# California CCPA Compliance Guide for Website Owners (2026)
Canonical: https://social-archive.org/arc/pMDNMLYTzu
Original URL: https://complystate.com/guides/california-ccpa/
Author: ComplyState Software
Platform: web
Share mode: full
## Content
![california-ccpa](https://complystate.com/wp-content/uploads/2026/07/california-ccpa-1024x576.png) **Your website must comply with the CCPA if your business meets any one of three tests: annual gross revenue over $26,625,000, you buy/sell/share the personal information of 100,000+ California consumers or households per year, or 50% or more of your annual revenue comes from selling or sharing personal information.** If none of these apply to you, CCPA doesn’t cover your site — though you may still need to check other state privacy laws with lower thresholds. --- ## Who Actually Has to Comply With CCPA? ![Image](https://complystate.com/wp-content/uploads/2026/07/Three-Thresholds.png) The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), only applies to **for-profit businesses** that collect personal information from California residents and meet at least one of the following thresholds: **The trap most small WooCommerce and Shopify store owners fall into:** thinking revenue is the only test. A niche blog with under $1M in revenue but 100,000+ annual visitors running third-party ad pixels or retargeting cookies can still trigger CCPA through the data-volume threshold alone. If you’re not sure which test applies to your site, run it through our free [Privacy Law Scanner](https://complystate.com/tools/website-scanner/) — it checks your live site for tracking scripts and flags which thresholds are likely relevant. --- ## What CCPA/CPRA Actually Requires From a Website ![Image](https://complystate.com/wp-content/uploads/2026/07/GPC-Do-Not-Sell.png) Once you’re in scope, the obligations that touch your actual website (not just internal data policy) are: 1. **A “Do Not Sell or Share My Personal Information” link** (or equivalent opt-out mechanism) visible in your footer. 2. **Honoring Global Privacy Control (GPC) signals** automatically — as of recent CPPA enforcement actions, failing to detect and honor GPC browser signals has become one of the most heavily fined violations. 3. **A “Notice at Collection”** shown at or before the point personal information is collected (checkout forms, contact forms, newsletter signups). 4. **An updated Privacy Policy** disclosing categories of data collected, purposes, retention, and third parties data is shared with. 5. **A process to handle consumer rights requests** — access, deletion, correction, and opt-out — typically within 45 days. 6. **Special handling for sensitive personal information** (precise geolocation, health data, etc.) — consumers must be able to limit its use. ## Penalties for Non-Compliance Under Civil Code §1798.155, the California Privacy Protection Agency (CPPA) can issue administrative fines of **up to $2,500 per violation, or up to $7,500 per intentional violation** (this rises automatically for violations involving a consumer known to be under 16). Because each affected consumer can count as a separate violation, fines scale fast — 2025–2026 enforcement actions against mid-size retailers have landed in the six- and seven-figure range, frequently tied to exactly the kind of issue small sites overlook: not honoring GPC signals, missing opt-out links, or letting third-party pixels fire before consent. Unlike most other state privacy laws, CCPA also grants consumers a **private right of action for data breaches** involving certain unencrypted personal information, with statutory damages of $100–$750 per consumer per incident — meaning a breach can trigger class-action-style exposure even without CPPA involvement. Curious how California compares to Texas, Virginia, and Colorado on penalties and private right of action? See the full [US State Privacy Laws Matrix](https://complystate.com/guides/us-state-privacy-laws-matrix/). ## CCPA Compliance Checklist for Small Business Websites ![Image](https://complystate.com/wp-content/uploads/2026/07/Compliance-checklist.png) - Confirm whether your business meets any of the 3 revenue/volume thresholds - Add a “Do Not Sell or Share My Personal Information” link to your site footer - Implement automatic GPC signal detection and honor opt-outs in real time - Add a Notice at Collection at every data collection point (forms, checkout, chat widgets) - Update your Privacy Policy with CCPA-required disclosures - Set up a workflow to respond to consumer rights requests within 45 days - Audit third-party scripts/pixels that may be “selling” or “sharing” data without your knowledge - Re-scan your site quarterly, since ad-tech scripts change often and can silently break compliance If you’re running WooCommerce, Shopify, or Wix, the technical implementation differs meaningfully by platform — see our platform-specific guides: [CCPA for Shopify](https://complystate.com/guides/california-ccpa/shopify/), [CCPA for WooCommerce](https://complystate.com/guides/california-ccpa/woocommerce/), [CCPA for Wix](https://complystate.com/guides/california-ccpa/wix/). --- ## FAQ **Does CCPA apply to my small business website?** Only if you meet one of the three thresholds above. Revenue alone isn’t the full picture — a high-traffic site with third-party tracking cookies can qualify even with modest revenue, because the data-volume threshold counts unique consumers whose data is collected via cookies and pixels, not just direct sales. **What is the CCPA revenue threshold in 2026?** $26,625,000 in annual gross revenue, company-wide (not California-only revenue). This figure is adjusted for inflation every two years by the CPPA. **Is Global Privacy Control (GPC) legally required under CCPA?** Yes. California treats a GPC browser signal as a valid, universal opt-out request, and recent enforcement actions have specifically targeted businesses that failed to detect and honor it. **Do I need a cookie consent banner for CCPA?** CCPA doesn’t require an EU-style cookie banner like GDPR. Instead it requires an opt-out mechanism (the “Do Not Sell/Share” link + GPC honoring) rather than opt-in consent for most data uses. **What happens if I ignore CCPA as a small e-commerce store?** You risk CPPA administrative fines ($2,500–$7,500 per violation), and if you experience a data breach, direct consumer lawsuits with statutory damages. Fines are calculated per affected consumer, so even a small breach can add up quickly.
