CPRA elimination of mandatory 30-day cure — discretionary relief under § 1798.199.45
Mandatory cure period eliminated. The California Privacy Rights Act (CPRA) eliminated the mandatory 30-day cure period for CCPA violations effective January 1, 2023. Under the original CCPA, codified at Cal. Civ. Code § 1798.155(b) (as enacted in 2018), "[a] business shall be in violation of this title if it fails to cure any alleged violation within 30 days after being notified of alleged noncompliance." This language created a safe harbor: no penalties could attach unless the business failed to cure within 30 days of receiving notice of the violation. The CPRA, passed by California voters as Proposition 24 on November 3, 2020 and operative January 1, 2023, deleted this subdivision in its entirety.
Current statutory posture. Section 1798.155 now governs administrative enforcement by the California Privacy Protection Agency (CPPA) but contains no mandatory cure language. Subdivision (a) sets the per-violation fine amounts ($2,500 for unintentional violations; $7,500 for intentional violations or violations involving minors' personal information), subject to the cure and aggregate-cap provisions originally set forth in former subdivision (b). The deletion means businesses are now exposed to administrative fines immediately upon a CPPA finding of violation, without an automatic 30-day window to remediate.
Discretionary cure authority. The CPRA vested the CPPA with discretionary authority to grant cure opportunities. Cal. Civ. Code § 1798.199.45(a) provides: "Upon notification of alleged noncompliance, the agency may provide a business, service provider, contractor, or person with a time period to cure the alleged violation, which shall be based on the totality of circumstances, including but not limited to: (1) The lack of intent to violate this title. (2) The voluntary efforts undertaken by the business, service provider, contractor, or person to cure the alleged violation prior to being notified by the agency." This authority is expressly discretionary — the CPPA "may" grant cure time, not "shall." In exercising this discretion, the CPPA may also consider the nature of the violation, the remediation already undertaken, and whether the violation appears to be systemic or isolated.
Practical effect. The shift from mandatory to discretionary cure changes the enforcement calculus. Under the original regime, the California Attorney General (who held enforcement authority until the CPPA stood up) sent hundreds of notice letters and approximately 75% of recipients cured the violation within 30 days, avoiding fines altogether. The discretionary cure regime gives the CPPA flexibility to escalate repeat violators or particularly egregious violations directly to administrative penalties, while still permitting first-time, inadvertent violators to demonstrate good faith through prompt remediation. However, businesses should no longer assume they will receive a cure window; the statutory entitlement no longer exists.
Private right of action — separate cure rule preserved. The CPRA did not eliminate the 30-day cure requirement for the private right of action under Cal. Civ. Code § 1798.150(b), which authorizes consumers to sue for statutory damages after a data breach involving specified categories of unencrypted or unredacted personal information. Section 1798.150(b) still requires that "prior to initiating any action against a business for statutory damages … a consumer shall provide a business 30 days' written notice identifying the specific provisions of this title the consumer alleges have been or are being violated." This separate cure provision remains intact and applies only to § 1798.150 breach actions, not to administrative enforcement by the CPPA.
Comparison to pre-CPRA enforcement. Before January 1, 2023, the California Attorney General enforced the CCPA and issued numerous "notice and cure" letters targeting businesses missing required disclosures or "Do Not Sell My Personal Information" links. Notable enforcement actions included a $1.2 million settlement with Sephora in August 2022, which occurred despite the mandatory cure period because Sephora failed to cure the violations within 30 days of the Attorney General's notice. The elimination of the mandatory cure provision means that businesses can no longer count on a guaranteed second chance before facing administrative penalties.
Source: Cal. Civ. Code § 1798.155 Source: Cal. Civ. Code § 1798.199.45 Source: Cal. Civ. Code § 1798.150
Private right of action under § 1798.150 — data breach statutory damages and 30-day cure requirement
The California Consumer Privacy Act (CCPA) grants consumers a limited private right of action to sue businesses directly for statutory damages following a data breach involving specified categories of personal information. Cal. Civ. Code § 1798.150(a)(1). This right is distinct from the administrative enforcement authority vested in the California Privacy Protection Agency (CPPA) and the California Attorney General, and it is the only provision of the CCPA that authorizes a private lawsuit—consumers cannot sue for violations of other CCPA rights such as deletion, access, or opt-out.
Triggering event: unauthorized access and exfiltration, theft, or disclosure. A consumer may bring a civil action when the consumer's "nonencrypted and nonredacted personal information" is "subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information." Cal. Civ. Code § 1798.150(a)(1). The statute does not define "reasonable security procedures and practices"; practitioners must assess whether security measures are "appropriate to the nature of the information" based on the facts of each case.
Covered personal information categories. The private right of action under § 1798.150 applies only to breaches involving the specific categories of personal information enumerated in Cal. Civ. Code § 1798.81.5(d)(1)(A), which include:
- Social Security numbers
- Driver's license or California identification card numbers
- Account, credit, or debit card numbers combined with any required security code, access code, or password
- Medical information
- Health insurance information
- Unique biometric data (fingerprints, retinal images, etc.)
- Genetic data
Breaches involving only email addresses, names, or general commercial data do not trigger the § 1798.150 private right of action unless those elements are combined with one of the enumerated categories above.
Statutory damages and actual damages alternative. A prevailing consumer may recover the greater of:
- Statutory damages of not less than $107 and not greater than $799 per consumer per incident (as adjusted for inflation, effective January 1, 2025), or
- Actual damages
Cal. Civ. Code § 1798.150(a)(1)(A); Cal. Civ. Code § 1798.199.95(d); CPPA CPI Adjustment Announcement (December 2024), effective January 1, 2025. The next Consumer Price Index adjustment will occur January 1, 2027. The CPPA publishes the current statutory damages range at https://cppa.ca.gov/regulations/cpi_adjustment.html.
Section 1798.150 does not impose a cap on aggregate damages. Cal. Civ. Code § 1798.150(a)(2) expressly permits consumers to seek "injunctive or declaratory relief," to bring "a class action," and to obtain "any other relief the court deems proper." There is no cap on the total damages that may be awarded in a certified class action.
Mandatory 30-day cure for § 1798.150 claims. Unlike the CPPA's discretionary cure authority under § 1798.199.45, the private right of action under § 1798.150 retains a mandatory 30-day cure provision. Cal. Civ. Code § 1798.150(b) provides: "Prior to initiating any action against a business for statutory damages on an individual or class-wide basis … a consumer shall provide a business 30 days' written notice identifying the specific provisions of this title the consumer alleges have been or are being violated. In the event a cure is possible, if within the 30 days the business actually cures the noticed violation and provides the consumer an express written statement that the violations have been cured and that no further violations shall occur, no action for individual statutory damages or class-wide statutory damages may be initiated against the business."
The cure must be actual, not merely promised, and the business must provide a written statement confirming both the cure and a commitment that no further violations will occur. Section 1798.150(c) also clarifies that post-breach implementation of reasonable security procedures and practices—if not in place at the time of the breach—does not constitute a cure for purposes of defeating statutory damages.
The statute does not define when a cure is "possible" for purposes of subdivision (b), and courts have not yet settled whether certain breaches—such as a one-time data theft in a resolved intrusion—are inherently "incurable" or whether the cure provision contemplates only prospective remediation of security procedures.
Relationship to administrative enforcement. The private right of action under § 1798.150 is not displaced by CPPA or Attorney General enforcement actions. Cal. Civ. Code § 1798.199.90(e) expressly provides that the Attorney General's enforcement authority "shall not affect the private right of action provided for in Section 1798.150." Similarly, CPPA enforcement decisions do not bar § 1798.150 suits arising from the same breach. However, the private right of action is limited to data-breach violations involving the enumerated personal information categories—consumers cannot use § 1798.150 to sue for violations of access, deletion, opt-out, or other CCPA rights.
No waiver of CCPA rights. Cal. Civ. Code § 1798.192 provides: "Any provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer's rights under this title, including, but not limited to, any right to a remedy or means of enforcement, shall be deemed contrary to public policy and shall be void and unenforceable." This includes the § 1798.150 right of action. Whether a pre-dispute arbitration agreement requiring individual arbitration of CCPA claims is enforceable under the Federal Arbitration Act presents a separate, unresolved question.
Injunctive and declaratory relief. In addition to statutory or actual damages, § 1798.150(a)(2) authorizes courts to award "injunctive or declaratory relief" and "any other relief the court deems proper." The statute does not expressly address attorney's fees; California Code of Civil Procedure § 1021 generally requires a statutory or contractual basis for shifting fees to the losing party. Whether the "any other relief" language in § 1798.150(a)(2) supports an award of attorney's fees to a prevailing consumer is unresolved as of June 2026.
Operative date. Section 1798.150 became operative January 1, 2020. Cal. Civ. Code § 1798.198(a). The provision applies to data breaches occurring on or after that date; it does not apply retroactively.
_Material update: January 1, 2025 CPI and Amendment — statutory damages figures increased to $107–$799 per consumer per incident. All prior $100–$750 references are no longer current._
Source: Cal. Civ. Code § 1798.150 Source: Cal. Civ. Code § 1798.81.5 Source: Cal. Civ. Code § 1798.199.95 Source: CPPA CPI Adjustment — Effective January 1, 2025 Source: Cal. Civ. Code § 1798.192 Source: Cal. Civ. Code § 1798.199.90 Source: Cal. Civ. Code § 1798.198
Per-violation fine structure — no statutory aggregate cap and CPPA's granular violation-counting approach
No aggregate cap on administrative fines. Unlike the European Union's General Data Protection Regulation (GDPR), which caps administrative fines at the greater of €20 million or 4% of annual worldwide turnover (Art. 83(5) GDPR), the California Consumer Privacy Act (CCPA) imposes no statutory ceiling on the total administrative fine that the California Privacy Protection Agency (CPPA) may assess in a single enforcement action. Cal. Civ. Code § 1798.155(a) establishes per-violation fines of "not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation or violations involving the personal information of consumers whom the business … has actual knowledge are under 16 years of age," as adjusted for inflation. The statute does not impose an upper limit on the number of violations that may be counted or the aggregate fine that may result.
Inflation-adjusted amounts effective January 1, 2025. Pursuant to the biennial Consumer Price Index adjustment mandated by Cal. Civ. Code § 1798.199.95(d), the CPPA increased the per-violation fine amounts effective January 1, 2025. The adjusted amounts are $2,975 per unintentional violation and $8,925 per intentional violation or violation involving minors' (under age 16) personal information. The next CPI adjustment will occur January 1, 2027. The CPPA publishes current amounts at https://cppa.ca.gov/regulations/cpi_adjustment.html.
Per-violation counting — CPPA's granular approach. The critical interpretive question is what constitutes "each violation" for purposes of multiplying the per-violation fine. The CCPA does not define "violation," and no published California or federal court decision has construed the term in the CCPA context. The CPPA's first major enforcement action, a March 12, 2025 stipulated order against American Honda Motor Co., signals that the agency will count violations granularly—on a per-consumer or per-affected-consumer basis—rather than treating a systemic practice as a single violation.
Honda enforcement decision — per-consumer counting. The CPPA's Honda order required Honda to pay a $632,500 administrative fine to resolve claims that Honda violated the CCPA by (1) requiring excessive personal information to verify consumers exercising privacy rights, (2) using a privacy management tool that failed to offer choices symmetrically, (3) making it difficult for authorized agents to submit requests on consumers' behalf, and (4) sharing personal information with advertising technology companies without executing contracts containing required privacy terms. In announcing the settlement, CPPA Enforcement Division head Michael Macko stated: "The order spells out the number of consumers whose rights were implicated by some of Honda's practices, underscoring that fines apply on a per violation basis. … We won't hesitate to use our cease-and-desist authority to change business practices, and we'll tally fines based on the number of violations."
The Honda settlement demonstrates that the CPPA will count each affected consumer as a separate violation when a systemic business practice implicates multiple consumers' rights. A business that denies 100,000 deletion requests by imposing an unlawful verification requirement faces potential exposure of up to $297.5 million (100,000 violations × $2,975 per violation) for an unintentional violation or up to $892.5 million (100,000 violations × $8,925) for an intentional violation—before any settlement discount for cooperation, remediation, or first-violation status.
Open questions on violation-counting methodology. The CPPA has not yet published regulations or formal guidance defining how violations will be counted in all contexts. Unresolved questions include:
- Multiple violations per consumer. If a business simultaneously violates several CCPA provisions with respect to the same consumer—for example, failing to provide a "Do Not Sell or Share My Personal Information" link, failing to honor an opt-out request, and selling the consumer's personal information without a contract compliant with Cal. Civ. Code § 1798.140(w)(2)(A)—does the CPPA count three violations or one?
- Continuing vs. discrete violations. If a business fails to post a required privacy notice for 365 days, is that one violation or 365 daily violations?
- Data-element granularity. If a business sells 50 data elements (name, email, browsing history, etc.) concerning a single consumer in a single transaction, is that one violation or 50?
The Honda order suggests the CPPA will favor consumer-based counting (each affected consumer = one violation per distinct CCPA requirement breached) rather than incident-based counting (one systemic failure = one violation regardless of consumer count). This methodology mirrors the approach taken by the California Attorney General in pre-CPPA enforcement actions, including the August 2022 Sephora settlement, in which the Attorney General alleged violations on a per-affected-consumer basis.
Comparison to GDPR fine caps. The absence of a statutory cap in the CCPA creates markedly different exposure than under the GDPR. A business with €10 billion in annual revenue faces a maximum GDPR fine of €20 million or €400 million (4% of turnover), whichever is greater—functionally capped at €400 million for Art. 83(5) violations. The same business, if it violates the CCPA with respect to 10 million California consumers, faces potential CCPA fines of $29.75 billion (unintentional) to $89.25 billion (intentional) under the per-violation × per-consumer multiplication—orders of magnitude larger than the GDPR cap, even before accounting for the practical reality that the CPPA has discretion to assess lower amounts and routinely settles enforcement actions for negotiated sums.
CPPA's discretion in fine assessment. While the statute sets a ceiling on the per-violation fine ($2,975 / $8,925 as adjusted), it does not mandate a floor. Cal. Civ. Code § 1798.155(a) states fines are "not more than" the specified amounts. The CPPA has full discretion to assess lower per-violation fines—or to decline to pursue certain violations—based on the totality of circumstances, including the factors enumerated in the discretionary cure provision at Cal. Civ. Code § 1798.199.45(a): lack of intent to violate, voluntary remediation efforts, the nature of the violation, and whether the violation is systemic or isolated. The Honda settlement ($632,500) reflects a negotiated resolution, not the theoretical maximum exposure.
Joint and several liability. When two or more persons are responsible for a violation, they are jointly and severally liable for the administrative fine. Cal. Civ. Code § 1798.199.55(b). This provision allows the CPPA to pursue the full fine amount from any one responsible party, leaving allocation among co-violators to private contribution or indemnity claims. Joint and several liability is particularly relevant in service provider and contractor relationships, where both the business and the service provider may be found responsible for the same CCPA violation.
No private right of action for non-breach violations. The per-violation fine structure under § 1798.155 applies only to administrative enforcement actions brought by the CPPA. Consumers cannot sue for statutory damages based on non-breach CCPA violations. The private right of action under Cal. Civ. Code § 1798.150 is limited to data breaches involving specified categories of unencrypted or unredacted personal information (see separate section). For all other CCPA violations—failure to honor deletion requests, missing disclosures, unlawful sale of personal information, etc.—only the CPPA (and the California Attorney General under concurrent authority) may pursue administrative fines. Cal. Civ. Code § 1798.199.90(a).
Practical risk mitigation. Because there is no aggregate cap and the CPPA has signaled it will count violations on a per-consumer basis, businesses subject to the CCPA should:
- Monitor consumer request volumes to quantify exposure. A business processing 500,000 consumer requests annually that inadvertently applies an unlawful verification standard to all requests faces potential exposure exceeding $1.4 billion (500,000 × $2,975) for an unintentional violation.
- Prioritize systemic compliance over incident-by-incident remediation. Violations that affect large consumer populations—such as missing "Do Not Sell or Share My Personal Information" links, non-compliant privacy policies, or failure to honor Global Privacy Control signals—generate the highest fine exposure under per-consumer counting.
- Document voluntary remediation to support a discretionary cure request under § 1798.199.45(a) or a reduced fine in settlement negotiations. The CPPA has discretion to credit good-faith compliance efforts and first-time violations.
- Conduct regular compliance audits of high-volume consumer-facing processes (request intake and response, opt-out mechanisms, automated decision-making disclosures) to identify and remediate violations before they accumulate exposure across hundreds of thousands of consumers.
Source: Cal. Civ. Code § 1798.155 Source: Cal. Civ. Code § 1798.199.95 Source: CPPA CPI Adjustment — Effective January 1, 2025 Source: CPPA Announcement — Honda Settlement (March 12, 2025) Source: Cal. Civ. Code § 1798.199.55 Source: Cal. Civ. Code § 1798.199.45 Source: Cal. Civ. Code § 1798.150 Source: Cal. Civ. Code § 1798.199.90
California Attorney General — retained concurrent civil enforcement authority under § 1798.199.90
The California Attorney General retains independent civil enforcement authority over the California Consumer Privacy Act (CCPA) even after the California Privacy Protection Agency (CPPA) commenced administrative enforcement on July 1, 2023. Cal. Civ. Code § 1798.199.90(a) provides that "[a]ny business, service provider, contractor, or other person that violates this title shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation and each violation involving the personal information of minor consumers … which shall be assessed and recovered in a civil action brought in the name of the people of the State of California by the Attorney General."
This dual-enforcement model creates parallel risk: a business may face either an administrative enforcement action by the CPPA or a civil enforcement action by the Attorney General, but not both for the same violation. The statutory coordination rules and the practical history of Attorney General enforcement define which authority a business is likely to confront.
Civil penalty amounts and inflation adjustment. The per-violation civil penalty under § 1798.199.90(a) mirrors the CPPA's administrative fine structure: $2,500 per unintentional violation and $7,500 per intentional violation or violation involving minors' (under age 16) personal information, as adjusted biennially for inflation pursuant to Cal. Civ. Code § 1798.199.95(d). Effective January 1, 2025, the inflation-adjusted amounts are $2,975 per unintentional violation and $8,925 per intentional violation or minors violation. The next adjustment will occur January 1, 2027. Unlike administrative fines assessed by the CPPA following a probable-cause hearing (Cal. Civ. Code § 1798.199.55), civil penalties under § 1798.199.90 are assessed by a court in a civil enforcement action filed in superior court. The Attorney General must prove the violation and the court has discretion to determine the appropriate penalty amount within the statutory ceiling. Cal. Civ. Code § 1798.199.90(a) expressly directs that "[t]he court may consider the good faith cooperation of the business, service provider, contractor, or other person in determining the amount of the civil penalty."
No aggregate cap — per-consumer multiplication risk. Like the CPPA's administrative fine authority, the Attorney General's civil penalty provision imposes no statutory ceiling on the aggregate penalty that may be assessed in a single enforcement action. The statute sets a per-violation maximum but does not cap the number of violations that may be counted or the total penalty. In the Attorney General's first major CCPA settlement—Sephora, Inc., resolved on August 24, 2022—the Attorney General alleged violations on a per-affected-consumer basis, demonstrating that systemic violations affecting large numbers of California consumers generate proportionally large penalty exposure. Under the settlement, Sephora paid $1.2 million in civil penalties and agreed to injunctive relief requiring updated disclosures, Global Privacy Control (GPC) implementation, conforming service-provider contracts, and two years of compliance reporting. The settlement followed the Attorney General's June 2021 notice of noncompliance, which Sephora failed to cure within the then-mandatory 30-day cure window.
The Sephora enforcement signals the Attorney General's approach to violation counting: systemic business practices that violate the CCPA with respect to multiple consumers are counted as one violation per affected consumer, not as a single systemic violation. This methodology is consistent with the CPPA's per-consumer counting approach articulated in the March 12, 2025 Honda settlement and creates potential exposure of hundreds of millions of dollars for large-scale violations affecting millions of California consumers.
Coordination with CPPA — bar on duplicative enforcement. Although the Attorney General and CPPA hold concurrent enforcement authority, Cal. Civ. Code § 1798.199.90(d) bars duplicative enforcement: "No civil action may be filed by the Attorney General under this section for any violation of this title after the agency has issued a decision pursuant to Section 1798.199.85 or an order pursuant to Section 1798.199.55 against that person for the same violation." Once the CPPA has issued a final administrative decision or order resolving a violation, the Attorney General may not pursue a civil penalty for that same violation. The converse, however, is not expressly stated—the statute does not bar the CPPA from pursuing administrative enforcement after the Attorney General files a civil action, though practical comity and resource constraints make such overlap unlikely.
Cal. Civ. Code § 1798.199.90(c) imposes a mandatory deference rule favoring the Attorney General: "The agency shall, upon request by the Attorney General, stay an administrative action or investigation under this title to permit the Attorney General to proceed with an investigation or civil action and shall not pursue an administrative action or investigation, unless the Attorney General subsequently determines not to pursue an investigation or civil action." If the Attorney General requests a stay of a CPPA investigation or proceeding, the CPPA must comply and may not resume its action unless the Attorney General affirmatively declines to pursue the matter. The statute also provides that "[t]he agency may not limit the authority of the Attorney General to enforce this title." § 1798.199.90(a).
Consumer Privacy Fund — penalty deposit. Any civil penalty recovered by the Attorney General in a CCPA enforcement action, and the proceeds of any settlement, "shall be deposited in the Consumer Privacy Fund," established by Cal. Civ. Code § 1798.160. § 1798.199.90(b). The Fund is appropriated to the CPPA "upon appropriation by the Legislature" to support the agency's operations and to "fully offset the costs incurred by the state courts" in adjudicating CCPA civil actions and the private right of action under § 1798.150. § 1798.160(a). The Fund may also be used to fund privacy-related grants to promote investment in the development of new technologies that facilitate consumer privacy, support the establishment of secure data repositories for data collected from connected devices, and promote education and awareness of California consumer privacy rights. § 1798.160(b).
No double recovery — single penalty for same violation. Cal. Civ. Code § 1798.199.100 prohibits double recovery: "A business shall not be required by the agency, a court, or otherwise to pay both an administrative fine and a civil penalty for the same violation." If a business has already paid an administrative fine to the CPPA for a particular violation, it cannot be assessed a civil penalty by the Attorney General (via court judgment) for that same violation, and vice versa. This rule protects businesses from duplicative monetary sanctions but does not prevent injunctive relief from being imposed by either or both authorities.
Private right of action not displaced. The Attorney General's civil enforcement authority under § 1798.199.90 is separate from, and does not displace, the private right of action under Cal. Civ. Code § 1798.150 for data breaches involving specified categories of unencrypted or unredacted personal information. § 1798.199.90(e) expressly provides: "This section shall not affect the private right of action provided for in Section 1798.150." A consumer may pursue a § 1798.150 data-breach action regardless of whether the Attorney General or CPPA has brought an enforcement action addressing the same incident or the same business's broader practices.
Injunctive relief — broader equitable powers. In addition to civil penalties, § 1798.199.90(a) authorizes the Attorney General to seek and obtain injunctive relief requiring a business to cease violating the CCPA and to implement specific compliance measures. The Sephora settlement illustrates the breadth of injunctive terms the Attorney General may negotiate or seek from a court: requirements to revise privacy policies, implement GPC recognition, amend service-provider contracts to include required privacy terms under Cal. Civ. Code § 1798.140(w)(2)(A), and submit periodic compliance reports to the Attorney General for a defined monitoring period (two years in Sephora). Injunctive relief may also be sought preventatively—the statute does not require that a violation has already occurred, only that a business is engaging in conduct that violates or threatens to violate the CCPA.
Historical enforcement posture and transition to CPPA. The Attorney General served as the sole enforcement authority for the CCPA from the statute's operative date (January 1, 2020) until the CPPA commenced administrative enforcement on July 1, 2023. During that period, the Attorney General issued hundreds of notice-and-cure letters to businesses alleging CCPA violations and published anonymized summaries of enforcement actions (without naming the businesses) on the California Department of Justice website. The vast majority of these early enforcement actions resolved through voluntary compliance during the then-mandatory 30-day cure period, avoiding civil penalties.
The Sephora settlement (August 24, 2022) was the first publicly disclosed CCPA enforcement action resulting in a monetary penalty. The Attorney General announced the settlement as part of an enforcement sweep targeting online retailers that failed to disclose the sale of personal information and failed to honor Global Privacy Control signals. In conjunction with the Sephora announcement, the Attorney General sent additional notice letters to unnamed businesses alleging similar GPC-related violations and signaled a shift toward more aggressive enforcement as the mandatory cure period neared its January 1, 2023 expiration.
Since the CPPA commenced administrative enforcement on July 1, 2023, the Attorney General's public CCPA enforcement activity has been limited—the CPPA has emerged as the primary regulator for administrative CCPA violations. However, the Attorney General retains full civil enforcement authority and may elect to pursue high-profile or egregious violations through civil litigation, particularly when injunctive relief or statewide impact justifies the Attorney General's broader public-enforcement role. Practitioners should assume that both authorities remain active and that the Attorney General may intervene in matters involving novel legal issues, widespread consumer harm, or systemic noncompliance by large businesses.
Strategic enforcement considerations. Businesses subject to the CCPA face a strategic choice when contacted by either the Attorney General or CPPA: cooperate and seek a negotiated resolution (potentially with a stay or reduced penalty based on good-faith cooperation and voluntary remediation), or contest the allegations through formal proceedings. The Attorney General's civil enforcement model differs procedurally from the CPPA's administrative model—civil actions are filed in superior court, subject to full civil discovery and motion practice, and resolved by a judge (or jury if triable issues of fact exist). Administrative enforcement by the CPPA follows the California Administrative Procedure Act (Chapter 5 (commencing with Section 11500) of Part 1 of Division 3 of Title 2 of the Government Code), with probable-cause determinations by the agency and formal hearings before an administrative law judge.
The good-faith-cooperation credit recognized in § 1798.199.90(a) and the discretionary cure authority vested in the CPPA under § 1798.199.45(a) both reward early, voluntary compliance efforts. Businesses that discover potential CCPA violations through internal audits or third-party assessments and remediate the violations before receiving a notice from either enforcement authority may be in a stronger position to argue for reduced penalties or prosecutorial discretion declining enforcement altogether.
Source: Cal. Civ. Code § 1798.199.90 Source: Cal. Civ. Code § 1798.199.95 Source: CPPA CPI Adjustment — Effective January 1, 2025 Source: California AG Press Release — Sephora Settlement (August 24, 2022) Source: Cal. Civ. Code § 1798.199.55 Source: Cal. Civ. Code § 1798.199.85 Source: Cal. Civ. Code § 1798.160 Source: Cal. Civ. Code § 1798.199.100 Source: Cal. Civ. Code § 1798.150 Source: Cal. Civ. Code § 1798.199.45
Consumer Privacy Fund under Cal. Civ. Code § 1798.160 — penalty deposit and authorized use
Statutory structure update (2025): Subfund creation, allocations, and authorized uses.
Cal. Civ. Code § 1798.160 was materially amended by Stats. 2025, ch. 20, § 2, effective June 30, 2025. As amended, the section now creates the Consumer Privacy Fund as a special fund in the state treasury, and subdivides it into three distinct subfunds:
- Consumer Privacy Subfund (administered by the California Privacy Protection Agency)
- Attorney General Consumer Privacy Enforcement Subfund
- Consumer Privacy Grant Subfund
Deposit of penalties and allocation mechanics. All administrative fines, settlements, and civil penalties collected under the CCPA/CPRA by the Agency or the Attorney General are deposited into the Consumer Privacy Fund. Of each deposit:
- 95% is allocated equally to the Consumer Privacy Subfund and Attorney General Consumer Privacy Enforcement Subfund (47.5% to each).
- 5% is allocated to the Consumer Privacy Grant Subfund.
Authorized expenditures and appropriations. Amounts in the Consumer Privacy Subfund and the AG’s subfund are available, upon appropriation by the Legislature, to fully offset the costs incurred by the Agency and the state courts (including costs related to private actions under § 1798.150). The statute further clarifies that separate subfunds help support each enforcement authority.
Consumer Privacy Grant Subfund — grant-making framework. Funds in the Grant Subfund may be used—again, subject to appropriation by the Legislature—for privacy-advancing grants. Permitted grant purposes include:
- Investing in new technologies that enhance consumer privacy;
- Developing secure data repositories;
- Privacy and security education initiatives; and
- Other statutory objectives identified by legislative appropriation.
The grant mechanism is a new feature authorized by the 2025 amendment. The statute does not itself create a direct or recurring grant program—grants are made only as and when funds are appropriated and programs are established by the Legislature.
One-time fund distribution for prior unappropriated amounts. For any funds remaining unappropriated by June 30, 2025, the amended statute directs a one-time reallocation: 45% each to the Agency and AG subfunds, 10% to the Grant Subfund.
No statutory provision for direct consumer restitution. As before, the Fund and its subfunds do not provide direct restitution or damages to private plaintiffs in § 1798.150 lawsuits; those are paid directly to the affected consumer.
Legislative history and compliance. Section 1798.160 was added by Stats. 2018, ch. 55, and substantively amended by the CPRA (2020, operative January 1, 2023) and by Stats. 2025, ch. 20, § 2 (operative June 30, 2025). Any use of fund monies remains subject to annual budget appropriations and legislative oversight per these enactments. Practitioners should review the current statutory text for operative allocation percentages or funding mechanisms, as periodic appropriation bills may further refine grant programs or enforcement support.
Material change note: This section now reflects the subfund structure, percentage allocations, and grant mechanisms created by the 2025 amendment to § 1798.160. Prior versions describing a single undivided fund or lacking the grant subfund should not be relied upon after June 30, 2025.
Source: Cal. Civ. Code § 1798.160 (as amended by Stats. 2025, ch. 20, § 2, eff. June 30, 2025)
Penalty assessment factors under Cal. Civ. Code § 1798.155 and CPPA regulations
Framework for penalty assessment (updated for 2025 CPI adjustments). When the California Privacy Protection Agency (CPPA) or a court assesses an administrative fine or civil penalty for a violation of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), both the statute and implementing regulations require consideration of several specific factors. The aim is to calibrate the penalty to the nature and severity of the violation and the conduct of the business, not simply apply the maximum in every case.
Statutory factors under Cal. Civ. Code § 1798.155(b). Section 1798.155(b) directs the CPPA or court to "consider all relevant circumstances" including:
- The nature and seriousness of the misconduct;
- The number of violations;
- The persistence of the misconduct;
- The length of time over which the misconduct occurred;
- The willfulness of the defendant's misconduct;
- The defendant's assets, liabilities, and net worth;
- The sensitivity and number of consumers affected;
- The actual or potential harm to consumers;
- Voluntary efforts to cure or mitigate the violation (including any prior compliance efforts and remedial action);
- The degree of cooperation with the agency;
- Any other relevant circumstances.
These factors, required in every penalty calculation, were added by the CPRA and must be considered in both CPPA administrative actions and Attorney General civil enforcement.
CPI-adjusted penalty amounts (effective 2025). Pursuant to AB 137 (Stats. 2025, ch. 20) and Cal. Civ. Code § 1798.155(c), beginning January 1, 2025, the statute mandates biennial adjustment of the per-violation fine amounts for inflation. As of January 1, 2025, the CPPA's published amounts are $2,663 per unintentional violation and $7,988 per intentional violation or violation involving minors’ personal information. The agency is required to publish updated amounts ahead of each CPI adjustment cycle.
CPPA regulations — additional context. CPPA regulations at 11 CCR § 7302 reinforce these factors, especially for probable cause hearings and stipulated orders. The agency is expressly empowered to take into account voluntary compliance, system improvements, and whether violations were isolated or systemic. The regulations also provide for consideration of the business’s size and financial condition, and whether remedial actions are substantial and prospective.
Remediation and cooperation. Voluntary, good-faith remediation prior to notification of noncompliance is weighed favorably. Prompt investigation of self-identified issues, consumer notification, and process amendments weigh toward penalty mitigation. CPPA may reduce or forgo penalties where clear steps were taken prior to enforcement contact.
Enforcement examples remain current. The Honda (2025) and Sephora (2022) enforcement actions continue to illustrate the use of these penalty factors in practice.
Material update: This section now reflects the biennial CPI-adjustment mechanism and the updated fine amounts effective as of January 1, 2025, per the statutory amendment (AB 137, Stats. 2025, ch. 20).
Source: Cal. Civ. Code § 1798.155 Source: CPPA regulations — 11 CCR § 7302 Source: CPPA CPI Adjustment Announcement (Dec. 2024)
Statute of limitations for CCPA/CPRA agency enforcement — five-year window for AG and CPPA (Cal. Civ. Code § 1798.199.90(e))
Agency enforcement period under Cal. Civ. Code § 1798.199.90(e).
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), establishes a five-year statute of limitations for enforcement actions filed by state agencies. Effective January 1, 2023, Cal. Civ. Code § 1798.199.90(e) provides: "An action to enforce any provision of this title shall be commenced within five years after the date on which the violation occurred." This language applies to enforcement actions brought by the California Attorney General (AG) and the California Privacy Protection Agency (CPPA). It requires that the AG or CPPA initiate an enforcement proceeding no later than five years after the underlying violation of the CCPA/CPRA. The statutory clock begins on the date the violation occurs, not the date it is discovered.
Scope — agency enforcement only.
Section 1798.199.90(e) sets the statute of limitations specifically for "action[s] to enforce any provision of this title" by state agencies. It does not apply to private lawsuits, including the private right of action for certain data breaches under Cal. Civ. Code § 1798.150, which is subject to other statutes of limitation under California law (typically two or three years depending on the cause of action).
No specific tolling provision stated.
The statute is silent on tolling (pausing) the limitations period, and does not state any exceptions for delayed discovery or other equitable doctrines. Unless further clarified by regulation or case law, practitioners should assume the five-year period runs strictly from the date of each violation.
Practical takeaway.
Corporations and service providers subject to the CCPA/CPRA should maintain compliance documentation—including request handling logs, privacy policy snapshots, and service provider agreements—for at least five years following any relevant action or event, as agency investigations may reach back throughout the limitations window. This is a risk-control measure, not a statutory requirement.
Comparison and context.
While other privacy regimes may set shorter or variable limitations periods, Cal. Civ. Code § 1798.199.90(e) establishes among the longest periods for agency enforcement in U.S. privacy law as of 2026. This long lookback increases potential exposure for historical noncompliance. The text does not grant any authority to extend the limitations period based on agency discovery.
Cross-references.
- For the private action window, see Cal. Civ. Code § 1798.150.
- For penalty structure and counting, see earlier sections in this guide.
Source: Cal. Civ. Code § 1798.199.90
Injunctive relief and corrective enforcement orders under CCPA/CPRA — statutory powers of CPPA and the Attorney General
Statutory injunctive relief authority under the CCPA/CPRA.
Both the California Privacy Protection Agency (CPPA) and the California Attorney General have explicit statutory power to obtain injunctive relief under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). For the Attorney General, Cal. Civ. Code § 1798.199.90(a) authorizes filing a civil action to obtain "injunctive relief as the court deems proper" against any business, service provider, or contractor that violates the CCPA. This authority encompasses court orders to stop unlawful practices, and, where appropriate, to compel affirmative compliance measures. The statute does not spell out detailed types of remedial relief, but courts have discretion to fashion injunctions fitting the violation.
For the CPPA, Cal. Civ. Code § 1798.199.55(a) states that after an administrative determination that a violation has occurred, the agency may order the violator to "cease and desist" and can impose "corrective actions," as part of its administrative authority. The implementing CPPA regulations at 11 CCR § 7302 further provide for the issuance of orders requiring a person to do or refrain from doing any act to comply with the CCPA, including entering stipulated remedial orders as part of settlements.
Limits and procedural posture.
- The statutes require administrative due process: the CPPA must hold an administrative hearing to determine a violation before issuing an order (Cal. Civ. Code § 1798.199.55(a)), and the Attorney General must secure a court order (Cal. Civ. Code § 1798.199.90(a)).
- Neither statute expressly addresses emergency preliminary injunctions or temporary restraining orders. Such measures, if pursued, would depend on general California civil procedure, not a power unique to the CCPA/CPRA.
Practical context: While neither statute lists specific remedies like compliance reporting or contract modifications, real-world enforcement (such as the Attorney General’s settlement with Sephora, Inc. in 2022) has demonstrated the use of broad injunctive terms requiring privacy policy updates, technical measures, and monitoring. However, such remedy types are grounded in court or agency discretion, not enumerated in the CCPA/CPRA statutory text. Practitioners should focus on the text of § 1798.199.90(a), § 1798.199.55(a), and 11 CCR § 7302 to understand the limits and procedural steps for injunctive relief in official enforcement.
Source: Cal. Civ. Code § 1798.199.90 Source: Cal. Civ. Code § 1798.199.55 Source: 11 CCR § 7302
Criminal liability under the CCPA/CPRA — statutory bar and overlaps with California Penal Code
No direct criminal liability for CCPA/CPRA violations.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), does not itself create criminal penalties for violations of its provisions. This is made explicit in Cal. Civ. Code § 1798.196(a), which states: “This title is intended to supplement, and not supplant, federal and state law. Nothing in this title shall serve as the basis for a criminal prosecution under California law.” This statutory bar means that violations of the CCPA — whether substantive requirements (such as failing to honor consumer rights) or procedural duties (like responding to requests) — are not crimes under the CCPA or CPRA. The enforcement mechanisms are exclusively civil, administrative, or private, as discussed in other sections of this guide.
Overlap with independent criminal statutes.
Importantly, conduct related to information security or privacy that also violates a provision of the California Penal Code may still be prosecuted criminally under those separate statutes. For example, acts such as willful unauthorized access to computer systems (California Penal Code § 502, the Comprehensive Computer Data Access and Fraud Act), identity theft (Penal Code § 530.5), or perjury in connection with information supplied to enforcement authorities (Penal Code §§ 118–129), are subject to prosecution independently of the CCPA/CPRA. The CCPA explicitly “does not relieve a party of any obligations imposed under other laws or the United States or California Constitutions.” Cal. Civ. Code § 1798.196(b). However, the mere fact that a business has violated a CCPA right or duty does not, in itself, create a criminal offense — except where the conduct separately constitutes a crime under another law.
No CCPA criminal aiding/abetting or conspiracy.
The CCPA contains no provisions establishing criminal liability for aiding, abetting, or conspiring to violate its provisions. This sharply distinguishes it from some sectoral privacy laws (such as HIPAA, which does have criminal penalties for willful violation). All CCPA enforcement for non-data-breach situations is administrative (by the CPPA), civil (by the Attorney General), or, for certain breaches, private (by affected consumers). Practitioners can advise with certainty that a CCPA-only violation will not trigger prosecution, but must separately evaluate the facts for criminal exposure where conduct invades privacy or data security beyond what the CCPA covers.
2026 currency and practical cross-references.
This CCPA/CPRA criminal carve-out remains current as of mid-2026, with no amendments or legislative proposals in print proposing to create direct criminal penalties for CCPA non-compliance.
- For penalties and agency powers, see earlier sections in this California enforcement guide.
- For relevant criminal statutes commonly implicated in commercial privacy incidents, consult California Penal Code §§ 502 (computer crimes), 530.5 (identity theft), and 118 et seq. (perjury).
Source: Cal. Civ. Code § 1798.196
Extraterritorial jurisdiction and enforcement against out-of-state and foreign entities under the CCPA/CPRA
Extraterritorial reach of CCPA/CPRA enforcement The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies not only to California-based businesses but to any entity that “does business in California” and meets the statutory thresholds—even if that business is located outside California or outside the United States. Cal. Civ. Code § 1798.140(d) defines a "business" to include any for-profit entity that determines the purposes and means of processing personal information about California residents and satisfies the gross revenue or data-processing thresholds. The statute does not further define “does business in California.” Guidance must therefore be drawn from California’s Code of Civil Procedure and general jurisdictional doctrine, which hold that jurisdiction extends to the outer limits permitted by due process under the U.S. Constitution. (Cal. Code Civ. Proc. § 410.10.)
Personal jurisdiction standards for nonresident entities California courts apply the state’s long-arm statute (Cal. Code Civ. Proc. § 410.10), which authorizes jurisdiction "on any basis not inconsistent with the Constitution of this state or of the United States." In practice, this allows for enforcement against any entity with sufficient minimum contacts in California—such as intentionally collecting data from, or targeting products or services to, California residents—even if the business does not have a physical presence in California. This interpretive layer is not explicit in the CCPA statutory text but is the default for all California civil enforcement.
Practical mechanics of service and enforcement California enforcement authorities—the California Privacy Protection Agency (CPPA) and the Attorney General—can pursue covered entities located outside California, including abroad, so long as the statutory requirements are met. Service of process may be accomplished according to California’s rules of civil procedure (Cal. Code Civ. Proc. §§ 413.10–416.90). Where a party is located outside the United States, service may require compliance with the Hague Service Convention or other applicable treaty, as appropriate. If an entity fails to respond, a default judgment may be entered, which can generally be enforced against assets located in the U.S.; recognition and enforcement abroad will depend on the law and courts of the foreign jurisdiction. The statute is silent on the limits of international recognition—this is governed by foreign law, not California law.
Nonresident service providers and contractors Service providers and contractors are within the enforcement scope even if outside California. Cal. Civ. Code § 1798.140(ag) (service provider) and § 1798.140(j) (contractor) include no geographic carveout. Cal. Civ. Code § 1798.199.55(b) provides that persons responsible for violations are "jointly and severally liable" for administrative fines. Thus, a nonresident service provider processing California personal information on behalf of a CCPA-covered business is subject to enforcement.
Summary for cross-border practitioners CCPA/CPRA enforcement can extend to businesses and service providers without a physical California presence if they collect California residents’ personal information and meet the criteria of “doing business” in the state, as read with reference to general jurisdictional law. Practical barriers may limit California’s ability to collect fines outside the United States, but the statutes are drafted for broad reach and joint liability.
Source: Cal. Civ. Code § 1798.140 Source: Cal. Civ. Code § 1798.155 Source: Cal. Civ. Code § 1798.199.55 Source: Cal. Code Civ. Proc. § 410.10 Source: Cal. Code Civ. Proc. §§ 413.10–416.90
Appeals and judicial review of CPPA enforcement orders — administrative process and writ of mandate
When the California Privacy Protection Agency (CPPA) issues a final decision in a California Consumer Privacy Act (CCPA) enforcement action—whether imposing an administrative fine or resolving a complaint—affected parties have a statutory right to challenge that decision by seeking judicial review in California Superior Court. The appeal mechanism is governed by Cal. Civ. Code § 1798.199.85, which explicitly provides that such decisions “shall be subject to judicial review in accordance with Section 11523 of the Government Code.”
Administrative appeal process and exhaustion. Parties must exhaust all administrative remedies with the CPPA before seeking court intervention. The CPPA decision becomes final only after the conclusion of administrative proceedings, including any post-hearing motions or requests for reconsideration permitted by CPPA regulations (see 11 CCR § 7302). Only final decisions are subject to judicial review; interlocutory or preliminary CPPA actions are generally not immediately appealable.
Procedure for judicial review—writ of mandate. Judicial review of CPPA decisions proceeds under the framework of a petition for writ of mandate pursuant to Gov. Code § 11523 and Cal. Code Civ. Proc. § 1094.5 (the administrative mandamus statute). The petition must be filed in the superior court within 30 days after the CPPA decision becomes final, as required by Gov. Code § 11523. The statute mandates that the CPPA prepare the administrative record (all pleadings, evidence, transcripts, and orders) for the court’s review. Unless the court grants otherwise, review is typically limited to the administrative record; new evidence is admitted only in narrowly defined circumstances.
Standard of review—abuse of discretion. Cal. Civ. Code § 1798.199.85 provides that judicial review of CPPA enforcement decisions uses the “abuse of discretion” standard. The court asks whether the agency acted arbitrarily, exceeded its statutory authority, failed to proceed in the manner required by law, or made findings not supported by substantial evidence in light of the whole record (see CCP § 1094.5(b), (c)). The reviewing court does not substitute its judgment as to fact; unless abuse is shown, the CPPA’s findings stand.
Relief and further appellate review. If the court grants the writ, it may set aside or modify the CPPA order and may remand for further proceedings. Either party may appeal the court’s judgment, subject to ordinary appellate procedure. There is no statutory stay of a CPPA order pending judicial review; a party must separately seek a stay from the court.
2026 currency and practice points. This appeals framework applies to all final CPPA administrative enforcement decisions under the CCPA/CPRA as of June 2026. Practitioners should advise clients on short timelines (30 days), the record-based nature of review, and the high threshold to overturn an agency finding under the abuse-of-discretion standard.
Source: Cal. Civ. Code § 1798.199.85 Source: Gov. Code § 11523 Source: CCP § 1094.5
Publication and confidentiality of CPPA enforcement actions — public disclosure, redaction, and confidentiality rules under the CCPA/CPRA
Statutory and regulatory transparency requirements for CPPA enforcement actions
The California Privacy Protection Agency (CPPA) is required by regulation to publish any final decision or order issued in an administrative enforcement proceeding under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Under 11 CCR § 7306(a), the CPPA "shall promptly make available to the public any final decision or order issued in an enforcement proceeding," including stipulated orders. Where the agency finds that no violation occurred, a declaration to that effect must also be published (see Cal. Civ. Code § 1798.199.55(a)).
Redaction and withholding of confidential information
Before publication, the CPPA must redact or withhold “[a]ny portion of a decision, order, or record containing trade secrets, confidential research, development, or commercial information, or personal information, as well as any information required by law to be kept confidential” (11 CCR § 7306(b)). The regulatory text echoes exemptions for trade secrets or sensitive information found elsewhere in California law. The regulations do not, however, provide the CPPA full discretion to withhold arbitrary enforcement material; only the categories specified in law may be withheld. Investigatory records themselves (as distinct from final enforcement orders) are not public records under 11 CCR § 7305, which addresses confidential treatment of agency investigative files.
California Public Records Act (CPRA) interface
If a member of the public requests records from the CPPA, the California Public Records Act (Cal. Gov. Code § 6250 et seq.) governs the agency’s disclosure obligations and exemptions. The statute provides specific exemptions for records of complaints to, or investigations conducted by, public agencies, where disclosure would impair enforcement or compromise confidential sources (Cal. Gov. Code § 6254(f)). Cal. Civ. Code § 1798.199.95(c) directs the agency to protect information made confidential by law—even in response to disclosure demands. The agency must interpret its disclosure duties in light of both Government Code § 6254 and its own confidentiality obligations.
Practical publication notes
The CPPA publishes final decisions and orders, with redactions as required, on its official website. However, at the time of writing (June 2026), the agency’s record of published orders is limited, corresponding with its early enforcement history. Parties can request additional redactions, but the agency’s redaction obligation is ultimately set by the categories specified in the relevant statutes and regulations. Practitioners should expect public release of enforcement outcomes, but not the full investigatory record or trade-secret content, absent a legal mandate to disclose.
Source: 11 CCR § 7306 Source: Cal. Civ. Code § 1798.199.55 Source: Cal. Civ. Code § 1798.199.95 Source: Cal. Gov. Code § 6254(f)
Service providers and contractors — enforcement liability, joint and several exposure, and contractual defenses under CCPA/CPRA
Direct enforcement liability and limits for service providers/contractors
Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), service providers and contractors (entities processing personal information on behalf of a business pursuant to a contract, Cal. Civ. Code § 1798.140(ag), (j)) may be held directly liable for CCPA violations only where they are actually "responsible" for the violation. Cal. Civ. Code § 1798.199.55(b) provides that "[t]wo or more persons who are responsible for any violation of this title…shall be jointly and severally liable," but direct liability is not automatic based solely on provider status. Instead, the critical question is whether the provider exceeded contractual limits, made improper use or disclosure of information, or knowingly assisted a business in a violation—factors established by statutory terms and the details of each factual scenario.
Contractual boundaries—what insulates a provider?
A service provider or contractor is generally shielded from enforcement when processing personal information strictly as permitted under a compliant contract. Such a contract, as described in § 1798.140(w)(2)(A) (service provider) and § 1798.140(aa)(2) (contractor), must prohibit:
- Selling or sharing the information,
- Any use or disclosure for purposes outside the business-relationship scope,
- Combining personal information across sources except as authorized by the CCPA.
If the provider acts strictly in accordance with these written terms—and does not know, or have reason to know, that the business's instructions are unlawful—enforcement for violations beyond the provider's control typically will not lie against the provider. Cal. Civ. Code § 1798.145(h) creates an express carveout for certain business directions, stating a service provider or contractor is not liable if it "reasonably relied on, and did not have actual knowledge or reason to believe that, such instruction was in violation of any provision of this title."
Triggering direct liability—key risk boundaries
A provider loses this insulation and faces direct liability where it:
- Uses or discloses personal information for its own purposes (e.g., analytics, resale, cross-context behavioral advertising),
- Exceeds contractually allowed actions,
- Does not have a CCPA-compliant contract,
- Knows or should know the business's instructions would generate a violation (subject to facts regarding actual or constructive knowledge).
Joint and several liability means the CPPA or Attorney General may recover the entire penalty from any person responsible—including a provider—if the criteria above are met. However, contractual allocation of indemnity or defense obligations is a matter between parties and does not limit state enforcement choices or obligations under the statute.
Open questions and enforcement practice (2026)
As of June 2026, there are no final CPPA or Attorney General enforcement decisions further narrowing or expanding service provider joint liability post-CPRA. Providers and contractors should monitor evolving agency publications and enforcement materials for any interpretive developments. The statutory language remains the practitioner's principal authority.
Source: Cal. Civ. Code § 1798.140 Source: Cal. Civ. Code § 1798.199.55 Source: Cal. Civ. Code § 1798.145