California CCPA Compliance Guide for Website Owners (2026)
Your website must comply with the CCPA if your business meets any one of three tests: annual gross revenue over $26,625,000, you buy/sell/share the personal information of 100,000+ California consumers or households per year, or 50% or more of your annual revenue comes from selling or sharing personal information. If none of these apply to you, CCPA doesn’t cover your site — though you may still need to check other state privacy laws with lower thresholds.
Who Actually Has to Comply With CCPA?
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), only applies to for-profit businesses that collect personal information from California residents and meet at least one of the following thresholds:
The trap most small WooCommerce and Shopify store owners fall into: thinking revenue is the only test. A niche blog with under $1M in revenue but 100,000+ annual visitors running third-party ad pixels or retargeting cookies can still trigger CCPA through the data-volume threshold alone.
If you’re not sure which test applies to your site, run it through our free Privacy Law Scanner — it checks your live site for tracking scripts and flags which thresholds are likely relevant.
What CCPA/CPRA Actually Requires From a Website
Once you’re in scope, the obligations that touch your actual website (not just internal data policy) are:
- A “Do Not Sell or Share My Personal Information” link (or equivalent opt-out mechanism) visible in your footer.
- Honoring Global Privacy Control (GPC) signals automatically — as of recent CPPA enforcement actions, failing to detect and honor GPC browser signals has become one of the most heavily fined violations.
- A “Notice at Collection” shown at or before the point personal information is collected (checkout forms, contact forms, newsletter signups).
- An updated Privacy Policy disclosing categories of data collected, purposes, retention, and third parties data is shared with.
- A process to handle consumer rights requests — access, deletion, correction, and opt-out — typically within 45 days.
- Special handling for sensitive personal information (precise geolocation, health data, etc.) — consumers must be able to limit its use.
Penalties for Non-Compliance
Under Civil Code §1798.155, the California Privacy Protection Agency (CPPA) can issue administrative fines of up to $2,500 per violation, or up to $7,500 per intentional violation (this rises automatically for violations involving a consumer known to be under 16). Because each affected consumer can count as a separate violation, fines scale fast — 2025–2026 enforcement actions against mid-size retailers have landed in the six- and seven-figure range, frequently tied to exactly the kind of issue small sites overlook: not honoring GPC signals, missing opt-out links, or letting third-party pixels fire before consent.
Unlike most other state privacy laws, CCPA also grants consumers a private right of action for data breaches involving certain unencrypted personal information, with statutory damages of $100–$750 per consumer per incident — meaning a breach can trigger class-action-style exposure even without CPPA involvement.
Curious how California compares to Texas, Virginia, and Colorado on penalties and private right of action? See the full US State Privacy Laws Matrix.
CCPA Compliance Checklist for Small Business Websites
- Confirm whether your business meets any of the 3 revenue/volume thresholds
- Add a “Do Not Sell or Share My Personal Information” link to your site footer
- Implement automatic GPC signal detection and honor opt-outs in real time
- Add a Notice at Collection at every data collection point (forms, checkout, chat widgets)
- Update your Privacy Policy with CCPA-required disclosures
- Set up a workflow to respond to consumer rights requests within 45 days
- Audit third-party scripts/pixels that may be “selling” or “sharing” data without your knowledge
- Re-scan your site quarterly, since ad-tech scripts change often and can silently break compliance If you’re running WooCommerce, Shopify, or Wix, the technical implementation differs meaningfully by platform — see our platform-specific guides: CCPA for Shopify, CCPA for WooCommerce, CCPA for Wix.
FAQ
Does CCPA apply to my small business website? Only if you meet one of the three thresholds above. Revenue alone isn’t the full picture — a high-traffic site with third-party tracking cookies can qualify even with modest revenue, because the data-volume threshold counts unique consumers whose data is collected via cookies and pixels, not just direct sales.
What is the CCPA revenue threshold in 2026? $26,625,000 in annual gross revenue, company-wide (not California-only revenue). This figure is adjusted for inflation every two years by the CPPA.
Is Global Privacy Control (GPC) legally required under CCPA? Yes. California treats a GPC browser signal as a valid, universal opt-out request, and recent enforcement actions have specifically targeted businesses that failed to detect and honor it.
Do I need a cookie consent banner for CCPA? CCPA doesn’t require an EU-style cookie banner like GDPR. Instead it requires an opt-out mechanism (the “Do Not Sell/Share” link + GPC honoring) rather than opt-in consent for most data uses.
What happens if I ignore CCPA as a small e-commerce store? You risk CPPA administrative fines ($2,500–$7,500 per violation), and if you experience a data breach, direct consumer lawsuits with statutory damages. Fines are calculated per affected consumer, so even a small breach can add up quickly.