Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Honour California Privacy Rights

CCPA and CPRA Consumer Privacy Compliance

The CCPA gives California consumers rights over their personal information. We help you meet those rights, handle requests properly, and stay clear of enforcement.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights to know, delete, correct, and opt out of the sale or sharing of their personal information. It matters because it reaches any business that meets its thresholds, wherever they are based, and the California Privacy Protection Agency actively enforces it. We help you map the personal information you hold, build the request and opt-out mechanisms the law expects, and keep your notices honest.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the CCPA engagement, 6 phases in order, each one selectable. Phase 1, Applicability and Data Mapping. We confirm whether the CCPA applies to you and map the personal information you collect and share. Activities: Test revenue and data volume thresholds; Inventory personal information categories collected; Map sale and sharing flows to third parties; Flag sensitive personal information handling. Hands over Applicability Assessment and Personal Information Data Map. Phase 2, Gap Assessment. We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments. Activities: Review privacy notices against CPRA requirements; Test the opt-out links and request channels; Check request handling against the 45-day deadline; Rank gaps by enforcement exposure. Hands over CCPA Gap Assessment Report. Phase 3, Rights and Opt-Out Design. We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling. Activities: Build workflows for know, delete, and correct requests; Implement the do not sell or share link; Configure Global Privacy Control signal handling; Set up identity verification for requests. Hands over Consumer Rights Request Workflow. Phase 4, Notice and Disclosure Updates. We help you write privacy notices and disclosures at collection that match what you actually do. Activities: Rewrite the privacy policy per CPRA content rules; Draft notices at collection for each channel; Disclose categories collected, sold, and shared; Align retention statements with actual practice. Hands over Updated Privacy Notices and Disclosures. Phase 5, Vendor and Contract Review. We review service provider and contractor agreements so data sharing stays inside the law. Activities: Classify vendors as service providers, contractors, or third parties; Review contracts for required CCPA clauses; Remediate agreements that permit unrestricted use; Document the sharing relationships for disclosures. Hands over Vendor Classification and Contract Remediation List. Phase 6, Readiness Review. We run a final check so you can respond to a consumer or the regulator with confidence. Activities: Test the rights workflow with sample requests; Verify Global Privacy Control handling in production; Check notices against live data practices; Compile the compliance evidence pack. Hands over CCPA Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Applicability and Data Mapping

We confirm whether the CCPA applies to you and map the personal information you collect and share.

What Happens In This Phase

  • Test revenue and data volume thresholds
  • Inventory personal information categories collected
  • Map sale and sharing flows to third parties
  • Flag sensitive personal information handling

The Handover

Applicability Assessment and Personal Information Data Map

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Applicability and Data Mapping

    We confirm whether the CCPA applies to you and map the personal information you collect and share.

    OutputApplicability Assessment and Personal Information Data Map

    Activities

    • Test revenue and data volume thresholds
    • Inventory personal information categories collected
    • Map sale and sharing flows to third parties
    • Flag sensitive personal information handling
  2. 02

    Gap Assessment

    We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments.

    OutputCCPA Gap Assessment Report

    Activities

    • Review privacy notices against CPRA requirements
    • Test the opt-out links and request channels
    • Check request handling against the 45-day deadline
    • Rank gaps by enforcement exposure
  3. 03

    Rights and Opt-Out Design

    We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling.

    OutputConsumer Rights Request Workflow

    Activities

    • Build workflows for know, delete, and correct requests
    • Implement the do not sell or share link
    • Configure Global Privacy Control signal handling
    • Set up identity verification for requests
  4. 04

    Notice and Disclosure Updates

    We help you write privacy notices and disclosures at collection that match what you actually do.

    OutputUpdated Privacy Notices and Disclosures

    Activities

    • Rewrite the privacy policy per CPRA content rules
    • Draft notices at collection for each channel
    • Disclose categories collected, sold, and shared
    • Align retention statements with actual practice
  5. 05

    Vendor and Contract Review

    We review service provider and contractor agreements so data sharing stays inside the law.

    OutputVendor Classification and Contract Remediation List

    Activities

    • Classify vendors as service providers, contractors, or third parties
    • Review contracts for required CCPA clauses
    • Remediate agreements that permit unrestricted use
    • Document the sharing relationships for disclosures
  6. 06

    Readiness Review

    We run a final check so you can respond to a consumer or the regulator with confidence.

    OutputCCPA Readiness Report

    Activities

    • Test the rights workflow with sample requests
    • Verify Global Privacy Control handling in production
    • Check notices against live data practices
    • Compile the compliance evidence pack

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the CCPA scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Osano, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: California Consumer Privacy Act, California Privacy Rights Act, CPPA Regulations, Global Privacy Control, NIST Privacy Framework.

What We Run

7 tools

  • OneTrust
  • Securiti
  • TrustArc
  • Osano
  • BigID
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • CCPACalifornia
  • CPRACalifornia
  • CPPACaliforniaRegulations
  • GPCGlobal Privacy Control
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Applicability assessment
  • Personal information data map
  • Consumer rights request workflow
  • Updated privacy notices
  • Service provider agreement review

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does the CCPA apply to businesses outside California?

Yes, if you handle the personal information of California residents and meet the revenue or data thresholds. Location does not exempt you.

What is the Global Privacy Control?

It is a browser signal that tells you a consumer opts out of the sale or sharing of their data. The CCPA expects you to honour it automatically, and we help you set that up.

How quickly must we respond to a consumer request?

Generally within 45 days, with a possible extension. We build a workflow that tracks deadlines so nothing slips.

Keep Moving Through Compliance

Service 9 of 13 in this practice area