skip to content

Enforcement and Penalties

Civil penalties per violation, a limited private right of action when a breach follows poor security, the CPPA's rulemaking authority, and how cure periods work. Interviewers use it to check you know where the financial risk really sits — often in the breach lawsuit rather than the regulator's fine.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

5

Under the CCPA, a company ignored opt-out preference signals for a year — what fine or penalty can each violation carry?

level: middleimportance: must knowfreq 48%

answer

  1. priced per violation, not per percent
  2. two tiers
  3. intent or known under-16 data
  4. statutory base, then CPI-adjusted
  5. January 2025, then every odd year

basics

~20 s

Under the CCPA, each violation carries up to $2,663, or $7,988 if intentional or involving consumers known to be under 16 (the CPPA's 2025 CPI adjustment), as an agency fine (1798.155(a)) or an Attorney General civil penalty (1798.199.90(a)), never both.

solid answer

~40 s

The statute prices violations one at a time. Civil Code 1798.155(a) (CPPA administrative fines) and 1798.199.90(a) (Attorney General civil penalties) both set a ceiling of **$2,500 per violation** and **$7,500 per intentional violation** or violation involving minors' personal information, **as adjusted** under 1798.199.95(d). The CPPA's CPI adjustment effective **2025-01-01** raised those to **$2,663** and **$7,988**. They are maximums: the agency or court considers **good-faith cooperation** (1798.199.100), and one violation cannot draw both a fine and a penalty. The statute does not say how violations are counted, so a year of ignored signals is priced by however many violations the agency or court finds, and whether they were **intentional** is a finding of fact. Beyond money, the agency can order the business to **cease and desist** and the Attorney General can seek an **injunction**.

go deeper

for a junior

Recall that the CCPA prices each violation, with a higher tier for intentional violations and minors' data, and that the amounts are CPI-adjusted.

for a middle

Explain the 2025 figures against the statutory base, how the odd-year adjustment works, and why a fine and a penalty never stack for one violation.

for a senior

Size exposure as a range, making clear the violation count is the open variable and intent is a finding of fact.

for a principal

Use the per-violation model to prioritise remediation, fixing systemic failures that multiply violations before one-off defects.

## Two ceilings per violation The CCPA as amended by the CPRA does not fine a percentage of revenue. It sets a **maximum amount per violation**, the same for the California Privacy Protection Agency's administrative fines and for the Attorney General's civil penalties. | Tier | Statutory text | 2025 CPI-adjusted amount | Sources | |---|---|---|---| | Each violation | not more than $2,500 | not more than **$2,663** | 1798.155(a); 1798.199.90(a) | | Each intentional violation, or violation involving minors' data | not more than $7,500 | not more than **$7,988** | 1798.155(a); 1798.199.90(a) | Both sections say the amounts are *as adjusted pursuant to subdivision (d) of Section 1798.199.95*, so the numbers printed in the statute are the base, not the current ceiling. When you quote a figure, say which one it is: the statutory base, or the amount as adjusted by the agency on 2025-01-01. ## How the CPI adjustment works Civil Code **1798.199.95(d)** tells the agency to adjust these amounts, along with the revenue threshold in the definition of a business and the breach statutory damages range: 1. On **January 1, 2025**, and on January 1 of **every odd-numbered year** after that. 2. Using the California Consumer Price Index percentage change over the previous two years, August to August, rounded to the nearest whole dollar. 3. Posted on the agency's website no later than **January 15** of the year the adjustment takes effect. 4. **Without** an Administrative Procedure Act rulemaking; the adjustment is automatic by statute (1798.199.95(d)(4)). The agency's announcement for 2025 raised the administrative fine and civil penalty ceilings from $2,500 and $7,500 to $2,663 and $7,988. ## What moves a violation into the higher tier - **Intent.** An *intentional* violation carries the higher ceiling. Whether conduct was intentional is decided on the facts, for example whether the business knew the signal arrived and chose not to act. - **Minors' data.** 1798.155(a) applies the higher tier to violations involving the personal information of consumers the violator has **actual knowledge are under 16**; 1798.199.90(a) and 1798.199.55(a)(2) phrase it as violations involving the personal information of **minor consumers**. ## Sizing the exposure for a year of ignored signals The statute prices **each violation** but does not define how violations are counted, whether per consumer, per signal, per day or per practice. So the honest way to size exposure is as a range, not a single number: - If an enforcer counted, say, 1,000 violations at the base tier, the ceiling would be 1,000 x $2,663 = **$2,663,000**. - If those violations were found intentional, the same count at $7,988 is **$7,988,000**. - The actual amount is set at or below the ceiling by the agency or the court, both of which must consider good-faith cooperation (1798.199.100; 1798.199.90(a) repeats the point for the court). These are illustrative arithmetic, not a prediction; the count is the variable the statute leaves open. ## Money is not the only remedy 1. The CPPA's order can require the business to **cease and desist** (1798.199.55(a)(1)). 2. The Attorney General can obtain an **injunction** (1798.199.90(a)). 3. If two or more persons are responsible, they are **jointly and severally liable** for an agency fine (1798.199.55(b)). 4. The agency has **five years** from the violation to commence an administrative action, tolled during fraudulent concealment (1798.199.70). One violation still draws only one payment: a business cannot be required to pay both an administrative fine and a civil penalty for the same violation (1798.199.100). ## Reading the figures correctly A figure without a date is a trap on this statute. Three habits keep quoted amounts honest: - Say whether a number is the **statutory base** ($2,500 / $7,500) or the **adjusted ceiling** ($2,663 / $7,988 from 2025-01-01). - Expect the next adjustment on **2027-01-01**; any internal risk register that hard-codes today's figure will go stale. - Keep the tiers attached to their conditions: the higher ceiling needs intent or minors' data, not merely a large incident. The same odd-year mechanism also moves the breach statutory damages range, so the private-lawsuit figures change on the same dates. ## Common misconceptions - Quoting $2,500 and $7,500 as today's ceilings without saying they are the pre-adjustment base. - Treating the amounts as minimums the enforcer must impose. - Assuming the higher tier covers any data about a young person, rather than the statute's own conditions.

  • Under the CCPA, does the agency need a formal rulemaking to raise the fine amounts for inflation?
    No. Civil Code 1798.199.95(d)(4) says the adjustments and their publication are **not subject to** the Administrative Procedure Act's rulemaking provisions. The agency applies the California CPI change for the prior two years, rounds to the nearest dollar, and posts the new amounts by January 15 of the year they take effect.
  • Under the CCPA, what does an enforcer weigh in setting the amount below the ceiling?
    Civil Code 1798.199.100 requires the agency and any court to consider the business's **good-faith cooperation**. When deciding whether to investigate at all, 11 CCR 7301(b) lets the agency weigh good-faith efforts to comply and the time since the requirement took effect.

saying these in an interview costs you the question

  • CCPA fines are still capped at $2,500 and $7,500 with no adjustment.
  • CCPA fines are a percentage of the company's global annual revenue.
  • The per-violation figure is a minimum the enforcer must impose.
  • Adjusted amounts apply only after the CPPA completes a formal rulemaking.
  • Good-faith cooperation cannot lower a CCPA fine or penalty.
open as a page

Under the CCPA, an unencrypted database breach exposes California residents' names, email addresses and passwords — can they sue, and for what damages?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Under the CCPA, yes if specified unencrypted data, or an email plus a password permitting account access, was stolen or disclosed because security was unreasonable: $107-$799 per consumer per incident (2025 adjustment) or actual damages (Civil Code 1798.150).

open as a page

Under the CCPA as amended by the CPRA, who enforces the law, and how do the CPPA and the Attorney General divide the work?

level: juniorimportance: should knowfreq 42%

basics

~20 s

Under the CCPA as amended by the CPRA, the California Privacy Protection Agency enforces through administrative actions and fines, the Attorney General through civil suits for penalties and injunctions, and consumers sue only over certain security breaches (Civil Code 1798.155, 1798.199.90, 1798.150).

open as a page

Under the CCPA as amended by the CPRA, a startup asks whether it gets 30 days to fix a violation — does it?

level: middleimportance: should knowfreq 36%

basics

~20 s

Under the CCPA as amended by the CPRA, not as of right: the Attorney General's mandatory 30-day cure is gone, the CPPA may offer time to cure at its discretion (1798.199.45), and only the breach lawsuit keeps a 30-day notice-and-cure (1798.150(b)).

open as a page

Under the CCPA, what steps must the CPPA take before it can order a business to pay an administrative fine?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

Under the CCPA, the CPPA investigates on a complaint or its own initiative, serves notice at least 30 days before deciding probable cause, then holds an Administrative Procedure Act hearing and orders any fine, unless the parties agree a stipulated order (1798.199.45-1798.199.55).

open as a page