CCPA Penalties for Non Compliance: 2026 Fines and Amounts
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
As of 2026, CCPA penalties are $2,663 per violation and $7,988 per intentional violation or any violation involving a consumer the business knows is under 16. Those are not the $2,500 and $7,500 figures in the original statute. The California Privacy Protection Agency adjusts them for inflation every odd-numbered January, and the current amounts took effect January 1, 2025. Penalties are assessed per violation and counted per affected consumer, which is why a systematic failure to honor data subject requests costs orders of magnitude more than a single late response.
How much is a CCPA fine in 2026?
There are two separate money exposures under the CCPA, and people mix them up constantly. Administrative fines under Civil Code section 1798.155 are what a regulator assesses. Statutory damages under section 1798.150 are what a consumer can recover in a private lawsuit, and only after a specific kind of data breach. Both numbers are inflation-adjusted.
| What | Statutory baseline | Amount in 2026 | Who collects it |
|---|---|---|---|
| Administrative fine, unintentional violation | $2,500 | $2,663 | California AG or CPPA |
| Administrative fine, intentional violation or minor under 16 | $7,500 | $7,988 | California AG or CPPA |
| Private statutory damages, per consumer per breach incident | $100 to $750 | $107 to $799 | The consumer, in a civil suit |
| Business applicability revenue threshold | $25,000,000 | $26,625,000 | Not a penalty, but adjusted the same way |
The adjustment mechanism is worth understanding because it means any article quoting $2,500 and $7,500 is out of date. The CPPA recalculates in January of every odd-numbered year using the California Consumer Price Index change published by the Department of Industrial Relations, measured August to August across the prior two years. The values above took effect January 1, 2025 and hold through 2026. The next revision lands in January 2027.
What are the penalties for violating the CCPA?
Mishandling a consumer request is the exposure most privacy teams underestimate, because it is quiet. Nobody issues a press release when you miss a 45-day deadline. But each of these is a countable violation:
- Failing to respond to a verifiable request to know, delete, or correct within 45 calendar days, or taking the 45-day extension without notifying the consumer.
- Failing to acknowledge receipt of a request within 10 business days, which is a separate CCPA obligation from the 45-day response.
- Responding but omitting categories of personal information you actually hold, usually because a system was never inventoried.
- Deleting from your primary database but not from your service providers, backups, or downstream tools.
- Continuing to sell or share data after an opt-out, including ignoring a Global Privacy Control signal.
- Requiring an account, a fee, or excessive identity documentation as a condition of exercising a right.
- Retaliating against a consumer for exercising a right, which is the non-discrimination provision.
The multiplier is the whole story. A single missed request at $2,663 is a rounding error for most businesses. The same process gap applied across 4,000 requests is over $10 million in theoretical exposure before anyone argues about intent. Regulators have shown they will count that way.
CCPA enforcement actions in 2026
California regulators moved harder in the first quarter of 2026 than in any comparable period before it, with more than $4 million in publicly announced penalties across three actions.
| Company | Penalty | Enforcing body | When |
|---|---|---|---|
| Disney | $2,750,000 | California Attorney General | February 2026 |
| PlayOn Sports | $1,100,000 | California Privacy Protection Agency | March 2026 |
| Ford Motor Company | $375,703 | California Privacy Protection Agency | March 2026 |
Two things stand out. First, the CPPA is now bringing its own actions rather than leaving everything to the attorney general, so there are two independent enforcers with the same penalty authority. Second, the amounts are settlements built from per-consumer counts, not headline numbers picked for effect. That is the arithmetic to keep in mind when you weigh a process fix against the cost of doing nothing.
Does the CCPA still have a 30-day cure period?
No. The original CCPA required a regulator to give a business 30 days to fix an alleged violation before enforcing. The CPRA removed that mandatory cure period effective January 1, 2023. A regulator may still consider whether you cured a problem, and good faith remedial effort can affect the outcome, but you have no right to a warning. The first missed deadline can be the violation rather than the notice. California was early to this, and most other states have followed; we track where each one stands in the state privacy law cure period breakdown.
Can consumers sue for CCPA violations?
Only in one narrow situation. California is the only state with a private right of action under its comprehensive privacy law, and it is limited to breaches of unencrypted and unredacted personal information caused by a failure to maintain reasonable security. It does not cover request handling. A consumer cannot sue you because you answered their access request late. They can recover $107 to $799 per incident, or actual damages if higher, when their data leaks through a security failure, and the consumer must first give you written notice and 30 days to cure, though that cure right does not apply to claims for actual damages.
What are the penalties under the California Delete Act?
The Delete Act runs on a separate and harsher arithmetic, and it applies only to data brokers. Failing to register by January 31 costs $200 for each day you are unregistered, plus the agency's expenses in the investigation and administrative action. Failing to process a deletion request costs $200 per deletion request per day, which multiplies rather than accumulates: one batch of a thousand unprocessed requests left for a month is a very different number from a single late response.
This stopped being theoretical in 2026. On January 8, 2026 the California Privacy Protection Agency announced two settlements the same day, both for the registration failure alone: Rickenbacher Data LLC, doing business as Datamasters, paid $42,000, and S&P Global, Inc. paid $62,000 after 313 days off the registry. Neither case required a consumer to have been harmed. The deletion exposure switches on next: from August 1, 2026 every registered broker must access the state's DROP platform at least once every 45 days and act on what it finds. We cover the mechanics in the California Delete Act compliance guide and the four-state filing duties in data broker registration requirements.
State privacy law penalties by state in 2026
Twenty states have a comprehensive consumer privacy law in effect in 2026. Most cap civil penalties at $7,500 per violation, but the spread is wider than people expect: Connecticut is the cheapest per violation at $5,000, and Florida is thirty times that. Positions below reflect July 2026. Statutes move, so confirm against the current text before relying on a single row.
| State | Law | Maximum civil penalty per violation |
|---|---|---|
| California | CCPA/CPRA | $2,663, or $7,988 intentional or involving a minor under 16 |
| Florida | FDBR | $50,000, tripling to $150,000 for child, deletion, or opt-out violations |
| Maryland | MODPA | $10,000, rising to $25,000 for repeated violations |
| New Jersey | NJDPA | $10,000 first violation, $20,000 subsequent |
| Colorado | CPA | $20,000 |
| Tennessee | TIPA | $7,500, trebling to $22,500 for willful or knowing violations |
| Delaware | DPDPA | $10,000 |
| New Hampshire | NHPA | $10,000 |
| Rhode Island | RIDTPPA | $10,000 |
| Connecticut | CTDPA | $5,000 |
| Virginia | VCDPA | $7,500 |
| Texas | TDPSA | $7,500 |
| Utah | UCPA | $7,500 |
| Oregon | OCPA | $7,500 |
| Montana | MCDPA | $7,500 |
| Iowa | ICDPA | $7,500 |
| Nebraska | NDPA | $7,500 |
| Minnesota | MCDPA | $7,500 |
| Indiana | ICDPA | $7,500 |
| Kentucky | KCDPA | $7,500 |
Read that table alongside two others before you decide where your real risk sits. A high penalty ceiling with a permanent cure period is often less dangerous than a modest ceiling with no cure right at all, and the states differ sharply on both. The applicability thresholds by state tell you which of these laws reach you in the first place, and the Tennessee Information Protection Act is worth a separate look because it is the only state that lets you assert a documented privacy program as an affirmative defense.
Which is worse, a CCPA fine or a state attorney general action?
For most companies the state action is worse, and not because of the per-violation number. California's enforcers publish their settlements, so you get the penalty plus the press coverage plus, usually, an injunctive term requiring specific process changes under supervision for a period of years. The penalty is a one-time cost. The compliance program you are then ordered to run is a recurring one. That is the pattern in the 2026 settlements: money plus mandated operational change.
How do you reduce CCPA penalty exposure?
Penalties attach to process failures, so the fix is process. Four things move the needle more than anything else:
Know every system that holds personal information. Most incomplete responses are not lies, they are blind spots. The help desk, the marketing automation tool, the data warehouse, the analytics platform, and the six spreadsheets in a shared drive all count. If you cannot enumerate them, you cannot answer an access request completely, and an incomplete response to a verifiable request is a violation on its own.
Put a clock on intake, not on memory. The 10-business-day acknowledgment and the 45-day response are separate obligations with separate deadlines. Tracking them in an inbox is how backlogs form. Our deadline breakdown by state lays out how the clocks differ once you operate in more than one state.
Close the loop downstream. Deletion is the request type most likely to produce a technically false response, because the record leaves your database and stays in a service provider, a backup, and an export somewhere. Deletion is not done until it has propagated, which is the operational gap we cover in the comparison of access and deletion requests.
Keep evidence, not just intent. When a regulator asks how you handled requests, a policy PDF is weak and a per-request audit trail is strong. Before you can prove a program works you usually need an honest read on how mature your internal processes actually are, because the gap between the documented workflow and the one people follow is where violations live.
What does Obtainer do about this
Obtainer is built for the operational half of the problem, which is where the penalties come from. It intakes a request, verifies the requester, finds where that person's personal data actually lives across your CRM, warehouse, help desk, billing system, and files, compiles it into one reviewable source-system manifest, drafts a deadline-safe response from templates, and tracks the CCPA 45-day clock and the GDPR one-month clock per request. Every step leaves a timestamped record of what was searched, what was found, who reviewed it, and what was redacted.
Nothing is disclosed or erased automatically. A human reviews, redacts, and approves before anything ships, because deletion cannot be undone and a bad disclosure cannot be recalled. You can start self-serve from $49/mo with our CCPA compliance software, and see the underlying capability in data discovery across systems.
One boundary worth stating plainly: Obtainer helps you comply, and it is not legal advice. Whether a specific violation is intentional, whether an exemption applies, and how to respond to a regulator are calls for your team and your counsel. What software can do is make sure the request was found, searched completely, answered on time, and documented, which is the part that turns into penalties when it goes wrong.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.