Law note · California

CCPA/CPRA Enforcement: California Privacy Protection Agency and Private Right of Action

cite Cal. Civ. Code sections 1798.150, 1798.155, 1798.199.10, 1798.199.90 stage In effect since 2023-07-01 reviewed 2026-08-23

The California Privacy Protection Agency, which assumed enforcement authority July 1, 2023, and the Attorney General share administrative enforcement of the CCPA/CPRA, with civil penalties currently up to $2,663 per violation or $7,988 per intentional violation or one involving a consumer known to be under 16, inflation-adjusted for 2025 under a streamlined adjustment mechanism AB 3286 (2024) put in place.

There is no general private right of action for a CCPA violation; a narrow one exists only under section 1798.150 for a business's failure to maintain reasonable security resulting in a breach of unencrypted, unredacted personal information, carrying statutory damages of $100 to $750 per consumer per incident and a 30-day cure notice that does not excuse a breach already suffered.

What it asks of an app

  • Expect administrative enforcement from the California Privacy Protection Agency and the Attorney General, with civil penalties up to $7,988 for an intentional violation or one involving a consumer under 16 (the 2025 inflation-adjusted amount).
  • Maintain reasonable security procedures for a California consumer's unencrypted, unredacted personal information; a breach caused by their absence exposes your business to a private lawsuit for $100 to $750 in statutory damages per consumer per incident, which cannot be cured by improving security after the fact.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)
California Attorney General (oag.ca.gov); California Privacy Protection Agency (cppa.ca.gov)

← Back to the example  ·  Lint your app →