Skip to main content

Compliance · CCPA

CCPA website compliance

CCPA website compliance means your site's tracking, disclosures, and opt-out mechanics satisfy the California Consumer Privacy Act (as amended by the CPRA): telling Californians what you collect, honoring opt-outs including the Global Privacy Control browser signal, and not selling or sharing data collected before consent. Complidar captures every tracker, cookie, and consent flow on up to 120 pages and checks the mechanics regulators have actually punished.

Who it applies to

The CCPA covers for-profit businesses that do business in California and meet any one of three thresholds: more than $25 million in annual gross revenue; buying, selling, or sharing personal information of 100,000+ California consumers or households; or deriving 50%+ of revenue from selling or sharing personal information. 'Doing business in California' follows your customers, not your headquarters: an out-of-state ecommerce site selling to Californians can qualify.

Even below the thresholds, the same mechanics show up in other state privacy laws (Texas, Virginia, Colorado, Connecticut and more, all of which Complidar checks too), so building to CCPA's bar is rarely wasted work. Whether the statute reaches your specific business is a counsel question; what your site actually does with trackers is a scan question.

What enforcement looks like

Civil penalties run $2,500 per violation and $7,500 per intentional violation (or violations involving minors), enforced by the Attorney General and the California Privacy Protection Agency. Each affected consumer interaction can count as a violation, which is how numbers compound. Consumers also hold a private right of action for data breaches with statutory damages of $100–$750 per consumer per incident.

The pattern that gets punished is mechanical. The first public CCPA enforcement, In re Sephora ($1.2M, 2022), turned on two things an automated scan sees directly: third-party trackers running without qualifying disclosures, and ignoring the Global Privacy Control signal. The AG called GPC-ignoring out by name.

What Complidar checks for CCPA

  • Every third-party tracker and cookie that fires before consent, captured from real network traffic
  • Whether the site honors the Global Privacy Control (GPC) browser signal
  • Privacy-policy disclosures: categories collected, sale/share language, consumer-rights mechanics
  • A 'Do Not Sell or Share My Personal Information' pathway, where required
  • Dark patterns in the consent flow: no equally prominent reject option, pre-ticked boxes, confirm-shaming
  • Session-replay and analytics vendors that receive page activity

Honest limits: A scan verifies what your site does: which trackers fire, when, and what your policy says. It cannot determine whether your business meets the statutory thresholds or how your back office handles consumer requests; those are questions for counsel and process review. The report labels which is which.

CCPA questions

Does the CCPA apply to businesses outside California?

It can. The thresholds attach to doing business with California consumers, not to where you're incorporated. If Californians are a meaningful slice of your traffic and you meet a threshold, assume exposure and confirm with counsel. Complidar's jurisdiction tags mark which findings carry California-specific risk.

What is the Global Privacy Control, and do I have to honor it?

GPC is a browser-level signal that tells sites 'treat this as an opt-out of sale/sharing.' California's AG made clear in the Sephora action that ignoring it is a violation, not a technicality. Complidar sends the signal during scans and reports whether your site's behavior changes.

What did Sephora actually do wrong?

Per the settlement: third-party advertising trackers ran on its site amounting to a 'sale' of data without the required disclosures and opt-outs, and the site ignored GPC signals. It cost $1.2M and an injunction. Both failure modes are detectable by scanning, which is the point of checking before the regulator does.

Check your site free

CCPA is 1 of the 22 checks in every scan · up to 120 pages · no card

Last updated 2026-06-11 · Informational, not legal advice: how to read this