What is the CCPA? | Transmit Security

Glossary

What is the CCPA?

The CCPA is California’s consumer privacy law giving residents rights over their personal data. Learn what it requires and how it compares to the GDPR.
by Transmit Security

The CCPA (California Consumer Privacy Act), as strengthened by the CPRA (California Privacy Rights Act), is California’s landmark privacy law granting consumers rights over their personal information and imposing obligations on businesses that collect it. It’s the most influential US state privacy law and, alongside the GDPR, a key regulation shaping how organizations handle personal and identity data.

In the absence of a comprehensive US federal privacy law, the CCPA/CPRA set the pace, and many other US states have since passed similar laws modeled on it.

What rights the CCPA grants

The CCPA gives California consumers rights including: the right to know what personal information is collected and how it’s used, the right to access their data, the right to delete it, the right to opt out of the sale or sharing of their personal information, the right to correct inaccurate data (added by CPRA), and the right to non-discrimination for exercising these rights. Businesses must provide clear privacy disclosures and mechanisms (like "Do Not Sell or Share My Personal Information") to honor them.

CCPA vs. GDPR

The CCPA and GDPR share goals (consumer control over personal data, transparency, and rights of access and deletion) but differ in approach. The GDPR requires a lawful basis for all processing and is broadly consent-oriented; the CCPA focuses heavily on the right to opt out (particularly of data "sale" or "sharing") rather than requiring opt-in consent for most processing. The GDPR’s penalties and scope are generally broader. Organizations subject to both often align to the stricter GDPR standard as a baseline, which then helps satisfy CCPA obligations.

What it means for identity and data

Like the GDPR, the CCPA bears directly on identity systems, which hold personal information. Compliance requires knowing what personal data is held and being able to honor access, deletion, and opt-out requests, which is far easier with unified, well-governed identity data than with information fragmented across silos. It reinforces the same good practices: data minimization, transparency, and giving customers control. Techniques that reduce stored personal data (privacy-preserving verification, going passwordless) also reduce CCPA exposure.

The broader trend

The CCPA is part of a global wave of privacy regulation. With more US states enacting their own laws and international regimes proliferating, businesses increasingly need privacy practices that satisfy many overlapping regulations. Building identity and data systems around core privacy principles (minimize, secure, be transparent, honor rights) is the pragmatic way to stay compliant across this patchwork rather than chasing each law individually.

Frequently asked questions

What is the CCPA?

California’s consumer privacy law (strengthened by the CPRA) giving residents rights over their personal information and imposing obligations on businesses.

What rights does the CCPA give?

To know, access, delete, and correct personal data, to opt out of its sale/sharing, and to non-discrimination for exercising these rights.

How does the CCPA differ from the GDPR?

The GDPR requires a lawful basis and leans opt-in/consent; the CCPA emphasizes the right to opt out of data sale/sharing, with narrower scope.

How does the CCPA affect identity systems?

They must support access, deletion, and opt-out requests, which is easier with unified identity data and data-minimizing practices.

What is the CPRA?

The California Privacy Rights Act, which strengthened and expanded the CCPA, adding rights like correction and creating a dedicated privacy enforcement agency.

Related: GDPR · Consent Management · Data Breach · Digital Identity · eIDAS

Request a Demo

By clicking the button, you agree to the Terms and Conditions