Any business collecting personal data of California residents that meets CCPA/CPRA thresholds: over $25M in annual revenue, or buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50%+ of revenue from selling or sharing personal information.
Privacy notice at the point of collection, honoring consumer rights requests (access, deletion, correction, opt-out of sale/sharing), data minimization, and CPRA-required terms in contracts with service providers and third parties.
The CCPA creates a private right of action for consumers following a data breach involving specific categories of personal information, not just regulator enforcement, which raises the stakes for demonstrable security controls.
Data inventory and mapping, an applicability-threshold assessment, a vendor and service-provider contract review, a rights-request process audit, and a security-control gap assessment against the "reasonable security" standard.
Confirm applicability thresholds and map personal data flows and vendors.
Update privacy notices, vendor contracts, and the rights-request handling process.
Maintain rights-request logs and security control documentation in audit-ready form.
Privacy notices, service-provider and third-party data-processing agreements, rights-request logs, risk assessment records for high-risk processing, and documentation of the security controls protecting covered personal information.
Assuming GDPR compliance automatically satisfies CCPA/CPRA (different rights, thresholds and enforcement mechanism); overlooking the private right of action tied to breaches of specific data categories; leaving vendor contracts without the CPRA-required service-provider terms.
See exactly where your data handling stands against CCPA/CPRA before a consumer request or regulator asks.
Request a Gap Assessment →