California's comprehensive privacy law protects 40 million residents with strict consumer rights and business obligations. We help you implement compliant data practices, respond to rights requests and avoid CPPA enforcement actions.
The California Consumer Privacy Act (CCPA), enacted in 2018 and effective January 1, 2020, created comprehensive privacy rights for California residents. The California Privacy Rights Act (CPRA), passed in 2020, significantly strengthened CCPA with amendments effective January 1, 2023.
Why this matters now: CPRA created the California Privacy Protection Agency (CPPA), California's dedicated privacy regulator with enforcement authority. The enhanced requirements include new consumer rights, sensitive PI protections and AI disclosure obligations.
California residents covered
Per intentional violation
Complements GDPR for global privacy compliance and integrates with EU AI Act for AI governance.
California revenue threshold
Annual gross revenues over $25 million
Data volume threshold
Buy, sell or share data of 100,000+ consumers/households
Revenue from data sales
50%+ of annual revenue from selling consumer PI
Companies processing CA residents
Doing business in California with consumer data
Service providers
Processing PI on behalf of covered businesses
Third parties
Receiving PI from businesses via sales/sharing
Comprehensive tools that address consumer rights, business obligations and CPPA enforcement risks
Automated workflows for processing Know, Delete, Correct, Opt-out and Limit requests within statutory deadlines. Track verification methods, response times and maintain complete audit trails for CPPA compliance.
Addresses: Right to Know, Delete, Correct, Opt-out, Limit
Comprehensive registry of personal information categories, collection sources, business purposes and third-party sharing. Maintain the detailed data maps CCPA requires for notice obligations.
Addresses: Privacy notice disclosures, data inventory requirements
Generate CCPA-compliant privacy notices that clearly disclose collection practices, consumer rights and contact information. Version control ensures historical compliance documentation.
Addresses: §1798.100-130 notice requirements
Register AI systems used for profiling and automated decisions. Document logic, significance and opt-out mechanisms as required by CPRA's ADMT provisions.
Addresses: CPRA §1798.185(a)(16) ADMT regulations
Track reasonable security procedures protecting personal information. Document technical, administrative and physical controls that demonstrate compliance with security obligations.
Addresses: §1798.150 security requirements
Maintain vendor contracts with required CCPA provisions. Monitor third-party processing activities and document compliance with service provider restrictions.
Addresses: §1798.140(w) service provider requirements
All consumer requests are timestamped with verification records, response dates and audit trails. This documentation demonstrates good-faith compliance efforts during CPPA investigations.
VerifyWise addresses all major compliance areas with dedicated workflows
CCPA/CPRA requirements
Requirements with platform support
Coverage across obligations
Know, delete, opt-out, correct, limit use
Privacy notices, data minimization, security
Automated decision-making disclosures
Categories, sources, purposes, sharing
Automated reminders for statutory response deadlines
Automated decision-making technology compliance tracking
Global Privacy Control and browser signal recognition
GDPR, EU AI Act and state privacy law integration
Six core rights California residents can exercise
Consumers can request disclosure of categories and specific pieces of personal information collected.
Key requirements
Consumers can request deletion of personal information with specified exceptions.
Key requirements
Opt-out of sale/sharing of personal information and targeted advertising.
Key requirements
Request correction of inaccurate personal information (CPRA addition).
Key requirements
Limit use and disclosure of sensitive personal information (CPRA addition).
Key requirements
Businesses cannot discriminate for exercising CCPA rights with limited exceptions.
Key requirements
What CCPA/CPRA requires from covered businesses
Inform consumers at or before collection about categories of PI collected and purposes
Deadline: At or before collection
Detailed disclosure of data practices, consumer rights and contact information
Deadline: Updated at least annually
Clear and conspicuous link on homepage for opt-out of sales/sharing
Deadline: Immediate implementation
Reasonable methods to verify consumer identity for rights requests
Deadline: Before responding to requests
Retain PI only as long as reasonably necessary for disclosed purposes
Deadline: Ongoing compliance
Service provider agreements with required CCPA provisions
Deadline: Before sharing data
A practical path to CCPA/CPRA compliance with clear milestones
CCPA/CPRA creates significant financial and legal risks
CPPA enforcement actions for violations
Consumer lawsuits for data breaches (§1798.150)
Beyond financial penalties
Data breaches affecting thousands of consumers can result in statutory damages multiplying to multimillion-dollar class actions. The private right of action under §1798.150 creates significant litigation risk even with reasonable security measures.
Access ready-to-use privacy policy templates aligned with CCPA/CPRA, GDPR and EU AI Act requirements
Common questions about CCPA/CPRA compliance
Start managing consumer rights requests, data inventories and privacy notices with our compliance platform.