CCPA Privacy FAQs: What is the statutory penalty for violation of the CCPA where there is no private right of action?

$2,500 for each violation and $7,500 for each intentional violation.

The CCPA only provides a private right of action to any consumer whose unencrypted sensitive-category information has been breached as a result of a business’s violation of its duty to “implement and maintain reasonable security procedures and practices.”1 But the California Attorney General may bring a civil action against any entity violating the act.  Specifically, the CCPA provides that “[a]ny business, service provider, or other person that violates this title shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation, which shall be assessed and recovered in a civil action brought in the name of the people of the State of California by the Attorney General.”2 The same section provides that these civil penalties may be assessed and recovered exclusively by the California Attorney General.