Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

CCPA

California Consumer Privacy Act - A state statute intended to enhance privacy rights and consumer protection for residents of California, USA. Provides consumers with rights to know what personal information is collected, delete personal data, opt-out of data sales, and non-discrimination for exercising privacy rights.

CCPA, the California Consumer Privacy Act, is a state statute that grants California residents rights over the personal information businesses collect about them. Enacted in 2018 and later strengthened by the California Privacy Rights Act (CPRA), it gives consumers the right to know what is collected, to delete it, to opt out of its sale or sharing, and to be free from discrimination for exercising those rights. It is the most influential U.S. state privacy law and a frequent point of comparison with Europe’s GDPR.

  • Right to know - Consumers can request the categories and specific pieces of personal information a business has collected.
  • Right to delete - Consumers can require a business to delete personal information it holds, subject to exceptions.
  • Opt-out of sale or sharing - Businesses must honor a request not to sell or share personal information, including via signals like Global Privacy Control.
  • Non-discrimination - A business may not penalize a consumer for exercising these rights.
  • CPRA expansion - The 2020 amendment added sensitive-data protections and created a dedicated enforcement agency.

For API operators, CCPA is not a wire protocol but a compliance obligation that shapes how personal data moves through an estate. It drives real API surface area—endpoints and workflows for data-access, deletion, and opt-out requests—and it pushes teams to inventory where personal information flows and who it is shared with. Alongside GDPR, it is one of the privacy regimes I weigh when reading an organization’s data-handling maturity, and honoring opt-out signals cleanly is a concrete, checkable marker of that maturity.