Everything You Need to Know About California‘s Cookie Consent Law in 2025
As one of the strictest privacy laws in the United States, the California Consumer Privacy Act (CCPA) has major implications for how businesses handle consumer data—including via cookies and tracking technologies. The CCPA first went into effect in 2020 and an amendment called the California Privacy Rights Act (CPRA) expanded it even further.
Here‘s a comprehensive look at what businesses need to know about California‘s cookie consent requirements in 2024 and beyond.
CCPA Overview and Relation to Cookies
At a high level, the California Consumer Privacy Act aims to give consumers more control over their personal information by granting them specific rights:
- The right to know what personal information a business has collected about them
- The right to delete personal information a business has collected
- The right to opt out of the sale of their personal information
- The right to non-discrimination for exercising their CCPA rights
The CCPA applies to for-profit entities doing business in California that meet certain thresholds related to annual revenue, data processing volume, or percentage of revenue derived from selling personal information.
While the CCPA doesn‘t mention cookies by name, it governs personal information collected through cookies and other online tracking technologies. IP addresses, unique identifiers, browsing history, search history, and information regarding a consumer‘s interaction with a website all fall under "personal information" when they can be linked back to a particular consumer or household.
This means that if your business deploys cookies or similar technologies on your website to monitor users and collect data that can be tied to individual consumers, you must comply with CCPA requirements around notification and consumer choice. Simply having a cookie banner is not enough—there are specific rules around the design of cookie controls, opt-out processes, and more.
CCPA Requirements for Cookie Use
Under the CCPA, businesses have certain obligations when it comes to using cookies:
-
Disclose data collection upfront. You must inform consumers at or before the point of collection about the categories of personal information to be collected and how it will be used. This notice should be conspicuous and clearly explain your site‘s cookie practices.
-
Give consumers the right to opt out. If your business "sells" personal information as defined by the CCPA (which may include allowing third party cookies), you must provide a "Do Not Sell My Personal Information" link that allows consumers to opt out. The opt-out process should be easy to access and use.
-
Respond to consumer requests. Consumers have the right to request access to the specific pieces of personal information your business has collected about them, including via cookies. They also have the right to request deletion of that information. You must be prepared to verify and fulfill these requests.
-
Avoid discriminating against consumers who exercise their rights. You can‘t penalize users for opting out or requesting information under the CCPA by denying goods/services, charging different prices, providing a different level of quality, or suggesting they will receive all of the above.
It‘s important to conduct a full audit of your site‘s cookie use so that you understand what data you collect, how it‘s used, and where it‘s sent in order to determine your disclosure requirements. You‘ll also need a process for securely storing any collected data and responding to consumer rights requests.
CPRA Amendments Now in Effect
The California Privacy Rights Act amendment to the CCPA expands consumer rights, creates a new category of sensitive personal information, and limits the use of dark patterns starting in 2024.
Some key changes under the CPRA:
- Sensitive personal information such as precise geolocation, racial/ethnic origin, religious beliefs, unions membership, contents of mail/email/text messages, and genetic data now have additional protections. Consumers can limit the use and disclosure of this info.
- Dark patterns designed to manipulate or impair consumer autonomy are restricted. Using dark patterns to obtain consent is now forbidden, so your cookie controls can‘t use confusing language or design elements to nudge people toward accepting tracking.
- The definition of businesses that must comply is updated to include joint ventures and partnerships where each business has at least a 40% interest.
- The opt-out requirement now applies to both the sale and "sharing" of personal information (including for cross-context behavioral advertising).
Comparing the CCPA and GDPR
While the CCPA and the EU‘s General Data Protection Regulation (GDPR) both aim to protect consumer privacy and regulate the use of personal information, there are some key differences. The CCPA is focused on California residents while the GDPR applies to all EU citizens. The CCPA also has thresholds related to business size, revenue, and percentage of revenue derived from data sales that limit who it applies to, while the GDPR covers all entities processing personal data of EU subjects regardless of size.
The penalties for violations are also different, with CCPA fines up to $7500 per violation and a 30 day cure period in most cases. The GDPR allows penalties up to 4% of annual global turnover or €20 million (whichever is greater) with no cure period.
Despite some differences, both laws grant consumers certain fundamental rights regarding their information and require companies to have a valid legal basis for collecting and using personal data. Transparency, data minimization, purpose limitation, and data subject rights are key themes for both.
Meeting GDPR requirements puts you on the right path but likely won‘t guarantee full CCPA compliance, so it‘s important to evaluate your practices against each law‘s unique stipulations, especially when it comes to cookie consent and consumer opt-out rights.
Best Practices for CCPA Cookie Compliance in 2024
To ensure your business is fully compliant with California‘s cookie consent requirements in 2024, follow these best practices:
-
Audit all cookies and tracking technologies on your digital properties to determine what personal information you collect, what‘s done with it, and where it‘s sent. Pay special attention to any sensitive data categories.
-
Update your website‘s cookie policy and privacy notice to disclose your data collection practices, how to opt out, and how to exercise CCPA rights. Make sure this information is clear and easy to understand. Get consent where required.
-
Provide a conspicuous "Do Not Sell or Share My Personal Information" link that allows people to opt out of the sale or sharing of their data via cookies/tracking tools.
-
Implement a system for verifying and responding to consumer requests to access, delete, or opt out of the sale/sharing of their information collected through cookies. Work out how to authenticate requests.
-
Review your cookie consent interface to make sure it doesn‘t utilize any dark patterns that impair consumer choice. Avoid things like pre-checked boxes, hard-to-see reject buttons, confusing wording, or confirmation shaming.
-
Ensure any third parties you allow to deploy cookies on your site are also compliant and have contractual obligations in place to safeguard any data they collect from your users.
-
Regularly review and update your cookie practices to keep up with any new legal requirements or guidance. Consider hiring a data privacy professional or consultant to help you stay on top of compliance.
While achieving full compliance may seem daunting, the risks of not adhering to California‘s strict requirements are significant. With the CPRA amendments now in effect, enforcement is likely to increase. Taking steps to give consumers transparency and control over their data is crucial for avoiding costly penalties and maintaining customer trust in 2024 and beyond.