Understanding the California Consumer Privacy Act (CCPA)

Jun 29, 2026 | 6 minute read
Reading Time: 6 minutes

The California Consumer Privacy Act (CCPA) (as amended by the California Privacy Rights Act, or CPRA) sets strict rules for how businesses collect and use personal information from California residents, and Visual Visitor offers visitor‑identification and analytics tools that are designed to operate within those rules when configured correctly.

What CCPA Is

The CCPA is a California privacy law, effective January 1, 2020, that gives residents more control over the personal information businesses collect about them. It applies to for‑profit entities doing business in California that collect, share, or sell Californians’ personal information and meet certain revenue or data‑volume thresholds.

Under CCPA, “personal information” is broadly defined as any information that identifies, relates to, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This can include obvious identifiers like names and emails, but also IP addresses, browsing history, and records of how someone interacts with a website or advertisement.

Key Consumer Rights Under CCPA

CCPA groups consumer rights into several core categories that every covered business needs to support, including on its websites and other channels that collect personal information from California residents.

  • Right to know: Consumers can request details about what personal information a business collects, uses, sells, or shares, and for what purposes.
  • Right to delete: Consumers can request deletion of personal information a business has collected, subject to certain exceptions.
  • Right to opt out of sale/share: Consumers must be able to opt out of the sale or sharing of their personal information, typically via a “Do Not Sell or Share My Personal Information” mechanism.
  • Right to non‑discrimination: Businesses cannot deny services, charge different prices, or otherwise discriminate against consumers for exercising their CCPA rights.
  • Additional rights under CPRA amendments: In certain cases, consumers also have the right to correct inaccurate personal information and to limit the use and disclosure of sensitive personal information.

To support these rights, businesses must provide clear privacy notices and easy ways for users to submit requests and manage their choices.

CCPA Requirements for Websites

For website owners, CCPA translates into practical obligations that need to be reflected in your policies, interfaces, and processes.

  • Transparent privacy policy: You must maintain a privacy policy that explains what data you collect, how you use it, what you share or sell, and how consumers can exercise their rights. This policy should be easily accessible, often via a conspicuous link in your footer or main navigation.
  • Cookie and tracking disclosures: Websites should disclose what cookies and similar technologies they use, what categories of data they collect (e.g., IP address, browsing activity, geolocation), and for what purposes.
  • Opt‑out and preference mechanisms: You need user‑friendly interfaces for opting out of the sale or sharing of personal information and, where appropriate, for managing cookie and tracking preferences—especially for activity that could be deemed a “sale” or “sharing” of data.
  • Internal data controls: CCPA‑compliant businesses maintain a data inventory, rights‑handling procedures, and security measures to respond to access/deletion requests and to protect collected data.

These requirements apply whether you collect data directly or through third‑party tools like visitor identification or analytics platforms.

What Visual Visitor Does

At Visual Visitor, we identify website visitors to help sales and marketing teams generate and qualify leads. Our services can capture data such as IP addresses, user agents, current URLs, referrers, and visit activity to infer company details or, in some offerings, person‑level information.

Our script typically collects:

  • IP address, user agent, referrer, current URL, page title, and display resolution for analytics and optimization.
  • Cookie‑based data, including session information and preferences, for personalization and tracking.

For some products, we process hashed email data and suppression lists provided by customers, using secure methods such as SHA‑256 hashing to avoid storing plain‑text emails. This data is handled with encryption in transit (TLS 1.2/1.3) and at rest (AES‑256), and access is controlled using role‑based access control and multi‑factor authentication where available.

How Visual Visitor Approaches CCPA

We implement measures aimed at aligning with CCPA and other privacy regulations. While each website owner remains responsible for compliance, the platform is built to support key requirements:

  • Notice and preference handling: We support cookie and tracking banners that inform visitors about data collection and allow them to manage certain preferences. When a visitor declines specific categories of tracking in the banner, tracked data for that visitor is not used for those purposes, which helps respect user choices and data‑minimization principles.
  • Data subject rights support: We have processes in place for handling data subject requests—such as access, correction of inaccurate information, and deletion—and confirm that deletion requests are logged, processed across active systems, and reconciled with backups to prevent re‑appearance of deleted data.
  • Opt‑out mechanisms: We also provide opt‑out options and documentation for customers to implement consumer opt‑outs, which are necessary for CCPA’s “Do Not Sell or Share My Personal Information” requirements when applicable.

Data Security and Governance in Visual Visitor

CCPA requires “reasonable security procedures and practices” to protect personal information, and our technical controls are part of how our customers can meet this standard.

Key elements of our security documentation include:

  • Encryption: TLS 1.2/1.3 for data in transit and AES‑256 encryption for sensitive data at rest, including IP addresses and hashed email data.
  • Key management: Keys generated within FIPS 140‑2 compliant cryptographic modules, stored in secure vaults, backed up securely, and rotated according to a formal cryptographic key‑management policy.
  • Access control: Role‑based access control, unique user IDs, multi‑factor authentication for remote access where available, and regular reviews (annual, with 90‑day checks) of user access rights.
  • Incident response: We have a documented incident‑response plan that includes incident identification, containment, evidence collection, notification of customers and regulators when required, and ongoing improvements.

For website owners, these practices matter because CCPA provides a private right of action in certain data‑breach scenarios where nonencrypted and nonredacted personal information is exposed due to a failure to implement reasonable security procedures and practices.

Data Retention and Deletion

Our data‑retention policy is structured to limit how long visitor and customer data is kept, which is relevant to CCPA’s focus on data minimization and deletion rights.

  • Online storage: Visitor data is stored in active systems for one year to support analytics and business needs.
  • Backup storage: After one year, data moves into secure backup storage for another year, after which it is permanently deleted.

When a client or user requests deletion, we log that request, use automated systems to remove the data from active repositories, and flag it so backup restorations do not reintroduce deleted records. This helps customers honor CCPA deletion requests in practice.

Your Responsibilities When Using Visual Visitor

While we provide tools and infrastructure that can be used in a CCPA‑compliant way, the legal responsibility for compliance rests with your business. If you install Visual Visitor on your or a client’s website, you should:

  • Update your privacy policy: Clearly describe Visual Visitor’s role in collecting visitor data (such as IP addresses, cookie data, and visit activity), the categories of personal information involved, and your business purposes for using it (analytics, lead generation, personalization).
  • Implement opt‑out and preference flows: Ensure your “Do Not Sell or Share My Personal Information” mechanisms and any cookie/tracking banner work correctly with Visual Visitor, including disabling non‑essential tracking when users decline relevant categories or opt out of sale/share.
  • Configure retention and deletion: Align your internal data‑retention timelines and deletion processes with our one‑year online and one‑year backup storage, and establish clear channels for users to submit access and deletion requests.
  • Review service‑provider agreements: Treat Visual Visitor as a CCPA “service provider” or “contractor,” as appropriate, and maintain a written agreement that defines each party’s roles and obligations under CCPA, including limits on how personal information may be used and prohibitions on selling or sharing that data for our own purposes.

By combining our built‑in privacy and security features with a robust privacy program on your side, you can use visitor‑identification data to grow your business while respecting CCPA rights.

 

CCPA FAQs

Q: What businesses are required to comply with CCPA?

A: CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds: annual gross revenue over $25 million, buying/selling/sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information.

Q: What counts as “personal information” under CCPA?

A: Personal information includes any data that identifies, relates to, or could reasonably be linked to a consumer or household. This includes names and emails, as well as IP addresses, browsing behavior, geolocation data, and interactions with websites or ads.

Q: What rights do California consumers have under CCPA?

A: Consumers have the right to know what data is collected and how it is used, request deletion of their data, opt out of the sale or sharing of personal information, and receive equal service without discrimination. Additional CPRA rights include correcting inaccurate data and limiting use of sensitive personal information.

Q: What are the key CCPA requirements for websites?

A: Websites must provide a clear and accessible privacy policy, disclose cookie and tracking practices, offer a “Do Not Sell or Share My Personal Information” option when applicable, and implement processes for handling consumer data requests such as access and deletion.

Q: How should businesses handle CCPA data requests and retention?

A: Businesses must provide at least two methods for consumers to submit requests, verify the requester’s identity, and respond within required timeframes. They should also maintain data retention policies that limit how long personal information is stored and ensure deleted data is not reintroduced.

4 Ways Website Visitor Tracking Software Works

Did you know that 98% of the visitors to your website simply leave without ever contacting you? We help you identify who these visitors are in real-time. Sign Up Now

Visual Visitor Knows Who is
Visiting Your Website. Do You?

Start Your 14-day Free Trial

Sign Up Now