California Consumer Privacy Act (CCPA)
Definition
California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA) is a state privacy law giving California consumers rights over the personal information a business collects about them. It covers what firms know, how they share it, and what a consumer can force them to delete.
Most people meet the law through a footer link asking whether their data can be sold or shared. Behind that link sits a whole operating process.
Someone has to receive the request, confirm the person is who they say they are, find every record, and answer inside the deadline. That work is routine, high-volume, and heavily documented.
Which is exactly why so much of it ends up with outsourced teams. If your provider touches California consumer data — the law reaches them too.
Key takeaways
- The CCPA grants Californians rights to know, delete, opt out of sale or sharing, and avoid retaliation for asking.
- Proposition 24 added the rights to correct inaccurate data and limit sensitive personal information from 1 January 2023.
- The California Privacy Rights Act (CPRA) amended the CCPA rather than replacing it.
- Businesses must offer at least two ways to submit a request.
- Outsourcing providers usually sit in the “service provider” role, with contractual limits on data use.
How it works
The CCPA works by handing consumers named rights and putting the burden of response on the business. A consumer submits a request — the business verifies identity, then acts within the law’s timeline. Exemptions apply, but far fewer than most teams assume.
The California Attorney General’s office sets out the core rights plainly. The California Attorney General’s CCPA overview lists the right to know — the right to delete, the right to opt out of sale or sharing, and the right to non-discrimination.
Opt-out includes the Global Privacy Control — a browser-level signal a consumer can switch on once rather than clicking through every site.
In November 2020, California voters approved Proposition 24, the California Privacy Rights Act (CPRA). It amended the CCPA and added protections from 1 January 2023.
Two extra rights arrived on that date: correction of inaccurate personal information, and limits on the use and disclosure of sensitive personal information.
The framing matters. The Attorney General treats CPRA as an amendment, not a separate law, and refers to the result as “CCPA, as amended.”
| Right | What the consumer can ask for |
|---|---|
| Know | What personal information is collected, and how it’s used and shared |
| Delete | Removal of personal information collected from them, with some exceptions |
| Opt out | No sale or sharing of their data, including via Global Privacy Control |
| Non-discrimination | Same price, same service, after exercising a right |
| Correct | Fixing inaccurate personal information held about them |
| Limit | Restricting use and disclosure of sensitive personal information |
Non-discrimination has teeth. A business cannot deny goods or services, charge a different price, or drop the quality of service because someone exercised a CCPA right.
Access has rules too. Businesses must designate at least two methods for submitting requests, such as a toll-free number, an email address, or a website form.
Two exemptions people still quote are gone. The carve-outs for employment-related personal information and for business-to-business transaction data are no longer in effect.
The regulations themselves became effective on 29 March 2023. The California Privacy Protection Agency is the state body responsible for writing those regulations and enforcing them.
For the statutory text, the law sits in the California Civil Code, Title 1.81.5.
Examples
CCPA work shows up as queues, not as abstract policy. Request intake, identity verification, and record retrieval are the three that land on offshore teams most often. Each one is measurable, trainable, and bound by a clock the client cannot extend.
Request intake desk. A retailer routes its toll-free privacy line and web form to an offshore team. Agents log each request, classify it as know, delete, correct, or opt out, and start the clock.
The same team handles tcpa-compliance style call-handling rules on the voice channel.
Identity verification. Before deleting anything, someone must confirm the requester owns the account. Offshore analysts run document checks against a script written by the client’s compliance officer, then escalate anything ambiguous.
Record retrieval across systems. Personal information rarely lives in one place. Teams pull from the customer relationship system, the marketing platform, and the billing stack, then assemble a single response file.
Providers holding a SOC 2 report or ISO 27001 certification usually win this work first, because the client can point at an audited control set. A security operations center (SOC) monitoring the access logs adds another layer buyers ask about during diligence.
Payment data brings its own overlay, since PCI DSS rules apply to card details regardless of what the CCPA says.
Related terms
The CCPA sits inside a wider set of privacy and security standards that outsourcing buyers evaluate together. These terms come up in the same contracts, the same audits, and the same vendor questionnaires — so it pays to know how each one differs.
- General Data Protection Regulation (GDPR): the European privacy regime that inspired much of the CCPA’s structure.
- Data Privacy Act of the Philippines: the national law governing offshore teams that process client data from Manila and Cebu.
- HIPAA Compliance: the United States health-data rulebook that overlaps with privacy work in medical outsourcing.
- Compliance Officer: the role that owns policy interpretation and sign-off on privacy request handling.
- Information Security Analyst: a specialist who tests controls and investigates access to personal information.
- SOC 2: an audit report covering security, availability, and confidentiality controls at a service provider.
FAQ
Who does the CCPA actually apply to?
It applies to businesses that collect personal information about California consumers, and it reaches their service providers through contract. Your outsourcing partner is bound by what your agreement says it may and may not do with that data.
Is the CPRA a different law from the CCPA?
No. The California Privacy Rights Act amended the CCPA rather than replacing it, and the Attorney General’s office refers to the combined result as “CCPA, as amended.”
What rights did consumers gain in 2023?
From 1 January 2023, consumers gained the right to correct inaccurate personal information and the right to limit the use and disclosure of sensitive personal information.
Can a company charge me more for opting out?
No. A business cannot deny goods or services, charge a different price, or give you a lower quality of service because you exercised a CCPA right.
Are employee records still exempt?
The statutory exemptions for employment-related personal information and for business-to-business transaction data are no longer in effect.
For more on how outsourcing teams handle privacy and compliance work, explore the guides at Outsource Accelerator.







Independent




