The CCPA does not impose a general requirement to obtain consent before placing every non-essential cookie. For a covered business, the starting points are notice at or before collecting personal information and an effective way to exercise applicable privacy rights, including opting out of sale or sharing.
A banner can help deliver those controls. Its presence does not establish compliance, and its absence does not, by itself, establish a violation. The important questions are what the business collects, how it uses and discloses that information, and whether the consumer's choice changes those activities.
This guide covers the CCPA as amended by the CPRA. It separates the California requirements from suggested implementation checks. Other laws and particular processing activities may impose additional obligations.
Establish whether the CCPA applies
The main business definition covers a for-profit entity doing business in California that determines the purposes and means of processing consumers' personal information and meets at least one threshold:
- Annual gross revenue over $26,625,000 in the preceding calendar year, assessed as of 1 January.
- Annually buying, selling or sharing the personal information of 100,000 or more consumers or households, alone or in combination.
- Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.
The revenue amount is the inflation-adjusted threshold effective from 1 January 2025, still applicable in 2026. Sources: Civil Code § 1798.140(d) and the Agency's monetary threshold notice.
100,000 website visits is not the statutory test. Assess the relevant California consumers or households and the buying, selling or sharing activity. The preceding-calendar-year wording above belongs to the revenue test; do not apply it indiscriminately to every threshold.
Related-entity rules and exemptions can affect the assessment. Being below the revenue threshold alone does not settle applicability.
Give notice before collection
The Attorney General's notice guidance explains that consumers must receive notice at or before collection. A conspicuous link can be used in the appropriate context; a mandatory pop-up is not the only format.
The notice should cover the categories of personal information, including sensitive information, the purposes, whether categories are sold or shared, and retention periods or criteria. It also needs the relevant opt-out notice link and privacy-policy link. A cookie inventory alone does not explain those practices.
Under 11 CCR § 7012, a link into a privacy policy must lead directly to the section containing the required notice, rather than making readers search the entire policy.
For implementation, map every collection point to its notice: the introductory page, checkout, account registration, embedded forms and app interfaces. Check the first network activity as well as the visible page. A notice that appears after collection begins does not solve the timing requirement.
Keep notice and consent distinct. A California configuration may use an opt-out model for relevant adult activity, but it must still honour existing opt-outs and GPC. Consent can be required in specific circumstances, including sale or sharing where the business knows the consumer is under 16, with parental authorisation for under-13s. See the Attorney General's explanation of children's sale/sharing protections.
Make the privacy choice clear and balanced
The CPPA's dark-patterns advisory emphasises understandable language and symmetrical choices. The effect of an interface matters, even where the designer did not intend to obstruct the consumer.
If a banner offers an acceptance path, do not make the more protective choice harder to find or complete. A useful design pattern is a direct refusal action beside acceptance, with optional settings for more detail. The labels must describe what those actions actually do.
Avoid treating a particular colour, pixel size or three-button layout as a universal legal template. Review prominence, meaning and the complete interaction. A visually balanced pair of buttons still fails the consumer if refusal opens a lengthy form while acceptance takes effect immediately.
Honda's order documents a two-step advertising-cookie opt-out and a one-step return to allowing cookies. Its remedy included a “Reject All” control. See the Honda order, paragraphs 53–65 and 77.
For the preference centre, our suggested review is:
- Use labels that make the active choice explicit.
- Count the steps for refusal and acceptance, including confirmation screens.
- Test a return visit after an earlier opt-out.
- Check keyboard focus, screen-reader labels, zoom and smaller screens.
- Check the languages used for consumer-facing information.
Accessibility is part of the disclosure requirement. Section 7003 references recognised standards such as WCAG 2.1; it does not state the simple blanket “WCAG 2.1 AA” rule sometimes attributed to it.
Provide a working opt-out route
The standard link is “Do Not Sell or Share My Personal Information”. The alternative is “Your Privacy Choices” or “Your California Privacy Choices”, with the prescribed opt-out icon. Its colour may be adjusted for visibility. Sections 7013 and 7015 place these links in the header or footer of the business's internet homepages.
The exception for frictionless signal processing requires all conditions in § 7025(f)–(g), including disclosures and full effectuation. Installing GPC detection alone is insufficient. See the current CCPA regulations.
As an implementation choice, a shared footer is a useful way to keep the route available throughout a site. Test it from product pages, campaign pages and checkout, rather than only the homepage.
The destination should make the right understandable and actionable. “Manage cookies” should not lead consumers to believe they have stopped sale or sharing if it only changes a subset of browser cookies. Keep the rights route available after dismissing a banner.
For the form behind the link, collect only necessary information and avoid identity-verification gates. Ford's order illustrates the failure caused by making email confirmation a condition of processing. See the Ford order and our opt-out form guide.
Honour GPC and show the result
The California Attorney General confirms that covered businesses that sell or share personal information must honour Global Privacy Control as a valid sale/sharing opt-out request. A manual form does not replace signal handling.
The GPC specification describes the HTTP header Sec-GPC: 1 and the browser property navigator.globalPrivacyControl. These expose the preference to different parts of an implementation. The law does not prescribe a particular server framework or require a specific three-line code sample.
Our engineering recommendation is to inspect the signal wherever decisions about disclosure are made. Check that a CDN, cache, tag manager or server endpoint does not lose it, and that browser-side handling happens before an affected transfer.
Under § 7025, processing covers the browser/device and associated profiles, including pseudonymous profiles, and the consumer if known. The website must display whether it processed the signal. The absence of a later signal is not a known consumer's consent to opt back in. See the 2026 regulations, § 7025(c).
Show an accurate status, such as “Your sale and sharing opt-out is active”, only when it is true. A message saying “GPC detected” describes an input, not the result of processing it.
Disney's settlement illustrates why account associations matter: a choice confined to one service or device did not fully stop sale or sharing for recognised consumers. Test the associated account as well as the original browser. See the Attorney General's Disney announcement.
Check data transfers, not just cookie categories
Under Civil Code § 1798.140, sale involves monetary or other valuable consideration. Sharing concerns cross-context behavioural advertising, regardless of payment. Qualifying service-provider and contractor processing may fall outside those definitions, subject to the applicable conditions.
A tag name alone cannot resolve the classification. Assess its configuration, payload, destination, purpose and recipient's permitted and actual use. Avoid blanket claims that every GA4 installation is a sale or every advertising request has the same legal treatment.
Use a transfer inventory alongside the cookie scan:
| Layer | Suggested inspection | Useful evidence |
|---|---|---|
| Browser | Requests before and after opting out, including embedded content | Network captures and tag configuration |
| Server | Forwarding, conversion APIs and scheduled exports | Destination settings and processing logs |
| Accounts and apps | Whether associated clients read the updated preference | Test-account results across clients |
| Recipients | How restrictions reach the recipient and affect use | Applicable agreements and configuration |
Deleting a cookie does not by itself stop server-side exports. Conversely, a continuing network request is not automatically proof of prohibited sale or sharing. Determine what the request does.
Use Consent Mode as an integration component
Google Consent Mode controls how Google's tags respond to storage and data-use choices. Its values are granted and denied, not JavaScript booleans. The four commonly used types are ad_storage, analytics_storage, ad_user_data and ad_personalization. Google documents their meanings and the order of default and update calls in its implementation guide.
Consent Mode does not provide the notice, decide whether processing is sale or sharing, or control every non-Google destination. In advanced mode, Google tags can send cookieless measurements while storage consent is denied. A denied state therefore does not mean no data is transmitted. See Google's Consent Mode overview.
Document how each privacy choice maps to vendor settings. Inspect actual requests after the update. Do not use a generic “Accept All” handler that silently overwrites an active sale/sharing opt-out.
Detailed configuration belongs in our Consent Mode implementation guide and basic versus advanced comparison.
A practical pre-release review
Use these checks as an engineering review, not a guarantee of compliance:
- Scope: record the applicability assessment and which transfers constitute sale or sharing.
- Notice: compare the deployed collection with the notice's categories, purposes, retention and links.
- Choice: follow acceptance and refusal through completion on desktop and mobile.
- Access: reopen the privacy controls after dismissal, using a keyboard as well as a pointer.
- Manual opt-out: submit without creating an account or completing an identity-verification challenge.
- GPC: use a fresh profile with the signal enabled; compare the displayed status with actual transfers.
- Persistence: revisit the site and test an associated account on another client.
- Integrations: check browser tags, server forwarding and advertising exports separately.
- Failures: interrupt an integration and confirm that monitoring catches the incomplete update.
- Ownership: keep the configuration version, expected result, observed result and responsible owner with the test record.
The Attorney General's guidance states that opt-outs must be fulfilled as soon as feasibly possible, within a maximum of 15 business days. Treat that as an outer limit, not a routine waiting period.
Penalties and enforcement context
For 2026, the Agency's published administrative fine limits are up to $2,663 per violation, or $7,988 for an intentional violation or one involving a consumer actually known to be under 16. These are maximum amounts, not an automatic price per banner error. See the current monetary threshold notice.
An opportunity to cure in Agency enforcement is discretionary under § 1798.199.45. Do not assume a guaranteed 30-day repair window. This is distinct from the provisions governing certain private data-breach claims.
For concrete findings and remedies, use our Honda, Ford and Disney case review. A settlement's specific reporting or audit obligation should not be presented as an automatic requirement for every other business.
FAQ
Do all sites need an Accept All and Reject All banner?
No. Determine the applicable notice and rights requirements first. If acceptance and refusal controls are offered, make the choices clear and balanced. A banner layout is one part of the implementation.
Can one platform support California and other regions?
Yes, but the configuration and notices need to reflect the applicable rules. A global prior-consent approach still needs California rights handling, including GPC and appropriate opt-out scope. Separate state laws also require their own assessment; California compliance is not a nationwide certification.
Is a cookie scan enough to verify the implementation?
No. It helps identify browser storage, but can miss server transfers, account-level preferences and scheduled exports. Combine it with the transfer and journey checks above.
Does adding GPC support mean we can remove the privacy link?
Not automatically. Review the full frictionless-processing exception discussed above before changing the available rights routes.
Further reading
For a transfer-by-transfer decision framework, see CCPA sale vs. sharing: analytics and advertising explained.
Continue with the CCPA audit framework, CCPA and CPRA comparison, or Global Privacy Control guide.
For help reviewing your current banner and integrations, request a free consent audit or discuss your CCPA and GPC setup.
