The Complete Guide to CCPA & CPRA: What SMBs Need to Know to Stay Compliant

California has set the most influential privacy standard in the United States. The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give California residents enforceable rights over their personal information and put real obligations on the businesses that collect it.

Many small and mid-sized businesses assume these laws apply only to big tech. In practice, CCPA/CPRA reaches professional services firms, healthcare-adjacent vendors, e-commerce brands, SaaS applications, financial services, and marketing agencies - including companies outside California that handle California residents' data.

This guide breaks down what the laws cover, what compliance requires, and how to prepare your business - in plain English.

What It Is

What is the CCPA?

The California Consumer Privacy Act is a state privacy law that gives California consumers rights over their personal information and imposes duties on the businesses that collect, store, use, and share it. It was enacted in 2018 as AB 375 and took effect January 1, 2020, and it is widely regarded as the first comprehensive state privacy law in the United States (California Attorney General).

What is the CPRA?

The California Privacy Rights Act amends and expands the CCPA, closing loopholes and moving California's model closer to the EU's GDPR. California voters approved it as Proposition 24 in November 2020, and its amendments took effect January 1, 2023 (California Attorney General).

The CPRA:

  • Created a dedicated enforcement agency: the California Privacy Protection Agency (CPPA) now writes and enforces the regulations.
  • Defined sensitive personal information (SPI): a new data category carrying stricter processing limits.
  • Tightened data minimization: collection is limited to what disclosed purposes actually require.
  • Expanded consumer rights: including correction and SPI limitation rights.
  • Mandated cybersecurity audits and risk assessments: requirements the CPPA finalized in 2025, with phased deadlines.

Together, these laws form one of the most comprehensive privacy regimes in the United States.

Who It Applies To

CCPA/CPRA applies to for-profit organizations that do business in California, handle California residents' personal information, and meet any one of three thresholds (California Attorney General):

  • Revenue: annual gross revenue over $26,625,000. That is the statutory $25 million figure, adjusted for inflation effective January 1, 2025.
  • Volume: buying, selling, or sharing the personal information of 100,000 or more consumers or households.
  • Data economy: deriving 50% or more of annual revenue from selling or sharing personal information.

Below the thresholds? You can still be pulled in.

Service providers and contractors are not covered "businesses" under the thresholds - they are separately defined roles with their own duties. The law requires covered businesses to bind their vendors by contract: restricted data use, required security, and help with consumer rights requests.

This is the big one for SMBs. If your customers must comply, meeting their contractual compliance requirements becomes a condition of keeping them.

What Information Is Regulated

The CCPA defines personal information (PI) broadly - nearly anything that identifies or can reasonably be linked to a person or household.

Examples of PI:

  • Names, addresses, and phone numbers
  • Email addresses
  • Account credentials
  • Browsing history and online identifiers
  • IP addresses
  • Location data
  • Purchase history
  • Device IDs
  • Inferred behavioral profiles

The CPRA adds sensitive personal information (SPI), including:

  • Social Security numbers
  • Driver's license numbers
  • Precise geolocation
  • Financial account information
  • Biometric data
  • Health data not covered by HIPAA
  • Racial or ethnic origin
  • Union membership
  • Sexual orientation
  • Contents of private messages

SPI triggers higher security obligations and stricter processing limits.

What rights do consumers have under CCPA/CPRA?

The law requires businesses to provide working mechanisms for consumers to:

1. Know: what personal information is collected, for what purposes, and who it is shared with. 2. Access: receive a copy of their personal information on request. 3. Correct: fix inaccurate information. The CPRA added this right. 4. Delete: have their information deleted, with limited exceptions. 5. Opt out: of the sale of their data, of sharing for cross-context behavioral advertising, and of certain uses of automated decisionmaking technology (ADMT). The ADMT regulations were finalized in 2025, with compliance required beginning January 1, 2027. 6. Limit: the use and disclosure of sensitive personal information. 7. Not face discrimination: consumers cannot be penalized for exercising any of these rights.

Relation to Other Frameworks

CCPA/CPRA is California law, but it does not exist in isolation.

The GDPR parallel. The CPRA moves California's model closer to the EU's GDPR: sensitive data categories, minimization, and expanded individual rights. Work done for one covers much of the other.

Other state privacy laws. Colorado (CPA), Virginia (CDPA), Connecticut (CTDPA), Utah (UCPA), New Jersey, and a growing list of states have followed California's lead. Building to CCPA/CPRA gives you a foundation those laws largely share - preparing now avoids costly fire drills later.

Overlapping data categories. Biometric SPI overlaps with Illinois's BIPA. Health data outside healthcare is SPI here, while HIPAA governs it inside covered entities. Children's data intersects with COPPA, and the CCPA/CPRA penalty tier for consumers under 16 raises those stakes.

Privacy management standards. ISO/IEC 27701 provides a certifiable structure for operationalizing these obligations across every privacy law you face.

IT Requirements

Many SMBs think privacy laws just mean updating the privacy policy. In reality, compliance requires real changes to technology, cybersecurity, and data management operations. Here is what the law expects to be in place:

1. Strong access controls. Only authorized individuals may access PI or SPI. That means role-based access controls (RBAC), enforced MFA, least-privilege permissions, and logging with audit trails.

2. Encryption at rest and in transit. The statute does not name encryption as a mandate. But the private right of action reaches breaches of nonencrypted, nonredacted personal information caused by a failure to maintain reasonable security (Civ. Code §1798.150) - which makes encryption one of the strongest mitigating controls available to you.

3. Data minimization. The CPRA limits collection to what disclosed purposes require. Stop collecting unnecessary data, stop retaining data longer than needed, and document your purpose limitations.

4. Data retention schedules. The CPRA requires disclosure of how long data is retained, why it is retained, and when it will be deleted. This is newer than most SMB documentation - many businesses have never written it down.

5. Vendor and contractor management. The law requires contracts holding your service providers to CPRA standards: restricted data use, no selling or sharing, security obligations, and assistance with consumer rights requests. You can remain accountable when a vendor mishandles data - the law expects contracts and due diligence, so vendor oversight is part of your compliance program, not someone else's.

6. Consumer rights workflows. Access, deletion, correction, opt-out, and SPI limitation requests all need to be fulfilled quickly and securely. That takes ticketing or case tracking, identity verification, and system integrations that can actually locate the data.

7. Incident response and breach notification. A documented incident response plan, trained staff, tabletop exercises, and prompt notification of affected consumers after a breach. Mishandled SPI raises breach exposure under the CPRA.

8. Cybersecurity audits and risk assessments. The CPPA finalized its cybersecurity audit, risk assessment, and ADMT regulations in September 2025; they took effect January 1, 2026. Annual audit certifications phase in by revenue: April 1, 2028 for businesses over $100 million, April 1, 2029 for $50 to $100 million, and April 1, 2030 below $50 million. Risk assessment obligations began January 1, 2026, with the first attestations due April 1, 2028 (CPPA regulations).

Why It Matters

What happens if you don't comply?

CCPA/CPRA carries some of the strictest privacy enforcement in the United States.

Civil penalties. Regulators can seek up to $2,663 per violation, and up to $7,988 per intentional violation or per violation involving consumers under 16. Those are the statutory $2,500 and $7,500 figures, CPI-adjusted effective January 1, 2025. Penalties count per violation, so totals climb fast.

The private right of action - consumers can sue you. When nonencrypted, nonredacted personal information is breached because a business failed to maintain reasonable security, consumers can sue directly (Civ. Code §1798.150). Statutory damages run $107 to $799 per consumer per incident, or actual damages, whichever is greater - the statutory $100 to $750 range, as adjusted January 1, 2025.

Do the math on a small incident: 2,000 affected consumers at the $799 cap is $1,598,000 in potential statutory damages. That is before any civil penalties, legal fees, or reputational cost.

Note where the line sits: the private right of action reaches only nonencrypted, nonredacted data. Encryption and reasonable security are not just good practice - they are what keeps a breach from becoming a class action.

How It Fits Into Cyber Risk Management

Treat CCPA/CPRA as a program, not a project. The obligations now arrive on a schedule - ADMT compliance beginning January 1, 2027, phased audit certifications from 2028 - and enforcement belongs to a dedicated agency with rulemaking authority.

That is exactly what a Governance, Risk & Compliance program manages: tracking which deadlines apply to you, keeping documentation current, and assigning ownership. Cyber Risk Management keeps the underlying controls real, and Third-Party Assessments validate them independently - the same evidence your privacy compliance rests on.

The CPPA remains active on retention guidance, SPI processing limits, and enforcement. Businesses that build the program now, with strong controls, documented data practices, and privacy built into operations, stay compliant and become safer, more trustworthy, and more resilient in the process.

How We Help With CCPA/CPRA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your data inventory and controls against the CCPA/CPRA thresholds, the CPPA's audit and risk assessment rules, and the reasonable-security bar behind the private right of action.

How to Prepare

  1. 01Identify what personal data you collect and where it lives

    Build the data inventory: systems, data types, data flows, and every vendor who receives data. You cannot protect or disclose what you have not mapped.

  2. 02Classify data into PI and SPI

    Sensitive personal information requires stricter controls and minimized processing. Classification decides which obligations attach to which systems.

  3. 03Implement or upgrade cybersecurity controls

    The essentials: MFA everywhere, endpoint protection, email security, encryption, logging, SIEM or monitoring, regular backups, and a tested incident response plan.

  4. 04Update your privacy policy

    It needs to disclose the categories of PI collected, purposes of use, retention periods, sales and sharing practices, SPI handling, and how consumers exercise their rights.

  5. 05Build a consumer rights request workflow

    Web forms for intake, identity verification, internal ticketing, and automated data lookup where possible. Requests need to be answered quickly and securely.

  6. 06Update vendor agreements

    Service provider and contractor terms are required: restrict data use, require compliance, and prevent selling or sharing. Vendor oversight is part of your program.

  7. 07Train your staff

    Everyone who handles personal data should understand privacy rights, data handling principles, SPI restrictions, and security basics.

  8. 08Conduct regular risk assessments

    Annually at minimum - more often when handling SPI at scale. If the CPPA's formal risk assessment regulations apply to you, obligations began January 1, 2026, with first attestations due April 1, 2028.

Frequently Asked Questions

Does CCPA/CPRA apply to my business?

It applies if you are a for-profit business handling California residents' personal information and you cross any one threshold: revenue over $26,625,000, personal information of 100,000 or more consumers or households, or 50% of revenue from selling or sharing personal information. Below the thresholds, you can still be bound by contract when your customers are covered - their compliance obligations flow down to you.

What happens if we're not compliant with CCPA/CPRA?

Civil penalties run up to $2,663 per violation and $7,988 per intentional violation or violation involving consumers under 16 (CPI-adjusted figures, effective January 1, 2025). Separately, consumers can sue after a breach of nonencrypted, nonredacted personal information - statutory damages of $107 to $799 per consumer per incident, no proof of loss required.

How long does it take to become CCPA/CPRA compliant?

It depends on how much of the foundation exists. The assessment that scopes it runs two to four weeks; most SMBs then close core gaps - data inventory, policy updates, rights workflows, vendor contracts - over the following months. Deadline-driven items like ADMT (January 1, 2027) and phased audits (2028-2030) get scheduled into the roadmap.

What does CCPA/CPRA compliance cost?

It depends on your data footprint and how much of the security foundation you already have. We publish no price list; you get a firm quote after the assessment, and the conversation costs nothing.

We already have an IT provider. Do we still need help with this?

Probably - CCPA/CPRA is a legal-and-governance program, not just an IT task. Our co-managed approach adds the compliance structure, documentation, and risk oversight alongside what your provider already does well. No turf wars, no duplication.

What's the difference between CCPA/CPRA and GDPR?

GDPR is EU law with broad extraterritorial reach and fines up to 4% of worldwide turnover; CCPA/CPRA is California law with revenue and volume thresholds, CPI-adjusted penalties, and a breach-triggered private right of action. The underlying controls overlap heavily - data inventory, minimization, rights workflows, vendor contracts - so building for one covers much of the other.

Can we handle CCPA/CPRA compliance ourselves?

Some businesses can, with the right structure. Our DIY-with-support tier gives you the gap analysis and executive decision support while your team does the work - scoped and quoted after your assessment.

Where do we start with CCPA/CPRA?

Start by finding out where you actually stand. Our Cyber Risk & Compliance Gap Assessment inventories your personal data, tests your controls against the law's expectations, and hands you a prioritized roadmap.

Official source

Official source: California Privacy Protection Agency

Secondary source: California Legislative Information - Civ. Code §1798.100 et seq.

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25