What is CCPA and CPRA?
The California Consumer Privacy Act, expanded by the California Privacy Rights Act, gives California residents rights to know about, delete and opt out of the sale or sharing of their personal information. Unlike the GDPR it is opt-out by default, and it applies only to businesses meeting revenue or data-volume thresholds.
Explanatory, not legal advice. Whether you are covered, and what you must do, depends on facts specific to your business.
Opt-out, not opt-in
This is the structural difference from the EU model. The GDPR generally requires a lawful basis before processing; CCPA generally permits processing while requiring you to honour a consumer’s request to stop.
The practical consequence is the “Do Not Sell or Share My Personal Information” link, and the requirement to honour the Global Privacy Control signal — a browser-level opt-out that California regulators have confirmed must be respected.
Who it applies to
For-profit businesses doing business in California that meet at least one threshold, broadly: annual gross revenue above $25 million; buying, selling or sharing the personal information of 100,000 or more consumers or households; or deriving 50% or more of annual revenue from selling or sharing personal information.
Small sites frequently fall outside all three. That is worth checking rather than assuming in either direction.
”Sharing” catches more than selling
The CPRA extended the definition beyond selling for money to include sharing for cross-context behavioural advertising. Passing visitor data to an advertising platform for targeting can count as sharing even when no money changes hands, which is what pulls conventional ad-tech analytics into scope.
Analytics that collects no personal information, sends nothing to advertising networks and builds no cross-site profile has nothing to sell or share. sonex is in that position by construction: it collects no personal information, and the geography it reports resolves to country, region and city, never to a person.