Back to the hub

CCPA fines and penalties: how much does a CCPA violation cost?

CCPA fines run to $2,663 per violation and $7,988 per intentional violation or one involving a consumer under 16, after the CPPA's inflation adjustment effective January 1, 2025. Separately, consumers may sue over a data breach for $107 to $799 per consumer, per incident, or actual damages.

Applies to: For-profit businesses covered by the CCPA that handle California residents' personal information; the breach right of action reaches any covered business that suffers a qualifying breach.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Penalties are usually the first thing a founder asks about, and with the CCPA the honest answer is that a single number is misleading. The law sets a per-violation amount that looks small until you multiply it across every affected consumer, plus a separate route for consumers to sue after a breach. Here is what each figure is and where it comes from.

How much is a CCPA fine?

A CCPA fine is not more than $2,663 for each violation, or $7,988 for each intentional violation or each violation involving the personal information of a consumer the business knows is under 16. Those amounts sit in Cal. Civ. Code Section 1798.155, which covers administrative fines, and Section 1798.199.90, which covers civil penalties in a court action.

The statute itself still prints $2,500 and $7,500, and that trips people up. Section 1798.199.95(d) requires the California Privacy Protection Agency to adjust the CCPA's monetary thresholds for inflation every odd-numbered year, and the Agency did so effective January 1, 2025. The adjusted figures are the operative ones. The next adjustment falls in 2027, so budget on the assumption that these numbers move again.

Who enforces the CCPA?

Two public bodies do. The California Privacy Protection Agency can bring an administrative enforcement action and assess the fines above. The Attorney General can bring a civil action in the name of the people of California and recover the same per-violation penalties. There is no mandatory cure period baked into the statute anymore, so a business cannot assume it will get a free chance to fix a problem before any penalty attaches. Enforcement mechanics differ by state, and the Texas TDPSA vs CCPA comparison shows how another large state handles it.

Can consumers sue under the CCPA?

Yes, but only in one situation: a data breach. Under Section 1798.150, a consumer whose nonencrypted and nonredacted personal information is subject to unauthorized access because the business failed to maintain reasonable security can sue for statutory damages of not less than $107 and not greater than $799 per consumer per incident, or actual damages if they are greater. This private right of action does not extend to other CCPA violations such as a missing opt-out link; those are left to the state.

Why the per-violation math matters

The reason the small per-violation number becomes serious is scale. If a compliance gap touches 10,000 California consumers, a regulator can treat that as 10,000 violations, and a breach claim can aggregate the same way across everyone exposed. That is why enforcement settlements land in the millions even though the unit figures are modest. The gaps regulators cite most are a missing opt-out mechanism or unmanaged sensitive data, so confirm your Do Not Sell or Share link and your sensitive personal information controls are in place. Knowing whether the CCPA even applies to your business is the first lever, because a business under every threshold has no exposure at all.

Where the administrative fine comes from

Section 1798.155(a) provides that any business, service provider, contractor, or other person that violates the title shall be liable for an administrative fine of not more than two thousand five hundred dollars for each violation, or seven thousand five hundred dollars for each intentional violation or violations involving the personal information of consumers the person has actual knowledge are under 16 years of age, as adjusted under Section 1798.199.95(d), in an administrative enforcement action brought by the California Privacy Protection Agency. The "as adjusted" clause is what makes the CPPA's published $2,663 and $7,988 the amounts that actually apply, rather than the dollar figures spelled out in the sentence itself. Note that the section names service providers and contractors alongside businesses, so a badly drafted vendor arrangement carries its own exposure: see service provider vs third party. Holding data past the period you disclosed is a violation in the same way a missing notice is, which is why the retention disclosure rule is worth closing early.

Is the maximum $2,500, $5,000, $7,500 or $10,000?

The statute says $7,500. The amount you would actually pay is $7,988. Both answers are correct, and which one is right depends on what is being asked.

Civil Code 1798.155(a) reads that any business, service provider, contractor or other person that violates the title "shall be liable for an administrative fine of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation or violations involving the personal information of consumers whom the business, service provider, contractor, or other person has actual knowledge are under 16 years of age, as adjusted pursuant to subdivision (d) of Section 1798.199.95, in an administrative enforcement action brought by the California Privacy Protection Agency."

So the printed statutory figures are $2,500 and $7,500. Neither $5,000 nor $10,000 appears anywhere in the section. If a compliance exam or certification question offers those four options, the intended answer is $7,500.

Why the operative number is $7,988

The clause "as adjusted pursuant to subdivision (d) of Section 1798.199.95" is not decoration. It requires the California Privacy Protection Agency to move the amounts with the Consumer Price Index in every odd-numbered year.

The Agency published that adjustment on December 17, 2024, effective January 1, 2025. The administrative fine amounts under 1798.155(a) became $2,663 for each violation and $7,988 for each intentional violation or violation involving a consumer the business knows is under 16. The same adjusted figures apply to the civil penalty amounts under Section 1798.199.90(a).

Because the adjustment cycle runs in odd-numbered years, those 2025 amounts remain the operative figures through 2026. The next scheduled adjustment would take effect on January 1, 2027.

A page, policy or training deck that still quotes $2,500 and $7,500 as the amount payable is quoting the pre-2025 figures. Quoting them as the text of the statute is accurate. Quoting them as your exposure is not.

Administrative fine or civil penalty? They are two different sections

A question asking for "the maximum civil penalty per intentional violation" is asking about a different provision from the one that sets the administrative fine, and since AB 137 the two have been cleanly separated.

Section 1798.155(a) is the administrative fine, and it belongs to the California Privacy Protection Agency. The section is headed "Administrative Enforcement" and the amounts are recoverable "in an administrative enforcement action brought by the California Privacy Protection Agency." That section carries the line "Amended by Stats. 2025, Ch. 20, Sec. 1. (AB 137) Effective June 30, 2025."

Section 1798.199.90(a) is the civil penalty, and it belongs to the attorney general. It reads that any business, service provider, contractor, or other person that violates the title "shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation and each violation involving the personal information of minor consumers, as adjusted pursuant to subdivision (d) of Section 1798.199.95, which shall be assessed and recovered in a civil action brought in the name of the people of the State of California by the Attorney General." The subdivision closes with a sentence worth knowing: "The court may consider the good faith cooperation of the business, service provider, contractor, or other person in determining the amount of the civil penalty." Section 1798.199.90 carries the same AB 137 credit line, effective June 30, 2025.

Three practical differences follow.

The amounts are identical, and both run through the same CPI adjustment in Section 1798.199.95(d), so the operative figures are $2,663 and $7,988 on either route.

The civil penalty route adds an injunction. Section 1798.155(a) provides for a fine; Section 1798.199.90(a) provides for an injunction and a penalty, which means the attorney general can seek an order changing what the business does, not only money.

And the civil penalty route has an express mitigation lever that the administrative route does not print: good faith cooperation, which the court may consider in setting the amount.

You are not exposed to both for the same violation

Section 1798.199.90 also contains the rule that stops the two routes from stacking. The subdivision bars the attorney general from bringing the civil action where the California Privacy Protection Agency has issued a decision or an order under Section 1798.199.55 against that person for the same violation.

What does survive alongside either is the consumer claim. Section 1798.199.90(e) states that the section "shall not affect the private right of action provided for in Section 1798.150." So a single security failure can produce a regulator action and a consumer suit for $107 to $799 per consumer per incident, but not both a CPPA order and an attorney general civil penalty for the same violation.

Next step

If you are covered, or unsure, the free 2-minute Obligation Scan checks your CCPA status and flags the notice, opt-out, security, and response duties whose absence is what regulators actually fine. It is faster to close those gaps now than to price a per-consumer penalty later. If you are weighing the spend, see what CCPA compliance costs. The US state privacy laws hub shows how California's penalties compare with other states.

Data brokers face a separate exposure on top of these amounts: failing to register under the Delete Act carries administrative fines and costs, as the California DROP page explains.

Compliance checklist

  • Confirm whether the CCPA applies to you before worrying about penalties: the fine exposure only attaches to covered businesses.
  • Treat each affected consumer as a potential separate violation, since fines are assessed per violation and multiply fast.
  • Post and maintain the required notices, opt-out links, and a privacy policy, because missing them is the most common enforced violation.
  • Keep reasonable security controls in place, as the $107 to $799 per-consumer breach claim turns on that duty.
  • Log how you respond to consumer requests within 45 days, since delay or denial is itself an enforceable violation.

Sources

Last verified: 2026-09-18

Informational, not legal advice.