Glossary · Privacy & compliance

What is the CCPA, and does it apply to analytics?

The CCPA, the California Consumer Privacy Act — as amended by the California Privacy Rights Act (CPRA) — is California's consumer privacy law, giving California residents rights over their personal information and requiring covered businesses to honor opt-outs from selling or sharing it.

Also called: California Consumer Privacy Act, CPRA, California Privacy Rights Act

Updated

Who does the CCPA apply to?

  • For-profit businesses doing business in California that meet any of these:
  • Annual gross revenue above $26,625,000 (the CPI-adjusted figure for 2025–2026; originally $25 million).
  • Buy, sell or share the personal information of 100,000+ California consumers or households a year.
  • Derive 50% or more of annual revenue from selling or sharing personal information.

What rights does it give consumers?

The right to know what's collected, to delete it, to correct it, to opt out of its sale or "sharing" (for cross-context behavioral advertising), to limit use of sensitive personal information, and not to be discriminated against for exercising those rights. Covered businesses must honor opt-out preference signals such as Global Privacy Control. It's enforced by the California Privacy Protection Agency and the Attorney General, with fines per violation (higher for intentional ones) that are adjusted for inflation.

Does analytics count as "selling" or "sharing"?

It depends on who uses the data. Analytics run by a service provider that processes data only for you under a contract restricting other uses is generally not a sale or share. Third-party pixels and tags whose providers use the data for their own advertising often are sharing, which triggers the opt-out requirement. This is general information, not legal advice.

Example

A US SaaS with $30 million in revenue uses first-party analytics plus a Meta pixel. The analytics vendor, contracted as a service provider, isn't selling or sharing. The pixel sends browsing data that Meta uses for ad targeting — that's sharing, so the site needs a "Do Not Sell or Share My Personal Information" link and must stop the pixel for visitors who opt out or send a GPC signal.

CCPA and VisitTrack

VisitTrack processes analytics data only for the site that collects it: it doesn't sell data, share it with ad networks or build cross-site profiles, and never stores IP addresses. That keeps it in the service-provider pattern rather than the sharing pattern. Other US states — more than a dozen as of 2026 — have their own comprehensive privacy laws with similar but not identical rules, so check where your visitors are. For EU-style protections everywhere, cookieless mode stores nothing on the device.

Frequently asked questions

Does the CCPA require a cookie banner?

No, the CCPA doesn't require opt-in consent for cookies. It requires notice at collection and, if you sell or share personal information, a clear way to opt out, including honoring Global Privacy Control signals.

What is the difference between CCPA and CPRA?

The CPRA is a 2020 ballot measure that amended and expanded the CCPA, adding rights such as correction and limiting sensitive data use, the concept of sharing for cross-context advertising, and a dedicated enforcement agency. People now usually say CCPA to mean the amended law.

Related terms

Tools and guides

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.