Skip to content
Regulation Guide

CCPA Compliance Guide

What MENA businesses need to know about the California Consumer Privacy Act when selling to US customers.

Jan 2020

Effective Date

$7,500

Per Violation

California

Residents

Overview

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state-level privacy law in the United States. Effective January 2020 with CPRA amendments taking effect January 2023, CCPA applies to for-profit businesses that collect personal information of California residents and meet certain revenue or data volume thresholds: annual gross revenues over $25 million, buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50%+ of annual revenue from selling or sharing personal information. For MENA businesses with US customers, CCPA is relevant because it applies based on the consumer's residence, not the business's location. CCPA uses an opt-out consent model, which differs significantly from the opt-in model required by GDPR and PDPL. Under CCPA, businesses can collect and use personal information without prior consent but must provide a clear 'Do Not Sell or Share My Personal Information' link and honor opt-out requests. Consumer rights include the right to know what personal information is collected, the right to delete, the right to opt-out of sale/sharing, the right to non-discrimination, the right to correct, and the right to limit use of sensitive personal information. Businesses must provide privacy notices, respond to consumer requests within 45 days, maintain records for 24 months, and implement reasonable security measures. The California Privacy Protection Agency (CPPA) enforces the law, with penalties of $2,500 per unintentional violation and $7,500 per intentional violation. Private right of action exists for data breaches. Arqam360's auto-regime detection identifies California visitors and applies the opt-out consent model automatically, defaulting analytics and preferences to enabled while providing clear opt-out mechanisms.

Key Requirements

Opt-Out Model

CCPA uses opt-out consent. Businesses can collect data without prior consent but must provide clear opt-out mechanisms for sale and sharing.

Do Not Sell Link

Display a clear 'Do Not Sell or Share My Personal Information' link on your website accessible to California visitors.

Consumer Rights

Honor rights to know, delete, correct, opt-out, and limit use of sensitive personal information within 45 days of request.

Privacy Notice

Provide a comprehensive privacy notice describing categories of data collected, purposes, third-party sharing, and consumer rights.

GPC Signal

Honor Global Privacy Control (GPC) browser signals as valid opt-out requests under CCPA/CPRA.

Reasonable Security

Implement reasonable security measures to protect personal information. Data breach victims have private right of action.

How Arqam360 Helps

Opt-Out Consent Model

Auto-regime detection identifies California visitors and applies the opt-out model — analytics and preferences default to enabled with clear opt-out.

GPC Signal Handling

Arqam360 detects Global Privacy Control signals and auto-opts-out visitors from non-essential data processing as CCPA requires.

Do Not Sell Support

Consent banner includes opt-out mechanisms that map to CCPA's Do Not Sell or Share requirements.

Multi-Regulation Ready

Serve CCPA consent to California visitors, GDPR to EU visitors, and PDPL to Saudi visitors — all from one widget.

Check your CCPA compliance

Run a free scan to identify CCPA compliance gaps on your website.

Check Compliance

Last updated:

FAQ

CCPA FAQ for MENA Businesses

Common questions about CCPA compliance for businesses outside the US.

If you meet CCPA's revenue or data volume thresholds and have California customers, yes. CCPA applies based on consumer residence, not business location.

Get CCPA Compliant Today

Auto-detect California visitors and apply the correct consent model. Start your free trial.