CCPA and CPRA compliance

The CPRA amended the California Consumer Privacy Act with effect from January 2023, adding correction rights, limits on sensitive information and a dedicated enforcement agency. The important thing for a website is that California works the other way round from Europe: tracking may begin, and the visitor must be given a clear way to stop the sale or sharing of their personal information.

  • California, since January 2020
  • Opt out, not opt in
  • Thresholds decide who is covered

From €10 a month. No credit card, no per-visitor billing.

What the CCPA and CPRA ask for

They apply to for-profit businesses meeting a revenue or volume threshold, so many smaller sites are outside them entirely. Check whether you are covered before building for it.

  • Disclose what personal information you collect and why
  • Offer a clear way to opt out of sale and sharing
  • Honour access, deletion and correction requests
  • Let consumers limit the use of sensitive information
  • Respect an opt-out signal sent by the browser

This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.

What Consent Studio does about it

  • Serves the Californian question, not the European one

    A visitor from California gets an opt out of sale and sharing rather than a prior consent prompt. The defaults follow the visitor’s region, so one configuration serves both without your team maintaining two.

    • By visitor region
    • One configuration
    • Correct in both
  • Honours the browser signal

    Global Privacy Control is treated as a valid opt out, which California regulations require. That matters because the signal arrives before any banner is answered, and a tool that only listens to clicks will miss it entirely.

    • Global Privacy Control
    • No click needed
  • Records the opt out

    Opting out is a request, and requests get answered and evidenced. The record holds what was asked for and when, which is what turns a claim that you honour opt outs into something you can show.

    • Timestamped
    • Exportable
    • Per request

Where sites get California wrong

  1. The EU banner is shown to everybody

    It looks like caution and it is a gap. A prior consent prompt does not provide the Do Not Sell or Share mechanism California asks for, so a site can block more than it needs to and still be missing the required control.

  2. Sharing is read as selling

    The CPRA covers sharing for cross-context behavioural advertising as well as sale for money. A site that takes no payment for data can still be sharing it, and most advertising pixels are exactly that.

  3. The browser signal is ignored

    Global Privacy Control is sent by the browser rather than clicked in your banner. Tools that only act on a banner interaction never see it, and California regulations treat it as a valid opt out that must be honoured.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.
  • Professional

    €36/month

    For growing teams that run on data, and the agencies serving them.

    Try Professional for Free
  • Enterprise

    From €250/month

    For a volume, or an obligation, a standard plan cannot answer.

    Explore Enterprise
  • Agencies & Resellers

    Buy at a partner rate and resell client sites at your own price.

    Discover Partner Programme
  • Public Sector

    Government, healthcare and education run on Enterprise.

    See Enterprise

Running under rules like these, in more than one country


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops
  • Dynamis
  • SB Supply
  • The Chosen

Other rules that may apply to you

Common questions about California

Does the CCPA apply to my business?

Only if you are a for-profit business doing business in California and you meet one of the thresholds: gross revenue above 25 million dollars, buying or selling the personal information of 100,000 or more consumers or households, or deriving half your revenue from selling or sharing it. Many sites are outside it entirely.

Do I need a cookie banner in California?

Not in the European sense. What is required is notice of what you collect and a clear way to opt out of sale and sharing, usually a Do Not Sell or Share My Personal Information link. Prior consent before anything loads is a European requirement, not a Californian one.

What counts as selling or sharing personal information?

Selling covers disclosure for money or other valuable consideration, and sharing covers disclosure for cross-context behavioural advertising even where no money changes hands. Most advertising and remarketing pixels fall into the second category, which is what catches sites out.

Do we have to honour Global Privacy Control?

Yes. California regulations treat a browser opt-out signal as a valid request, so it has to be respected without the visitor clicking anything in your banner. Several other US states now require the same, which is why we apply it on the first page load rather than after an interaction.

Does Consent Studio make us compliant?

No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.

Where is our consent data stored?

In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.