Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Honour California Privacy Rights

CCPA and CPRA Consumer Privacy Compliance

The CCPA, as amended by the CPRA, gives California residents rights over their personal information and reaches Indian companies that meet its thresholds. We help you confirm whether it applies, build the request and opt-out flows it expects, and keep your notices honest.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights to know, delete, correct and opt out of the sale or sharing of their personal information, and to limit the use of sensitive personal information. It applies to for-profit businesses that do business in California and meet one of its thresholds, wherever they are based, so an Indian SaaS or services company with Californian customers can fall within it. The California Privacy Protection Agency enforces it alongside the Attorney General, and its regulations continue to develop. We help Indian companies test applicability honestly, map the personal information they hold, and build request, opt-out and vendor processes that work.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the CCPA engagement, 6 phases in order, each one selectable. Phase 1, Applicability and Data Mapping. We confirm whether the CCPA applies to you and map the personal information you collect and share. Activities: Test revenue and data volume thresholds; Inventory personal information categories collected; Map sale and sharing flows to third parties; Flag sensitive personal information handling. Hands over Applicability Assessment and Personal Information Data Map. Phase 2, Gap Assessment. We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments. Activities: Review privacy notices against CPRA requirements; Test the opt-out links and request channels; Check request handling against the 45-day deadline; Rank gaps by enforcement exposure. Hands over CCPA Gap Assessment Report. Phase 3, Rights and Opt-Out Design. We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling. Activities: Build workflows for know, delete, and correct requests; Implement the do not sell or share link; Configure Global Privacy Control signal handling; Set up identity verification for requests. Hands over Consumer Rights Request Workflow. Phase 4, Notice and Disclosure Updates. We help you write privacy notices and disclosures at collection that match what you actually do. Activities: Rewrite the privacy policy per CPRA content rules; Draft notices at collection for each channel; Disclose categories collected, sold, and shared; Align retention statements with actual practice. Hands over Updated Privacy Notices and Disclosures. Phase 5, Vendor and Contract Review. We review service provider and contractor agreements so data sharing stays inside the law. Activities: Classify vendors as service providers, contractors, or third parties; Review contracts for required CCPA clauses; Remediate agreements that permit unrestricted use; Document the sharing relationships for disclosures. Hands over Vendor Classification and Contract Remediation List. Phase 6, Readiness Review. We run a final check so you can respond to a consumer or the regulator with confidence. Activities: Test the rights workflow with sample requests; Verify Global Privacy Control handling in production; Check notices against live data practices; Compile the compliance evidence pack. Hands over CCPA Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Applicability and Data Mapping

We confirm whether the CCPA applies to you and map the personal information you collect and share.

What Happens In This Phase

  • Test revenue and data volume thresholds
  • Inventory personal information categories collected
  • Map sale and sharing flows to third parties
  • Flag sensitive personal information handling

The Handover

Applicability Assessment and Personal Information Data Map

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Applicability and Data Mapping

    We confirm whether the CCPA applies to you and map the personal information you collect and share.

    OutputApplicability Assessment and Personal Information Data Map

    Activities

    • Test revenue and data volume thresholds
    • Inventory personal information categories collected
    • Map sale and sharing flows to third parties
    • Flag sensitive personal information handling
  2. 02

    Gap Assessment

    We check your notices, opt-out mechanisms, and processes against the CCPA and CPRA amendments.

    OutputCCPA Gap Assessment Report

    Activities

    • Review privacy notices against CPRA requirements
    • Test the opt-out links and request channels
    • Check request handling against the 45-day deadline
    • Rank gaps by enforcement exposure
  3. 03

    Rights and Opt-Out Design

    We build the consumer request workflow and the opt-out signals, including Global Privacy Control handling.

    OutputConsumer Rights Request Workflow

    Activities

    • Build workflows for know, delete, and correct requests
    • Implement the do not sell or share link
    • Configure Global Privacy Control signal handling
    • Set up identity verification for requests
  4. 04

    Notice and Disclosure Updates

    We help you write privacy notices and disclosures at collection that match what you actually do.

    OutputUpdated Privacy Notices and Disclosures

    Activities

    • Rewrite the privacy policy per CPRA content rules
    • Draft notices at collection for each channel
    • Disclose categories collected, sold, and shared
    • Align retention statements with actual practice
  5. 05

    Vendor and Contract Review

    We review service provider and contractor agreements so data sharing stays inside the law.

    OutputVendor Classification and Contract Remediation List

    Activities

    • Classify vendors as service providers, contractors, or third parties
    • Review contracts for required CCPA clauses
    • Remediate agreements that permit unrestricted use
    • Document the sharing relationships for disclosures
  6. 06

    Readiness Review

    We run a final check so you can respond to a consumer or the regulator with confidence.

    OutputCCPA Readiness Report

    Activities

    • Test the rights workflow with sample requests
    • Verify Global Privacy Control handling in production
    • Check notices against live data practices
    • Compile the compliance evidence pack

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

DPDP Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the CCPA scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Osano, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: California Consumer Privacy Act (as amended by the CPRA), CPPA Regulations, Global Privacy Control, ISO/IEC 27701:2025, NIST Privacy Framework.

What We Run

7 tools

  • OneTrust
  • Securiti
  • TrustArc
  • Osano
  • BigID
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • CCPACalifornia
  • CPPACaliforniaRegulations
  • GPCGlobal Privacy Control
  • ISO/IEC 27701:2025
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Applicability assessment
  • Personal information data map
  • Consumer rights request workflow
  • Updated privacy notices
  • Service provider agreement review

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does the CCPA apply to a company based in India?

It can. The law applies to for-profit businesses that do business in California, determine the purposes and means of processing Californians' personal information, and meet at least one threshold: annual gross revenue above the adjusted amount, which the California Privacy Protection Agency set at 26,625,000 dollars from 1 January 2025 and reviews in odd-numbered years; buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing personal information. Revenue is measured globally, not just in California. Indian companies more often meet the law indirectly, as service providers to a covered business, which brings contractual duties rather than the full set. We test applicability against your actual figures and contracts during scoping. Getting this wrong in either direction is costly: assuming the law applies creates work you do not owe, and assuming it does not can surface during a customer's due diligence at the worst moment.

What rights must we support, and how fast?

California residents can ask to know what personal information you collect and how you use it, to receive a copy, to delete it, to correct inaccuracies, to opt out of its sale or sharing, and to limit the use and disclosure of sensitive personal information. You must confirm receipt of a request within ten business days and respond substantively within 45 calendar days, with one further 45-day extension where reasonably necessary and the consumer is told why. You must offer at least two designated methods of contact, verify the requester, and not discriminate against people who exercise rights. We build a workflow that tracks every deadline, records verification and produces an auditable log, because missing dates is the most visible failure mode. We also make sure the request routes reach the systems that actually hold the data, including analytics and marketing tools, because a workflow that only covers the main database produces incomplete responses that a regulator would treat as a failure to comply.

What is the Global Privacy Control, and must we honour it?

The Global Privacy Control is a browser or extension signal that communicates a consumer's choice to opt out of the sale or sharing of their personal information. Under the CCPA regulations, a business that sells or shares personal information must treat such an opt-out preference signal as a valid request from that browser or device, without requiring the consumer to do anything more, and without a pop-up asking them to confirm. In practice that means your consent and tag management has to read the signal server-side or client-side and suppress the relevant advertising and analytics transfers, and your privacy notice has to describe how you honour it. We test the signal end to end, because the common failure is a banner that records the choice while trackers keep firing. We also check the signal is honoured for known users as well as anonymous browsers where you can link them, since that is a frequent gap in implementations built purely around cookie banners.

What does the CCPA require in contracts with vendors?

The law distinguishes service providers and contractors, which process personal information on your documented business purposes, from third parties, to whom a transfer may count as a sale or sharing. Keeping a vendor in the service provider category requires a written contract with specific terms: limits on retaining, using or disclosing the information outside the direct business relationship, a prohibition on combining it with data from other sources except as permitted, a commitment to comply with the law, your right to take steps to stop and remediate unauthorised use, and equivalent obligations flowed down to subcontractors. Without those terms, a disclosure can be treated as a sale, which triggers opt-out duties you may not have built. We review your vendor agreements and data flows together, because the contract and the actual transfer have to match. Where a vendor genuinely is a third party, we help you surface that in the notice and add the opt-out mechanism, rather than relabelling the relationship to avoid the obligation.

How does CCPA work differ from our DPDP Act or GDPR programme?

Most of the foundations are shared: knowing what personal information you hold and why, giving clear notice, honouring individual rights, securing the data and controlling vendors. One inventory and one rights process can serve all three. The differences are in the detail. The CCPA is threshold-based rather than universal, centres on the concepts of selling and sharing and on opt-out rather than opt-in consent, has its own notice-at-collection requirement and its own timelines, and requires honouring an automated opt-out signal. The DPDP Act relies mainly on consent and legitimate uses and follows the DPDP Rules for breaches, while the GDPR requires a lawful basis for every purpose. We build shared controls and document the California-specific handling rather than assuming one programme covers everything. We also keep the notices aligned, since California expects a notice at collection and specific disclosures that a GDPR privacy policy written for Europe does not automatically satisfy. One policy can serve both if it is structured for it.

Do CCPA obligations keep changing?

Yes, more than most privacy regimes, which is why we treat the programme as something to maintain rather than finish. The California Privacy Protection Agency adjusts the monetary thresholds for inflation in odd-numbered years, and it has been issuing and updating regulations covering areas such as risk assessments, cybersecurity audits and automated decision-making technology, with obligations phasing in over several years. Enforcement activity by the Agency and the Attorney General also signals where expectations are tightening. For a company outside the United States, the practical approach is to build the core rights, opt-out and vendor processes properly, then review applicability and new obligations annually against current regulations. We flag the items that apply to your business rather than describing every rule. We also recommend a scheduled annual review of applicability, because a growth year or a new advertising arrangement can bring a company over a threshold it comfortably sat below the year before, and the obligations arrive with it.

Keep Moving Through Compliance

Service 9 of 13 in this practice area