The CCPA (California Consumer Privacy Act, expanded by the CPRA) gives California residents rights over their personal information — including data collected through scraping — and applies to any business meeting its size or data-volume thresholds, regardless of where that business is located.
CCPA coverage turns on thresholds, not location: a business with $25 million or more in annual revenue, or one that buys, sells, or shares the personal information of 100,000 or more California consumers or households a year, or one that derives 50% or more of its revenue from selling or sharing personal information, is covered. A company with no office in California can still fall under the law the moment it processes California residents' data and crosses one of those thresholds.
That reach matters for scraping specifically: collecting data about California residents at meaningful scale, or reselling or sharing scraped datasets that include their personal information, can trigger CCPA obligations even for an out-of-state or international operation.
CCPA is opt-out-centric — consumers have the right to tell a business to stop selling or sharing their data — rather than GDPR's opt-in, lawful-basis-first model where you need a valid legal basis before processing begins at all. That's a materially lighter starting obligation, though not a lighter one once a consumer actually exercises their rights.
CCPA also defines "sale" and "sharing" broadly enough to catch some data-broker and ad-tech arrangements that don't look like a traditional sale on their face — relevant if scraped data is ever resold, licensed, or shared with a third party rather than used purely internally.
How Crawlora handles this
The same acceptable-use boundary that shapes Crawlora's approach to GDPR applies here — public, structured, low-sensitivity data by default, with the threshold and sale/sharing questions treated as real compliance work rather than assumed away because the source data was publicly visible.
Related reading
Glossary
FAQ
Yes, if the business meets one of the coverage thresholds (revenue, data volume, or share of revenue from selling personal information) and processes California residents' data — physical location doesn't exempt a business from the law.
CCPA is opt-out-centric — consumers ask a business to stop selling or sharing their data — while GDPR requires a valid legal basis before processing begins at all. CCPA's coverage also depends on specific revenue and data-volume thresholds, unlike GDPR's broader territorial scope.
It can, once you meet a coverage threshold and the data qualifies as personal information under the law — public availability doesn't automatically exempt it, similar to how GDPR treats publicly visible personal data.
Beyond CCPA (California Consumer Privacy Act), Crawlora's own docs cover the rest of the stack — browse the APIs, test a request in Playground, and move from scraping infrastructure work to production data workflows.