Evaluate compliance with California Consumer Privacy Act and California Privacy Rights Act requirements for businesses handling California resident data
$25M+ annual revenue, OR 100k+ consumers/households, OR 50%+ revenue from selling PI
💡 If no, CCPA may not apply to your business
CCPA defines 11 categories including identifiers, commercial info, biometric, geolocation
SSN, financial accounts, precise geolocation, health data, genetic data, biometric data
At least 2 methods: toll-free number and website (email optional)
Deadline to provide information or deny request
Right to access: categories and specific pieces of PI
Right to delete with statutory exceptions (legal obligations, fraud prevention)
CPRA addition: right to correction of inaccurate PI
Prominent "Do Not Sell or Share My Personal Information" link required
Must disclose categories collected, purposes, 3rd party sharing, retention
Right to know, delete, correct, opt-out, non-discrimination
At or before collection: categories and purposes
Effective date and description of material changes required
CCPA has broad definition including advertising and cross-context behavioral advertising
Cannot request opt-in again for 12 months after opt-out
CPRA requires recognizing browser/device-level privacy signals
Contract must prohibit retention, use, or disclosure for purposes other than providing services
Service provider certification required in contract
Required under CCPA; enhanced for sensitive PI under CPRA
CPRA requires annual cybersecurity audits for high-risk businesses
Training for personnel handling consumer requests
Please answer all required questions to see your results