CCPA Compliance for File Sharing: California Privacy Guide
Navigate CCPA compliance for file sharing services including consumer rights, data sale opt-outs, privacy notices, and California-specific requirements.
The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act (CPRA, effective 1 January 2023) applies to businesses handling California residents' personal information that meet one of three thresholds: $25M+ annual revenue, 100k+ consumers or households, or 50%+ revenue from selling or sharing personal information. For file sharing services, CCPA compliance means publishing a privacy notice meeting § 1798.130, honoring consumer requests to know, delete, correct, and opt out of sale/sharing within 45 days, implementing Global Privacy Control (GPC) signals, and executing service provider contracts under § 1798.140(ag) with every vendor processing data.
Who qualifies as a business, service provider, or third party
CCPA uses three roles. A "business" determines purposes and means (equivalent to GDPR controller) and bears the compliance load. A "service provider" processes on behalf of a business under a written contract (equivalent to processor). A "third party" is anyone else receiving data, typically for their own purposes. File transfer platforms are usually service providers — they handle personal information on behalf of the customer. The service provider contract under § 1798.140(ag) must prohibit retention, use, or disclosure for any purpose other than the specific business purpose, prohibit selling or sharing, and require the service provider to notify of any use that no longer qualifies.
Consumer rights under CPRA
The CPRA introduced five core rights: (1) right to know what personal information is collected, used, disclosed, or sold; (2) right to delete with exceptions for transaction completion, security, legal obligations; (3) right to correct inaccurate personal information; (4) right to opt out of sale or sharing; (5) right to limit use of sensitive personal information. Rights (1)-(3) must be honored within 45 days of request, extendable by another 45 days with notice. For file sharing services, implement: a "Do Not Sell or Share My Personal Information" link, a rights request form, identity verification procedures, and logs of fulfilled requests retained 24 months.
What counts as sensitive personal information
CPRA § 1798.140(ae) defines sensitive personal information: SSN, driver's license, state ID, passport number; account log-in with security credentials; precise geolocation (radius of 1,850 feet); racial or ethnic origin; religious or philosophical beliefs; union membership; contents of mail, email, and text messages not directed to the business; genetic data; biometric identifiers for unique identification; health information; sex life or sexual orientation. For file transfer services, file contents frequently include SPI — medical records, payment spreadsheets, scans of IDs. Consumers can direct businesses to limit SPI use to specific business purposes under § 1798.121.
Service provider contracts under § 1798.140(ag)
Every vendor touching California resident data needs a service provider contract. Required terms: (1) prohibit sale or sharing, (2) prohibit retention for any purpose other than the specific business purpose, (3) prohibit use outside the business context, (4) require compliance with CCPA obligations, (5) grant the business audit rights, (6) require the service provider to notify the business of sub-processors, (7) require assistance with consumer rights requests. File transfer providers publishing a CCPA-aligned service provider agreement — HexaTransfer, Box, Dropbox Business — make compliance a signature exercise. Providers without one need a custom amendment.
Privacy notice requirements under § 1798.130
The at-collection notice must identify categories of personal information collected and the purposes, and include a "Do Not Sell or Share" link if applicable. The full privacy policy must list all categories collected in the past 12 months, sources, business or commercial purposes, categories sold or shared (or statement that no sale/share occurs), categories disclosed for business purposes, and retention periods. Update the policy at least every 12 months. For file sharing products, the notice should cover: account data, uploaded content, metadata (IPs, timestamps), sub-processor list, and retention schedule.
Global Privacy Control and opt-out signals
CCPA regulations § 7025 require businesses that sell or share personal information to process the Global Privacy Control (GPC) as a valid opt-out signal. GPC is a browser setting (Firefox, Brave, DuckDuckGo; Chrome and Safari pending) that broadcasts a Sec-GPC: 1 header. Treating the signal as a valid consumer request is mandatory. For file sharing platforms that don't sell or share, GPC support is recommended but not strictly required. If the platform uses analytics that qualify as sharing (most cross-context behavioral advertising pixels), GPC must be honored — which often means disabling those pixels for GPC users.
The CPRA Agency and enforcement reality
The California Privacy Protection Agency (CPPA), established by CPRA, began enforcement in July 2023. Fines: $2,500 per violation, $7,500 per intentional violation or violation involving a minor. Violations accrue per consumer affected — a breach touching 10,000 California residents can hit $75M in theory. The CPPA has been active: first major enforcement action against Sephora (August 2022, $1.2M), second against DoorDash (February 2024, $375k), third and fourth against software companies in 2024 for service provider contract failures. The pattern: procedural violations (missing notices, missing contracts) get hit first; substantive violations (real harm) escalate.
Shine the Light Act and AB 1950 overlap
California's older Shine the Light Act (Cal. Civ. Code § 1798.83, effective 2005) predates CCPA and gives consumers the right to request disclosure of personal information shared with third parties for direct marketing. It remains in force alongside CCPA — respond to both. AB 1950 (Cal. Civ. Code § 1798.81.5) requires reasonable security for personal information of California residents — encryption, access controls, vendor management. Technical security for file transfer under AB 1950: AES-256 encryption, MFA for admin access, annual risk assessment. Violations trigger private right of action under § 1798.150 if a breach results from failure to implement reasonable security.
The private right of action
§ 1798.150 gives consumers a private right of action for breaches of non-encrypted, non-redacted personal information. Statutory damages: $100-$750 per consumer per incident or actual damages. A breach of a spreadsheet containing 100,000 California consumers' contact info plus SSNs could trigger a class action with $10M-$75M in exposure. The statutory safe harbor: encryption. If the leaked data was encrypted and the keys weren't compromised, the private right of action doesn't attach. This is why file sharing providers serving California customers default to AES-256 with strict key separation.
Practical compliance checklist
For a file sharing platform serving California users: (1) publish a CCPA-compliant privacy policy and update annually; (2) add a "Do Not Sell or Share" link even if you don't sell — document why it's a no-op; (3) build a rights request intake form with 45-day SLA; (4) implement identity verification (email confirmation plus one additional factor); (5) execute service provider contracts with every sub-processor; (6) honor GPC signals at the analytics layer; (7) retain records of requests for 24 months; (8) log access to personal information for audit; (9) encrypt everything at AES-256; (10) test the rights workflow quarterly.
Multi-state complications ahead
California isn't alone. Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and more than ten other states have enacted privacy laws with overlapping but not identical requirements. Building compliance around CCPA as the strictest common denominator usually covers the rest, but watch for state-specific wrinkles: Virginia requires DPIAs for certain processing; Colorado mandates universal opt-out mechanisms; Texas extends applicability based on targeting California residents. Use compliance tooling (OneTrust, DataGrail, Ethyca) to manage the matrix at scale.
California sets the floor; every US state is layering on top. Design for flexibility. Try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file