Коротко
- CCPA is California state law on residents' rights over personal information; since 2023 it has been strengthened by CPRA amendments.
- Типичные пороги бизнеса (ориентир CPRA): $25M выручки · 100 000 consumers/households · ≥50% дохода от sale/share PI.
- Key rights: know, delete, correct, opt-out of sale/share, limit SPI, non-discrimination.
- For a marketer with smart links: cookies, pixels, and identifiers often fall under PI; sale/share is your assessment as controller.
Not legal advice
This article is an educational guide for a ClikBy account owner and marketer. Thresholds, exceptions, and wording change through CPPA regulations; check with counsel and official sources.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → CCPA. This is not legal advice and not a verbatim translation of other articles.
Timeline CCPA → CPRA
- January 1, 2020 — CCPA took effect.
- July 2020 — Attorney General enforcement began.
- November 3, 2020 — voters passed Proposition 24 (CPRA).
- January 1, 2023 — CPRA became operative; the California Privacy Protection Agency (CPPA) appears.
- 2023+ — CPRA enforcement / updated regulations (confirm enforcement dates against current CPPA rules).
In correspondence and on sites, «CCPA» often means «CCPA as amended by CPRA» — clarify which text is meant.
What CCPA is
The California Consumer Privacy Act is the first major state-level privacy act in the US. It gives California residents control over how for-profit businesses collect, use, sell, and disclose their personal information.
CPRA (often «CCPA 2.0») expands CCPA: sensitive data (SPI), the right to limit use of SPI, the right to correct, opt-out not only of sale but also of share for cross-context behavioral advertising, a separate CPPA regulator, and stricter requirements on disclosures and security assessments for some businesses.
The law's goal is transparency and data-subject rights, not a «European opt-in banner by default». The CCPA model is generally opt-out for sale/sharing of PI (with exceptions for minors and certain scenarios).
Who it covers
Guide (for-profit, does business in California / collects PI of Californians) — a business that collects consumers' personal information and meets at least one threshold:
- Валовая годовая выручка $25 000 000 or больше;
- Покупает, продаёт or share PI ≥ 100 000 California consumers or households в год (порог CPRA; в ранних материалах по «чистому» CCPA часто фигурировало 50 000 / devices — сверяйте актуальную редакцию);
- Derives 50%+ of annual income from selling or sharing personal information.
The law can apply to a company outside California if it «does business in California» and collects PI of state residents (for example, a site with a California audience). Non-profit is usually out of scope; there are sector carve-outs (HIPAA/CMIA, FCRA, GLBA, and others) — their borders are narrow, not «our site is not in CA → the law does not apply».
Практический сигнал: ~8 500–9 000 уникальных калифорнийских визитов в месяц легко дают ~100 000 в год — порог по объёму PI достижим и для среднего SaaS/e‑com.
What personal information is
PI is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
- Identifiers: name, alias, address, email, SSN, driver's license, passport, online ID, IP, and similar;
- Internet / electronic network activity: browser history, search history, interaction with a site, app, or ad;
- Geolocation; audio / electronic / visual / thermal / olfactory and similar data;
- Professional / employment-related information;
- Protected classifications under CA/federal law (race, religion, age, disability, sex, sexual orientation, and others);
- Inferences drawn from other PI.
Publicly available government records and de-identified / pseudonymized information that cannot reasonably be linked to a person are often excluded — but «we removed the name» ≠ automatically outside CCPA.
Cookies and unique personal identifiers that recognize a device linked to a consumer/family across services are treated as PI in CookieYes materials. Pixels on smart links follow the same logic.
Sensitive personal information (SPI)
CPRA singles out SPI — higher-risk categories: SSN and government ID, precise geolocation, health data, biometrics, race/ethnicity, religion, union membership, logins/financial accounts with access codes, data on sexual life/orientation, correspondence if the business is not the intended recipient, and others.
Besides Do Not Sell or Share, the consumer has the right to limit the use and disclosure of SPI if you use it more broadly than needed for the requested service. For ad funnels this more often concerns precise geolocation and identifiers that you yourself put in «sensitive» categories in the notice — do not promise SPI «automatically from ClikBy».
Sale, share, third party, service provider
- Sale — selling, rent, release, disclosure, dissemination, making available, transfer, or other communication of PI to another party for monetary or other valuable consideration. A cash payment is not required.
- Share (CPRA) — disclosing PI for cross-context behavioral advertising (targeting across contexts).
- Service provider — processes PI on behalf of the business under a written contract for a business purpose and may not use PI otherwise. Transfer to a service provider under a proper contract is usually not a sale.
- Third party — in essence «neither a business collector nor a contracted service provider».
Behavioral ads via third-party cookies / pixels are often discussed precisely as a possible sale or share. Sending data to a Meta/Google/TikTok pixel that you enable on the redirect is a judgment call for the campaign controller.
Consumer rights (CCPA + CPRA)
- Right to know / access — categories and specific pieces of PI, sources, purposes, third parties, sale/share.
- Right to delete — deletion of collected PI (with exceptions) and directing service providers to delete.
- Right to correct — correction of inaccurate PI (CPRA).
- Right to opt-out of sale / share — stop sale and share for cross-context ads.
- Right to limit SPI — limit the use/disclosure of sensitive data.
- Right to non-discrimination — you may not «punish» for exercising rights (denial of service, a different price — with caveats).
- Data portability — a copy in a usable format (in CPRA materials).
Response time for a verifiable consumer request — about 45 days, with a possible further 45-day extension with notice. Acknowledgment of receipt is often discussed around ~10 days. You need ≥2 ways to submit a request (form, email, toll-free, etc.).
How to prepare: a practical checklist
1. Data inventory
- What PI you collect (including cookies, IP, UTM, pixels, CRM);
- Why; where it is stored; who you share it with; whether there is SPI;
- Which vendors are service providers vs third parties; whether written contracts exist.
2. Notices and policy
- Privacy policy with 12-month categories, purposes, sources, sale/share, rights, contacts, update date;
- Notice at collection — before/at the moment of collection;
- Notice of right to opt-out / limit SPI — if you sell/share or use SPI beyond what is necessary;
- A description of how you handle Global Privacy Control (GPC), if applicable.
3. Opt-out mechanisms
- A Do Not Sell or Share My Personal Information link (or Your California Privacy Choices);
- An opt-out form / button; alternative channels;
- A cookie notice if third-party trackers may count as sale/share;
- Do not use dark patterns (extra steps, double negatives, «scroll the policy to find opt-out»).
4. Processes and security
- Consumer request forms + identity verification;
- Reasonable security; for some businesses — risk assessments / audits (CPRA);
- Contracts with service providers;
- Minimization and purpose limitation: do not collect «just in case».
The full Do Not Sell/Share guide — in a separate article.
Fines and enforcement
- Административные civil penalties: ориентир до $2 500 за unintentional и до $7 500 за intentional violation (за каждое нарушение; по минорам CPRA часто обсуждает усиленные штрафы).
- Private right of action — mainly for certain data breaches without reasonable security; statutory damages about $100–$750 per incident (or actual damages).
- Regulators: California Attorney General and CPPA (after CPRA).
- Historically CCPA had a 30-day cure period; in CPRA materials cure is often described as reduced/removed — do not rely on «they always give 30 days first».
How it connects to the ClikBy product
- The clicker of your smart link is the data subject; you (Customer) are the business/controller for the campaign purpose; ClikBy is the service provider/processor under instruction.
- Visits may include IP, UA, geo, referer, UTM, engagement, fingerprint_* — treat them as PI.
- Turning on ad pixels = potential share/sale to vendors; enable pixel_notification and describe vendors in your policy.
- The /cookies module helps on the client site; it is not an automatic Do Not Sell footer for all jurisdictions.
In ClikBy: roles Customer = controller / ClikBy = processor for clicks; the controls are Cookie Consent and pixel_notification on the redirect. A CCPA badge on the landing page does not replace your Do Not Sell or Share notice.
FAQ
Does CPRA replace CCPA?
CPRA is an amendment/expansion of CCPA, not «a different law instead». In everyday use both names get mixed.
Is GDPR compliance enough?
No. GDPR gives a strong base (rights, transparency, contracts), but the consent model, thresholds, sale/share, and notices in California are different. Comparison — in CCPA vs GDPR.
What about children?
Sale/share of PI of minors 13–16 — with the child's consent; under 13 — with parent/guardian consent (opt-in).