B2B Digital Marketing Services, Blog

If You Collect Customer Data, California Privacy Law Already Affects You

April 28, 2026 | 8 minutes to read
Is Your Business Ready for California's Privacy Laws? What CCPA & CPRA Mean for You
Summary:If your business collects customer data – like names, emails, or browsing activity – California’s privacy laws (CCPA/CPRA) likely apply, even if you’re not based in California. These laws grant consumers rights over their data and impose strict rules on businesses, such as: Complying if you earn over $26,625,000 annually, process data from 100,000+ California …

If your business collects customer data – like names, emails, or browsing activity – California’s privacy laws (CCPA/CPRA) likely apply, even if you’re not based in California. These laws grant consumers rights over their data and impose strict rules on businesses, such as:

  • Complying if you earn over $26,625,000 annually, process data from 100,000+ California residents, or earn 50%+ of revenue from data sales.
  • Displaying “Do Not Sell or Share My Personal Information” and “Limit Use of My Sensitive Personal Information” links.
  • Responding to data requests within 10-45 days.
  • Avoiding fines, which can reach $7,988 per violation.

Non-compliance risks include hefty penalties, lawsuits, and reputational damage. But meeting these standards can also build trust with your customers and prepare you for future regulations.

Takeaway: If you collect data from California residents, review your practices now to avoid penalties and stay ahead of evolving privacy requirements.

CCPA Explained: Your Quick Guide to the California Consumer Privacy Act

CCPA

How California Privacy Laws Apply to Your Business

California’s CCPA and CPRA laws give consumers rights over their personal data, including the ability to access, delete, correct, opt out of, and limit the use of sensitive information.

To comply, businesses must include a “Do Not Sell or Share My Personal Information” link on their homepage. If sensitive data is processed for non-essential purposes, a “Limit the Use of My Sensitive Personal Information” link is also required. Additionally, businesses must honor Global Privacy Control signals and respond to data requests promptly – acknowledging within 10 business days and fully addressing them within 45 days (or up to 90 days with an extension).

When collecting data, use it only for clearly stated purposes. Vague justifications like “to improve services” won’t cut it. Businesses must document specific retention periods for each data category.

When B2B Businesses Must Comply

B2B companies aren’t exempt from these laws. Compliance is required if your business meets any of these thresholds:

  • Gross annual revenues over $26,625,000 (starting in 2025)
  • Processing data from 100,000 or more California consumers or households
  • Deriving 50% or more of revenue from selling or sharing personal data

B2B activities like lead generation or managing a CRM with California contacts could easily trigger these thresholds.

“Businesses should pay special attention to B2B data and clearly document which categories of personal data are stored and on which systems.”

  • Kathryn M. Rattigan, Robinson & Cole LLP

As of January 1, 2023, work-related information – such as emails, job titles, and business contacts – is treated like consumer data. This extends privacy rights to employees, applicants, contractors, and business partners.

What Counts as Personal Information and Sensitive Data

California law defines personal information as any data that directly identifies or can be linked to an individual or household. This includes names, email addresses, IP addresses, browsing history, purchase records, professional details, and even inferences drawn from profiles.

Sensitive Personal Information includes highly specific data such as Social Security numbers, driver’s licenses, passport numbers, precise geolocation (within 1,850 feet), racial or ethnic origin, religious beliefs, union memberships, genetic data, and login credentials. Neural data will also fall under this category starting in September 2024.

In B2B settings, even business contact details, such as work email addresses and job titles, are treated as personal information. If your business tracks visitors using precise geolocation, you’re required to provide a “Limit Use” link and implement additional safeguards.

Penalties and Risks for Non-Compliance

California Privacy Law Penalties and Fines by Violation Type 2025-2026

California Privacy Law Penalties and Fines by Violation Type 2025-2026

Failing to meet California’s stringent privacy standards can result in serious consequences. The state’s privacy laws come with hefty fines, and regulators are quick to act on violations.

Typical Compliance Violations

Some of the most common compliance missteps involve inadequate consumer notices and opt-out mechanisms. For instance, failing to include a “Do Not Sell or Share My Personal Information” link on your homepage can affect every visitor to your site. Similarly, ignoring Global Privacy Control (GPC) signals can lead to enforcement actions. A notable example is Sephora, which paid $1,200,000 in August 2022 after an investigation revealed that the company had ignored GPC signals and failed to properly disclose data sales. As part of the settlement, Sephora also agreed to submit regular compliance reports to the Attorney General for two years.

Another frequent issue stems from poor data collection practices. In February 2024, DoorDash faced a $375,000 penalty for sharing customer data with a marketing cooperative without offering proper notice or an opt-out option. Additionally, businesses often fall short with service-provider contracts that fail to limit how customer data is used downstream – a critical requirement under California privacy laws.

Here are some examples of violations businesses must be cautious to avoid:

Financial Penalties and Fines

California imposes fines on a per-violation basis, which means a single mistake can multiply quickly. For example, a non-compliant tracking script affecting 10,000 visitors could be counted as 10,000 separate violations. Fines for unintentional violations can reach $2,663 per instance, while intentional violations – or those involving minors’ data – can climb to $7,988 each.

Violation Type Maximum Fine (2025-2026) Real-World Example
Unintentional Violation $2,663 per violation Missing opt-out link impacting thousands of users
Intentional Violation $7,988 per violation Ignoring GPC signals (e.g., Sephora: $1.2M settlement)
Minors’ Data Violation $7,988 per violation Failure to honor minors’ opt-out rights (Sling TV: $530,000)
Data Breach (Statutory) $107–$799 per consumer Lapses in security measures (e.g., Blackbaud: $6.75M settlement)

These cases highlight how even seemingly minor errors can snowball into substantial penalties.

Beyond fines, businesses also face lawsuits from consumers in cases of data breaches. If a company fails to safeguard personal information and a breach occurs, affected individuals can claim statutory damages ranging from $107 to $799 per incident – or higher if actual damages exceed these amounts.

For example, Blackbaud agreed to a $6,750,000 settlement in October 2024 following a 2020 ransomware attack that exposed weaknesses in its compliance with the California Consumer Privacy Act (CCPA).

Adding to the pressure, the traditional 30-day cure period for violations has been eliminated. Now, regulators can impose fines as soon as they identify a breach. As Michael Macko, Deputy Director of Enforcement at the California Privacy Protection Agency, put it:

“There is no vacation here from enforcement”.

Notably, 91% of enforcement actions result in settlements, often resolved within six to eight months.

How to Comply with California Privacy Laws

Avoiding hefty penalties and maintaining consumer trust starts with a clear compliance strategy. Tackling California’s privacy regulations doesn’t have to feel overwhelming. By breaking the process into clear steps, you can protect your business while respecting consumer rights.

Review Your Data Collection Practices

Start by documenting every way your business collects personal data. This includes forms, cookies, CRMs, marketing platforms, and any third-party tools. For each data category, note its source, purpose, retention period, and any sharing partners.

Pay extra attention to sensitive personal information (SPI). By 2026, SPI will include neural data and information collected from minors under 16. Also, review advanced tracking tools to identify any potential risks related to data sharing.

An important update: consumers can now request access to all data collected since January 1, 2022, removing the previous 12-month limit. Once you’ve mapped out your data flow, make sure your public disclosures reflect this information.

Update Your Privacy Policies

Your privacy policy needs an annual refresh. Clearly state the types of data collected, how it’s used, how long it’s retained, and include prominent links like “Do Not Sell or Share” and “Limit Use of My Sensitive Personal Information” if applicable.

Ensure consent mechanisms are clear and honest. For example, the “Decline” button must be just as visible as the “Accept” button. Patrick Spencer, a cybersecurity risk expert at Kiteworks, emphasizes:

“Closing or clicking away from a consent popup – without affirmatively clicking an ‘accept’ button – does not constitute consent”.

Set Up Opt-Out and Data Rights Systems

Once your policies are updated, establish systems to handle consumer data rights efficiently. Requests like opt-outs must be processed within 15 business days, while access, deletion, or correction requests must be addressed within 45 days, extendable to 90 days if necessary.

Request Type Response Deadline Action Required
Right to Opt-Out 15 business days Stop selling or sharing data; honor GPC signals
Right to Know/Access 45 days (extendable) Provide data categories or specific pieces in a portable format
Right to Delete 45 days (extendable) Remove data from production and backups; notify service providers
Right to Correct 45 days (extendable) Update inaccurate data across internal and vendor systems
Right to Limit SPI 15 business days Restrict sensitive data use to allowed purposes only

Global Privacy Control (GPC) is another key requirement. Configure your site to detect the Sec-GPC: 1 header and automatically disable tracking. Starting January 1, 2026, you’ll also need to display a confirmation message, like “Opt-Out Request Preference Signal Honored”, whenever a GPC signal is processed.

To make rights requests simple, provide an interactive web form, a toll-free number, or a dedicated email address. Use a risk-based verification system: basic opt-outs might only need email confirmation, while more sensitive requests could require authenticated sessions and signed declarations under penalty of perjury.

Collect and Store Only Necessary Data

Follow the principle of data minimization: only collect what you need and delete it when it’s no longer required. Assign retention periods for each data type. For instance:

  • Former customer data: 1–3 years
  • Prospect data (no engagement): 2 years
  • Application logs: 90 days to 1 year

Document how you delete data, whether through hard deletion or de-identification, and automate the process wherever possible. This reduces your exposure in the event of a breach and simplifies your response to deletion requests.

Get Expert Help with Compliance

Compliance isn’t a one-time task – it requires consistent effort, vendor coordination, and quick responses to verified consumer requests. Partnering with WSI Smart Web Marketing can help. They offer AI-powered tools, GA4 analytics, and automation platforms to keep your business compliant while improving performance.

WSI supports B2B companies in aligning lead generation strategies with privacy laws, ensuring that transparency and consent go hand in hand with growth. From setting up GPC detection to automating data mapping and updating vendor contracts, expert guidance can help you avoid mistakes and focus on growing your business. With the right support, you can build a compliance framework that works seamlessly alongside your business goals.

Conclusion

California’s privacy laws are reshaping how businesses across the U.S. handle customer data. For companies collecting information from California residents, compliance isn’t optional – it’s essential. The stakes are high, and falling short can lead to serious consequences.

But beyond avoiding penalties, meeting these standards can enhance your reputation and foster trust. In fact, many B2B clients now require vendors to comply with CCPA/CPRA guidelines. Viewing privacy as an opportunity rather than a hurdle can set businesses apart. As Patrick Spencer, a cybersecurity risk management expert at Kiteworks, puts it:

“The businesses that treat these regulations as an opportunity rather than a burden will find themselves ahead of the curve”.

Adopting this proactive approach not only ensures compliance but positions your business to thrive as privacy regulations expand nationwide. California’s framework is essentially a preview of what’s to come. With nearly 20 states already implementing similar laws, aligning with California’s standards now can prepare you for future changes. Andrew R. Lee, Partner at Bracewell LLP, highlights this point:

“Even if your business manages to avoid the effects of the CCPA, turning attention to privacy compliance now could pay returns in the future”.

FAQs

Does CCPA/CPRA apply if my business is outside California?

Yes, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) can apply to businesses located outside of California. If your company processes the personal data of California residents and meets certain criteria, these laws may still apply to you.

Here are the key thresholds that could bring your business under the scope of these regulations:

  • Annual gross revenue exceeding $25 million
  • Handling personal data for 100,000 or more consumers, households, or devices

The physical location of your business doesn’t exempt you. If you’re collecting or managing data from California residents and hit any of these benchmarks, compliance with these laws is required.

What counts as “selling” or “sharing” personal information?

Under the CCPA, the definition of “selling” or “sharing” personal information goes beyond simply trading it for money. It also includes any instance where personal information is disclosed, released, or transferred to third parties or businesses – whether that’s done verbally, in writing, or electronically – in exchange for any kind of value or for other uses.

What do I need to build to handle CCPA requests and GPC signals?

To effectively manage CCPA requests and Global Privacy Control (GPC) signals, you’ll need systems designed to address consumer rights and consent. Here are the key elements to focus on:

  • Consumer Rights Management: Provide users with tools to request access to their data, make corrections, or request deletion.
  • Opt-Out Tools: Implement mechanisms to process opt-out requests, including honoring GPC signals.
  • Documentation: Maintain detailed records of requests and user consent to prove compliance when needed.

By putting these systems in place, you not only meet legal requirements but also strengthen trust with your customers.

About the Author

Howard Walker is a Digital Marketing Consultant and owner of WSI Smart Web Marketing. He serves as a manager and strategic advisor and uses his experience, expertise, and knowledge from many years of experience in the tech industry as a product marketing engineer and project manager. His experience with digital marketing services and the use of online analysis tools allow him to implement strategies and recommendations that provide the best-in-class services and results for clients.

The Best Digital Marketing Insight and Advice

The WSI Digital Marketing Blog is your go-to-place to get tips, tricks and best practices on all things digital
marketing related. Check out our latest posts.

    I consent to have WSI Smart Web Marketing collect my name, email and phone number to send me digital communications.

    We are committed to protecting your privacy. For more info, please review our Privacy and Cookie Policies. You may unsubscribe at any time.

    Don't stop the learning now!

    Here are some other blog posts you may be interested in.VIEW ALL BLOG POSTS

    AI Readiness Checklist for B2B

    July 28, 2026 | 8 minutes to read

    AI Readiness Assessment Most AI projects fail when the business is not ready for them first. If I want AI to help my B2B company, I need to check five things before I buy tools: data quality, system connections, repeatable workflows, team skills, and clear rules. Here’s the short version: Data: My CRM and marketing …

    READ MORE

    AI SEO Strategy to Future‑Proof Your Business

    April 21, 2026 | 14 minutes to read

    How to Future-Proof Your Business with AI-Powered SEO AI is changing how people search online, and businesses need to keep up. By 2026, search volumes may drop by 25% as AI tools like ChatGPT, Claude, Google Gemini, and Perplexity become the primary sources of answers and recommendations. To stay visible, businesses must shift from traditional SEO (keywords and backlinks) to AI-powered …

    READ MORE

    AI Training Gap Hurting ROI in Business

    April 14, 2026 | 10 minutes to read

    New Research Finds AI Training Gap Driving Inconsistent Business Results 88% of businesses use AI, but only 12% of employees get proper training, leading to major inefficiencies. Companies investing in AI tools without equipping their teams to use them effectively are seeing poor returns: 74% report no measurable ROI, while only 39% achieve any EBIT …

    READ MORE

    © 2025 WSI. All rights reserved. WSI ICE and WSI IM are registered trademarks of RAM. Privacy Policy and Cookie Policy. Each WSI Franchise is an independently owned and operated business.

    Yes I'm Interested
    Kindliy Inform Me About Your Next
    Upcoming Workshop

      Get Your Free Copy Now!

        Download Ebook

          WS AI Strategies