Honour California Privacy Rights
CCPA and CPRA Consumer Privacy Compliance
The CCPA, as amended by the CPRA, gives California residents rights over their personal information and reaches Indian companies that meet its thresholds. We help you confirm whether it applies, build the request and opt-out flows it expects, and keep your notices honest.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights to know, delete, correct and opt out of the sale or sharing of their personal information, and to limit the use of sensitive personal information. It applies to for-profit businesses that do business in California and meet one of its thresholds, wherever they are based, so an Indian SaaS or services company with Californian customers can fall within it. The California Privacy Protection Agency enforces it alongside the Attorney General, and its regulations continue to develop. We help Indian companies test applicability honestly, map the personal information they hold, and build request, opt-out and vendor processes that work.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the CCPA engagement, 6 phases in order, each one selectable. Phase 1, Applicability and Data Mapping. We confirm whether the CCPA applies to you and map the personal information you collect and share. Activities: Test revenue and data volume thresholds; Inventory personal information categories collected; Map sale and sharing flows to third parties; Flag sensitive personal information handling. Hands over Applicability Assessment and Personal Information Data Map. Phase 2, Gap Assessment. We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments. Activities: Review privacy notices against CPRA requirements; Test the opt-out links and request channels; Check request handling against the 45-day deadline; Rank gaps by enforcement exposure. Hands over CCPA Gap Assessment Report. Phase 3, Rights and Opt-Out Design. We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling. Activities: Build workflows for know, delete, and correct requests; Implement the do not sell or share link; Configure Global Privacy Control signal handling; Set up identity verification for requests. Hands over Consumer Rights Request Workflow. Phase 4, Notice and Disclosure Updates. We help you write privacy notices and disclosures at collection that match what you actually do. Activities: Rewrite the privacy policy per CPRA content rules; Draft notices at collection for each channel; Disclose categories collected, sold, and shared; Align retention statements with actual practice. Hands over Updated Privacy Notices and Disclosures. Phase 5, Vendor and Contract Review. We review service provider and contractor agreements so data sharing stays inside the law. Activities: Classify vendors as service providers, contractors, or third parties; Review contracts for required CCPA clauses; Remediate agreements that permit unrestricted use; Document the sharing relationships for disclosures. Hands over Vendor Classification and Contract Remediation List. Phase 6, Readiness Review. We run a final check so you can respond to a consumer or the regulator with confidence. Activities: Test the rights workflow with sample requests; Verify Global Privacy Control handling in production; Check notices against live data practices; Compile the compliance evidence pack. Hands over CCPA Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
What Happens In This Phase
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
The Handover
Applicability Assessment and Personal Information Data Map
The next phase starts from this.
Phase 01 Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
What Happens In This Phase
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
The Handover
Applicability Assessment and Personal Information Data Map
The next phase starts from this.
- 01
Applicability and Data Mapping
We confirm whether the CCPA applies to you and map the personal information you collect and share.
OutputApplicability Assessment and Personal Information Data MapActivities
- Test revenue and data volume thresholds
- Inventory personal information categories collected
- Map sale and sharing flows to third parties
- Flag sensitive personal information handling
- 02
Gap Assessment
We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments.
OutputCCPA Gap Assessment ReportActivities
- Review privacy notices against CPRA requirements
- Test the opt-out links and request channels
- Check request handling against the 45-day deadline
- Rank gaps by enforcement exposure
- 03
Rights and Opt-Out Design
We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling.
OutputConsumer Rights Request WorkflowActivities
- Build workflows for know, delete, and correct requests
- Implement the do not sell or share link
- Configure Global Privacy Control signal handling
- Set up identity verification for requests
- 04
Notice and Disclosure Updates
We help you write privacy notices and disclosures at collection that match what you actually do.
OutputUpdated Privacy Notices and DisclosuresActivities
- Rewrite the privacy policy per CPRA content rules
- Draft notices at collection for each channel
- Disclose categories collected, sold, and shared
- Align retention statements with actual practice
- 05
Vendor and Contract Review
We review service provider and contractor agreements so data sharing stays inside the law.
OutputVendor Classification and Contract Remediation ListActivities
- Classify vendors as service providers, contractors, or third parties
- Review contracts for required CCPA clauses
- Remediate agreements that permit unrestricted use
- Document the sharing relationships for disclosures
- 06
Readiness Review
We run a final check so you can respond to a consumer or the regulator with confidence.
OutputCCPA Readiness ReportActivities
- Test the rights workflow with sample requests
- Verify Global Privacy Control handling in production
- Check notices against live data practices
- Compile the compliance evidence pack
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
DPDP Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the CCPA scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Osano, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: California Consumer Privacy Act (as amended by the CPRA), CPPA Regulations, Global Privacy Control, ISO/IEC 27701:2025, NIST Privacy Framework.
What We Run
7 tools
- OneTrust
- Securiti
- TrustArc
- Osano
- BigID
- Jira
- Confluence
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- CCPACalifornia
- CPPACaliforniaRegulations
- GPCGlobal Privacy Control
- ISO/IEC 27701:2025
- NIST Privacy Framework
Deliverables
What You Receive
- Applicability assessment
- Personal information data map
- Consumer rights request workflow
- Updated privacy notices
- Service provider agreement review
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Does the CCPA apply to a company based in India?
It can. The law applies to for-profit businesses that do business in California, determine the purposes and means of processing Californians' personal information, and meet at least one threshold: annual gross revenue above the adjusted amount, which the California Privacy Protection Agency set at 26,625,000 dollars from 1 January 2025 and reviews in odd-numbered years; buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing personal information. Revenue is measured globally, not just in California. Indian companies more often meet the law indirectly, as service providers to a covered business, which brings contractual duties rather than the full set. We test applicability against your actual figures and contracts during scoping. Getting this wrong in either direction is costly: assuming the law applies creates work you do not owe, and assuming it does not can surface during a customer's due diligence at the worst moment.
What rights must we support, and how fast?
California residents can ask to know what personal information you collect and how you use it, to receive a copy, to delete it, to correct inaccuracies, to opt out of its sale or sharing, and to limit the use and disclosure of sensitive personal information. You must confirm receipt of a request within ten business days and respond substantively within 45 calendar days, with one further 45-day extension where reasonably necessary and the consumer is told why. You must offer at least two designated methods of contact, verify the requester, and not discriminate against people who exercise rights. We build a workflow that tracks every deadline, records verification and produces an auditable log, because missing dates is the most visible failure mode. We also make sure the request routes reach the systems that actually hold the data, including analytics and marketing tools, because a workflow that only covers the main database produces incomplete responses that a regulator would treat as a failure to comply.
What is the Global Privacy Control, and must we honour it?
The Global Privacy Control is a browser or extension signal that communicates a consumer's choice to opt out of the sale or sharing of their personal information. Under the CCPA regulations, a business that sells or shares personal information must treat such an opt-out preference signal as a valid request from that browser or device, without requiring the consumer to do anything more, and without a pop-up asking them to confirm. In practice that means your consent and tag management has to read the signal server-side or client-side and suppress the relevant advertising and analytics transfers, and your privacy notice has to describe how you honour it. We test the signal end to end, because the common failure is a banner that records the choice while trackers keep firing. We also check the signal is honoured for known users as well as anonymous browsers where you can link them, since that is a frequent gap in implementations built purely around cookie banners.
What does the CCPA require in contracts with vendors?
The law distinguishes service providers and contractors, which process personal information on your documented business purposes, from third parties, to whom a transfer may count as a sale or sharing. Keeping a vendor in the service provider category requires a written contract with specific terms: limits on retaining, using or disclosing the information outside the direct business relationship, a prohibition on combining it with data from other sources except as permitted, a commitment to comply with the law, your right to take steps to stop and remediate unauthorised use, and equivalent obligations flowed down to subcontractors. Without those terms, a disclosure can be treated as a sale, which triggers opt-out duties you may not have built. We review your vendor agreements and data flows together, because the contract and the actual transfer have to match. Where a vendor genuinely is a third party, we help you surface that in the notice and add the opt-out mechanism, rather than relabelling the relationship to avoid the obligation.
How does CCPA work differ from our DPDP Act or GDPR programme?
Most of the foundations are shared: knowing what personal information you hold and why, giving clear notice, honouring individual rights, securing the data and controlling vendors. One inventory and one rights process can serve all three. The differences are in the detail. The CCPA is threshold-based rather than universal, centres on the concepts of selling and sharing and on opt-out rather than opt-in consent, has its own notice-at-collection requirement and its own timelines, and requires honouring an automated opt-out signal. The DPDP Act relies mainly on consent and legitimate uses and follows the DPDP Rules for breaches, while the GDPR requires a lawful basis for every purpose. We build shared controls and document the California-specific handling rather than assuming one programme covers everything. We also keep the notices aligned, since California expects a notice at collection and specific disclosures that a GDPR privacy policy written for Europe does not automatically satisfy. One policy can serve both if it is structured for it.
Do CCPA obligations keep changing?
Yes, more than most privacy regimes, which is why we treat the programme as something to maintain rather than finish. The California Privacy Protection Agency adjusts the monetary thresholds for inflation in odd-numbered years, and it has been issuing and updating regulations covering areas such as risk assessments, cybersecurity audits and automated decision-making technology, with obligations phasing in over several years. Enforcement activity by the Agency and the Attorney General also signals where expectations are tightening. For a company outside the United States, the practical approach is to build the core rights, opt-out and vendor processes properly, then review applicability and new obligations annually against current regulations. We flag the items that apply to your business rather than describing every rule. We also recommend a scheduled annual review of applicability, because a growth year or a new advertising arrangement can bring a company over a threshold it comfortably sat below the year before, and the obligations arrive with it.
Keep Moving Through Compliance
Service 9 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Build a certifiable privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.