What are the fines and penalties under the CCPA?
California's CCPA carries fines of up to $2,500 per violation, or $7,500 per intentional violation or one involving a consumer under 16, imposed by the California Privacy Protection Agency or the Attorney General. Separately, consumers may sue over a data breach for $100 to $750 per consumer, per incident.
Applies to: For-profit businesses covered by the CCPA that handle California residents' personal information; the breach right of action reaches any covered business that suffers a qualifying breach.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Penalties are usually the first thing a founder asks about, and with the CCPA the honest answer is that a single number is misleading. The law sets a per-violation amount that looks small until you multiply it across every affected consumer, plus a separate route for consumers to sue after a breach. Here is what each figure is and where it comes from.
How much is a CCPA fine?
A CCPA fine is up to $2,500 for each violation, or up to $7,500 for each intentional violation or each violation involving the personal information of a consumer the business knows is under 16. Those amounts sit in Cal. Civ. Code Section 1798.155, which covers administrative fines, and Section 1798.199.90, which covers civil penalties in a court action. Both figures are adjusted for inflation by the California Privacy Protection Agency, so the statutory numbers are a baseline that rises over time rather than a permanent ceiling.
Who enforces the CCPA?
Two public bodies do. The California Privacy Protection Agency can bring an administrative enforcement action and assess the fines above. The Attorney General can bring a civil action in the name of the people of California and recover the same per-violation penalties. There is no mandatory cure period baked into the statute anymore, so a business cannot assume it will get a free chance to fix a problem before any penalty attaches. Enforcement mechanics differ by state, and the Texas TDPSA vs CCPA comparison shows how another large state handles it.
Can consumers sue under the CCPA?
Yes, but only in one situation: a data breach. Under Section 1798.150, a consumer whose nonencrypted and nonredacted personal information is subject to unauthorized access because the business failed to maintain reasonable security can sue for statutory damages of $100 to $750 per consumer per incident, or actual damages if they are greater. This private right of action does not extend to other CCPA violations such as a missing opt-out link; those are left to the state.
Why the per-violation math matters
The reason the small per-violation number becomes serious is scale. If a compliance gap touches 10,000 California consumers, a regulator can treat that as 10,000 violations, and a breach claim can aggregate the same way across everyone exposed. That is why enforcement settlements land in the millions even though the unit figures are modest. The gaps regulators cite most are a missing opt-out mechanism or unmanaged sensitive data, so confirm your Do Not Sell or Share link and your sensitive personal information controls are in place. Knowing whether the CCPA even applies to your business is the first lever, because a business under every threshold has no exposure at all.
Where the administrative fine comes from
Section 1798.155(a) provides that any business, service provider, contractor, or other person that violates the title shall be liable for an administrative fine of not more than two thousand five hundred dollars for each violation, or seven thousand five hundred dollars for each intentional violation or violations involving the personal information of consumers the person has actual knowledge are under 16 years of age, as adjusted under Section 1798.199.95(d), in an administrative enforcement action brought by the California Privacy Protection Agency. Note that the section names service providers and contractors alongside businesses, so a badly drafted vendor arrangement carries its own exposure: see service provider vs third party. Holding data past the period you disclosed is a violation in the same way a missing notice is, which is why the retention disclosure rule is worth closing early.
Next step
If you are covered, or unsure, the free 2-minute Obligation Scan checks your CCPA status and flags the notice, opt-out, security, and response duties whose absence is what regulators actually fine. It is faster to close those gaps now than to price a per-consumer penalty later. If you are weighing the spend, see what CCPA compliance costs. The US state privacy laws hub shows how California's penalties compare with other states.
Compliance checklist
- Confirm whether the CCPA applies to you before worrying about penalties: the fine exposure only attaches to covered businesses.
- Treat each affected consumer as a potential separate violation, since fines are assessed per violation and multiply fast.
- Post and maintain the required notices, opt-out links, and a privacy policy, because missing them is the most common enforced violation.
- Keep reasonable security controls in place, as the $100 to $750 per-consumer breach claim turns on that duty.
- Log how you respond to consumer requests within 45 days, since delay or denial is itself an enforceable violation.
Sources
- Cal. Civ. Code Section 1798.155 (administrative fines; California Privacy Protection Agency enforcement)
- Cal. Civ. Code Section 1798.199.90 (civil penalties in an action by the Attorney General)
- Cal. Civ. Code Section 1798.150 (private right of action for data breaches)
Last verified: 2026-08-14
Informational, not legal advice.