CCPA – The Hebrew Guide to the California Consumer Privacy Act
Guides
25 August, 2026
Executive Summary: What is the CCPA?
The California Consumer Privacy Act (CCPA) is a landmark data privacy regulation that went into effect on January 1, 2020. It was enacted in response to growing consumer privacy anxieties (such as high-profile data leaks) and aims to give California residents simple, practical control over their personal data.
Crucially, the CCPA features extra-territorial jurisdiction. This means it applies to businesses located anywhere in the world—not just in California—if they do business in California and collect personal data from California residents (even when those residents are temporarily located outside the state).
Aligning your operations with the CCPA, even if compliance is technically borderline or voluntary for your business, offers major commercial and strategic advantages:
Future-Proofing: With many other US states actively modeling laws after the CCPA, building this foundation now prepares your business for the evolving regulatory landscape.
Competitive Advantage: Demonstrating active compliance builds brand trust and makes you a highly preferred partner for enterprises demanding clean data governance.
Risk Mitigation: Integrating compliance into your corporate risk registry significantly reduces exposure to devastating private class-action lawsuits and state regulatory fines.
Key Entities: Who is Affected?
The framework applies broadly to any organization deploying generative AI, affecting several key internal and external roles:
- Personnel & Employees: All staff members using AI tools must understand their capabilities and limitations, follow clear usage boundaries, and be held accountable for safe deployment.
- Customer Support & Marketing Teams: Support teams must be trained to verify facts internally before sharing AI-generated answers with customers, while marketing teams must run "privacy by design" checks to protect individual data.
- Business Partners & Investors: You must review agreements with business partners to balance responsibilities, and properly disclose AI use to investors in your representations, warranties, and disclosure schedules.
(Note: The source text does not detail any vendor-specific exemptions, such as distinguishing standard cloud storage vendors from simple transport "conduits.")
Key Entities: Who is Affected?
The CCPA defines several primary roles. Knowing where your business and your vendors fit is crucial to executing the proper compliance steps:
| Role / Entity | Key Definition | Crucial Rules & Restrictions |
|---|---|---|
| Business | A for-profit legal entity that collects CA consumers’ data, determines processing purposes, and meets specific thresholds. | Must comply with all CCPA obligations, including disclosures, identity checks, and rights requests. |
| Service Provider | A legal entity that processes personal data on behalf of a Business under a written agreement. | Prohibited from retaining, using, or disclosing personal data for any purpose other than performing services in the contract. |
| Third Party | Any entity that is neither the primary Business nor a Service Provider. | Sharing data with them legally constitutes a ‘Sale’ under the CCPA unless a specific exemption applies. |
| Data Broker | A business that collects and sells data of consumers with whom they have no direct relationship. | Must register annually with the California Attorney General by January 31st each year. |
| תפקיד / ישות | הגדרת מפתח | כללים ומגבלות קריטיים |
|---|---|---|
| עסק (Business): | ישות משפטית למטרות רווח שאוספת נתונים של צרכנים מקליפורניה, קובעת את מטרות העיבוד ועומדת בספי רף ספציפיים. | חייב לעמוד בכל חובות ה-CCPA, לרבות גילויים נאותים, בדיקות זהות ובקשות למימוש זכויות. |
| ספק שירות (Service Provider) | ישות משפטית המעבדת נתונים אישיים בשמו של "עסק" תחת הסכם בכתב. | נאסר עליו לשמור, להשתמש או לחשוף נתונים אישיים לכל מטרה מלבד ביצוע השירותים המפורטים בחוזה. |
| צד שלישי (Third Party) | כל ישות שאינה ה"עסק" העיקרי או "ספק שירות". | שיתוף נתונים עמם מהווה מבחינה חוקית 'מכירה' (Sale) תחת ה-CCPA, אלא אם חל פטור ספציפי. |
| ברוקר נתונים (Data Broker) | עסק שאוסף ומוכר נתונים של צרכנים שאין לו עמם קשר ישיר. | חייב להירשם מדי שנה אצל התובע הכללי של קליפורניה עד ה-31 בינואר בכל שנה. |
Crucial Exemptions & Edge Cases
The CCPA provides complete or partial exemptions for specific types of data already governed by other federal or state frameworks:
- Medical and Health Information: Data protected under medical confidentiality laws or HIPAA, as well as data collected during clinical trials, is exempt.
- Financial Sector: Data governed by the Gramm-Leach-Bliley Act (GLBA) or Fair Credit Reporting Act (FCRA) is exempt from most consumer rights.
- Driver’s Privacy: Personal data covered by the Driver’s Privacy Protection Act (DPPA) is exempt.
- Employment & B2B Data (Expired Exemption): The CCPA originally exempted the personal information of job applicants, employees, and contractors—as well as most business-to-business contacts—from consumer rights requests when used within those relationships. This was only a temporary exemption: it expired on January 1, 2023 under the CPRA. Employee and B2B data is now fully subject to consumer rights, so businesses must extend their notices and rights workflows (access, deletion, correction, and opt-out) to these individuals.
- Out-of-State Activity: The CCPA does not apply if all commercial activity, collection, and storage occur entirely outside of California.
- Vehicle Warranties: Dealers and manufacturers can share vehicle ownership data for warranty repairs or recalls without triggering ‘sale’ opt-out rules.
The Core Pillars of the CCPA
The entire regulation rests upon three essential principles that restore transparency and control to the consumer:
- 1. Absolute Transparency: Businesses must inform consumers—at or before collection—exactly what categories of data are gathered and the precise purposes for which they are used.
- 2. Active Consumer Control: Consumers have the right to halt the sale of their personal information (‘opt-out’) or demand that their collected data be deleted permanently.
- 3. Guaranteed Non-Retaliation: Businesses are legally prohibited from discriminating against consumers who exercise their rights. You cannot deny service, lower quality, or charge different prices.
Essential Business Obligations (What You Actually Have to Do)
To establish compliance, your business must put these practical, structural measures in place:
Security Safeguards (Required): Implement and maintain reasonable security procedures and practices appropriate to the sensitivity of the stored data to prevent unauthorized access or breaches.ct legally recognized individual rights.)
Notice at Collection: Display a clear notice before or when collecting data, stating the categories of personal data collected and their specific business purposes.
Annual Privacy Policy Updates: Update your public privacy policy every 12 months to explicitly list the categories of data collected, sold, or shared, and describe consumer rights.
The ‘Do Not Sell’ Homepage Link: If you share or sell personal information for commercial benefit, place a clear link on your website homepage titled ‘Do Not Sell My Personal Information’.
Dual Request Submission Channels: Provide consumers with at least two easy ways to submit access requests. This must include a toll-free telephone number and (if you have a website) a web address.
Mandatory Written Contracts: All agreements with vendors (Service Providers) must include written contracts that strictly prohibit them from selling, keeping, or using personal data for any purpose other than the specific service.
Strict Identity Verification: Establish reasonable procedures to verify a consumer’s identity before deleting or disclosing data. Use verification data solely for the verification process.
Employee and Staff Training: Ensure all employees responsible for handling customer privacy inquiries or compliance are trained on CCPA rules and request workflows.
Response Timelines: Respond to verified requests within 45 days, free of charge. You can extend this once by an additional 45 days if you provide the consumer with a written explanation.
User / Individual Rights
California residents hold powerful, legally enforceable rights over their personal data. Your business must have systems in place to fulfill these requests:
The Right to Non-discrimination: You cannot deny service, reduce quality, or charge different rates for exercising privacy rights. However, you can offer reasonable financial incentives (discounts/loyalty programs) for data collection if transparent and non-coercive.t does not outline specific breach notification timelines, civil penalty tiers, or criminal liabilities for individuals.)
The Right to Know / Access: Consumers can request a free, exportable report detailing the categories and specific pieces of data collected, the sources, the commercial purposes, and third parties shared with.
The Right to Deletion: Consumers can request deletion of data collected from them. You must comply and instruct your Service Providers to do the same, unless one of 9 legal exceptions applies (such as completing transactions, debugging, security, or complying with laws).
The Right to Opt-Out of Sale: Consumers can stop the sale of their personal data at any time. Once they opt out, you must wait at least 12 months before asking for consent again.
Minors’ Opt-In Protection (Under 16): You cannot sell the data of minors under 16 without explicit consent. Minors aged 13-16 must opt in themselves; for children under 13, a parent or guardian must provide consent.
The Right to Non-discrimination: You cannot deny service, reduce quality, or charge different rates for exercising privacy rights. However, you can offer reasonable financial incentives (discounts/loyalty programs) for data collection if transparent and non-coercive.
The Consequences of Non-Compliance
Failing to comply with the CCPA carries severe financial risks through two independent legal channels:
Private Civil Actions (Class-Action Security Lawsuits)
Consumers can file lawsuits ONLY after a security breach where unencrypted or unredacted personal information (SSN, driver’s license, financial account with password, or medical data) is compromised because the business failed to maintain reasonable security safeguards.
- Statutory Damages: Courts can award $100 to $750 per consumer, per incident, or actual damages—whichever is higher. Because violations are counted per affected person (People v. Superior Court of Los Angeles), exposing 1,000 users can instantly trigger up to $750,000 in statutory fines, even with no proven financial loss.
- The 30-Day Right to Cure: Before filing a lawsuit for statutory damages, the consumer must give the business 30 days’ written notice of the specific violation. If the business successfully cures the breach and provides a written commitment to prevent future violations within 30 days, no statutory lawsuit can be filed.
California Attorney General Enforcement
The AG handles general CCPA violations. If a business fails to cure any violation within 30 days of notice, it faces severe civil penalties:
These penalties are assessed on a per-affected-consumer basis, meaning a systematic non-compliant practice affecting thousands of users can quickly lead to business-threatening figures.
Up to $2,500 per violation for any unintentional breach of the CCPA.
Up to $7,500 per violation for any intentional breach of the CCPA.
Practical Next Steps
Aligning your business with the CCPA doesn’t have to be overwhelming. ClearPath recommends this simple, structured path:
Step 1: CCPA Applicability & Threshold Assessment
- Verify if you collect or store personal information of California residents (including customers, website visitors, or employees).
- Check if you meet at least one of the three thresholds: (1) Gross annual revenue over $25,000,000; (2) Annually buy, sell, or share personal data of 50,000+ consumers, households, or devices; or (3) Derive 50% or more of your annual revenue from selling personal data.
Step 2: Gap Analysis
- Data Mapping: Map out exactly where and how your website, apps, and systems collect, store, share, or sell personal information.
- Vendor Audit: Review all third parties and vendors who receive your data, and audit your vendor agreements against strict CCPA Service Provider requirements.
Step 3: Build and Execute Your Plan
- Update website disclosures and publish a compliant online Privacy Policy with required CCPA disclosures.
- Implement a conspicuous ‘Do Not Sell My Personal Information’ link and request submission forms.
- Execute written amendments with Service Providers and incorporate CCPA data risks into your corporate risk registry and insurance coverage.
Strengthen Your CCPA Compliance Strategy
Managing privacy obligations requires more than meeting regulatory requirements. Organizations need practical frameworks that integrate legal, operational, and technological considerations.
ClearPath helps organizations develop CCPA compliance strategies, assess privacy risks, establish governance frameworks, and implement responsible data protection practices aligned with evolving global regulations.
The California Consumer Privacy Act (CCPA) introduced significant privacy obligations for businesses that collect personal information from California residents, giving consumers greater rights and placing new transparency and compliance requirements on organizations.
Recognizing the importance of the CCPA for Israeli companies doing business in California or processing the personal information of California residents, we created this practical Hebrew- guide to help organizations better understand the law and its key requirements.
The guide provides an accessible overview of the key concepts, principles, and obligations under the CCPA, and is designed to help organizations understand how the law may apply to their activities and what its requirements mean in practice.
The guide is intended as a practical starting point for understanding the CCPA and does not replace professional legal advice tailored to the specific circumstances of an organization
Frequently asked questions
Do I need to comply with the CCPA if my business is located outside California?
Yes, the CCPA features extra-territorial jurisdiction, meaning it applies to companies located anywhere in the world if they do business in California and collect personal data from California residents. Unlike some other international privacy frameworks, the CCPA strictly follows the legal residency of the consumer, even when they are temporarily traveling outside the state. Any contract clause attempting to waive or limit these consumer rights is legally void.
How do I know if my business is legally required to comply with the CCPA?
Your for-profit business must comply if it operates in California and meets at least one of three specific statutory thresholds. These thresholds are: having gross annual revenues over $25 million, annually buying, selling, or sharing the personal data of 50,000 or more consumers, households, or devices, or deriving 50% or more of your annual revenue from selling personal data.
What is the difference between a "Business" and a "Service Provider"?
A Business is the primary entity that collects consumer data and decides how and why it will be processed. A Service Provider is an external vendor that processes that data on behalf of the Business under a strict written agreement. To prevent this data sharing from legally qualifying as a “sale,” the contract must explicitly prohibit the Service Provider from retaining, using, or disclosing the data for any purpose other than performing the services specified in the agreement.
What primary rights do California consumers have over their personal data?
Under the law, California consumers are granted the Right to Know (accessing reports on what categories and specific pieces of data a business collects and shares), the Right to Deletion (requesting that their collected data be permanently erased), and the Right to Opt-Out of the sale of their information. Additionally, consumers have the Right to Non-discrimination, meaning businesses cannot deny services, decrease quality, or change prices if a consumer decides to exercise these rights.
Does my website need to display a "Do Not Sell" link?
If your business sells personal information to third parties, you are required to place a clear and conspicuous link on your website homepage and in your privacy policy titled “Do Not Sell My Personal Information”. This link must direct visitors to an opt-out page where they can easily submit their choice without being forced to create a user account.
What are the financial penalties if my business fails to comply?
The California Attorney General handles regulatory enforcement and can assess civil fines of up to $2,500 per unintentional violation and up to $7,500 per intentional violation, which are calculated on a per-affected-consumer basis. Separately, if a business suffers a data breach involving unencrypted personal data because it failed to maintain reasonable security safeguards, consumers can file private civil class actions to recover statutory damages ranging from $100 to $750 per consumer, per incident.