CCPA and CPRA
Not legal advice. This page describes legal and regulatory frameworks in general terms. Jurisdiction changes the answer, and the same voice deployment can be lawful in one market and unlawful in another. Take advice on your specific circumstances.
In one sentence
The CCPA, as amended by the CPRA, gives California residents rights to know about, delete, correct and stop the sharing of the personal information a business holds, and it asks whether that business disclosed and can service requests rather than whether it had a basis to collect at all.
Not to be confused with GDPR.
Definition
The CCPA is the California consumer privacy law, and the CPRA widened it.
Together they hand California residents rights over the personal information a business holds, and they bind businesses well outside California.
The California Consumer Privacy Act, amended by the California Privacy Rights Act whose main provisions have been operative since January 2023, is put together differently from GDPR. Consumer rights and disclosure carry the structure, not lawful bases for processing.
The rights a voice deployment has to service
- Right to know: what personal information is held, where it came from, what it is being used for, and who it has been disclosed to.
- Right to delete, subject to exceptions.
- Right to correct personal information that is wrong, which the CPRA added.
- Right to opt out of sale or sharing, where sharing is a defined term reaching cross-context behavioral advertising.
- Right to limit how sensitive personal information is used, also from the CPRA.
- Right to be treated no differently for having exercised any of them.
Why the structure matters practically
- Nothing requires a lawful basis to be established before processing starts. What is required is disclosure, plus honoring opt-out and deletion requests when they arrive.
- So the work lands in the notice, in being able to service a request, and in reading opt-out signals, rather than in justifying the collection.
- Which is why a design can clear California and fail GDPR: it never had to find a basis. Going the other direction, the design usually survives.
What voice adds
- Audio and transcripts are personal information wherever they relate to a consumer who can be identified.
- The sensitive personal information categories the CPRA covers include things a conversation can pick up by accident, and the right to limit use reaches them.
- Automated decision-making and profiling have drawn subsequent rulemaking, so check the current position rather than trusting a snapshot.
The opt-out signal is the piece that lands directly on a website widget. Businesses are expected to honor recognized opt-out preference signals sent by a browser. A widget that ignores one while passing data on for advertising purposes is a concrete exposure, and unlike most privacy obligations it can be tested.
California is the most developed of the US state privacy laws and it is not the only one. Numerous other states have passed comprehensive laws carrying broadly similar rights and differing in detail, so a US deployment needs a multi-state view rather than a Californian one.
This page describes a statute and its amendments and is not legal advice. The state landscape is expanding, rulemaking is active, and a US deployment should be checked against a maintained tracker and against counsel rather than against a page written on one date.
Common misconception
That CCPA is a thinner GDPR over the same ground. The two are built on different questions. GDPR wants to know whether you may process at all. California wants to know whether you disclosed it and whether requests get honored. Building for one leaves the other unanswered.
Why it matters commercially
For any voice deployment reaching US consumers, the Californian obligations are the practical floor, and the multi-state patchwork is increasingly what a compliance program has to cover. For a website widget, reading browser opt-out signals is a specific, testable requirement rather than a general posture.
In voice specifically
A voice conversation collects whatever the visitor happens to say, which is a wider net than a form. Some of that falls into the sensitive personal information categories the CPRA lets a consumer restrict, and none of it passed through a schema on the way in.
Where AsqVox fits
Transcripts, sentiment and captured leads from Californian visitors are personal information. Three concrete requirements follow: the site privacy notice has to disclose what the Orb collects, deletion and know requests have to be serviceable, and where data is passed on for advertising purposes the browser opt-out signal has to be honored.
Visual
Two different questions about the same data
Disclosure and service, rather than justification.
Statistics
Every figure carries its source and year. Vendor numbers are labelled as vendor numbers, and where no reliable figure exists this page says so rather than borrowing one.
Enacted in 2018, the CCPA became operative in 2020. The CPRA then amended and widened it, and its main provisions have been operative since January 2023.
January 2023industry rangeCalifornia Consumer Privacy Act and California Privacy Rights Act, 2023 - The two work as one regime in practice. A 2026 document citing the CCPA alone is usually describing a position three years out of date.
The rights on offer are to know, to delete, to correct, to opt out of sale or sharing, to limit use of sensitive personal information, and not to be penalized for using any of them.
Six rightsindustry rangeCalifornia Consumer Privacy Act as amended by the California Privacy Rights Act, 2023 - Correction, the limit on sensitive use and non-discrimination are the three most often missing from a compliance page written against the original Act.
Businesses are expected to honor recognized opt-out preference signals sent by a browser.
Browser opt-out signalsindustry rangeCalifornia Consumer Privacy Act as amended by the California Privacy Rights Act, 2023 - The most testable obligation on this page, and the one a website widget can fail silently until somebody raises it.
The US state privacy map is still being drawn, and which states have a comprehensive law in force keeps changing, so no fixed roster is asserted here.
-no reliable figureLink to a maintained tracker instead. A published roster is accurate on the day it ships and misleading a quarter later.
Rulemaking covering automated decision-making and profiling has been active, so the current position cannot be settled from a snapshot.
-no reliable figureRelevant to any voice agent whose output feeds a decision about the consumer. Check where the rulemaking stands rather than relying on a page like this one.
No reliable published statistic exists for CCPA enforcement aimed at voice AI.
-no reliable figureThe same gap runs through every regime in this category. General enforcement numbers exist and say nothing about voice-specific exposure.
Examples
In practice
A website voice widget hands conversation metadata to an ad platform so it can build audiences. The browser of a Californian visitor sends an opt-out preference signal, the widget never reads it, and the sharing carries on. None of that failure touches the quality of the AI. A signal went unchecked. The fix costs almost nothing. The liability does not.
The everyday version
California hands people three practical powers: find out what you hold on them, have it deleted, and stop you sharing it. Europe starts somewhere else and asks whether you had any business collecting it. California asks whether you said so plainly and whether you do as people ask.
Usage
Who says it
- US privacy counsel and compliance teams, watching the whole state map rather than California by itself.
- Marketing operations, who meet it through opt-out signals and advertising data sharing.
- Procurement on US enterprise deals.
Where it turns up
- Alongside what the privacy notice has to say, how consumer requests are handled and how fast, support for opt-out signals, disclosures about data sharing and the sub-processor list.
- A website widget should answer the opt-out signal question before anybody asks it.
Common misuse
- Filing CCPA under GDPR compliance. They are built on different structures.
- Overlooking the other state laws because California is the one with the name recognition.
- Believing a privacy policy finishes the job. Answering consumer requests inside the statutory clock is the operational half, and it takes engineering.
Questions people ask
Is CCPA the same as GDPR?
No. GDPR asks whether you may process personal data at all and wants a documented lawful basis for it. California asks whether you disclosed what you collect and whether you honor consumer requests to know, delete, correct and opt out. Satisfying one does not satisfy the other, and building for California alone leaves the GDPR question open.
Do I have to honor browser opt-out signals?
Businesses are expected to honor recognized opt-out preference signals sent by a browser, which puts the obligation squarely on a website widget. A widget passing data on for advertising purposes that never reads the signal is a concrete exposure. It is also one of the few privacy obligations anybody can test in a browser in a minute.
Are voice recordings covered by CCPA?
Audio and transcripts are personal information wherever they relate to a consumer who can be identified. Some of what a conversation picks up by accident falls into the sensitive personal information categories the CPRA added, and the right to limit use reaches those. The rights to know, delete and correct reach the rest.
Does a privacy policy make a business CCPA compliant?
No. The policy is the disclosure half. The operational half is answering consumer requests inside the statutory clock, reading opt-out signals, and being able to find and delete the right records, all of which take engineering. California is also not the only state with a comprehensive law, so a US deployment needs a multi-state view.
Last reviewed 30 July 2026. Written and reviewed by Dhruv Dholakia, founder of AsqVox.