verified_user
Standardful
首頁chevron_right標準chevron_rightCCPA/CPRA
現行有效國際標準update 最後更新:2025年1月

CCPA/CPRA

加州消費者隱私法案與加州隱私權法案

apartment發布組織:加利福尼亞州

標準簡介

CCPA/CPRA 是由 加利福尼亞州 發布的現行有效標準,常用於科技、金融銀行、零售、醫療健康、服務業等產業,並適用於美國等市場。

本頁整理了 CCPA/CPRA 的官方文件、目前狀態以及常見相關認證或評估機構,便於快速理解要求與落地路徑。

privacy_tip

Consumer Rights

Grants California residents the right to know, delete, correct, and opt out of the sale or sharing of their personal information — including rights over automated decision-making.

account_balance

Dedicated Enforcement Agency

The California Privacy Protection Agency (CPPA), established by CPRA, is the first dedicated state privacy enforcement body in the US, with rulemaking and enforcement authority.

gavel

Private Right of Action

Consumers can bring private lawsuits for data breaches involving unencrypted or non-redacted personal information, with statutory damages of $107 to $799 per consumer per incident.

list_alt Core Consumer Rights

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of sale/sharing of personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising rights
  • Right to opt out of automated decision-making technology

Who Needs to Comply?

groups

For-profit businesses that collect California residents' personal information and meet any threshold: annual gross revenue over $26.6 million, buy/sell/share data of 100,000+ consumers or households, or derive 50%+ of revenue from selling/sharing personal information.

Key Requirements

1

Privacy Notice & Disclosures

Provide a comprehensive privacy policy disclosing categories of personal information collected, purposes of collection, consumer rights, and whether information is sold or shared. Update at least annually.

2

Consumer Request Handling

Establish processes to receive and respond to consumer requests to know, delete, correct, and opt out. Verify consumer identity and respond within 45 days (extendable to 90 days).

3

Opt-Out Mechanisms

Provide a clear "Do Not Sell or Share My Personal Information" link. Honor Global Privacy Control (GPC) signals. Obtain opt-in consent before selling data of consumers under 16.

4

Data Minimization & Purpose Limitation

Collect, use, retain, and share personal information only as reasonably necessary and proportionate to the disclosed purposes. Inform consumers before using data for new purposes.

5

Service Provider Agreements

Enter written contracts with service providers and contractors restricting their use of personal information to the specific business purposes outlined in the agreement.

Penalties & Enforcement

warning

Administrative fines up to $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors (2025 adjusted amounts). Private lawsuits for data breaches can yield $107-$799 per consumer per incident. The largest settlement to date exceeded $1.5 million.

官方文件

查看全部

實施時間線

gavel
2018年6月
CCPA signed into law (AB 375)
check_circle
2020年1月
CCPA became effective
how_to_vote
2020年11月
CPRA (Proposition 24) approved by California voters, amending CCPA
update
2023年1月
CPRA amendments became operative, expanding consumer rights
payments
2025年1月
Penalty amounts adjusted for inflation — up to $7,988 per intentional violation

相關分類