CCPA Accessibility

The California Consumer Privacy Act (CCPA) gives California residents the right to opt out of the sale and sharing of their personal information, and it obligates your website to make that opt-out visible, easy, and functional. It is a notice-and-opt-out model, not an opt-in model: tracking may run, but the visitor must be told and must be able to stop it, including through a Global Privacy Control signal.

The CCPA is the regulatory side of California law, actively enforced by a dedicated agency. It sits alongside GDPR and CIPA within website privacy compliance.

CCPA website obligations at a glance
Key Point What It Means for You
Opt-out model Tracking may run by default, but California residents must be able to stop the sale and sharing of their data.
Do Not Sell or Share A clear link or mechanism on your site, and it has to actually work.
Global Privacy Control Browser-based opt-out signals must be honored automatically, without extra steps.
Symmetry of choice Opting out cannot be harder than opting in. Asymmetric interfaces are a violation.
Active enforcement A dedicated regulator investigates and penalizes, and cookie tools have been examined in its orders.

What does the CCPA require from your website?

The CCPA applies to for-profit businesses that collect Californians’ personal information and meet at least one threshold: annual gross revenue above $25 million, personal information of 100,000 or more consumers or households, or half of revenue derived from selling or sharing personal information. If it applies to you, your website must provide:

  • Notice at collection. Tell visitors what personal information you collect and why, at or before the point of collection
  • A Do Not Sell or Share mechanism. “Sharing” includes disclosing data for cross-context behavioral advertising, which is what most advertising pixels do. If pixels like the Meta Pixel send visitor data to ad platforms, you are likely sharing
  • Automatic honoring of Global Privacy Control. GPC is a browser signal expressing the opt-out. It must be treated as a valid request without making the visitor do anything more
  • Symmetry of choice. The path to decline or opt out cannot require more steps than the path to accept
  • An accurate privacy policy. Your policy must reflect the tracking actually in use and the rights available, updated as your practices change
  • A working result. After the opt-out, the sale and sharing must actually stop, which is a technical outcome you can verify, not a legal formality

What does CCPA enforcement look like?

The California Privacy Protection Agency investigates and issues orders, and the Attorney General enforces as well. Cookie consent tooling has already featured directly in enforcement. In one order, the agency penalized American Honda $632,500, and among its findings, the order examined Honda’s cookie management interface and the asymmetry between accepting and declining tracking. The lesson generalizes: installing a consent tool is not the obligation. Configuring it so the opt-out is easy and effective is the obligation, and regulators are reading the configuration.

Private lawsuits under the CCPA itself are limited to certain data breaches, with statutory damages of $100 to $750 per consumer per incident. Website tracking lawsuits by private plaintiffs mostly travel under a different statute, covered on our CIPA page, and the two arrive together in demand letters often enough that they should be addressed together.

How does the CCPA differ from GDPR and CIPA?

  • GDPR is opt-in. Non-essential tracking stays blocked until EU and UK visitors agree. Details on our GDPR cookie consent page
  • CCPA is notice and opt-out. Tracking may run, but Californians must be able to stop the sale and sharing, including via GPC
  • CIPA is timing-based litigation. Private claims over tracking that fires before any consent, with statutory damages per violation

A site with European and Californian visitors needs both behaviors, served to the right people: opt-in blocking for the EU and UK, plus a functioning opt-out and GPC honoring for California. One consent implementation has to do both correctly.

Why is an inaccessible opt-out a CCPA problem?

The CCPA’s promise is a right the consumer can exercise. An opt-out link that keyboard users cannot reach, a preference center that screen readers cannot navigate, or a toggle with no accessible name is a right that some Californians cannot exercise at all. For those visitors, the business never honored the request because the visitor could never make it.

The symmetry requirement sharpens this. Regulators already treat an opt-out that takes more steps than acceptance as a violation. An opt-out that is unreachable for a disabled visitor is not merely harder. It is impossible, which is the extreme end of the same asymmetry. A consent interface that conforms to WCAG 2.1 AA and WCAG 2.2 AA, keyboard operable with proper announcements, focus management, and contrast, is what makes the opt-out real for every visitor. Implementation specifics are on our cookie banner page.

What are the essentials for CCPA compliance?

  1. Inventory your tracking and identify what constitutes selling or sharing, especially advertising pixels
  2. Add the Do Not Sell or Share mechanism and notice at collection
  3. Honor GPC signals automatically for California visitors
  4. Make declining as easy as accepting, in steps and in presentation
  5. Confirm the opt-out interface conforms to WCAG 2.1 AA as rendered on your site
  6. Verify with testing that tracking tied to sale and sharing actually stops after the opt-out and under GPC
  7. Update your privacy policy to match, and keep records of requests honored

How do the app and services address CCPA obligations?

The app

Our consent app, available for Shopify, WordPress, and as a general script for all other sites, serves California visitors the opt-out experience the CCPA requires: a Do Not Sell or Share mechanism, automatic GPC honoring, and symmetric choices where declining takes no more effort than accepting. When a visitor opts out, the app stops the associated tracking scripts rather than only recording a preference, and it logs each request so you can prove it was honored. The interface conforms to WCAG 2.1 AA and WCAG 2.2 AA, so the right is exercisable by every visitor.

The services

We implement the setup on your site and conduct manual verification testing of the outcomes the CCPA measures: what transmits to advertising platforms before and after the opt-out, whether GPC is honored without extra steps, and whether the opt-out is operable by keyboard and screen reader as rendered in your theme. The testing is recorded, dated, and preserved. We also provide privacy policy language that accurately reflects your practices and guidance for keeping the opt-out effective as your tags change.

Frequently asked questions

Does the CCPA require a cookie banner?

Not by name. It requires notice, a working opt-out, and GPC honoring. A banner and preference center are the common way to deliver those, which is why the banner’s function and accessibility matter.

Do advertising pixels count as selling or sharing?

Usually. Sharing includes disclosing personal information for cross-context behavioral advertising, and that is precisely what advertising pixels transmit. If pixels run, plan on providing the opt-out.

Do I have to honor Global Privacy Control?

Yes. California treats GPC as a valid opt-out request, and enforcement has targeted businesses that ignored it. Honoring it must be automatic.

Can individuals sue my website under the CCPA?

Only for certain data breaches involving their information. Website tracking claims from private plaintiffs generally arrive under CIPA instead, which is why the two are best addressed as one project.

Where to start

  1. Determine whether the CCPA’s thresholds cover your business
  2. Inventory tracking and identify your sale and sharing, starting with pixels
  3. Implement the Do Not Sell or Share mechanism with GPC honoring and symmetric choices
  4. Confirm the opt-out conforms to WCAG 2.1 AA as rendered on your site
  5. Verify with recorded testing that opting out actually stops the sharing, and preserve the evidence

Sign up for Accessibility Tracker

New platform has real AI. Tracking and fixing accessibility issues is now much easier.

Kris Rivenburgh, Founder of Accessible.org holding his new Published Book.

Kris Rivenburgh

I've helped thousands of people around the world with accessibility and compliance. You can learn everything in 1 hour with my book (on Amazon).