SardineCon SF/2026

Learn More

What is CCPA?

SUBSCRIBE

The California Consumer Privacy Act gives California residents rights over their personal data, including the right to access, delete, and opt out of the sale of that data. For fraud and KYC teams, those rights can collide with the records you are legally required to keep.

What is the CCPA, in plain English?

The California Consumer Privacy Act is a data-privacy law, not an AML law, but it lands on the same desks. It gives California residents a set of rights over their personal information: the right to know what a business collects, the right to have it deleted, the right to opt out of its sale or sharing, and protection from being penalized for exercising those rights. Businesses that meet certain thresholds must honor these requests.

For a fraud or compliance team, the friction is obvious. A customer might send a deletion request for data you are required by AML rules to retain, or an access request that touches records tied to a suspicious activity investigation. The privacy right and the financial-crime obligation point in opposite directions.

The good news is that privacy laws like the CCPA generally include carve-outs for legal obligations and fraud prevention. You usually do not have to delete records you are legally required to keep, and you can generally keep using data to detect and prevent fraud. The skill is knowing exactly where those exceptions end.

Privacy rights versus AML duties

What changes

CCPA privacy right

AML or fraud duty

Deletion request

Customer can ask you to erase data.

Retention rules often require you to keep it.

Opt out of sale

Customer can refuse data sale or sharing.

Fraud-detection use generally has a carve-out.

Access request

Customer can ask what you hold.

SAR-related records may be withheld.

Default posture

Honor the right unless an exception applies.

Preserve records the law requires you to keep.

Who is involved?

Who

Their role

California residents

Hold the privacy rights and submit access, deletion, and opt-out requests.

Covered businesses

Firms meeting the thresholds that must honor requests and respect the law's limits.

Privacy and legal teams

Interpret requests, apply exemptions, and coordinate with compliance on conflicts.

Fraud and AML teams

Flag records that must be retained and uses that fall under fraud-prevention carve-outs.

What it looks like in practice

In practice

A customer who was recently the subject of an internal fraud investigation submits a request to delete all of their personal data. The privacy team routes it to compliance before acting, because deleting the wrong records could destroy evidence and breach retention rules.

Compliance confirms the records tie to a filed report and to AML retention duties, so those are preserved under the law's exemptions. Marketing and non-essential data outside any legal hold are deleted as requested. The customer's right is honored where it applies, and the protected records stay put.

Why it matters to operators

Fraud and AML teams handle exactly the kind of personal data privacy laws are designed to govern: identity documents, device data, transaction histories, and monitoring outputs. If you blindly honor every deletion request, you risk destroying records you are legally required to keep and undermining active investigations. If you ignore privacy law entirely, you expose the business to a different set of penalties.

The practical answer is to know where the fraud and AML exceptions end and ordinary privacy duties begin. Retention-required records and genuine fraud-prevention uses generally sit inside the carve-outs, but data collected and used for other purposes does not. Building that line into your request-handling process keeps both obligations satisfied.

Operator notes

  • Do not auto-delete. Route deletion requests through a check for legal holds and AML retention before acting.
  • Fraud use has cover. Using data to detect and prevent fraud generally falls under a carve-out, but document why.
  • Access is not unlimited. Records tied to suspicious activity reporting can and should be withheld from disclosure.
  • Scope the data. Marketing and non-essential data outside a legal hold can usually be deleted even when core records cannot.
  • It is one of many. The CCPA is a leading example, but similar state and global privacy laws create the same tension.

Quick questions

Does the CCPA force me to delete AML records?

Generally no. Privacy laws like the CCPA include exceptions for data you are legally required to retain, so records held under AML retention rules usually do not have to be deleted.

Can I still use customer data to fight fraud?

Yes, in most cases. Fraud detection and prevention typically fall within a carve-out. You should still document the purpose and limit use to what the exception covers.

Is the CCPA an AML law?

No. It is a consumer-privacy law. It matters to AML and fraud teams because it governs the personal data they collect and use, and its rights can conflict with financial-crime obligations.

What happens when a deletion request hits protected records?

You honor the request only for data not covered by an exception. Records under a legal hold or AML retention requirement are preserved, while other data may be deleted.

How is the CCPA different from the GDPR?

Both grant privacy rights and both include exceptions for legal duties, but they are separate laws with different scopes and mechanics. The GDPR covers the EU; the CCPA covers California residents.

Who should decide a conflicting request?

Privacy or legal teams typically own the request, but they should coordinate with fraud and AML before deleting or disclosing anything that could touch retained records or an investigation.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

What to know alongside CCPA