Reference Glossary
CCPA compliance
How a DAM operator handling California residents' personal information — identifiable photos, names in metadata — honors CCPA/CPRA rights to know, delete, correct, and opt out, if it meets the law's thresholds.
Why it matters in a DAM
CCPA only applies to for-profit businesses that clear at least one threshold — over $25 million in annual gross revenue, buying/selling/sharing personal information of 100,000 or more California consumers or households, or deriving 50% or more of revenue from selling personal information — so many mid-size DAM customers are outside its scope entirely, while others who assume they're too small actually cross the 100,000-consumer threshold quickly through marketing lists or web analytics tied to identifiable photos and profiles. When it does apply, a deletion request under the right to delete has to reach every copy of a Californian's personal information sitting in the DAM, including any downstream copy the CPRA now requires businesses to instruct third parties to delete as well.
A worked example
Common mistake
Treating CCPA as a smaller version of GDPR that applies the same way to any company with California customers or employees — CCPA has explicit revenue and volume thresholds, so smaller DAM customers may genuinely be exempt, while others wrongly assume exemption when their marketing data already crosses 100,000 consumers or households.
CCPA compliance is conditional in a way GDPR is not: the law only applies to a for-profit business that meets at least one of three thresholds — annual gross revenue over $25 million, buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or deriving 50% or more of annual revenue from selling personal information. A DAM vendor or customer that clears none of these thresholds is simply not subject to CCPA, which is a genuinely different starting point from GDPR’s much broader applicability.
Where it does apply, CCPA as amended by the CPRA gives California residents rights to know what personal information a business holds about them, to delete it, to correct inaccurate records, and to opt out of its sale or sharing, along with protection from discrimination for exercising those rights. For a DAM specifically, personal information can mean identifiable photos, names attached to testimonials or contributor credits, or contact details captured through a self-service portal — any of which could trigger a right-to-know or right-to-delete request that has to be honored across the library, not just in a customer database elsewhere in the company.
The CPRA also sharpened the deletion right: businesses that receive a deletion request must now notify and instruct any third parties who purchased or received that consumer’s personal information to delete it as well, and certain service providers and contractors must pass deletion requests downstream. For a DAM integrated with ad platforms, CDNs, or partner portals, that means a deletion request isn’t complete until it’s propagated to every system the asset or metadata was shared with.
Frequently asked
Does CCPA apply to every DAM customer with California users?
No — it only applies to a for-profit business meeting at least one threshold: over $25 million in annual revenue, buying/selling/sharing data of 100,000+ CA consumers or households, or deriving 50%+ of revenue from selling personal information.
How is CCPA applicability different from GDPR's?
GDPR applies far more broadly, while CCPA is conditional on explicit revenue and volume thresholds, so smaller DAM customers may genuinely be exempt.
What rights does CCPA/CPRA give California residents over DAM-held data?
Rights to know what personal information a business holds, to delete it, to correct inaccurate records, to opt out of its sale or sharing, and protection from discrimination for exercising those rights.
What counts as personal information in a DAM under CCPA?
Identifiable photos, names attached to testimonials or contributor credits, or contact details captured through a self-service portal.
How did the CPRA strengthen the right to delete?
Businesses that receive a deletion request must now notify and instruct third parties who purchased or received that consumer's personal information to delete it too, and some service providers must pass requests downstream.
What's a common mistake companies make about CCPA thresholds?
Assuming they're exempt without checking whether their marketing data already crosses the 100,000-consumer/household threshold through mailing lists or web analytics.
Sources
- CCPA applies to businesses meeting at least one of: over $25 million in annual gross revenue, buying/selling/sharing personal information of 100,000 or more California consumers or households, or deriving 50% or more of revenue from selling personal information. checked 2026-08-07 — California Attorney General — CCPA
- The CPRA requires businesses that receive a deletion request to notify and instruct third parties who purchased or received the consumer's personal information to delete it, and requires some service providers/contractors to pass deletion requests downstream. checked 2026-08-07 — IAPP — Top-10 operational impacts of the CPRA, Part 8: Rights to delete