Compliance
CCPA/CPRA Compliance Guide
Everything you need to know about California privacy laws
Everything you need to know about California's privacy laws and how to implement compliant cookie consent.
What is CCPA/CPRA?
- CCPA (California Consumer Privacy Act) - Effective January 2020
- CPRA (California Privacy Rights Act) - Amended CCPA, effective January 2023
These laws give California residents rights over their personal data and require businesses to provide opt-out mechanisms.
Who Must Comply?
Your business must comply with CCPA/CPRA if you:
- Have gross annual revenues over $25 million, OR
- Buy, sell, or share personal data of 100,000+ consumers, OR
- Derive 50%+ of annual revenue from selling personal data
AND you do business in California (even without physical presence).
Key Requirements
1. "Do Not Sell" Link
You must provide a clear link titled:
- "Do Not Sell or Share My Personal Information"
This link must be:
- Visible on your homepage
- In your privacy policy
- Easy to use (minimal clicks)
2. Right to Opt-Out
Users must be able to opt out of:
- Sale of personal information
- Sharing for cross-context behavioral advertising
3. Privacy Notice
Your privacy policy must disclose:
- Categories of personal information collected
- Purposes for collection
- Categories of third parties receiving data
- Instructions for exercising rights
CCPA vs GDPR: Key Differences
| Aspect | GDPR | CCPA/CPRA |
|---|---|---|
| Default | Opt-in required | Opt-out available |
| Applies to | All users | California residents |
| Consent | Prior consent | Can collect, must allow opt-out |
| Focus | All data processing | Sale/sharing of data |
GetCookies CCPA Features
Do Not Sell Banner
GetCookies automatically shows a compliant "Do Not Sell" banner for California visitors:
- Go to Domain Settings > Compliance
- Enable CCPA Mode
- Configure detection method:
- IP-based - Auto-detect California IPs
- Always Show - Show to all US visitors
Configuration Options
| Setting | Description |
|---|---|
| GPC Support | Honor Global Privacy Control signals |
| Link Text | Customize "Do Not Sell" link text |
| Confirmation | Show confirmation after opt-out |
| Cookie Duration | How long to remember opt-out |
Global Privacy Control (GPC)
GetCookies automatically detects and honors GPC browser signals. GPC is now legally binding in 12+ US states:
Legally Binding: CA, CO, CT, TX, OR, MT, DE, NJ, NH, NE, MN, MD
// GetCookies checks for GPC automatically
if (navigator.globalPrivacyControl) {
// User has GPC enabled - treat as opt-out
}Do Not Track (DNT)
GetCookies also detects the legacy DNT signal for completeness:
// DNT detection (not legally binding but good faith)
navigator.doNotTrack === '1'Implementation Checklist
- "Do Not Sell" link visible on homepage
- Privacy policy updated with CCPA disclosures
- Opt-out mechanism functional
- GPC signals honored (legally required in 12+ states)
- Opt-out persists for 12+ months
- No discrimination against users who opt out
- Data inventory documented
CPRA Updates (2023)
The CPRA added new requirements:
- Sensitive Personal Information - New category with enhanced protections
- Sharing - "Do Not Sell" expanded to include "sharing"
- Retention Limits - Must disclose and limit data retention
- Right to Correction - Users can correct inaccurate data
- Automated Decision-Making - Right to opt out of profiling
Penalties
Non-compliance can result in:
- $2,500 per unintentional violation
- $7,500 per intentional violation
- Private right of action for data breaches
Still stuck?
Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.