Privacy Compliance Guide

Understanding the California Consumer Privacy Act

Everything hotels need to know about CCPA compliance requirements and consumer rights

What is the CCPA?

The California Consumer Privacy Act (CCPA) is a state-wide data privacy law that regulates how businesses collect, use, and share personal information of California residents. It went into effect on January 1, 2020, and applies to businesses that meet certain thresholds.

Revenue Threshold

Annual gross revenue over $25 million

Data Volume

Process personal info of 50,000+ consumers annually

Data Sales

Derive 50%+ revenue from selling personal information

Consumer Rights Under CCPA

The CCPA grants California consumers four fundamental rights regarding their personal information

Right to Know

Consumers can request information about what personal data is collected, used, sold, or disclosed

Right to Delete

Consumers can request deletion of their personal information

Right to Opt-Out

Consumers can opt-out of the sale of their personal information

Right to Non-Discrimination

Businesses cannot discriminate against consumers for exercising their CCPA rights

CCPA Requirements for Hotels

Key compliance obligations that hotels must implement to meet CCPA standards

  • 1
    Implement privacy policies that clearly explain data collection practices
  • 2
    Provide mechanisms for consumers to submit data subject requests
  • 3
    Verify the identity of consumers making requests
  • 4
    Respond to consumer requests within 45 days (extendable to 90 days)
  • 5
    Train staff on CCPA compliance procedures
  • 6
    Maintain records of consumer requests and responses
  • 7
    Implement technical safeguards to protect personal information

CCPA Violation Penalties

Understanding the financial and legal consequences of non-compliance

Civil Penalties

Up to $7,500

Per intentional violation

Data Breach Fines

$100-750

Per consumer per incident

Injunctive Relief

Variable

Court-ordered compliance measures

Important Note

The California Privacy Rights Act (CPRA), which went into effect in 2023, significantly expanded CCPA requirements and penalties. Hotels should ensure compliance with both CCPA and CPRA standards.

Automate Your CCPA Compliance

GuardStay handles all CCPA requirements automatically, from privacy policies to data subject requests

Get CCPA Compliant