Logo GH

CCPA: California privacy law

1) What is CCPA/CPRA and to whom is it applied

CCPA (California Consumer Privacy Act) is a California personal data protection law. CPRA (California Privacy Rights Act) - amendments expanding CCPA (in force from 01. 01. 2023).

To match (if at least one is in progress):
  • Annual revenue ≥ $25 million (global, not only from California);
  • Data processing ≥ 100,000 consumers/households/devices per year;
  • ≥50% of annual revenue from the sale or "sharing" of personal data.

Applies to "for-profit" businesses, including controlling/controlled companies with general branding. Exceptions: data already regulated by HIPAA/GLBA/FRCA/COPPA (within their scope), non-profit organizations (non-profit).

2) Key concepts

Personal Data (PI) - any information related to or reasonably associated with a consumer/household/device.
Sensitive personal data (SPI) - SSN number/passport/driver, financial details with access codes, geolocation with accuracy, racial and ethnic origin, religion, health/biometrics/genetics, private communications, etc.
Sale - Provide PI to a third party for value (not necessarily money).
Sharing - providing PI for behavioral advertising in different contexts (cross-context behavioral advertising), even without money.
Third Party/Service Provider/Contractor - categories of counterparties with different contractual requirements and restrictions on the use of PI.

3) Consumer rights (which must be implemented in the product)

1. Right to notification (notice at collection): what categories of data, goals, "sell/share" whether, shelf life.
2. Access (know) and portability: copies of categories and specific data for the last 12 months.
3. Delete: Must delete and notify the contractor/third party chain.
4. Correct: the right to request editing of inaccurate PIs.

5. Opt-out from sale/sharing:
  • visible links "Do Not Sell or Share My Personal Information";
  • GPC (Global Privacy Control) support - automatic browser/extension signal;
  • 6. Limitation of SPI use: only for the stated purposes (for example, CUS/safety), at the request of the consumer - "limit use of sensitive PI."
  • 7. Non-discrimination: services cannot be degraded for exercising rights (fair price programs are permissible if they comply with the law).
💡 Response time to requests (DSR): usually 45 days (with a possible extension of another 45), free channel, applicant verification, logging.

4) Notices and Privacy Policy

Notice at collection point: PI/SPI categories, goals, retention, sale/share status, links to opt-out.
Privacy Policy: rights, request methods (phone/web form/mail), recipient categories, retention period, sell/share PI, GPC support, verification/appeal procedures, date of last update.

5) Cookies, adtech и «sharing»

Any behavioral advertising in different contexts = "sharing" requires opt-out and GPC compliance.
For children <16: opt-in (up to 13 years - only with the consent of the parent/guardian).

Do not hide the refusal: banner/preference control center, understandable categories and a unified button "Do Not Sell or Share...."

Ensure that third-party SDKs/pixels comply with PI reuse bans after opt-out (through contracts and technical settings).

6) Contracts with suppliers and contractors

Contracts shall:
  • Prohibit secondary use of PIs other than as instructed by the controller.
  • require security and incident notification;
  • oblige to support consumer requests (delete/correct/opt-out) and pass them down the chain;
  • grant audit/evaluation authority;
  • identify sub-processors and their terms of engagement.

7) Child/youth data

🚨 13 years: only opt-in parent for sale/sharing.

13-16: the teenager's own opt-in.
Approved mechanisms for obtaining and storing evidence of consent, understandable interfaces for recall.

8) Security and incident liability

Duty to implement reasonable safety measures based on PI scope/sensitivity.
The private right to claim is limited to leaks caused by violation of security duties for certain categories of data: $100- $750 per user/incident (or actual damage).
Administrative supervision fines: up to $2,500 for violation and up to $7,500 for intentional violations and violations related to children.
An automatic "correction period" is no longer guaranteed (possible at the discretion of the regulator).

9) Storage and minimization

You want to publish retention periods by PI/SPI category or criteria for their definition.
It is forbidden to store longer than necessary for the stated purposes (data minimization).
Embed "Retention Schedule" + deletion/anonymization processes, cascade in backups.

10) Verification and DSR Appeals

Before issuing/deleting data - verification of the applicant (the level of verification depends on the sensitivity).
There should be a procedure for appealing refusals to the DSR with an understandable explanation.

11) Inquiry Register, Training and Documentation

Keep records of DSRs, SLA indicators/results, store justification of failures;

Annual training of personnel working with PI/DSR/advertising;

Data map: sources of PI, flows to suppliers/third parties, goals, legal grounds and sale/share statuses.

12) How CCPA/CPRA relates to GDPR (brief)

GDPR is broader in subjects and grounds, CCPA focuses on consumer rights and sales/sharing.
CCPA requires a GPC signal, a separate opt-out for sharing (behavioral advertising).
The SPI (CPRA) category is conceptually closer to the GDPR "special categories," but the regime is different: restriction of use/disclosure and a separate link/process.
GDPR has DPA/controller-processor and global legality; CCPA has strict service provider/contractor/third party contracts and sale/share management.

13) Implementation checklist (operational)

Policies and interfaces

  • Update Privacy Policy and Notice at collection (PI/SPI categories, targets, retention, sale/share).
  • Place "Do Not Sell or Share My PI" + "Limit Use of My SPI" where applicable.
  • Enable GPC support; describe the behavior in politics.
  • Separate processes for <13 and 13-16 (opt-in).

DSR Processes

  • Request channels (web form/phone/mail), SLA 45 days, verification, appeals.
  • Logging, reporting, response templates; accounting for a 12-month window for access.

Adtech и SDK

  • Third party tag/pixel/SDK inventory, sale/share classification.
  • Transfer of opt-out/GPC statuses down the chain; idioms restricted data processing.
  • Test: No behavioral targeting after opt-out.

Contracts and Vendors

  • DPA/contracts with service provider/contractor/third party with the necessary reservations.
  • Sub-Processor Registry, Audit Privilege, No Recycling.

Storage and security

  • Retention Schedule by PI/SPI Category, Deletion/Anonymization Plan.
  • "Reasonable security measures": encryption, RBAC/ABAC, DLP, logs, IR plan tests.
  • Procedure for recording/investigating incidents and notifications.

14) Category → action → interface matrix

ScenarioMandatory actionWhere in UI
Behavioral advertisingOpt-out от sharing + GPCBanner/Preference Center + Footer
Value transferOpt-out by saleFooter/Privacy Settings
SPI processingLimit use of SPIPrivacy Page/Preference Center
Access/Delete/Fix RequestDSR form + verificationPrivacy Profile/Center
Children <16Opt-in (parent/user)Registration/Settings

15) Metrics and quality control

DSR SLAs:% closed on time; middle/95th percentile.
GPC Honor Rate: the proportion of sessions where the signal is correctly taken into account.
Opt-out Efficiency: percentage of adtech events after failure (should tend to 0).
Retention Adherence% of records deleted on schedule.
Incident MTTR/MTTD and repeatability.
Vendor Compliance: results of inspections/audits of counterparties.

16) Implementation Roadmap (6 steps)

1. Data mapping: sources, streams, tags/SDK, categories PI/SPI, sale/share.
2. Policies: Notice/Privacy Policy, DSR procedures, children's data, GPC.
3. UI and technical contours: links "Do Not Sell or Share...," "Limit SPI," banner, preference center, GPC.
4. Contracts: update the statuses of counterparties (service provider/contractor/third party), prohibitions on secondary use, subprocessors.
5. Retention & Security: storage schedules, deletion/anonymization, IR playbook.
6. Training and monitoring: trainings, metrics, regular audits/scoreboards for management.

17) Frequent mistakes and how to avoid them

To assume that "we are not selling data, then CCPA is not about us" is ignored by sharing.
Ignoring GPC is a violation, even if you have your own banner.
It is wrong to classify a contractor as a "service provider," allowing them to use PI for their own purposes.
Do not specify retention and criteria - required transparently.
Lack of evidence of applicant verification and DSR logs.

Total

CCPA/CPRA compliance is not one banner, but a system: transparent notifications and UI for rights, technical support for GPC and opt-out, correct contracts with suppliers, a data card with retention, and reliable DSR and security processes. By embedding these elements in architecture and operations, you reduce legal and reputational risks and maintain user trust without sacrificing product speed.

Contact

Get in Touch

Reach out with any questions or support needs.We are always ready to help!

Telegram
@Gamble_GC
Start Integration

Email is required. Telegram or WhatsApp — optional.

Your Name optional
Email optional
Subject optional
Message optional
Telegram optional
@
If you include Telegram — we will reply there as well, in addition to Email.
WhatsApp optional
Format: +country code and number (e.g., +380XXXXXXXXX).

By clicking this button, you agree to data processing.