CCPA fines and fees: what a violation costs
Three different numbers travel under the phrase “CCPA fees”, and mixing them up is how a business ends up budgeting carefully for the wrong risk. An administrative penalty runs up to $2,500 per violation, or up to $7,500 where the violation is intentional or involves a minor’s personal information — statutory figures that the law provides for adjusting over time. Statutory damages in private litigation run $100 to $750 per consumer per incident, and attach only to certain security breaches. And then there are ordinary fees: what you may charge a consumer, what you may not, and the annual registration fee a data broker pays. The first number is the one everybody quotes. For most small businesses it is the smallest of the three, and this guide ends with the arithmetic that puts them in order.
The three things called “CCPA fees”
Before any figure means anything, it has to be attached to the right mechanism. The three tracks have different triggers, different decision-makers and different orders of magnitude, and a planning conversation that does not separate them will reach a confident wrong answer.
| Track | Published figure | Who decides | What triggers it |
|---|---|---|---|
| Administrative penalty | Up to $2,500 per violation; up to $7,500 if intentional or involving a minor | CPPA (administrative) or Attorney General (civil action) | Any breach of duty: disclosures, opt-outs, requests, contracts |
| Statutory damages | $100–$750 per consumer per incident, or actual damages if greater | A court, in private litigation | Certain breaches of unencrypted personal information caused by unreasonable security |
| Fees you charge or pay | Reasonable cost of an excessive request; a data broker’s annual registration fee | You, within the statute’s limits | Repetitive or unfounded requests; qualifying as a data broker |
Notice that the middle row is the only one tied to a breach, and the top row is the only one that can be triggered by a purely paperwork failure. A business with flawless security and a broken “Do Not Sell or Share” link is exposed on the first track and not the second. A business with immaculate notices and weak encryption is exposed on the second and not the first. Most real exposure sits on one track, not both, and knowing which one you are on tells you whether the fix is a lawyer or an engineer.
Administrative penalties and the multiplier that does the damage
The published amounts look modest, and that is exactly what makes them misleading. The figure is assessed per violation, and a violation is generally counted per affected consumer rather than per defective feature. So the unit price is small and the multiplier is your customer base. One misconfigured preference signal, left in place for a few months, does not produce one violation; it produces as many violations as there were consumers whose choice it quietly discarded.
That structure has a consequence worth stating plainly: the arithmetic ceiling on a single mistake routinely exceeds the entire value of the business that made it. A ceiling with that property is not a forecast of anything. It is a statutory maximum, deliberately set high enough to cover the worst conceivable conduct by the largest conceivable defendant, and it tells a twenty-person company almost nothing about its own exposure.
What narrows the gap is the discretion built into the process. California’s enforcement regulations direct the agency to weigh factors before setting an amount — among them the nature and seriousness of the misconduct, the number of violations, how persistent the failure was, how much time elapsed, whether the business cooperated, and its assets and net worth. Each of those factors pulls a small, quickly remediated failure a long way down from the ceiling. Publicly announced California resolutions in this area have generally settled in the hundreds of thousands of dollars with a compliance programme attached, not at anything approaching the theoretical product.
One structural change is worth knowing about, because businesses still plan around the old rule. The original CCPA gave a 30-day opportunity to cure before the Attorney General could seek penalties. The CPRA amendments removed that automatic entitlement, leaving remediation as something a regulator may offer rather than something you are owed. The official text of the relevant Civil Code sections is published by California Legislative Information, and both the California Privacy Protection Agency and the Attorney General’s privacy pages publish their own enforcement material. None of this is legal advice, and how any of it applies to your particular facts is a question for counsel.
The breach track, in one paragraph
The second number is larger and is triggered differently. California’s private right of action allows a consumer whose unencrypted, unredacted personal information was exposed in a breach resulting from a failure to maintain reasonable security to seek statutory damages of $100 to $750 per incident, or actual damages if greater, typically pursued as a class action. It does not care about your privacy notice, your opt-out link or your request workflow. It cares about whether your security was reasonable. Size the band for your own record count with the CCPA/CPRA exposure calculator, and see how the published thresholds compare with the other regimes in the dated regulatory penalties table.
A worked example: where the ceiling and the plan diverge
Take a 23-person subscription-box company based outside California but selling nationally. It holds personal information on 104,700 California consumers, shares that information with advertising platforms, and therefore crosses the sharing threshold comfortably despite revenue of only $8.6 million. Its opt-out link works, but for seven months a deployment error meant browser-level opt-out signals were not honoured. 14,200 California visitors arrived with such a signal set during that window.
The ceiling arithmetic is brutal and almost useless:
- 14,200 violations × $2,500 = $35,500,000
- If treated as intentional: 14,200 × $7,500 = $106,500,000
Neither number belongs in a budget. The failure was a deployment error rather than a business decision, it was remediated once found, the population affected is identifiable, and the company’s net worth is a small fraction of either figure — every one of which is a factor the regulator is directed to weigh. A defensible planning approach replaces the ceiling with an expected value and declares the assumptions.
Suppose the company assumes a 2.5% chance in any given year of an enforcement action reaching a resolution — an assumption, not a statistic, chosen to reflect a small business that is neither a household name nor a data broker — and models a resolution plus legal response at $340,000. The annualized administrative exposure is 0.025 × $340,000 = $8,500 a year.
Now price the other track on the same basis. Its sector’s indicative annual breach probability is about 24%, and a realistic incident would expose roughly 18,900 of its California records. At the lower statutory bound that is 18,900 × $100 = $1,890,000 of damages exposure, which annualizes to 0.24 × $1,890,000 = $453,600 a year.
Annualized statutory-damages exposure (lower bound): $453,600
Ratio: the breach track is about 53 times the fine track
That ratio is the point of the whole exercise. The number that dominates the conversation — the per-violation fine, with its nine-figure ceiling — annualizes to less than the company spends on its helpdesk software. The number nobody mentions, because it has no headline attached, is fifty times larger. And the two are reduced by completely different spending: the first by disclosures, workflows and testing your opt-out path; the second by encryption, access control and everything else that makes security reasonable. The same comparison, generalized, is what the annual loss expectancy calculator formalizes, and the loss figure it needs comes from the data breach cost estimator.
The fees you may charge, and the one you may have to pay
Three smaller money questions round out the picture, and they are the ones most often answered wrongly in both directions.
Charging for a consumer request. Responding to a verified request to know, delete or correct is meant to be free. The statute carves out a single narrow exception: where a request is manifestly unfounded or excessive, in particular because it is repetitive, a business may charge a reasonable fee reflecting its administrative cost, or refuse to act, as long as it explains the reason. The exception is easy to over-read. A request that is merely inconvenient, or that arrives from a customer you would rather not hear from, is not an excessive one.
Charging a different price to people who exercise rights. The non-discrimination rule forbids penalising a consumer for using their rights — no worse price, no degraded service, no denial of goods. What it does permit is a disclosed financial incentive for the collection, sale or retention of personal information: a loyalty discount, a price difference tied to data, a payment. The condition is that the difference must be reasonably related to the value the data provides to the business, must be disclosed, and must be entered into voluntarily. A discount for joining a programme is generally fine; a surcharge for opting out is the thing the rule exists to prevent.
Data-broker registration. If your business knowingly collects and sells personal information about consumers with whom it has no direct relationship, it may meet the data-broker definition, which carries an annual registration with the state and a fee set by regulation. This is the only CCPA obligation that produces a genuine invoice, and it is also the easiest to overlook, because the businesses that meet the definition rarely describe themselves that way.
What actually moves your exposure
Three variables change these numbers far more than any interpretive nuance.
The size of the affected population, not the seriousness of the mistake. Because violations are counted per consumer, exposure scales with how many Californians a defective feature touched. A failure that ran for a week across a small segment and one that ran for a year across the whole base are the same engineering mistake and two entirely different numbers. This is an argument for detection and monitoring of consumer-facing privacy mechanisms, not just of servers — nobody discovers a broken opt-out link from a security alert.
Whether the data was encrypted. The statutory-damages track reaches unencrypted, unredacted personal information. Encryption at rest is therefore not only a security control but the single most direct reducer of the largest of the three numbers, which is an unusual property and worth weighing explicitly when it comes up for budget. The general form of that argument is set out in the ROI of security controls.
Whether the failure looks like a decision or an accident. The gap between the $2,500 and $7,500 figures is the difference between a mistake and a choice, and the evidence that distinguishes them is usually your own documentation. A written decision log, a record of what you tested and when, and a dated remediation trail are cheap to keep and do more to keep a matter in the lower band than anything bought afterwards.
The wider mapping of which regimes attach to which data sits in which penalties actually apply to an SMB, and the cost of running a compliance programme in the first place — a different budget line from every figure above — is worked through in what CCPA compliance actually costs a small business. For keeping any of this repeatable, the practitioner material published by the IAPP is a more useful reference than a penalty table, because the thing that keeps you out of the top row is process, not arithmetic.
Frequently asked questions
Is there a registration fee to comply with the CCPA?
For an ordinary business, no. There is no licence, no filing and no fee attached to being subject to the CCPA — you comply by doing the work, not by paying an authority. The one exception is a business that qualifies as a data broker, meaning it knowingly collects and sells personal information about consumers with whom it has no direct relationship: those businesses must register annually with the California Privacy Protection Agency and pay a registration fee set by regulation. If you sell data you did not collect from your own customers, check the broker definition carefully, because the registration obligation is the one CCPA duty that carries an actual invoice.
How are CCPA violations counted?
This is the question that decides whether a penalty figure is five digits or nine. The published amounts are per violation, and a violation is generally understood to run per affected consumer rather than per defective feature, so one broken opt-out mechanism becomes as many violations as there were consumers whose rights it defeated. That is why the arithmetic ceiling on a single mistake can exceed the revenue of the business that made it, and why the ceiling is a poor planning figure: it multiplies a modest unit amount by a population, with nothing in the multiplication reflecting how serious the underlying failure was.
Does a business still get 30 days to fix a problem before being fined?
Not as a right. The original CCPA gave a business a 30-day window to cure an alleged violation before the Attorney General could seek penalties; the CPRA amendments removed that automatic entitlement. An opportunity to remediate may still be offered, and in practice regulators frequently prefer a fixed problem to a contested penalty, but it is now discretionary rather than guaranteed. Planning on a cure period that may not arrive is a poor bet; the defensible assumption is that the first notice you receive could be the only one.
Can a business charge a consumer for handling a data request?
As a rule, no — responding to a verified request to know, delete or correct is meant to be free. The statute leaves one narrow exception: where a request is manifestly unfounded or excessive, in particular because it is repetitive, a business may charge a reasonable fee reflecting the administrative cost, or decline to act, provided it explains why. That exception is narrow and easy to over-read. Treating a merely inconvenient request as an excessive one is how a $37 handling cost turns into an enforcement conversation.
Who actually collects a CCPA penalty, and where does the money go?
Two routes exist. The California Privacy Protection Agency can bring an administrative enforcement action and assess a penalty directly; the Attorney General can bring a civil action in court seeking civil penalties. Amounts recovered under either route are directed to the state’s Consumer Privacy Fund, which supports the cost of enforcement rather than compensating individual consumers. Compensation for individuals runs through the separate private right of action, which is why the same breach can produce a penalty paid to the state and damages paid to consumers.
Do administrative penalties and statutory damages stack?
They can, because they answer different questions. An administrative penalty addresses a failure of duty — a missing disclosure, an ignored opt-out, an unhonoured deletion request. Statutory damages in private litigation address a specific harm: a breach of unencrypted, unredacted personal information resulting from a failure to maintain reasonable security. A single incident can trigger both tracks at once, and the two are assessed independently, so the exposures add rather than substitute.
Disclaimer. BreachCostLab provides cost and risk estimates for informational purposes only, based on published industry benchmarks (e.g. IBM/Ponemon Cost of a Data Breach, Verizon DBIR) and publicly available statutory figures as of the verification date shown (Jun 25, 2026). These figures are estimates for planning, not a prediction of the cost of any specific incident, and are not legal, financial, insurance, or compliance advice. Actual breach costs vary widely; for regulatory obligations consult qualified counsel. Always verify current figures with the cited sources.