Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

CCPA and Email Marketing: What You Need to Know

On this page

What Is the CCPA?

The California Consumer Privacy Act (CCPA), amended and expanded by the California Privacy Rights Act (CPRA), is a privacy law that gives California residents specific rights over their personal data. Email addresses are personal information under the CCPA.

If you collect or use email addresses from California residents, the CCPA likely applies to you, regardless of where your business is located.

Does the CCPA Apply to You?

The CCPA applies to for-profit businesses that collect California residents' personal information AND meet at least one of these thresholds:

  • Revenue: Annual gross revenue exceeding $25 million.
  • Data volume: Buy, sell or share the personal information of 100,000 or more California residents, households or devices annually.
  • Revenue from data: Derive 50% or more of annual revenue from selling or sharing consumers' personal information.

Nonprofit organisations are generally exempt. Small businesses below all three thresholds are also exempt, though voluntarily complying is good practice.

Note: The 100,000 threshold can be reached more easily than you might think. If your website gets 100,000 unique visitors from California in a year and you use tracking cookies, you may meet this threshold.

CCPA vs GDPR: Key Differences

If you are already familiar with GDPR, the CCPA has important differences:

Aspect GDPR CCPA
Geography EU/EEA residents California residents
Consent model Opt-in (consent before processing) Opt-out (consumers must request to stop)
Scope All organisations processing EU data For-profit businesses meeting thresholds
Right to delete Yes Yes
Right to know Yes (access request) Yes (specific categories and data pieces)
Selling data Requires consent Must offer opt-out
Private right of action Limited Yes, for data breaches

The biggest practical difference: GDPR requires consent before you process personal data for marketing. CCPA allows you to collect and use personal information but requires you to let consumers opt out of sales and sharing.

Consumer Rights Under CCPA

Right to know

California consumers can request:

  • What categories of personal information you collect.
  • The specific pieces of personal information you have about them.
  • Where the data came from.
  • Why you collect it.
  • Who you share it with.

For email marketers: If a subscriber asks what data you have about them, you must be able to provide it within 45 days. This includes their email address, any profile data, and engagement data (opens, clicks, purchase history).

Right to delete

Consumers can request that you delete their personal information. You must also direct your service providers to delete it.

Exceptions: You can retain data if needed to complete a transaction, detect security incidents, comply with a legal obligation, or use it internally in ways the consumer would reasonably expect.

For email marketers: A deletion request means removing the person from your email lists and deleting their data from your CRM, email marketing platform and any other system where you store it. You should keep the email address on a suppression list (with no other data) to prevent re-adding them.

Right to opt out of sale/sharing

Consumers can opt out of the "sale" or "sharing" of their personal information. Under the CPRA amendments, "sharing" includes sharing data for cross-context behavioural advertising.

For email marketers: If you share email lists with partners, use third-party tracking pixels that share data with ad platforms, or participate in co-registration programmes, consumers must be able to opt out.

Right to non-discrimination

You cannot deny goods or services, charge different prices or provide different quality to consumers who exercise their CCPA rights.

For email marketers: You cannot provide a worse customer experience to people who opt out of data sharing.

Right to correct

Consumers can request that you correct inaccurate personal information.

Right to limit use of sensitive personal information

Sensitive personal information (which can include precise geolocation, racial or ethnic origin, and other categories) is subject to additional restrictions.

Email addresses alone are not considered sensitive personal information under the CCPA, but other data you collect alongside them might be.

Compliance Requirements for Email Marketing

1. Privacy notice

You must provide a clear, accessible privacy notice that describes:

  • Categories of personal information collected (e.g., email addresses, names, IP addresses, browsing behaviour).
  • Purposes for collection and use.
  • Categories of third parties with whom you share data.
  • Consumer rights and how to exercise them.
  • Whether you sell or share personal information.

Placement: Your website's privacy policy. Link to it from your signup forms and email footers.

2. "Do Not Sell or Share My Personal Information" link

If you sell or share personal information, your website must prominently display this link. Consumers click it to opt out.

For email marketers: If you share subscriber data with advertising platforms, affiliate partners or data brokers, you need this link.

3. Notice at collection

At or before the point where you collect personal information, you must inform consumers:

  • What categories of data you are collecting.
  • The purposes for which you will use it.
  • Whether you sell or share it.

For email marketers: Your signup forms should link to your privacy notice. A brief statement next to the email field (e.g., "See our privacy policy for how we use your information") suffices.

4. Request handling process

You must provide at least two methods for consumers to submit requests (e.g., a web form and an email address). You must respond within 45 days (with a possible 45-day extension for complex requests).

Verification: You must verify the identity of the requestor. For email-based requests, sending a verification email to the address in question is a reasonable verification method.

5. Service provider agreements

Your email marketing platform, CRM and other tools that process subscriber data are "service providers" under the CCPA. You need contracts with each one that:

  • Limit their use of your data to providing their service.
  • Require them to comply with the CCPA.
  • Prohibit them from selling the data.

Most major email platforms include CCPA-compliant terms in their standard agreements.

How This Applies to Email Extraction

When you extract email addresses from files using Email Extractor, the CCPA applies to what you do with those addresses, not to the extraction itself (which happens client-side in your browser for file processing).

Key considerations:

  • Source matters. If you extracted addresses from documents, exports or files, consider how those addresses were originally collected. Were the people informed about how their email would be used?
  • Purpose limitation. Use extracted addresses for the purpose consistent with how they were collected. Customer support emails extracted from support tickets should not automatically be used for marketing without proper notice.
  • Right to delete. If someone requests deletion, you must remove their address from all lists, including any extracted lists you created.
  • Suppression list. Maintain a suppression list that survives across list builds. When you extract new lists, always check against your suppression list before use.

Practical Steps

Audit your data flows

  1. Document where you collect email addresses.
  2. Map where that data flows (CRM, email platform, analytics, ad platforms, partners).
  3. Identify any sharing that qualifies as "selling" or "sharing" under the CCPA.

Update your privacy policy

Ensure your privacy policy covers:

  • All categories of personal information you collect.
  • Your purposes for each category.
  • Third parties who receive the data.
  • Consumer rights and how to exercise them.

Set up request handling

  1. Create a web form for consumer requests (know, delete, opt-out).
  2. Set up a dedicated email address for privacy requests.
  3. Train your team on how to verify and process requests within the 45-day deadline.
  4. Document every request and response.

Review vendor contracts

Ensure your email marketing platform, CRM and other data processors have CCPA-compliant service provider agreements in place.

Implement opt-out mechanisms

If you share data for advertising purposes, add a "Do Not Sell or Share My Personal Information" link to your website.

Enforcement

The CCPA is enforced by the California Attorney General and the California Privacy Protection Agency (CPPA).

Penalties:

  • Up to $2,500 per unintentional violation.
  • Up to $7,500 per intentional violation.
  • Violations involving minors: up to $7,500 per violation.

Private right of action: Consumers can sue directly for data breaches involving unencrypted personal information. Statutory damages range from $100 to $750 per consumer per incident.

The CPPA has been actively issuing enforcement actions and investigative sweeps, making compliance increasingly important.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)