← ALL REGULATIONS
CCPA cookie compliance: the opt-out, and the signal.
The CCPA does not require opt-in consent for cookies. It requires a way to opt out of the sale or sharing of personal information, including through advertising cookies, and it requires honouring opt-out signals such as Global Privacy Control.
CCPA at a glanceOpt-out, opt-in for some data
- Applies to
- For-profit businesses in California over an inflation-adjusted revenue threshold, handling data of 100,000+ consumers, or earning 50%+ of revenue from selling or sharing it
- In force
- January 2020, with the CPRA amendments since January 2023
- Enforced by
- California Privacy Protection Agency and the Attorney General
- Penalties
- $2,500 per violation and $7,500 per intentional violation or one involving minors, adjusted for inflation
WHAT CCPA REQUIRES
What the CCPA asks of a site that uses advertising cookies.
THE RULEA Do Not Sell or Share linkAdvertising cookies that pass data to third parties for cross-context behavioural advertising count as sharing. Consumers must be able to opt out through a clear link or button.
WITH KATLAIn US State Laws (CCPA) mode, the banner’s main button is "Do Not Sell or Share My Personal Information", and the marketing category is labelled as the sale or sharing of personal information.
THE RULEHonour opt-out preference signalsThe CCPA regulations require treating a signal such as Global Privacy Control as a valid request to opt out. The Attorney General’s 2022 settlement with Sephora turned on exactly this.
WITH KATLAKatla honours Global Privacy Control: a visitor whose browser sends it is recorded as opted out, unless they have already made a choice. In CCPA mode, the banner tells the visitor their signal was honoured.
THE RULELimit the use of sensitive personal informationA business that uses sensitive personal information beyond the permitted purposes must offer a link to limit that use.
WITH KATLAKatla does not provide a "Limit the Use of My Sensitive Personal Information" link. If you need one, it has to come from your own site.
THE RULEOpt-in for minorsSelling or sharing the personal information of consumers under 16 requires opt-in consent, and a parent’s consent for children under 13.
WITH KATLAKatla has no age-specific flow. A site that knowingly serves under-16s can run Katla in GDPR mode, where nothing non-essential is set before an opt-in.
THE RULENotice at collectionConsumers must be told what is collected and why, at or before the point of collection.
WITH KATLASites set to CCPA mode get a generated policy with CCPA disclosures, built from the cookies the scan found.
CCPA questions, answered
A summary for website owners, not legal advice. Reviewed against the sources below.
- Does the CCPA require a cookie banner?
- Not an opt-in banner. It requires notice at collection and a Do Not Sell or Share opt-out, and many sites use a banner to provide both.
- What is Global Privacy Control?
- A browser setting that sends an opt-out signal with every request. Under the CCPA regulations, a business must treat it as a request to opt out of the sale and sharing of personal information.
- What was Sephora fined for?
- In 2022 the California Attorney General settled with Sephora for $1.2 million over third-party tracking on its site that counted as a sale, and over failing to honour Global Privacy Control.
- How does Katla decide which visitors get the CCPA banner?
- You choose per site: GDPR mode, US State Laws (CCPA) mode, or Auto. Auto reads the visitor’s timezone and uses the CCPA banner for timezones in the Americas, which includes Canada and Latin America, so choose explicitly if that matters for your audience.
See what your site sets before anyone asks.
The free plan scans your site, classifies every cookie and generates the policy, without a card. The cookie checker needs no account at all.