Glossary · Privacy & compliance
What is the CCPA, and does it apply to analytics?
The CCPA, the California Consumer Privacy Act — as amended by the California Privacy Rights Act (CPRA) — is California's consumer privacy law, giving California residents rights over their personal information and requiring covered businesses to honor opt-outs from selling or sharing it.
Also called: California Consumer Privacy Act, CPRA, California Privacy Rights Act
Updated
Who does the CCPA apply to?
- For-profit businesses doing business in California that meet any of these:
- Annual gross revenue above $26,625,000 (the CPI-adjusted figure for 2025–2026; originally $25 million).
- Buy, sell or share the personal information of 100,000+ California consumers or households a year.
- Derive 50% or more of annual revenue from selling or sharing personal information.
What rights does it give consumers?
The right to know what's collected, to delete it, to correct it, to opt out of its sale or "sharing" (for cross-context behavioral advertising), to limit use of sensitive personal information, and not to be discriminated against for exercising those rights. Covered businesses must honor opt-out preference signals such as Global Privacy Control. It's enforced by the California Privacy Protection Agency and the Attorney General, with fines per violation (higher for intentional ones) that are adjusted for inflation.
Does analytics count as "selling" or "sharing"?
It depends on who uses the data. Analytics run by a service provider that processes data only for you under a contract restricting other uses is generally not a sale or share. Third-party pixels and tags whose providers use the data for their own advertising often are sharing, which triggers the opt-out requirement. This is general information, not legal advice.
Example
A US SaaS with $30 million in revenue uses first-party analytics plus a Meta pixel. The analytics vendor, contracted as a service provider, isn't selling or sharing. The pixel sends browsing data that Meta uses for ad targeting — that's sharing, so the site needs a "Do Not Sell or Share My Personal Information" link and must stop the pixel for visitors who opt out or send a GPC signal.
CCPA and VisitTrack
VisitTrack processes analytics data only for the site that collects it: it doesn't sell data, share it with ad networks or build cross-site profiles, and never stores IP addresses. That keeps it in the service-provider pattern rather than the sharing pattern. Other US states — more than a dozen as of 2026 — have their own comprehensive privacy laws with similar but not identical rules, so check where your visitors are. For EU-style protections everywhere, cookieless mode stores nothing on the device.
Frequently asked questions
Does the CCPA require a cookie banner?
No, the CCPA doesn't require opt-in consent for cookies. It requires notice at collection and, if you sell or share personal information, a clear way to opt out, including honoring Global Privacy Control signals.
What is the difference between CCPA and CPRA?
The CPRA is a 2020 ballot measure that amended and expanded the CCPA, adding rights such as correction and limiting sensitive data use, the concept of sharing for cross-context advertising, and a dedicated enforcement agency. People now usually say CCPA to mean the amended law.
Related terms
- GDPRGDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how personal data about people in the EU is collected, used and stored, in force since May 25, 2018.
- Consent bannerA consent banner, or cookie banner, is the notice a website shows to ask visitors for permission before storing or reading non-essential cookies and similar identifiers on their device, and to record their choice.
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- First-party vs third-party cookiesA first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
- Server-side trackingServer-side tracking is sending analytics or conversion events from your own server to the analytics or ad platform, instead of (or in addition to) from a script running in the visitor's browser.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.