iQ Cookie State Law Series
Cookie & Privacy Law in California
Educational purposes only — not legal advice. This guide is intended to help you understand California’s privacy and cookie consent laws. Laws change, and your situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
California is where US privacy law started — and it is still the toughest state in the country. The California Consumer Privacy Act (CCPA) passed in 2018 and took effect January 1, 2020. Voters then strengthened it in November 2020 with Proposition 24, the California Privacy Rights Act (CPRA), which took full effect January 1, 2023 and created the California Privacy Protection Agency (CPPA) — the only dedicated privacy regulator in the nation.
Every other state law in this series is, in one way or another, a reaction to California. And unlike most of those laws, California’s is actively enforced: regulators have collected seven-figure settlements from household names, and cookie banners and opt-out links are exactly what they keep checking. If you sell to Californians, this is the one state guide you cannot skip.
California Consumer Privacy Act (CCPA)
AB 375 · In effect since January 1, 2020
California Privacy Rights Act (CPRA)
Prop 24 · In full effect since January 1, 2023
Who does it apply to?
The CCPA covers any for-profit business that does business in California and meets at least one of these three thresholds:
Annual gross revenue above $26.6 million — the original $25M figure, adjusted for inflation ($26,625,000 for 2026).
Buys, sells, or shares personal information of 100,000 or more California consumers or households per year.
Derives 50% or more of annual revenue from selling or sharing personal information.
Exemptions are narrower than other states: certain data covered by HIPAA, GLBA, and FCRA is exempt, but the businesses themselves are not automatically off the hook. Nonprofits and government agencies are out of scope.
That 100,000 threshold is easier to hit than it sounds. Roughly 275 California visitors a day puts a website over it in a year — and “consumers or households” counts browsing data collected by cookies, not just customer accounts. Plenty of mid-sized ecommerce and content sites are in scope without realizing it.
Consumer rights
California residents have the broadest set of privacy rights in the country:
Businesses must respond within 45 days (extendable once by 45 more). Consumers also have a right to non-discrimination — you cannot charge more or degrade service because someone exercised their rights.
What makes California different
The only state with a dedicated privacy agency. The CPPA exists to write rules and enforce this law, alongside the Attorney General. Sephora, Honda, Healthline, Disney, and Ford have all paid settlements — several specifically over broken cookie opt-outs.
Global Privacy Control (GPC) is mandatory. If a visitor’s browser sends an opt-out preference signal, you must treat it as a valid opt-out of sale and sharing — automatically, no click required. Regulators have penalized businesses whose sites ignored the signal.
“Sharing” counts, not just selling. The CPRA closed the “we don’t sell data” loophole: passing personal information to ad platforms for cross-context behavioral advertising is regulated even when no money changes hands. Most third-party ad and analytics cookies are covered.
No cure period. The CCPA’s original 30-day fix-it window was eliminated in 2023. Regulators may consider good-faith efforts, but they are not required to give you a chance to cure before penalties.
Consumers can sue over data breaches. California is the only state in this series with a private right of action — $100 to $750 per consumer per incident (inflation-adjusted upward) when unencrypted personal information is breached due to weak security.
New rules keep landing. CPPA regulations on cybersecurity audits and risk assessments took effect January 1, 2026. Opt-out rights for automated decision-making technology (ADMT) phase in by January 1, 2027. Data brokers must honor one-click deletion through the state’s DROP system as of August 1, 2026.
Sensitive data & children
California defines sensitive personal information broadly — but handles it differently than the opt-in states. Instead of requiring consent up front, California gives consumers the right to limit its use to what is necessary to deliver the service:
Children flip the default: you may not sell or share the personal information of a consumer you know is under 16 without opt-in consent. Ages 13–15 can consent themselves; under 13 requires a parent or guardian. Violations involving minors carry the higher penalty tier automatically — intent does not matter.
What this means for your cookies
| Cookie / data type | Requirement | What to do |
|---|---|---|
| Advertising cookies (cross-context behavioral) | Opt-out required | "Do Not Sell or Share My Personal Information" link, and actually stop the cookies when someone uses it. |
| GPC / opt-out signals | Required | Honor the browser signal automatically, site-wide. This is the #1 thing California enforcers test. |
| Sensitive data cookies (precise geolocation, health) | Limit-use right | Offer "Limit the Use of My Sensitive Personal Information" if you use it beyond delivering the service. |
| Any cookies — users under 16 | Opt-in required | No sale or sharing of known under-16 data without affirmative consent (parental under 13). |
| Analytics cookies | Check your setup | Third-party analytics that builds cross-site profiles can count as "sharing." Disclose it, and include it in your opt-out. |
Enforcement
Penalties are per violation — and every affected consumer can count as one. The statutory $2,500/$7,500 amounts adjust for inflation each year ($2,663 and $7,988 in 2026). This is not a paper tiger: California regulators have run coordinated sweeps of connected cars, streaming services, and data brokers, and settlements in 2025–2026 alone have topped $8 million combined. Broken opt-out links and ignored GPC signals are the most common violations cited.
Your action checklist
The law is already in effect and there is no cure period — this list is for right now:
Check your thresholds. Over $26.6M in revenue, 100,000+ California consumers or households, or 50%+ of revenue from selling or sharing data? Any one puts you in scope.
Add the “Do Not Sell or Share” link. Footer and cookie banner. Then verify it actually shuts off ad and tracking cookies — a link that does nothing is what Sephora, Honda, and Disney got cited for.
Honor GPC signals automatically. Your consent tool must detect the browser signal and apply the opt-out with zero clicks. Test it with a GPC-enabled browser before regulators do.
Handle sensitive data correctly. If cookies collect precise geolocation or health data beyond what the service needs, add the “Limit the Use of My Sensitive Personal Information” option.
Protect under-16 users. If minors use your site, no sale or sharing without opt-in — and remember the penalty tier triples automatically for minors’ data.
Update your privacy policy. California requires specific disclosures: categories collected, purposes, retention periods, who receives data, and how to exercise every right — refreshed at least every 12 months.
Get ahead of the 2027 deadlines. ADMT opt-out rights and built-in browser signals (AB 566) both land January 1, 2027. If your compliance is solid now, those become easy updates instead of fire drills.
iQ Cookie scans your site for compliance gaps, honors GPC out of the box, and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 3 of 25 · Next: Colorado →