- © 2026 Mailsoftly Inc. The name "Mailsoftly" and the Mailsoftly logo are registered trademarks of Mailsoftly Inc.
Who has to comply, what opt-out and deletion requests really mean, and why purchased California lists put your program at risk.
by Alkan Balkaya · Last updated: 2026-07-29CCPA can apply to your email marketing, but only when your business crosses its thresholds: roughly $25 million in annual revenue, personal information on 100,000 or more California consumers or households, or 50 percent of revenue from selling or sharing data. If it applies, you must honor requests to know, delete, and opt out of the sale or sharing of personal information.
The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), does not replace the federal rules every US sender already follows. It layers new consumer rights on top of them. That means an email address, a location, a purchase history, and even a device identifier tied to a California resident are all in scope, whether the person is a customer, a lead, or a subscriber who once downloaded a guide.
This article explains where the line sits, what changes operationally, and how to keep your list clean without a legal team on speed dial.
New here? Start with our primer on Email Deliverability & Authentication for the fundamentals, then come back to this guide.
Quick context: Mailsoftly offers transparent pricing, free hands-on migration, and human support. 500 contacts and 2,000 emails per month, no credit card.
Start free with Mailsoftly →
Key Takeaways
CCPA applies to a for-profit business that collects California residents’ personal information, does business in California, and meets at least one threshold. Nonprofits and most very small senders are not directly regulated, though the rights still matter the moment a California resident lands on your list.
The three qualifying thresholds are set out by the California Attorney General. A business is covered if it hits any one of them, not all three. The revenue figure is adjusted periodically for inflation, so confirm the current number against the official guidance rather than a blog before you make a compliance decision. You can review the current thresholds and consumer rights on the California Attorney General’s CCPA overview.
If none of these apply, your email program is governed mainly by the baseline federal rules that require accurate headers, a working unsubscribe, and honest subject lines. Our umbrella resource on email deliverability and permission covers those fundamentals in depth, and this article stays focused on the California-specific layer.
Read enough? Try Mailsoftly free with 500 contacts and 2,000 emails per month, no credit card.Start free with Mailsoftly →
CCPA gives California residents four rights that reach directly into your email database: the right to know, the right to delete, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination. These sit on top of the unsubscribe mechanics you already run, and they apply to data you hold, not just to the emails you send.
The opt-out right is the one email marketers underestimate. “Sale” and “sharing” are defined broadly and can include passing email or behavioral data to ad networks and lookalike audience tools, even when no money changes hands. If you feed subscriber data into cross-context behavioral advertising, you likely need a clear “Do Not Sell or Share My Personal Information” path and you must honor opt-out preference signals from the browser. Treat every marketing partner integration as a place where this right can quietly attach.
In practice, CCPA turns your email platform into a system of record for privacy requests. When a California resident asks to be deleted, removing them from one campaign is not enough. You have to delete their personal information across your active lists, segments, and stored history, then keep them off future sends without re-importing them by accident.
This is exactly what suppression lists are built for. A suppression entry is a permanent do-not-contact marker that survives new imports and integrations, so a deleted or opted-out address cannot slip back in through a fresh CSV or a synced CRM. Pair it with strong email authentication service settings and you protect both compliance and deliverability at the same time, since a clean, permission-based list is what inbox providers reward.
When you buy a list, you inherit contacts you cannot prove consent for and cannot honor rights requests about, because you do not know where the data came from. Under CCPA that is a documentation gap you can never close, and it also crushes deliverability. There is no safe way to bolt compliance onto a purchased California list after the fact.
Build lists the durable way instead: collect email through your own forms, log the source and timestamp of each opt-in, and give people a real reason to stay. That record is your best defense when a request or a complaint arrives, and it is the same practice that keeps engagement high enough to reach the inbox.
CPRA amended and expanded CCPA, adding a new category called sensitive personal information and a right to limit its use. It also created a dedicated regulator, the California Privacy Protection Agency, which now writes and enforces the rules. For email marketers, the practical change is that some data types you might collect carry extra obligations.
Sensitive personal information includes things like precise geolocation, government identifiers, account credentials, and data revealing race, religion, health, or sexual orientation. A plain email address is personal information but is generally not sensitive on its own. The distinction matters when your segments or profiles pull in richer attributes. You can track current rulemaking and enforcement priorities directly from the California Privacy Protection Agency, and review the detailed obligations in the official CCPA regulations.
The more attributes you attach to a subscriber, the closer you get to sensitive personal information territory. Collect what you genuinely use, document why, and give people a way to limit it.
None of this makes California email marketing off-limits. It makes it deliberate. Businesses that map their data, minimize what they store, and route requests through one reliable workflow find the ongoing burden modest. The teams that struggle are usually the ones with scattered spreadsheets and no single suppression system.
A working checklist keeps compliance operational instead of theoretical. Run through these steps once to set your program up, then revisit them whenever your stack or data practices change.
This is not legal advice. CCPA and CPRA obligations depend on your specific business, data, and revenue. Use this article to get oriented, then confirm the current thresholds and requirements with the official California sources cited above or with qualified counsel before you act.
Mailsoftly is built so deletion and opt-out requests are simple to execute and easy to prove. When a California resident asks to be removed, you delete the contact and add them to a suppression list in the same motion, which guarantees they stay off every future send even if their address reappears in a later import.
Consent tooling is GDPR-grade, which sets a higher bar than CCPA requires and covers you comfortably for California. That means source and timestamp capture on your forms, granular preferences, and a clean audit trail for every subscriber. Deliverability benefits directly, because the same permission hygiene that satisfies a regulator is what keeps your sender reputation healthy.
You can put all of this to work on the free plan, which includes 500 contacts and 2,000 emails per month with no credit card. It is enough room to migrate a list, set up suppression, and test your request workflow before you scale.
For the broader picture on this topic, see our complete Email Deliverability & Authentication guide, which covers strategy, fundamentals, and advanced playbooks.


No, CCPA does not add an opt-in consent requirement for sending marketing email. It is a privacy law about consumer rights over personal information, not a sending law. Your permission and unsubscribe obligations come from the baseline federal rules, while CCPA adds rights to know, delete, and opt out of the sale or sharing of data.
Yes. An email address that identifies or can be linked to a California resident is personal information under CCPA. That is why deletion and opt-out requests reach into your list. An email address by itself is generally not classified as the newer sensitive personal information category created by CPRA.
Businesses generally must respond to a verifiable consumer request within 45 days, with a possible extension when reasonably necessary. Building deletion into a suppression workflow inside your email platform is the most reliable way to meet that window and to document that you acted.
The problem is not a single rule but a documentation gap. With a purchased list you cannot verify where the data came from or honor rights requests about it, and you inherit consent problems you cannot fix. Combined with the deliverability damage, purchased California lists are best avoided entirely.
Ready to switch?Start free with Mailsoftly →
500 contacts, 2,000 emails per month. Free hands-on migration. No credit card.

Ready to boost your email marketing?
Start sending beautiful, targeted emails that convert — free to get started.
Try Mailsoftly FreeNo credit card required