Zarv

US state privacy laws (CCPA/CPRA)

Also known as: CCPA · CPRA · California Consumer Privacy Act · California Privacy Rights Act · State privacy laws

The state laws that govern how businesses collect, use and share personal information in the absence of a general federal privacy law — led by California's CCPA as amended by the CPRA.

Legal basis

California Civil Code §1798.155

The United States has no general federal privacy statute; privacy is regulated by sector (FCRA for consumer reports, GLBA for financial institutions, HIPAA for health) and, increasingly, by state. California's CCPA, expanded by the CPRA ballot measure, gives residents the right to know, delete, correct and opt out of the sale or sharing of their personal information, and is enforced by the California Privacy Protection Agency and the Attorney General. Administrative fines run up to $2,500 per violation and $7,500 per intentional violation, adjusted for inflation.

The rules keep moving. Regulations approved in September 2025 took effect on January 1, 2026: businesses whose processing presents significant risk must run risk assessments from that date, and those using automated decisionmaking technology for significant decisions must meet the ADMT requirements from January 1, 2027. A growing list of other states has passed comprehensive privacy laws of its own, each with its own thresholds.

For risk decisions, the CCPA does not block the use of data, and information regulated by the FCRA or processed under GLBA is largely exempt. What it demands is purpose, proportionality and a record: why this data was used in this decision, and what the consumer was told. Behavioral models built for underwriting or fraud need that trail from day one.

Frequently asked questions

Does the CCPA apply to credit and financial data?

Partly. The CCPA exempts information regulated by the Fair Credit Reporting Act when it is used as that law authorizes, and personal information collected or processed under the Gramm-Leach-Bliley Act. Data outside those regimes, such as marketing or device data, is still covered, and the exemptions do not apply to the private right of action for data breaches.

What are the CCPA fines?

Up to $2,500 per violation and $7,500 per intentional violation or violation involving minors' data, adjusted for inflation, in actions by the California Privacy Protection Agency or civil penalties sought by the Attorney General.

Sources

Related terms

See it in practice

See risk before it costs you.

GDPR & CCPA Compliant · No commitment · Live in minutes