Skip to main content

IN EFFECT since January 1, 2020

Last verified against primary sources:

CCPA / CPRA (California)

US-State · Effective January 1, 2020

California privacy law: notice, opt-out of sale/sharing, deletion, and Global Privacy Control honoring. Applies at $25M+ revenue, 100K+ CA consumers, or 50%+ revenue from data sales.

Overview

New CPPA regulations took effect January 1, 2026 (automated decision-making/ADMT, risk assessments, cybersecurity audits), but their compliance deadlines phase in 2027-2030 and bite only at $25M+ revenue or large user counts - not immediate for $0-5K MRR founders. The applicability revenue threshold is CPI-adjusted (~$25M; confirm the current figure). Businesses must honor the Global Privacy Control browser signal.

Official text: https://cppa.ca.gov/regulations/

See where your app stands

SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.

Scan Your App