CCPA and Email Marketing: What You Need to Know
On this page
What Is the CCPA?
The California Consumer Privacy Act (CCPA), amended and expanded by the California Privacy Rights Act (CPRA), is a privacy law that gives California residents specific rights over their personal data. Email addresses are personal information under the CCPA.
If you collect or use email addresses from California residents, the CCPA likely applies to you, regardless of where your business is located.
Does the CCPA Apply to You?
The CCPA applies to for-profit businesses that collect California residents' personal information AND meet at least one of these thresholds:
- Revenue: Annual gross revenue exceeding $25 million.
- Data volume: Buy, sell or share the personal information of 100,000 or more California residents, households or devices annually.
- Revenue from data: Derive 50% or more of annual revenue from selling or sharing consumers' personal information.
Nonprofit organisations are generally exempt. Small businesses below all three thresholds are also exempt, though voluntarily complying is good practice.
Note: The 100,000 threshold can be reached more easily than you might think. If your website gets 100,000 unique visitors from California in a year and you use tracking cookies, you may meet this threshold.
CCPA vs GDPR: Key Differences
If you are already familiar with GDPR, the CCPA has important differences:
| Aspect | GDPR | CCPA |
|---|---|---|
| Geography | EU/EEA residents | California residents |
| Consent model | Opt-in (consent before processing) | Opt-out (consumers must request to stop) |
| Scope | All organisations processing EU data | For-profit businesses meeting thresholds |
| Right to delete | Yes | Yes |
| Right to know | Yes (access request) | Yes (specific categories and data pieces) |
| Selling data | Requires consent | Must offer opt-out |
| Private right of action | Limited | Yes, for data breaches |
The biggest practical difference: GDPR requires consent before you process personal data for marketing. CCPA allows you to collect and use personal information but requires you to let consumers opt out of sales and sharing.
Consumer Rights Under CCPA
Right to know
California consumers can request:
- What categories of personal information you collect.
- The specific pieces of personal information you have about them.
- Where the data came from.
- Why you collect it.
- Who you share it with.
For email marketers: If a subscriber asks what data you have about them, you must be able to provide it within 45 days. This includes their email address, any profile data, and engagement data (opens, clicks, purchase history).
Right to delete
Consumers can request that you delete their personal information. You must also direct your service providers to delete it.
Exceptions: You can retain data if needed to complete a transaction, detect security incidents, comply with a legal obligation, or use it internally in ways the consumer would reasonably expect.
For email marketers: A deletion request means removing the person from your email lists and deleting their data from your CRM, email marketing platform and any other system where you store it. You should keep the email address on a suppression list (with no other data) to prevent re-adding them.
Right to opt out of sale/sharing
Consumers can opt out of the "sale" or "sharing" of their personal information. Under the CPRA amendments, "sharing" includes sharing data for cross-context behavioural advertising.
For email marketers: If you share email lists with partners, use third-party tracking pixels that share data with ad platforms, or participate in co-registration programmes, consumers must be able to opt out.
Right to non-discrimination
You cannot deny goods or services, charge different prices or provide different quality to consumers who exercise their CCPA rights.
For email marketers: You cannot provide a worse customer experience to people who opt out of data sharing.
Right to correct
Consumers can request that you correct inaccurate personal information.
Right to limit use of sensitive personal information
Sensitive personal information (which can include precise geolocation, racial or ethnic origin, and other categories) is subject to additional restrictions.
Email addresses alone are not considered sensitive personal information under the CCPA, but other data you collect alongside them might be.
Compliance Requirements for Email Marketing
1. Privacy notice
You must provide a clear, accessible privacy notice that describes:
- Categories of personal information collected (e.g., email addresses, names, IP addresses, browsing behaviour).
- Purposes for collection and use.
- Categories of third parties with whom you share data.
- Consumer rights and how to exercise them.
- Whether you sell or share personal information.
Placement: Your website's privacy policy. Link to it from your signup forms and email footers.
2. "Do Not Sell or Share My Personal Information" link
If you sell or share personal information, your website must prominently display this link. Consumers click it to opt out.
For email marketers: If you share subscriber data with advertising platforms, affiliate partners or data brokers, you need this link.
3. Notice at collection
At or before the point where you collect personal information, you must inform consumers:
- What categories of data you are collecting.
- The purposes for which you will use it.
- Whether you sell or share it.
For email marketers: Your signup forms should link to your privacy notice. A brief statement next to the email field (e.g., "See our privacy policy for how we use your information") suffices.
4. Request handling process
You must provide at least two methods for consumers to submit requests (e.g., a web form and an email address). You must respond within 45 days (with a possible 45-day extension for complex requests).
Verification: You must verify the identity of the requestor. For email-based requests, sending a verification email to the address in question is a reasonable verification method.
5. Service provider agreements
Your email marketing platform, CRM and other tools that process subscriber data are "service providers" under the CCPA. You need contracts with each one that:
- Limit their use of your data to providing their service.
- Require them to comply with the CCPA.
- Prohibit them from selling the data.
Most major email platforms include CCPA-compliant terms in their standard agreements.
How This Applies to Email Extraction
When you extract email addresses from files using Email Extractor, the CCPA applies to what you do with those addresses, not to the extraction itself (which happens client-side in your browser for file processing).
Key considerations:
- Source matters. If you extracted addresses from documents, exports or files, consider how those addresses were originally collected. Were the people informed about how their email would be used?
- Purpose limitation. Use extracted addresses for the purpose consistent with how they were collected. Customer support emails extracted from support tickets should not automatically be used for marketing without proper notice.
- Right to delete. If someone requests deletion, you must remove their address from all lists, including any extracted lists you created.
- Suppression list. Maintain a suppression list that survives across list builds. When you extract new lists, always check against your suppression list before use.
Practical Steps
Audit your data flows
- Document where you collect email addresses.
- Map where that data flows (CRM, email platform, analytics, ad platforms, partners).
- Identify any sharing that qualifies as "selling" or "sharing" under the CCPA.
Update your privacy policy
Ensure your privacy policy covers:
- All categories of personal information you collect.
- Your purposes for each category.
- Third parties who receive the data.
- Consumer rights and how to exercise them.
Set up request handling
- Create a web form for consumer requests (know, delete, opt-out).
- Set up a dedicated email address for privacy requests.
- Train your team on how to verify and process requests within the 45-day deadline.
- Document every request and response.
Review vendor contracts
Ensure your email marketing platform, CRM and other data processors have CCPA-compliant service provider agreements in place.
Implement opt-out mechanisms
If you share data for advertising purposes, add a "Do Not Sell or Share My Personal Information" link to your website.
Enforcement
The CCPA is enforced by the California Attorney General and the California Privacy Protection Agency (CPPA).
Penalties:
- Up to $2,500 per unintentional violation.
- Up to $7,500 per intentional violation.
- Violations involving minors: up to $7,500 per violation.
Private right of action: Consumers can sue directly for data breaches involving unencrypted personal information. Statutory damages range from $100 to $750 per consumer per incident.
The CPPA has been actively issuing enforcement actions and investigative sweeps, making compliance increasingly important.