective
January 1, 2020
Most provisions added or amended by the CPRA (Proposition 24) became operative January 1, 2023.Archived excerpt — the text we read1798.198.
(a) Subject to limitation provided in subdivision (b), and in Section 1798.199, this title shall be operative January 1, 2020.
(b) This title shall become operative only if initiative measure No. 17-0039, The Consumer Right to Privacy Act of 2018, is withdrawn from the ballot pursuant to Section 9604 of the Elections Code.
(Amended (as added …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Enforcement began
July 1, 2020
CPRA-added or amended provisions: enforcement from July 1, 2023, for violations on or after that date (1798.185(d)).Archived excerpt — the text we read…rational mechanisms in this title to promote clarity and the functionality of this title for consumers.
(b) The Attorney General may adopt additional regulations as necessary to further the purposes of this title.
(c) The Attorney General shall not bring an enforcement action under this title until six months after the publication of the final regulations issued pursuant to this section or July 1, 2020, whichever is sooner.
(d) Notwithstanding subdivision (a), the timeline for adopting final regulations required by the act adding this subdivision shall be July 1, 2022. Beginning the later of July 1, 2021, or six months after the agency pr…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Signed
June 28, 2018
AB 375 (Stats. 2018, ch. 55) (approval line)Archived excerpt — the text we readBill Start
Assembly Bill
No. 375
CHAPTER 55
An act to add Title 1.81.5 (commencing with Section 1798.100) to Part 4 of Division 3 of the Civil Code, relating to privacy.
[
Approved by
Governor
June 28, 2018.
Filed with
Secretary of State
June 28, 2018.
]
LEGISLATIVE COUNSEL'S DIGEST
AB 375, Chau.
Privacy: personal information: businesses.
The California Constitution grants a right of privacy. Existing law provides for …Archived from source — captured 2026-08-14 · snapshot bc0edd68Verify at the source ↗
Corroborated byLegislative record
Enforced by
CPPA and Attorney General
California Privacy Protection Agency and the California Attorney GeneralArchived excerpt — the text we read1798.199.10.
(a) There is hereby established in state government the California Privacy Protection Agency, which is vested with full administrative power, authority, and jurisdiction to implement and enforce the California Consumer Privacy Act of 2018. The agency shall be governed by a five-member board, including the chairperson. The chairperson and one member of the board shall be appointed by the Governor. The Attorney General, Senate Rules
Committee, and Speaker o…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
No mandatory cure; the CPPA may allow one at its discretion. Statutory-damage breach suits need 30 days' notice to cure.Archived excerpt — the text we read1798.199.45.
(a) Upon the sworn complaint of any person or on its own initiative, the agency may investigate possible violations of this title relating to any business, service provider, contractor, or person. The agency may decide not to investigate a complaint or decide to provide a business with a time period to cure the alleged violation. In making a decision not to investigate or provide more time to cure, the agency may consider the following:
(1) Lack of intent to violate this title.
(2) Voluntary efforts undertaken by the business, service provider…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Private right of action
Yes, for data breaches only.
Archived excerpt — the text we read1798.150.
Personal Information Security Breaches
(a) (1) Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’
violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action for any of the following:
(A) To recover damages in an amount not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is great…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Universal opt-out signal
Required
Archived excerpt — the text we read… preference signal, a consumer can opt-out of sale and sharing of their personal
information with all businesses they interact with online without having to make
individualized requests with each business.
(b)
(c)
A business that sells or shares personal information shall process any opt-out preference
signal that meets the following requirements as a valid request to opt-out of sale/sharing:
(1)
The signal shall be in a format commonly used and recognized by businesses. An
example would be an HTTP header field or JavaScript object.
(2)
The platform, technology, or mechanism that sends the opt-out prefer…Archived from source — captured 2026-07-16 · snapshot 8d57eba9Verify at the source ↗
For-profit businesses that do business in California, collect consumers' personal information, and decide why and how it is processed, and meet: more than $26,625,000 annual revenue, or annually buys, sells, or shares the personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing personal information; other entities are covered regardless of this test (see full text)
A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers’ personal information, or on the behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers’ personal information, that does business in the State of California, and meets: more than $26,625,000 annual revenue, or annually buys, sells, or shares the personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing personal information. Also covered, regardless of the test above: Any entity that controls or is controlled by a business that meets the test above and that shares common branding with the business and with whom the business shares consumers' personal information; A joint venture or partnership composed of businesses in which each business has at least a 40 percent interest; A person that does business in California, that is not covered by the tests above, and that voluntarily certifies to the California Privacy Protection Agency that it is in compliance with, and agrees to be bound by, this title
Statutory base $25,000,000 (gross revenue in the preceding calendar year, measured as of January 1), adjusted by the CPPA under subdivision (d) of Section 1798.199.95; $26,625,000 has applied since January 1, 2025 (next adjustment January 1, 2027).
“that does business in the State of California, and that satisfies one or more of the following thresholds”
Right to accessArchived excerpt — the text we read1798.110.
Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information
(a) A consumer shall have the right to request that a business that collects personal information about the consumer disclose to the consumer the following:
(1) The categories of personal information it has collected about that consumer.
(2) The categories of sources from which the personal information is collected.
(3) The business or commercial purpose for collecting,…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to deleteArchived excerpt — the text we read1798.105.
Consumers’ Right to Delete Personal Information
(a) A consumer shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer.
(b) A business that collects personal information about consumers shall disclose, pursuant to Section 1798.130, the consumer’s rights to request the deletion of the consumer’s personal information.
(c) (1) A business …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to correctArchived excerpt — the text we read1798.106.
Consumers’ Right to Correct Inaccurate Personal Information
(a) A consumer shall have the right to request a business that maintains inaccurate personal information about the consumer to correct that inaccurate personal information, taking into account the nature of the personal information and the purposes of the processing of the personal information.
(b) A business that collects personal information about consumers shall disclose, pursuant to …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to know the categories of third-party recipientsArchived excerpt — the text we read1798.115.
Consumers’ Right to Know What Personal Information is Sold or Shared and to Whom
(a) A consumer shall have the right to request that a business that sells or shares the consumer’s personal information, or that discloses it for a business purpose, disclose to that consumer:
(1) The categories of personal information that the business collected about the consumer.
(2) The categories of personal information that the business sold or shared about the consumer and the categories of third pa…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to opt out of saleArchived excerpt — the text we read1798.120.
Consumers’ Right to Opt Out of Sale or Sharing of Personal Information
(a) (1) A consumer shall have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer’s personal information. This right may be referred to as the right to opt out of sale or sharing.
(2) A business to which another business transfers the personal information of a consumer as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the transferee assumes control of a…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to opt out of sharing for cross-context behavioral advertisingArchived excerpt — the text we read1798.120.
Consumers’ Right to Opt Out of Sale or Sharing of Personal Information
(a) (1) A consumer shall have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer’s personal information. This right may be referred to as the right to opt out of sale or sharing.
(2) A business to which another business transfers the personal information of a consumer as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the transferee assumes control of a…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to limit use of sensitive data (limited)Applies only to sensitive personal information collected or processed for the purpose of inferring characteristics about the consumer (1798.121(d)).Archived excerpt — the text we read1798.121.
Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information
(a) A consumer shall have the right, at any time, to direct a business that collects sensitive personal information about the consumer to limit its use of the consumer’s sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services, to perform the services set forth in paragraphs (2), (4), (5),…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right against discriminationArchived excerpt — the text we read1798.125.
Consumers’ Right of No Retaliation Following Opt Out or Exercise of Other Rights
(a) (1) A business shall not discriminate against a consumer because the consumer exercised any of the consumer’s rights under this title, including, but not limited to, by:
(A) Denying goods or services to the consumer.
(B) Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing pen…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Right to data portabilityArchived excerpt — the text we read… the business or commercial purpose for collecting, selling, or sharing the consumer’s personal information; and the categories of third parties to whom the business discloses the consumer’s personal information.
(iii) Provide the specific pieces of personal information
obtained from the consumer in a format that is easily understandable to the average consumer, and to the extent technically feasible, in a structured, commonly used, machine-readable format that may also be transmitted to another entity at the consumer’s request without hindrance. “Specific pieces of information” do not include data generated to help ensure security and integrity or as prescribed by regulation. Personal information is not considered to have been disclosed by a business when a con…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Private right of actionArchived excerpt — the text we read1798.150.
Personal Information Security Breaches
(a) (1) Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’
violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action for any of the following:
(A) To recover damages in an amount not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is great…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Who the law governs
BusinessesArchived excerpt — the text we read… a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.
(d) “Business” means:
(1) A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is
organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers’ personal information, or on the behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers’ personal information, that does business in the State of California, and that satisfies one or more of the following thresholds:
(A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Service providersArchived excerpt — the text we read…be considered sensitive personal information or personal information.
(af) “Service” or “services” means work, labor, and services, including services furnished in connection with the sale or repair of goods.
(ag) (1) “Service provider” means a person that processes personal information on behalf of a business and that receives from or on behalf of the business consumer’s personal information for a business purpose pursuant to a written contract, provided that the contract prohibits the person from:
(A) Selling or sharing the personal information.
(B) Retaining, using, or disclosing the personal information for any purpose other than for the business purposes specified in the contract for the business, including retaining, using, or disclosing the personal infor…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
ContractorsArchived excerpt — the text we read…on who is a California resident, as defined in Section 17014 of Title 18 of the California Code of Regulations, as that section read on September 1, 2017, however identified, including by any unique identifier.
(j) (1) “Contractor” means a person to whom the business makes available a consumer’s
personal information for a business purpose, pursuant to a written contract with the business, provided that the contract:
(A) Prohibits the contractor from:
(i) Selling or sharing the personal information.
(ii) Retaining, using, or disclosing the personal information for any purpose other than for the business purposes specified in the contract, including retaining, using, or disclosing the personal information for a com…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Third partiesArchived excerpt — the text we read…ry or categories of consumers’ personal information it has disclosed for a business purpose, or if the business has not disclosed consumers’ personal information for a business purpose, it shall disclose that fact.
(d) A third party shall not sell or share personal information about a consumer that has been sold to, or shared with, the third party by a business unless the consumer has received explicit notice and is provided an opportunity to exercise the right to opt-out pursuant to Section 1798.120.
(Amended November 3, 2020, by initiative Proposition 24, Sec. 8. Effective December 16, 2020. Operative January 1, 2023, pursuant to Sec. 31 of Proposition 24.)
Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Exemptions
Medical information under CMIA / HIPAA protected health informationArchived excerpt — the text we read…viding the personal information of a consumer to a person covered by an evidentiary privilege under California law as part of a privileged communication.
(c) (1) This title shall not apply to any of the following:
(A) Medical information governed by the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) or protected health information that is collected by a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human
Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191) and the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5).
(B) A provide…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Clinical trial/research data under Common Rule, ICH or FDAClinical trial / biomedical research data under the Common Rule, ICH good clinical practice guidelines or FDA human-subject rules (only if not sold or shared in a manner not permitted; an inconsistent use requires participant notice and consent).Archived excerpt — the text we read…c Law 104-191), to the extent the provider or covered entity maintains patient information in the same manner as
medical information or protected health information as described in subparagraph (A) of this section.
(C) Personal information collected as part of a clinical trial or other biomedical research study subject to, or conducted in accordance with, the Federal Policy for the Protection of Human Subjects, also known as the Common Rule, pursuant to good clinical practice guidelines issued by the International Council for Harmonisation or pursuant to human subject protection requirements of the United States Food and Drug…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
FCRA-regulated consumer reporting data (partial)Breach private right of action under 1798.150 still applies.Archived excerpt — the text we read…are” in Section 56.05 shall apply and the definitions of “business associate,” “covered entity,” and “protected health information” in Section 160.103 of Title 45 of the Code of Federal Regulations shall apply.
(d) (1) This title shall not apply to an activity involving the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer’s
creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, as defined in subdivision (f) of Section 1681a of Title 15 of the United States Code, by a furnisher of information, as set forth in Section 1681s-2 of Title 15 of the United States Code, who provides information for u…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
GLBA/California Financial Information Privacy Act/Farm Credit Act data (partial)Breach private right of action under 1798.150 still applies.Archived excerpt — the text we read…States Code and the information is not collected, maintained, used, communicated, disclosed, or sold except as authorized by the Fair Credit Reporting Act.
(3) This subdivision shall not apply to Section 1798.150.
(e) This title shall not apply to personal information collected, processed, sold, or disclosed subject to the federal Gramm-Leach-Bliley Act (Public Law 106-102), and implementing regulations, or the California Financial Information Privacy Act (Division 1.4 (commencing with Section 4050) of the Financial Code), or the federal Farm Credit Act of 1971 (as amended in 12 U.S.C. 2001-2279cc and implementing regulations, 12 C.F.R. 600, et seq.). This subdivision sh…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Driver's Privacy Protection Act data (partial)Breach private right of action under 1798.150 still applies.Archived excerpt — the text we read…4050) of the Financial Code), or the federal Farm Credit Act of 1971 (as amended in 12 U.S.C. 2001-2279cc and implementing regulations, 12 C.F.R. 600, et seq.). This subdivision shall not apply to Section 1798.150.
(f) This title shall not apply to personal information collected, processed, sold, or disclosed pursuant to the Driver’s Privacy Protection Act of 1994 (18 U.S.C. Sec. 2721 et seq.). This subdivision shall not apply to Section 1798.150.
(g) (1) Section 1798.120 shall not apply to vehicle information or ownership information retained or shared between a new motor vehicle dealer, as defined in Sectio…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Dealer-manufacturer vehicle warranty/recall data (sale opt-out only)Vehicle information and ownership information shared between a new motor vehicle dealer and the manufacturer for warranty repair or recall (opt-out of sale/sharing only, 1798.120).Archived excerpt — the text we read…pply to personal information collected, processed, sold, or disclosed pursuant to the Driver’s Privacy Protection Act of 1994 (18 U.S.C. Sec. 2721 et seq.). This subdivision shall not apply to Section 1798.150.
(g) (1) Section 1798.120 shall not apply to vehicle information or ownership information retained or shared between a new motor vehicle dealer, as defined in Section 426 of the Vehicle Code, and the vehicle’s manufacturer, as defined in Section 672 of the Vehicle Code, if the vehicle information or ownership information is shared for the purpose of effectuating, or in anticipation of effectuating, a vehicle repair covered by a vehicle warranty or a recall conducted pursuant to Sections 30118 to 30120, inclusive, of Title 49 of the United
States Code, provided that the new motor vehicle dealer or vehicle manufacturer with which that vehicle information or ownership information is shared does not sell, share, or use that information for any other purpose.
(2) Section 1798.120 shall not apply to vessel information or ownership information retained or shared between a vessel dealer and the vessel’s manufacturer, as defined in Section 651 of the Harbors and Navigation Code…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Dealer-manufacturer vessel warranty/recall data (sale opt-out only)Vessel information and ownership information shared between a vessel dealer and the manufacturer for warranty repair or recall (opt-out of sale/sharing only, 1798.120).Archived excerpt — the text we read…s Code, provided that the new motor vehicle dealer or vehicle manufacturer with which that vehicle information or ownership information is shared does not sell, share, or use that information for any other purpose.
(2) Section 1798.120 shall not apply to vessel information or ownership information retained or shared between a vessel dealer and the vessel’s manufacturer, as defined in Section 651 of the Harbors and Navigation Code, if the vessel information or ownership information is shared for the purpose of effectuating, or in anticipation of effectuating, a vessel repair covered by a vessel warranty or a recall conducted pursuant to Section 4310 of Title 46 of the United States Code, provided that the vessel dealer or vessel manufacturer with which that vessel information or ownership information is shared does not sell, share, or use
that information for any other purpose.
(3) For purposes of this subdivision:
(A) “Ownership information” means the name or names of the registered owner or owners and the contact information for the owner or owners.
(B) “Vehicle information” means the veh…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Commercial credit reporting agency business controller information (partial)Delete and opt-out only; only when used solely to identify the consumer's relationship to, or contact them in their role at, a business.Archived excerpt — the text we read…tors or of individuals exercising similar functions.
(iii) Has the power to exercise a controlling influence over the management of a company.
(3) This subdivision shall become inoperative on January 1, 2023.
(o) (1) Sections 1798.105 and 1798.120 shall not apply to a commercial credit reporting agency’s collection, processing, sale, or disclosure of business controller information to the extent the commercial credit reporting agency uses the business controller information solely to identify the relationship of a consumer to a business that the consumer owns or contact the consumer only in the consumer’s role as the owner, director, officer, or management employee of the business.
(2) For the purposes of this subdivision:
(A) “Business controller information” means the name or
names of the owner or owners, director, officer, or management employee of a business and the contact information, incl…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Household data (partial)Only the delete, correct, and know obligations in 1798.105, 1798.106, 1798.110 and 1798.115 do not apply; opt-out of sale/sharing, sensitive-PI limits, notice and other duties still apply.Archived excerpt — the text we read…ation is reported
to or collected by a commercial credit reporting agency as the primary manager of a business and used solely within the context of the natural person’s role as the primary manager of the business.
(p) The obligations imposed on businesses in Sections 1798.105, 1798.106, 1798.110, and 1798.115 shall not apply to household data.
(q) (1) This title does not require a business to comply with a verifiable consumer request to delete a consumer’s personal information under Section 1798.105 to the extent the verifiable consumer request applies to a …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Student grades held for a school (deletion requests only)Student grades, educational scores or test results held on behalf of the local educational agency at which the student is currently enrolled (deletion requests only; the business must notify the consumer).Archived excerpt — the text we read… context of the natural person’s role as the primary manager of the business.
(p) The obligations imposed on businesses in Sections 1798.105, 1798.106, 1798.110, and 1798.115 shall not apply to household data.
(q) (1) This title does not require a business to comply with a verifiable consumer request to delete a consumer’s personal information under Section 1798.105 to the extent the verifiable consumer request applies to a student’s grades, educational scores, or educational test results that the business holds on behalf of a local educational agency, as defined in subdivision (d) of Section 49073.1 of the Education Code, at which the
student is currently enrolled. If a business does not comply with a request pursuant to this section, it shall notify the consumer that it is acting pursuant to this exception.
(2) This title does not require, in response to a request pursuant to Section 1798.110, that a business disclose on educational standardized assessment or educational assessment or a consumer’s specific responses to th…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Physical items such as school yearbooks produced with consumer consent (partial)Delete and opt-out only; the business must have incurred significant expense in reliance on the consent, compliance must not be commercially reasonable, and it must comply as soon as commercially reasonable.Archived excerpt — the text we read…ucational standardized assessment or educational assessment” means releasing
information that would provide an advantage to the consumer who has submitted a verifiable consumer request or to another natural person.
(r) Sections 1798.105 and 1798.120 shall not apply to a business’s use, disclosure, or sale of particular pieces of a consumer’s personal information if the consumer has consented to the business’s use, disclosure, or sale of that information to produce a physical item, including a school yearbook containing the consumer’s photograph if:
(1) The business has incurred significant expense in reliance on the consumer’s consent.
(2) Compliance with the consumer’s request to opt out of the sale of the consumer’s personal information or to delete the co…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Deidentified information derived from HIPAA/Common Rule regulated patient informationExemption lost if the information is subsequently reidentified.Archived excerpt — the text we read…ns, uses, and discloses patient information in the same manner as medical information or protected health information as described in paragraph (1).
(4) (A) Information that meets both of the
following conditions:
(i) It is deidentified in accordance with the requirements for deidentification set forth in Section 164.514 of Part 164 of Title 45 of the Code of Federal Regulations.
(ii) It is derived from patient information that was originally collected, created, transmitted, or maintained by an entity regulated by the Health Insurance Portability and Accountability Act, the Confidentiality Of M…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Research information under HIPAA/Common Rule/FDA human subject protectionsArchived excerpt — the text we read…o applicable federal and state data privacy and security laws, including, but not limited to, the Health Insurance
Portability and Accountability Act, the Confidentiality Of Medical Information Act, and this title.
(5) Information that is collected, used, or disclosed in research, as defined in Section 164.501 of Title 45 of the Code of Federal Regulations, including, but not limited to, a clinical trial, and that is conducted in accordance with applicable ethics, confidentiality, privacy, and security rules of Part 164 of Title 45 of the Code of Federal Regulations, the Federal Policy for the Protection of Human Subjec…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
CMIA providers and HIPAA entities treating data as PHICMIA providers of health care / HIPAA covered entities treating patient information like medical information or PHI (1798.145(c)(1)(B); 1798.146(a)(2)).Archived excerpt — the text we read…gulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191) and the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5).
(B) A provider of health care governed by the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) or a covered entity governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), to the extent the provider or covered entity maintains patient information in the same manner as
medical information or protected health information as described in subparagraph (A) of this section.
(C) Personal information collected as part of a clinical trial or other biomedical research study subject to, or conducted in accordance with, the Federal Policy for the Protection of Human Subjects, also known as the …Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
HIPAA business associates, to the same extent (1798.146(a)(3))Archived excerpt — the text we read…Law 104-191), to the extent the provider or covered entity maintains, uses, and discloses patient information in the same manner as
medical information or protected health information as described in paragraph (1).
(3) A business associate of a covered entity governed by the privacy, security, and data breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191) and the federal Health Information Technology for Economic and Clinical Health Act, Title XIII of the federal American Recovery and Reinvestment Act of 2009 (Public Law 111-5), to the extent that the business associate maintains, uses, and discloses patient information in the same manner as medical information or protected health information as described in paragraph (1).
(4) (A) Information that meets both of the
following conditions:
(i) It is deidentified in accordance with the requirements for deidentification set forth in Section 164.514 of Part 164 of Title 45 of the Code of Fede…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Deidentified or aggregate consumer information (partial)1798.145(a)(1)(F). Does not apply to personal information related to accessing, procuring, or searching for contraception, pregnancy, perinatal, or abortion services, 1798.145(a)(2)(A).Archived excerpt — the text we read…y care, and perinatal care, including, but not limited to, abortion services, shall not constitute a natural person being at risk or danger of death or serious physical injury.
(E) Exercise or defend legal claims.
(F) Collect, use, retain, sell, share, or disclose consumers’ personal information that is deidentified or aggregate consumer information.
(G) Collect, sell, or share a consumer’s personal information if every aspect of that commercial conduct takes place wholly outside of California. For purposes of this title, commercial conduct takes place wholly outsi…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Commercial conduct taking place wholly outside California (partial)1798.145(a)(1)(G). Does not apply to personal information related to accessing, procuring, or searching for contraception, pregnancy, perinatal, or abortion services, 1798.145(a)(2)(A).Archived excerpt — the text we read…of death or serious physical injury.
(E) Exercise or defend legal claims.
(F) Collect, use, retain, sell, share, or disclose consumers’ personal information that is deidentified or aggregate consumer information.
(G) Collect, sell, or share a consumer’s personal information if every aspect of that commercial conduct takes place wholly outside of California. For purposes of this title, commercial conduct takes place wholly outside of California if the business collected that information while the
consumer was outside of California, no part of the sale of the consumer’s pers…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Privileged communications to a person covered by an evidentiary privilegeArchived excerpt — the text we read…ed on businesses by Sections 1798.110, 1798.115,
1798.120, 1798.121, 1798.130, and 1798.135 shall not apply where compliance by the business with the title would violate an evidentiary privilege under California law and shall not prevent a business from providing the personal information of a consumer to a person covered by an evidentiary privilege under California law as part of a privileged communication.
(c) (1) This title shall not apply to any of the following:
(A) Medical information governed by the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) or protected health…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Noncommercial free-press activities (1798.145(l))Archived excerpt — the text we read…obligation under this title or any other provision of law to take any action under this title in the event of a dispute between or
among persons claiming rights to personal information in the business’s possession.
(l) The rights afforded to consumers and the obligations imposed on any business under this title shall not apply to the extent that they infringe on the noncommercial activities of a person or entity described in subdivision (b) of Section 2 of Article I of the
California Constitution.
(m) (1) This title shall not apply to any of the following:
(A) Personal information that is collected by a business about a natural person in the course of the natural person acting as a job applicant to, an employe…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Evidentiary privilege (partial)Obligations under 1798.110, .115, .120, .121, .130 and .135 do not apply where compliance would violate a California evidentiary privilege.Archived excerpt — the text we read…egated and deidentified form and is not sold or shared.
(C) This paragraph does not alter the duty of a business to preserve or retain evidence pursuant to California or federal law in an ongoing civil proceeding.
(b) The obligations imposed on businesses by Sections 1798.110, 1798.115,
1798.120, 1798.121, 1798.130, and 1798.135 shall not apply where compliance by the business with the title would violate an evidentiary privilege under California law and shall not prevent a business from providing the personal information of a consumer to a person covered by an evidentiary privilege under California law as part of a privileged communication.
(c) (1) This title shal…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Rights and freedoms of other natural personsArchived excerpt — the text we read…in identifiable, linkable, or associable form, or collect, obtain, retain, or access any data or technology, in order to be capable of linking or associating a verifiable consumer request with personal information.
(k) The rights afforded to consumers and the obligations imposed on
the business in this title shall not adversely affect the rights and freedoms of other natural persons. A verifiable consumer request for specific pieces of personal information pursuant to Section 1798.110, to delete a consumer’s personal information pursuant to Section 1798.105, or to correct inaccurate personal informa…Archived from source — captured 2026-08-15 · snapshot fb97e290Verify at the source ↗·Official PDF ↗
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.
What you must do
Switch to your role
You collect and sell third-party personal data.
1
Register with the CPPA every year
Data brokers doing business in California must register with the CPPA each year by January 31. Failing to register carries a $200 per day administrative fine.
Beginning August 1, 2026, a data broker must access DROP at least once every 45 days and delete the personal information of consumers who requested it.
The DROP mechanism must let the consumer, or their authorized agent, verify the status of their deletion request — a distinct duty from checking DROP and deleting data (see "Data brokers must process via DROP" below).
Real regulatory actions and settlements under the California privacy laws we track. Every entry is a DataGrail summary linking to the primary source.
$478.5MTotal penalties
13Actions on record
Aug 262026Meta pays $459M to settle Cambridge Analytica privacy claims with four statesEight years after Cambridge Analytica broke, states are still collecting on it. This time it's $459 million, folded into an even larger settlement over Meta's design choices for kids.$459,300,000Source: California Attorney General
May 82026California AG fines GM and OnStar $12.75M for selling driver dataConnected-vehicle data is squarely in scope, and data minimization is now being enforced. Collect only what a stated purpose needs, and get real consent before selling location or behavior data.$12,750,000Source: California Attorney General
Jul 12025California AG fines Healthline $1.55M for sharing health data with advertisersTracking pixels that leak health-related signals draw the largest penalties. When a user opts out, the data flow to third parties has to actually stop, including page titles and identifiers.$1,550,000Source: California Attorney General
Sep 302025CPPA fines Tractor Supply a record $1.35M for CCPA violationsCPPA's largest fine to date, and its first decision addressing privacy protections for job applicants.$1,350,000Source: California Privacy Protection Agency (CalPrivacy)
Aug 242022California AG fines Sephora $1.2M for ignoring opt-out signalsSelling data through routine ad-tech and analytics tags still counts as a 'sale' under the CCPA. Honor Global Privacy Control automatically, and audit every vendor tag against your service-provider contracts.$1,200,000Source: California Attorney General
Mar 32026CPPA fines PlayOn Sports $1.1M for forcing tracking consent on school ticketing platformA first: California's privacy regulator drew a direct line from a school sports ticketing app to a company's ad-tracking practices, and fined it accordingly.$1,100,000Source: California Privacy Protection Agency (CalPrivacy)
DataGrail’s wording, not statutory text. The figures are computed from the linked sources.
Am I affected?
The data-broker check
If you collect and sell personal information about consumers you have no direct relationship with, the Delete Act's registration and processing obligations may apply to you.
581data brokers registered with California Privacy Protection Agency (CPPA) · as of Jul 15, 2026 · registry
Five questions, about a minute. Based on the “Not a Data Broker? California May Disagree” explainer. A self-assessment prompt, not legal advice.
Question 1 of 5
Does your business meet any of the following?
Select all that apply — you need at least one for California's data-broker rules to apply.
Published Jul 25, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.
When tracking Delete Act isn't enough, DataGrail automates the work.
Broker registration tracking, DSR automation, and the 45-day processing cycle — handled by the platform behind this reference. Clearly separate from the answer above.