California Privacy Law
CCPA and Email Marketing, Made Practical for 2026

Who has to comply, what opt-out and deletion requests really mean, and why purchased California lists put your program at risk.

💰
$25M+
revenue trigger
👥
100,000
CA consumers
45
days to respond
3
core rights
Alkan Balkayaby Alkan Balkaya · Last updated: 2026-07-29

CCPA and Email Marketing: What California Law Actually Requires in 2026

CCPA can apply to your email marketing, but only when your business crosses its thresholds: roughly $25 million in annual revenue, personal information on 100,000 or more California consumers or households, or 50 percent of revenue from selling or sharing data. If it applies, you must honor requests to know, delete, and opt out of the sale or sharing of personal information.

The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), does not replace the federal rules every US sender already follows. It layers new consumer rights on top of them. That means an email address, a location, a purchase history, and even a device identifier tied to a California resident are all in scope, whether the person is a customer, a lead, or a subscriber who once downloaded a guide.

This article explains where the line sits, what changes operationally, and how to keep your list clean without a legal team on speed dial.

New here? Start with our primer on Email Deliverability & Authentication for the fundamentals, then come back to this guide.

Quick context: Mailsoftly offers transparent pricing, free hands-on migration, and human support. 500 contacts and 2,000 emails per month, no credit card.
Start free with Mailsoftly →

Key Takeaways

  • CCPA applies to for-profit businesses that meet a revenue or data-volume threshold, so many small senders are not directly covered, though the rights still travel with California residents on your list.
  • The law adds four consumer rights on top of existing email rules: the right to know, delete, opt out of the sale or sharing of personal information, and non-discrimination for exercising those rights.
  • Deletion and opt-out requests must be honored inside your email platform, which makes reliable suppression lists and a real audit trail essential.
  • Purchased California lists are the fastest way to inherit consent problems you cannot document, and CPRA raised the stakes by adding a sensitive personal information category.

Does CCPA Apply to Your Email Marketing?

CCPA applies to a for-profit business that collects California residents’ personal information, does business in California, and meets at least one threshold. Nonprofits and most very small senders are not directly regulated, though the rights still matter the moment a California resident lands on your list.

The three qualifying thresholds are set out by the California Attorney General. A business is covered if it hits any one of them, not all three. The revenue figure is adjusted periodically for inflation, so confirm the current number against the official guidance rather than a blog before you make a compliance decision. You can review the current thresholds and consumer rights on the California Attorney General’s CCPA overview.

Any one of these makes a business subject to CCPA
01Annual gross revenue above roughly $25 million (adjusted for inflation, verify the current figure).
02Buys, sells, or shares the personal information of 100,000 or more California consumers or households.
03Derives 50 percent or more of annual revenue from selling or sharing personal information.

If none of these apply, your email program is governed mainly by the baseline federal rules that require accurate headers, a working unsubscribe, and honest subject lines. Our umbrella resource on email deliverability and permission covers those fundamentals in depth, and this article stays focused on the California-specific layer.

Read enough? Try Mailsoftly free with 500 contacts and 2,000 emails per month, no credit card.Start free with Mailsoftly →

What New Rights Does CCPA Give California Subscribers?

CCPA gives California residents four rights that reach directly into your email database: the right to know, the right to delete, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination. These sit on top of the unsubscribe mechanics you already run, and they apply to data you hold, not just to the emails you send.

Right to know
What personal information you collected, where it came from, and why you use it.
Right to delete
Remove their personal information, subject to a few narrow exceptions.
Right to opt out
Stop the sale or sharing of their personal information with third parties.
Non-discrimination
You cannot punish someone with worse pricing or service for exercising a right.

The opt-out right is the one email marketers underestimate. “Sale” and “sharing” are defined broadly and can include passing email or behavioral data to ad networks and lookalike audience tools, even when no money changes hands. If you feed subscriber data into cross-context behavioral advertising, you likely need a clear “Do Not Sell or Share My Personal Information” path and you must honor opt-out preference signals from the browser. Treat every marketing partner integration as a place where this right can quietly attach.

What Does CCPA Mean for Your Email List?

In practice, CCPA turns your email platform into a system of record for privacy requests. When a California resident asks to be deleted, removing them from one campaign is not enough. You have to delete their personal information across your active lists, segments, and stored history, then keep them off future sends without re-importing them by accident.

This is exactly what suppression lists are built for. A suppression entry is a permanent do-not-contact marker that survives new imports and integrations, so a deleted or opted-out address cannot slip back in through a fresh CSV or a synced CRM. Pair it with strong email authentication service settings and you protect both compliance and deliverability at the same time, since a clean, permission-based list is what inbox providers reward.

Why purchased California lists are radioactive

When you buy a list, you inherit contacts you cannot prove consent for and cannot honor rights requests about, because you do not know where the data came from. Under CCPA that is a documentation gap you can never close, and it also crushes deliverability. There is no safe way to bolt compliance onto a purchased California list after the fact.

Build lists the durable way instead: collect email through your own forms, log the source and timestamp of each opt-in, and give people a real reason to stay. That record is your best defense when a request or a complaint arrives, and it is the same practice that keeps engagement high enough to reach the inbox.

What Did CPRA Change for Marketers?

CPRA amended and expanded CCPA, adding a new category called sensitive personal information and a right to limit its use. It also created a dedicated regulator, the California Privacy Protection Agency, which now writes and enforces the rules. For email marketers, the practical change is that some data types you might collect carry extra obligations.

Sensitive personal information includes things like precise geolocation, government identifiers, account credentials, and data revealing race, religion, health, or sexual orientation. A plain email address is personal information but is generally not sensitive on its own. The distinction matters when your segments or profiles pull in richer attributes. You can track current rulemaking and enforcement priorities directly from the California Privacy Protection Agency, and review the detailed obligations in the official CCPA regulations.

Rule of thumb

The more attributes you attach to a subscriber, the closer you get to sensitive personal information territory. Collect what you genuinely use, document why, and give people a way to limit it.

None of this makes California email marketing off-limits. It makes it deliberate. Businesses that map their data, minimize what they store, and route requests through one reliable workflow find the ongoing burden modest. The teams that struggle are usually the ones with scattered spreadsheets and no single suppression system.

What Is a Practical CCPA Compliance Checklist for Email?

A working checklist keeps compliance operational instead of theoretical. Run through these steps once to set your program up, then revisit them whenever your stack or data practices change.

  1. Confirm whether you meet a CCPA threshold, and reconfirm after major growth or an acquisition.
  2. Publish a privacy notice that explains what personal information you collect through email sign-ups and why.
  3. Give California residents a clear way to submit know, delete, and opt-out requests, and respond within 45 days.
  4. Add a “Do Not Sell or Share My Personal Information” mechanism if you pass subscriber data to ad or audience tools, and honor browser opt-out signals.
  5. Maintain a permanent suppression list so deleted and opted-out contacts never return through a new import.
  6. Log the source, timestamp, and consent basis for every contact you collect.
  7. Stop buying, renting, or importing third-party California lists you cannot document.
  8. Audit your integrations to see where subscriber data flows to third parties.
  9. Keep a simple record of requests received and actions taken, so you can show your work.

This is not legal advice. CCPA and CPRA obligations depend on your specific business, data, and revenue. Use this article to get oriented, then confirm the current thresholds and requirements with the official California sources cited above or with qualified counsel before you act.

How Does Mailsoftly Handle CCPA Requests?

Mailsoftly is built so deletion and opt-out requests are simple to execute and easy to prove. When a California resident asks to be removed, you delete the contact and add them to a suppression list in the same motion, which guarantees they stay off every future send even if their address reappears in a later import.

Consent tooling is GDPR-grade, which sets a higher bar than CCPA requires and covers you comfortably for California. That means source and timestamp capture on your forms, granular preferences, and a clean audit trail for every subscriber. Deliverability benefits directly, because the same permission hygiene that satisfies a regulator is what keeps your sender reputation healthy.

You can put all of this to work on the free plan, which includes 500 contacts and 2,000 emails per month with no credit card. It is enough room to migrate a list, set up suppression, and test your request workflow before you scale.

For the broader picture on this topic, see our complete Email Deliverability & Authentication guide, which covers strategy, fundamentals, and advanced playbooks.

CCPA and Email Marketing: What California Law Actually Requires in 2026 visual 1
CCPA and Email Marketing: What California Law Actually Requires in 2026 visual 2

Frequently Asked Questions

Does CCPA require consent before sending marketing emails?

No, CCPA does not add an opt-in consent requirement for sending marketing email. It is a privacy law about consumer rights over personal information, not a sending law. Your permission and unsubscribe obligations come from the baseline federal rules, while CCPA adds rights to know, delete, and opt out of the sale or sharing of data.

Is an email address personal information under CCPA?

Yes. An email address that identifies or can be linked to a California resident is personal information under CCPA. That is why deletion and opt-out requests reach into your list. An email address by itself is generally not classified as the newer sensitive personal information category created by CPRA.

How long do I have to honor a CCPA deletion request?

Businesses generally must respond to a verifiable consumer request within 45 days, with a possible extension when reasonably necessary. Building deletion into a suppression workflow inside your email platform is the most reliable way to meet that window and to document that you acted.

Are purchased California email lists legal under CCPA?

The problem is not a single rule but a documentation gap. With a purchased list you cannot verify where the data came from or honor rights requests about it, and you inherit consent problems you cannot fix. Combined with the deliverability damage, purchased California lists are best avoided entirely.

Ready to switch?Start free with Mailsoftly →
500 contacts, 2,000 emails per month. Free hands-on migration. No credit card.

Alkan Balkaya
Alkan Balkaya
Founder & CEO at Mailsoftly
Alkan is the founder and CEO of Mailsoftly, building AI-powered email marketing tools for businesses of all sizes. He writes about email marketing strategy, deliverability, and the future of marketing automation.