What CCPA actually requires
The CCPA gives California residents the right to know what personal information businesses collect about them and the right to opt out of the sale or sharing of that information. For cookies, the focus is on a clear opt-out mechanism — not opt-in like the GDPR.
Key requirements
- Provide a clear 'Do Not Sell or Share My Personal Information' link or signal
- Honour the Global Privacy Control (GPC) browser signal
- Disclose the categories of personal information collected and the purposes for collection
- Respond to consumer requests to know, delete, or correct their data within 45 days
- Avoid discriminating against users who exercise their privacy rights
At a glance
Full name
California Consumer Privacy Act
Region
California, USA
Status
In force since January 2020
Who it affects
For-profit businesses that collect personal information from California residents and meet at least one of: $25M+ in annual revenue; data on 100,000+ Californians; or 50%+ of revenue from selling personal data.
Penalties
Up to $2,500 per unintentional violation and $7,500 per intentional violation, per affected consumer. Class actions are also possible for data breaches.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
