verified_user
Standardful
首页chevron_right标准chevron_rightCCPA/CPRA
有效国际标准update 最后更新:2025年1月

CCPA/CPRA

加州消费者隐私法案与加州隐私权法案

apartment发布组织:加利福尼亚州

标准简介

CCPA/CPRA 是由 加利福尼亚州 发布的有效标准,常用于科技、金融银行、零售、医疗健康、服务业等行业,并适用于美国等市场。

本页汇总了 CCPA/CPRA 的官方文档、当前状态以及常见相关认证或评估机构,便于快速理解要求与落地路径。

privacy_tip

Consumer Rights

Grants California residents the right to know, delete, correct, and opt out of the sale or sharing of their personal information — including rights over automated decision-making.

account_balance

Dedicated Enforcement Agency

The California Privacy Protection Agency (CPPA), established by CPRA, is the first dedicated state privacy enforcement body in the US, with rulemaking and enforcement authority.

gavel

Private Right of Action

Consumers can bring private lawsuits for data breaches involving unencrypted or non-redacted personal information, with statutory damages of $107 to $799 per consumer per incident.

list_alt Core Consumer Rights

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of sale/sharing of personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising rights
  • Right to opt out of automated decision-making technology

Who Needs to Comply?

groups

For-profit businesses that collect California residents' personal information and meet any threshold: annual gross revenue over $26.6 million, buy/sell/share data of 100,000+ consumers or households, or derive 50%+ of revenue from selling/sharing personal information.

Key Requirements

1

Privacy Notice & Disclosures

Provide a comprehensive privacy policy disclosing categories of personal information collected, purposes of collection, consumer rights, and whether information is sold or shared. Update at least annually.

2

Consumer Request Handling

Establish processes to receive and respond to consumer requests to know, delete, correct, and opt out. Verify consumer identity and respond within 45 days (extendable to 90 days).

3

Opt-Out Mechanisms

Provide a clear "Do Not Sell or Share My Personal Information" link. Honor Global Privacy Control (GPC) signals. Obtain opt-in consent before selling data of consumers under 16.

4

Data Minimization & Purpose Limitation

Collect, use, retain, and share personal information only as reasonably necessary and proportionate to the disclosed purposes. Inform consumers before using data for new purposes.

5

Service Provider Agreements

Enter written contracts with service providers and contractors restricting their use of personal information to the specific business purposes outlined in the agreement.

Penalties & Enforcement

warning

Administrative fines up to $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors (2025 adjusted amounts). Private lawsuits for data breaches can yield $107-$799 per consumer per incident. The largest settlement to date exceeded $1.5 million.

官方文档

查看全部

实施时间线

gavel
2018年6月
CCPA signed into law (AB 375)
check_circle
2020年1月
CCPA became effective
how_to_vote
2020年11月
CPRA (Proposition 24) approved by California voters, amending CCPA
update
2023年1月
CPRA amendments became operative, expanding consumer rights
payments
2025年1月
Penalty amounts adjusted for inflation — up to $7,988 per intentional violation

相关分类