Back to the help center

Compliance

CCPA/CPRA Compliance Guide

Everything you need to know about California privacy laws

Everything you need to know about California's privacy laws and how to implement compliant cookie consent.

What is CCPA/CPRA?

  • CCPA (California Consumer Privacy Act) - Effective January 2020
  • CPRA (California Privacy Rights Act) - Amended CCPA, effective January 2023

These laws give California residents rights over their personal data and require businesses to provide opt-out mechanisms.

Who Must Comply?

Your business must comply with CCPA/CPRA if you:

  • Have gross annual revenues over $25 million, OR
  • Buy, sell, or share personal data of 100,000+ consumers, OR
  • Derive 50%+ of annual revenue from selling personal data

AND you do business in California (even without physical presence).

Key Requirements

You must provide a clear link titled:

  • "Do Not Sell or Share My Personal Information"

This link must be:

  • Visible on your homepage
  • In your privacy policy
  • Easy to use (minimal clicks)

2. Right to Opt-Out

Users must be able to opt out of:

  • Sale of personal information
  • Sharing for cross-context behavioral advertising

3. Privacy Notice

Your privacy policy must disclose:

  • Categories of personal information collected
  • Purposes for collection
  • Categories of third parties receiving data
  • Instructions for exercising rights

CCPA vs GDPR: Key Differences

AspectGDPRCCPA/CPRA
DefaultOpt-in requiredOpt-out available
Applies toAll usersCalifornia residents
ConsentPrior consentCan collect, must allow opt-out
FocusAll data processingSale/sharing of data

GetCookies CCPA Features

Do Not Sell Banner

GetCookies automatically shows a compliant "Do Not Sell" banner for California visitors:

  1. Go to Domain Settings > Compliance
  2. Enable CCPA Mode
  3. Configure detection method:
  • IP-based - Auto-detect California IPs
  • Always Show - Show to all US visitors

Configuration Options

SettingDescription
GPC SupportHonor Global Privacy Control signals
Link TextCustomize "Do Not Sell" link text
ConfirmationShow confirmation after opt-out
Cookie DurationHow long to remember opt-out

Global Privacy Control (GPC)

GetCookies automatically detects and honors GPC browser signals. GPC is now legally binding in 12+ US states:

Legally Binding: CA, CO, CT, TX, OR, MT, DE, NJ, NH, NE, MN, MD

javascript
// GetCookies checks for GPC automatically
if (navigator.globalPrivacyControl) {
  // User has GPC enabled - treat as opt-out
}

Do Not Track (DNT)

GetCookies also detects the legacy DNT signal for completeness:

javascript
// DNT detection (not legally binding but good faith)
navigator.doNotTrack === '1'

Implementation Checklist

  • "Do Not Sell" link visible on homepage
  • Privacy policy updated with CCPA disclosures
  • Opt-out mechanism functional
  • GPC signals honored (legally required in 12+ states)
  • Opt-out persists for 12+ months
  • No discrimination against users who opt out
  • Data inventory documented

CPRA Updates (2023)

The CPRA added new requirements:

  1. Sensitive Personal Information - New category with enhanced protections
  2. Sharing - "Do Not Sell" expanded to include "sharing"
  3. Retention Limits - Must disclose and limit data retention
  4. Right to Correction - Users can correct inaccurate data
  5. Automated Decision-Making - Right to opt out of profiling

Penalties

Non-compliance can result in:

  • $2,500 per unintentional violation
  • $7,500 per intentional violation
  • Private right of action for data breaches

Still stuck?

Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.