Definition
The California Consumer Privacy Act (CCPA), effective 1 January 2020, grants California residents specific rights over their personal information, including email addresses collected for marketing purposes. Unlike GDPR which uses a consent-first framework, CCPA operates on an opt-out model: businesses may collect and use personal information unless the consumer explicitly directs them to stop. The law applies to for-profit businesses that meet at least one of three thresholds: annual gross revenue over $25 million; buy, receive, or sell the personal information of 100,000 or more California residents, households, or devices; or derive 50 per cent or more of annual revenue from selling consumers' personal information.
For email marketers, CCPA compliance fundamentally affects how subscriber data is collected, stored, and shared. The law defines "sale" broadly to include any exchange of data for monetary or other valuable consideration, which can cover co-registration partnerships, data enrichment arrangements, and certain types of audience targeting. The California Privacy Rights Act (CPRA), which amended CCPA effective 1 January 2023, introduced the concept of "sharing" data for cross-context behavioural advertising, further expanding obligations for email marketers who use subscriber lists for lookalike audiences or ad platform integrations.
CCPA enforcement is carried out by the California Privacy Protection Agency (CPPA), with penalties of up to $7,500 per intentional violation and $2,500 per unintentional violation. A key distinction from GDPR is the private right of action, which is limited to data breaches involving unencrypted personal information rather than general compliance failures. Businesses must respond to verified consumer requests within 45 days, extendable by an additional 45 days with notice. According to a 2023 survey by the International Association of Privacy Professionals, 67 per cent of US businesses reported making significant changes to their email marketing data practices in response to CCPA.
Best Practices
Maintain a dedicated CCPA compliance page on your preference centre that clearly explains California residents' rights to know, delete, and opt out of the sale or sharing of their personal information. Include a straightforward "Do Not Sell or Share My Personal Information" link in your email footer alongside your standard unsubscribe link, as required by the CPRA amendments.
Implement a consent management platform that captures and stores California residency signals at the point of email collection. Use IP geolocation and self-declared residency to determine CCPA applicability, and document the methodology used to classify subscribers as California residents versus non-residents for audit purposes.
Build automated workflows that process consumer rights requests across all systems where subscriber data resides, including your ESP, CRM, analytics platform, and any data enrichment or co-registration partners. CPRA requires mapping all data flows that involve personal information shared with third parties, so maintain an up-to-date data inventory that tracks every downstream recipient of subscriber email addresses.
Segment your email suppression files to distinguish between general unsubscribe requests and CCPA-specific deletion or opt-out requests. A CCPA deletion request requires removing the subscriber's data from backup systems within a reasonable period, whereas a standard unsubscribe may only require ceasing future email sends while retaining the data for compliance records.
Review your data retention schedules to align with CCPA's requirement that personal information be retained only as long as reasonably necessary for the disclosed purpose. Archive compliance records — including the date, nature, and resolution of each consumer request — separately from active marketing databases to demonstrate adherence during regulatory investigations or private litigation.
Related Glossary Terms
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Data Portability
Data portability under GDPR Article 20 gives subscribers the right to receive their email marketing data in a machine-readable format and transfer it to another provider. Common export formats are CSV and JSON.
Email Data Retention
Email data retention policies govern how long subscriber data, activity logs, consent records, and campaign data are kept. GDPR requires data not be kept longer than necessary for the processing purpose.
Email Encryption
Email encryption uses TLS for transit security and end-to-end methods like PGP, with compliance requirements for HIPAA, GDPR, and impacts on marketing email tracking.
Frequently Asked Questions
Yes, CCPA applies to any business that meets the revenue or data volume thresholds, regardless of where the business is physically located, if it collects personal information from California residents. A UK-based e-commerce brand selling to California customers must comply.
CCPA assumes data collection is permitted unless the consumer opts out, whereas GDPR requires affirmative consent before collection begins. CCPA's opt-out applies specifically to data sale and sharing, while GDPR's opt-in covers most processing of personal data for marketing purposes.
Yes, a verified deletion request requires you to delete the subscriber's personal information from your active databases and direct any service providers to do the same. You may retain a limited record of the request for compliance purposes, but you must cease all marketing processing.
You must acknowledge receipt within 10 business days and substantively respond within 45 calendar days. You may extend the response period by an additional 45 days if reasonably necessary, provided you notify the consumer within the initial 45-day window.
Intentional violations carry a penalty of up to $7,500 per violation, and unintentional violations up to $2,500 per violation. The CPPA may also seek injunctive relief. Data breaches involving unencrypted email addresses may trigger private lawsuits with statutory damages of $100 to $750 per consumer per incident.