CCPA and CPRA compliance
The CPRA amended the California Consumer Privacy Act with effect from January 2023, adding correction rights, limits on sensitive information and a dedicated enforcement agency. The important thing for a website is that California works the other way round from Europe: tracking may begin, and the visitor must be given a clear way to stop the sale or sharing of their personal information.
- California, since January 2020
- Opt out, not opt in
- Thresholds decide who is covered
From €10 a month. No credit card, no per-visitor billing.
What the CCPA and CPRA ask for
They apply to for-profit businesses meeting a revenue or volume threshold, so many smaller sites are outside them entirely. Check whether you are covered before building for it.
- Disclose what personal information you collect and why
- Offer a clear way to opt out of sale and sharing
- Honour access, deletion and correction requests
- Let consumers limit the use of sensitive information
- Respect an opt-out signal sent by the browser
This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.
What Consent Studio does about it
Serves the Californian question, not the European one
A visitor from California gets an opt out of sale and sharing rather than a prior consent prompt. The defaults follow the visitor’s region, so one configuration serves both without your team maintaining two.
- By visitor region
- One configuration
- Correct in both
Honours the browser signal
Global Privacy Control is treated as a valid opt out, which California regulations require. That matters because the signal arrives before any banner is answered, and a tool that only listens to clicks will miss it entirely.
- Global Privacy Control
- No click needed
Records the opt out
Opting out is a request, and requests get answered and evidenced. The record holds what was asked for and when, which is what turns a claim that you honour opt outs into something you can show.
- Timestamped
- Exportable
- Per request
Where sites get California wrong
The EU banner is shown to everybody
It looks like caution and it is a gap. A prior consent prompt does not provide the Do Not Sell or Share mechanism California asks for, so a site can block more than it needs to and still be missing the required control.
Sharing is read as selling
The CPRA covers sharing for cross-context behavioural advertising as well as sale for money. A site that takes no payment for data can still be sharing it, and most advertising pixels are exactly that.
The browser signal is ignored
Global Privacy Control is sent by the browser rather than clicked in your banner. Tools that only act on a banner interaction never see it, and California regulations treat it as a valid opt out that must be honoured.
Essential
€10/month
For a single site that has to be compliant, and stay that way.
- Unlimited pages and displays
- 200,000 consent actions a month
- The full stack, not a starter tier
Professional
€36/month
For growing teams that run on data, and the agencies serving them.
Try Professional for FreeEnterprise
From €250/month
For a volume, or an obligation, a standard plan cannot answer.
Explore EnterpriseAgencies & Resellers
Buy at a partner rate and resell client sites at your own price.
Discover Partner ProgrammePublic Sector
Government, healthcare and education run on Enterprise.
See Enterprise
Running under rules like these, in more than one country
Other rules that may apply to you
Common questions about California
Does the CCPA apply to my business?
Only if you are a for-profit business doing business in California and you meet one of the thresholds: gross revenue above 25 million dollars, buying or selling the personal information of 100,000 or more consumers or households, or deriving half your revenue from selling or sharing it. Many sites are outside it entirely.
Do I need a cookie banner in California?
Not in the European sense. What is required is notice of what you collect and a clear way to opt out of sale and sharing, usually a Do Not Sell or Share My Personal Information link. Prior consent before anything loads is a European requirement, not a Californian one.
What counts as selling or sharing personal information?
Selling covers disclosure for money or other valuable consideration, and sharing covers disclosure for cross-context behavioural advertising even where no money changes hands. Most advertising and remarketing pixels fall into the second category, which is what catches sites out.
Do we have to honour Global Privacy Control?
Yes. California regulations treat a browser opt-out signal as a valid request, so it has to be respected without the visitor clicking anything in your banner. Several other US states now require the same, which is why we apply it on the first page load rather than after an interaction.
Does Consent Studio make us compliant?
No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.
Where is our consent data stored?
In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.






