Solutions / By Regulation

CCPA & CPRA compliance, on autopilot.

Honor every California consumer's right to know, delete, correct, and opt out of sale or sharing — across every web property, app, and downstream system you operate.

CCPA & CPRA at a glance
$7,500
max civil penalty per intentional violation
100K+
consumers triggers CCPA applicability
45 days
to respond to a verifiable consumer request
12 mo.
look-back window for disclosures

What is CCPA & CPRA?

Overview

The California Consumer Privacy Act (CCPA), expanded by the California Privacy Rights Act (CPRA), gives California residents broad rights over their personal information — including the right to access, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. The California Privacy Protection Agency (CPPA) and Attorney General actively enforce the law.

Who must comply

Typical applicability thresholds

  • Annual gross revenue over $25M, or
  • Buys/sells/shares PI of 100,000+ CA consumers, or
  • Derives 50%+ of revenue from selling/sharing PI
  • Service providers processing PI on your behalf

Key requirements

What CCPA & CPRA requires from your organization.

Notice at collection

Inform consumers at or before collection what categories of PI you collect and the purposes of use, with links to your privacy policy.

Right to opt out of sale/share

Provide a clear 'Do Not Sell or Share My Personal Information' link and honor Global Privacy Control (GPC) signals automatically.

Right to delete & correct

Verify identity and complete deletion or correction requests within 45 days, propagating to service providers.

Sensitive PI controls

Allow consumers to limit the use of sensitive personal information (precise geo, biometrics, health, etc.).

Service provider contracts

Maintain CPRA-compliant data processing agreements with vendors and contractors.

Risk & cybersecurity audits

Conduct and document annual cybersecurity audits and risk assessments for high-risk processing.

Penalties & enforcement

What's at stake

The CPPA and California AG can impose civil penalties of up to $2,500 per violation and $7,500 per intentional violation or violation involving minors. Consumers also have a private right of action for certain data breaches with statutory damages of $100–$750 per consumer per incident.

How Clarip helps

Operationalize CCPA & CPRA on one platform.

Clarip unifies consent, data discovery, subject rights, and regulatory reporting with workflows pre-configured for CCPA & CPRA.

Consent & GPC handling

  • Honor GPC signals automatically
  • Opt-out of sale/share preference center
  • Sensitive PI use limitation toggles

DSR automation

  • Verifiable consumer request portal
  • ID verification & deduplication
  • 45-day SLA tracking with audit log

Data mapping

  • Auto-discover PI across systems
  • Visualize data lineage
  • Inventory of vendors and processors

Risk assessments

  • Templated CCPA/CPRA risk assessments
  • Cybersecurity audit workpapers
  • Evidence retention by control

Notice management

  • Notice at collection generator
  • Privacy policy version control
  • Disclosure metrics dashboard

AI assistance

  • Auto-classify various categories of PI
  • Auto Detect PHI across websites/apps
  • Detect undisclosed data sales
FAQ

CCPA & CPRA compliance, answered.

Quick answers to the questions privacy, legal, and engineering teams most often ask about CCPA.

For-profit businesses doing business in California that meet any of: $25M+ in annual revenue; buy, sell, or share personal information of 100,000+ California consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Service providers and contractors handling personal information on behalf of covered businesses also have obligations.

The CPRA amends and expands the CCPA. It created the California Privacy Protection Agency, added the rights to correct and to limit the use of sensitive personal information, expanded the right to opt out to cover "sharing" for cross-context behavioral advertising, and introduced new requirements like risk assessments and cybersecurity audits.

Yes. The CPPA has confirmed that businesses must treat GPC as a valid opt-out of sale/share request from the user's browser or device. Clarip detects and processes GPC signals automatically across web properties.

Businesses must confirm receipt within 10 business days and substantively respond within 45 calendar days, with a one-time 45-day extension if needed and the consumer is notified.

Civil penalties up to $2,500 per violation, or $7,500 per intentional violation or one involving a minor. Consumers have a private right of action for certain breaches with statutory damages of $100–$750 per consumer per incident.

Clarip provides an end-to-end platform for CCPA/CPRA: cookie consent and GPC handling, a DSR portal with ID verification, automated data mapping and ROPA, vendor management with CPRA-compliant DPAs, and templated risk and cybersecurity assessments — all with audit-ready evidence.

Get Clarip and stay compliant with CCPA.

Book a 30-minute walkthrough and a custom gap assessment against CCPArequirements — mapped to the systems and vendors you already use.