Skip to main content
Back to Guides
Compliance10 min read

CCPA/CPRA Cookie Consent: California Privacy Law Guide for Website Owners

Everything website owners need to know about California's CCPA and CPRA cookie consent requirements, from opt-out mechanisms to GPC support and enforcement penalties.

California's privacy laws have reshaped how websites handle cookies and personal data. The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), give residents the right to control how businesses collect and use their data. If your website serves California visitors, you need to understand what these laws require and how they affect your cookie consent practices.

This guide covers what CCPA and CPRA actually require, how they differ from European regulations like GDPR, and what you need to do on your website to stay compliant.

CCPA vs CPRA: What's the Difference?

The CPRA amended and expanded the CCPA effective January 1, 2023. When people say "CCPA" today, they usually mean the combined CCPA + CPRA framework. This guide covers both. The CPRA added new rights (correction, limiting use of sensitive data), created the California Privacy Protection Agency (CPPA), and introduced the concept of "sharing" data alongside "selling" it.

Who Needs to Comply?

CCPA/CPRA applies to for-profit businesses that collect personal information from California residents and meet at least one of these thresholds:

  • Annual gross revenue over $25 million
  • Buy, sell, or share the personal information of 100,000 or more California residents, households, or devices per year
  • Derive 50% or more of annual revenue from selling or sharing personal information

The second threshold is the one that catches most websites off guard. If you run analytics tools, advertising pixels, or any third-party tracking across your site, you're likely "sharing" data with those vendors. With 100,000 visitors a year (about 275 per day), you've crossed that line.

Opt-Out vs. Opt-In: How California Differs from Europe

This is the most important distinction for website owners to understand.

GDPR (Europe): Opt-in. You must get explicit consent before placing non-essential cookies. The default is "no" until the visitor clicks "Accept."

CCPA/CPRA (California): Opt-out. You can place cookies and collect data by default, but you must give visitors a clear way to opt out of the sale or sharing of their personal information. The default is "yes" until the visitor says "stop."

In practice, this means your cookie banner behaves differently for California visitors than for European ones. A European visitor sees a consent dialog they must interact with before tracking begins. A California visitor sees (or can access) an opt-out mechanism that stops the sale or sharing of their data when they use it.

GDPR vs. CCPA/CPRA: Cookie Consent at a Glance

RequirementGDPR (EU/EEA)CCPA/CPRA (California)
Consent modelOpt-in (prior consent required)Opt-out (data collection allowed by default)
Cookie banner required?Yes, before any non-essential cookiesNot technically, but a 'Do Not Sell/Share' link is required
Blocking before consent?Yes, scripts must wait for consentNo, scripts can load; opt-out stops future sharing
GPC signalEncouraged but not mandatedMust be honored as a valid opt-out
Applies toAny org processing EU residents' dataFor-profit businesses meeting revenue/data thresholds
PenaltiesUp to 4% of global annual turnover$2,500 per violation; $7,500 per intentional violation

What CCPA/CPRA Requires on Your Website

1. A "Do Not Sell or Share My Personal Information" Link

Every covered business must display a clear, conspicuous link on their website with the text "Do Not Sell or Share My Personal Information" (or a substantially similar phrase). This link must be accessible from every page, typically in the footer.

When a visitor clicks this link, they should reach a mechanism that lets them opt out of the sale and sharing of their personal information. This can be a preference center, a toggle panel, or a simple confirmation page.

2. A "Limit the Use of My Sensitive Personal Information" Link

If you collect sensitive personal information (precise geolocation, race, ethnicity, health data, financial accounts, etc.), you also need a separate link that lets visitors limit how you use that data. This was added by the CPRA.

3. Honor the Global Privacy Control (GPC) Signal

Since January 2023, California law requires businesses to treat the GPC browser signal as a valid opt-out request. If a visitor's browser sends a GPC signal (Sec-GPC: 1), your website must treat that as if they clicked your "Do Not Sell or Share" link.

This means you can't ignore it, you can't require a separate confirmation, and you can't prompt them to "reconsider." The signal is the opt-out.

GPC Is Not Optional

In 2024, the California Attorney General fined Sephora $1.2 million partly for failing to honor GPC signals. The CPPA has made GPC enforcement a stated priority. If your consent tool doesn't detect and act on GPC signals, you're exposed.

4. A Privacy Policy That Discloses Your Practices

Your privacy policy must explain:

  • The categories of personal information you collect
  • The purposes for collecting it
  • The categories of third parties you share it with
  • Whether you sell or share personal information (and which categories)
  • How consumers can exercise their rights (opt-out, deletion, access, correction)
  • Your data retention periods for each category

The policy must be updated at least once every 12 months.

5. Consumer Rights You Must Support

Beyond opt-out, CCPA/CPRA gives California residents these rights:

  • Right to Know: What personal information have you collected about me?
  • Right to Delete: Delete my personal information.
  • Right to Correct: Fix inaccurate personal information (added by CPRA).
  • Right to Opt-Out: Stop selling or sharing my data.
  • Right to Limit: Limit use of sensitive personal information (added by CPRA).
  • Right to Non-Discrimination: Don't punish me for exercising my rights.

You must respond to verifiable consumer requests within 45 days (extendable to 90 with notice).

Cookies and "Personal Information" Under CCPA

CCPA defines personal information broadly. It includes any information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household."

In the context of cookies, this covers:

  • Analytics cookies that track browsing behavior (Google Analytics, Hotjar, etc.)
  • Advertising cookies that build user profiles (Meta Pixel, Google Ads, etc.)
  • Device identifiers like IP addresses, browser fingerprints, and advertising IDs
  • Cross-site tracking via third-party cookies or server-side data sharing

Strictly necessary cookies (session management, shopping carts, security) are generally not considered "selling" or "sharing" and don't require an opt-out.

What Counts as "Selling" or "Sharing" Data?

This is where many businesses get tripped up.

Selling means disclosing personal information to a third party for monetary or other valuable consideration. If you use an analytics tool that collects your visitors' data and uses it to improve its own products, that could be considered a sale.

Sharing (added by CPRA) means disclosing personal information to a third party for cross-context behavioral advertising. If you run a Meta Pixel that sends visitor data to Meta for ad targeting, that's sharing.

The key insight: you don't have to receive money for it to count. If a third party gets your visitors' data and uses it for their own purposes (ad targeting, product improvement, data brokering), you're selling or sharing.

How to Make Your Website CCPA/CPRA Compliant

1

Audit your cookies and third-party scripts

Run a cookie scan to identify every cookie and script on your site. Categorize them as strictly necessary, analytics, marketing, or preferences. Document which third parties receive data from each one. CookieBeam's automated scanner does this for you and keeps the inventory updated as your site changes.

2

Add the required opt-out links

Place a "Do Not Sell or Share My Personal Information" link in your website footer. If you collect sensitive data, add a "Limit the Use of My Sensitive Personal Information" link too. These should be visible without scrolling through your footer and must link to a functional opt-out mechanism.

3

Implement a US opt-out panel

When a California visitor clicks your opt-out link, they need a clear interface to exercise their rights. This typically includes toggles for sale/sharing of data, targeted advertising, and sensitive data processing. CookieBeam provides a purpose-level opt-out panel that automatically adapts to US privacy requirements.

4

Honor GPC signals automatically

Configure your consent tool to detect the Sec-GPC: 1 header and automatically suppress data sharing for visitors who send it. With CookieBeam, GPC detection is built in. When a visitor's browser sends the signal, the banner automatically applies opt-out preferences without showing a dialog.

5

Block scripts after opt-out

When a visitor opts out, the scripts that share data with third parties must actually stop. This means blocking analytics and advertising scripts, not just recording the preference. Verify that your consent tool enforces blocking at the script level, not just at the cookie level.

6

Update your privacy policy

Add CCPA/CPRA-specific disclosures to your privacy policy: categories of data collected, third parties you share with, retention periods, and instructions for exercising consumer rights. Review and update it at least annually.

7

Set up a consumer rights request process

Provide at least two methods for consumers to submit requests (e.g., web form and email). Verify the requester's identity before processing. Track requests and respond within 45 days.

How CookieBeam Handles CCPA/CPRA

CookieBeam's regional consent system automatically detects visitor location and adapts the consent experience accordingly. For California visitors, here's what happens:

  • Opt-out model: Instead of blocking scripts until consent (GDPR mode), CookieBeam shows a US opt-out panel that lets visitors stop the sale and sharing of their data
  • GPC detection: When a browser sends the GPC signal, CookieBeam automatically applies opt-out preferences without showing a banner. The visitor's choice is honored silently.
  • Purpose-level controls: Visitors can opt out of specific purposes (sale/sharing, targeted advertising, sensitive data) rather than facing an all-or-nothing choice
  • Script blocking: When a visitor opts out, CookieBeam blocks the relevant third-party scripts from loading on subsequent page views
  • Consent logging: Every opt-out action is recorded with a timestamp and the visitor's choices, creating an audit trail you can reference if questioned by the CPPA

The key advantage is that you don't need to maintain separate consent flows for different regions. CookieBeam's framework presets handle the opt-in/opt-out distinction automatically based on the visitor's location.

Enforcement and Penalties

The California Privacy Protection Agency (CPPA), created by the CPRA, is the primary enforcement body. The California Attorney General also retains enforcement authority.

Civil penalties:

  • $2,500 per unintentional violation
  • $7,500 per intentional violation or per violation involving a minor's data

These are per-violation penalties. If your website serves thousands of California visitors without proper opt-out mechanisms, each visitor's interaction could be counted as a separate violation. The math gets large quickly.

Private right of action: Consumers can sue directly for data breaches involving unencrypted personal information, with statutory damages of $100 to $750 per consumer per incident.

The CPPA has been actively enforcing since 2024, with particular focus on:

  • Websites that don't honor GPC signals
  • Dark patterns that make opting out unreasonably difficult
  • Businesses that lack proper "Do Not Sell/Share" links
  • Inadequate privacy policy disclosures

Common CCPA Mistakes That Draw Enforcement

Burying the opt-out link: Placing the "Do Not Sell/Share" link deep in a submenu or making it hard to find. It must be conspicuous.
Requiring account creation: Forcing visitors to create an account before they can opt out. Opt-out must be frictionless.
Ignoring GPC: Not detecting or acting on the Global Privacy Control signal. This is a top enforcement priority.
Opt-out that doesn't actually stop data sharing: Recording the preference but continuing to fire tracking scripts. The opt-out must be technically enforced.

CCPA and Other US State Privacy Laws

California isn't alone anymore. As of 2026, over a dozen US states have enacted comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and Montana (MCDPA). Most follow a similar opt-out model to CCPA, though the specifics vary.

The trend is clear: US privacy regulation is expanding. Building your consent infrastructure to handle opt-out requirements now prepares you for new state laws as they take effect.

CookieBeam supports multi-state US privacy compliance through its regional consent framework, which maps each state's requirements to the appropriate opt-out behavior. You configure one banner, and it adapts to whichever law applies to each visitor.

Frequently Asked Questions

Do I need a cookie banner for California visitors?

Not in the same way as GDPR. California law doesn't require prior consent for cookies. However, you must provide a "Do Not Sell or Share My Personal Information" link and a functional opt-out mechanism. Many businesses use a banner or floating button to make this accessible.

Does CCPA apply to non-profit organizations?

No. CCPA/CPRA applies only to for-profit businesses that meet the revenue or data thresholds. Non-profits, government agencies, and businesses below the thresholds are exempt. However, if you're close to the threshold, it's safer to comply proactively.

What happens if a California visitor opts out but then clears their cookies?

If the opt-out preference was stored in a cookie and the visitor clears it, their preference is lost and they'll need to opt out again. CookieBeam mitigates this by using multiple storage mechanisms and by honoring GPC signals, which persist at the browser level regardless of cookie clearing.

Do I need to verify that a visitor is actually in California?

You should make a reasonable determination based on available signals (IP geolocation, account address, etc.). You don't need to demand proof of residency. If someone accesses your opt-out mechanism, it's best practice to honor the request regardless of location.

Can I use Google Consent Mode with CCPA?

Yes. Google Consent Mode v2 supports both opt-in (GDPR) and opt-out (CCPA) models. For California visitors, you can set the default consent state to "granted" and update it to "denied" when a visitor opts out. CookieBeam handles this automatically through its Consent Mode v2 integration.

Next Steps

If you're ready to make your website compliant with California's privacy laws, start with a cookie audit. Knowing what data you collect and which third parties receive it is the foundation for everything else.

CookieBeam's automated scanner identifies every cookie and script on your site, categorizes them, and sets up the opt-out mechanisms California law requires. The regional consent framework handles the differences between GDPR's opt-in model and CCPA's opt-out model automatically, so you don't need to maintain separate configurations for each region.

CCPA/CPRA Cookie Consent: California Privacy Law Guide | CookieBeam