CCPA / CPRA
Who needs it
Assess whether the business operates in California and meets the applicable revenue, data-volume or revenue-source thresholds. The adjusted annual revenue threshold is $26.625 million from 2025; other thresholds concern information about 100,000 consumers or households, or at least half of revenue from selling or sharing personal information.
Key requirements
Privacy notice at the point of collection, honoring consumer rights requests (access, deletion, correction, opt-out of sale/sharing), data minimization, and CPRA-required terms in contracts with service providers and third parties.
Cyber/privacy implications
The CCPA creates a private right of action for consumers following a data breach involving specific categories of personal information, not just regulator enforcement, which raises the stakes for demonstrable security controls.
Assessment methodology
Data inventory and mapping, an applicability-threshold assessment, a vendor and service-provider contract review, a rights-request process audit, and a security-control gap assessment against the "reasonable security" standard.
Implementation phases
Assess
Confirm applicability thresholds and map personal data flows and vendors.
Remediate
Update privacy notices, vendor contracts, and the rights-request handling process.
Evidence
Maintain rights-request logs and security control documentation in audit-ready form.
Evidence & documentation requirements
Privacy notices, service-provider and third-party data-processing agreements, rights-request logs, risk assessment records for high-risk processing, and documentation of the security controls protecting covered personal information.
Common mistakes
Assuming GDPR compliance automatically satisfies CCPA/CPRA (different rights, thresholds and enforcement mechanism); overlooking the private right of action tied to breaches of specific data categories; leaving vendor contracts without the CPRA-required service-provider terms.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your data handling stands against CCPA/CPRA before a consumer request or regulator asks.
Request a Gap Assessment →