Honour California Privacy Rights
CCPA and CPRA Consumer Privacy Compliance
The CCPA gives California consumers rights over their personal information. We help you meet those rights, handle requests properly, and stay clear of enforcement.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights to know, delete, correct, and opt out of the sale or sharing of their personal information. It matters because it reaches any business that meets its thresholds, wherever they are based, and the California Privacy Protection Agency actively enforces it. We help you map the personal information you hold, build the request and opt-out mechanisms the law expects, and keep your notices honest.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the CCPA engagement, 6 phases in order, each one selectable. Phase 1, Applicability and Data Mapping. We confirm whether the CCPA applies to you and map the personal information you collect and share. Activities: Test revenue and data volume thresholds; Inventory personal information categories collected; Map sale and sharing flows to third parties; Flag sensitive personal information handling. Hands over Applicability Assessment and Personal Information Data Map. Phase 2, Gap Assessment. We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments. Activities: Review privacy notices against CPRA requirements; Test the opt-out links and request channels; Check request handling against the 45-day deadline; Rank gaps by enforcement exposure. Hands over CCPA Gap Assessment Report. Phase 3, Rights and Opt-Out Design. We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling. Activities: Build workflows for know, delete, and correct requests; Implement the do not sell or share link; Configure Global Privacy Control signal handling; Set up identity verification for requests. Hands over Consumer Rights Request Workflow. Phase 4, Notice and Disclosure Updates. We help you write privacy notices and disclosures at collection that match what you actually do. Activities: Rewrite the privacy policy per CPRA content rules; Draft notices at collection for each channel; Disclose categories collected, sold, and shared; Align retention statements with actual practice. Hands over Updated Privacy Notices and Disclosures. Phase 5, Vendor and Contract Review. We review service provider and contractor agreements so data sharing stays inside the law. Activities: Classify vendors as service providers, contractors, or third parties; Review contracts for required CCPA clauses; Remediate agreements that permit unrestricted use; Document the sharing relationships for disclosures. Hands over Vendor Classification and Contract Remediation List. Phase 6, Readiness Review. We run a final check so you can respond to a consumer or the regulator with confidence. Activities: Test the rights workflow with sample requests; Verify Global Privacy Control handling in production; Check notices against live data practices; Compile the compliance evidence pack. Hands over CCPA Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
What Happens In This Phase
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
The Handover
Applicability Assessment and Personal Information Data Map
The next phase starts from this.
Phase 01 Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
What Happens In This Phase
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
The Handover
Applicability Assessment and Personal Information Data Map
The next phase starts from this.
- 01
Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
OutputApplicability Assessment and Personal Information Data MapActivities
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
- 02
Gap Assessment
We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments.
OutputCCPA Gap Assessment ReportActivities
- Review privacy notices against CPRA requirements
- Test the opt-out links and request channels
- Check request handling against the 45-day deadline
- Rank gaps by enforcement exposure
- 03
Rights and Opt-Out Design
We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling.
OutputConsumer Rights Request WorkflowActivities
- Build workflows for know, delete, and correct requests
- Implement the do not sell or share link
- Configure Global Privacy Control signal handling
- Set up identity verification for requests
- 04
Notice and Disclosure Updates
We help you write privacy notices and disclosures at collection that match what you actually do.
OutputUpdated Privacy Notices and DisclosuresActivities
- Rewrite the privacy policy per CPRA content rules
- Draft notices at collection for each channel
- Disclose categories collected, sold, and shared
- Align retention statements with actual practice
- 05
Vendor and Contract Review
We review service provider and contractor agreements so data sharing stays inside the law.
OutputVendor Classification and Contract Remediation ListActivities
- Classify vendors as service providers, contractors, or third parties
- Review contracts for required CCPA clauses
- Remediate agreements that permit unrestricted use
- Document the sharing relationships for disclosures
- 06
Readiness Review
We run a final check so you can respond to a consumer or the regulator with confidence.
OutputCCPA Readiness ReportActivities
- Test the rights workflow with sample requests
- Verify Global Privacy Control handling in production
- Check notices against live data practices
- Compile the compliance evidence pack
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the CCPA scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Osano, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: California Consumer Privacy Act, California Privacy Rights Act, CPPA Regulations, Global Privacy Control, NIST Privacy Framework.
What We Run
7 tools
- Securiti
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- CCPACalifornia
- CPRACalifornia
- CPPACalifornia
- GPC
Deliverables
What You Receive
- Applicability assessment
- Personal information data map
- Consumer rights request workflow
- Updated privacy notices
- Service provider agreement review
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Does the CCPA apply to businesses outside California?
Yes, if you handle the personal information of California residents and meet the revenue or data thresholds. Location does not exempt you.
What is the Global Privacy Control?
It is a browser signal that tells you a consumer opts out of the sale or sharing of their data. The CCPA expects you to honour it automatically, and we help you set that up.
How quickly must we respond to a consumer request?
Generally within 45 days, with a possible extension. We build a workflow that tracks deadlines so nothing slips.
Keep Moving Through Compliance
Service 9 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.