CCPA: California privacy law
1) What is CCPA/CPRA and to whom is it applied
CCPA (California Consumer Privacy Act) is a California personal data protection law. CPRA (California Privacy Rights Act) - amendments expanding CCPA (in force from 01. 01. 2023).
To match (if at least one is in progress):- Annual revenue ≥ $25 million (global, not only from California);
- Data processing ≥ 100,000 consumers/households/devices per year;
- ≥50% of annual revenue from the sale or "sharing" of personal data.
Applies to "for-profit" businesses, including controlling/controlled companies with general branding. Exceptions: data already regulated by HIPAA/GLBA/FRCA/COPPA (within their scope), non-profit organizations (non-profit).
2) Key concepts
Personal Data (PI) - any information related to or reasonably associated with a consumer/household/device.
Sensitive personal data (SPI) - SSN number/passport/driver, financial details with access codes, geolocation with accuracy, racial and ethnic origin, religion, health/biometrics/genetics, private communications, etc.
Sale - Provide PI to a third party for value (not necessarily money).
Sharing - providing PI for behavioral advertising in different contexts (cross-context behavioral advertising), even without money.
Third Party/Service Provider/Contractor - categories of counterparties with different contractual requirements and restrictions on the use of PI.
3) Consumer rights (which must be implemented in the product)
1. Right to notification (notice at collection): what categories of data, goals, "sell/share" whether, shelf life.
2. Access (know) and portability: copies of categories and specific data for the last 12 months.
3. Delete: Must delete and notify the contractor/third party chain.
4. Correct: the right to request editing of inaccurate PIs.
- visible links "Do Not Sell or Share My Personal Information";
- GPC (Global Privacy Control) support - automatic browser/extension signal;
- 6. Limitation of SPI use: only for the stated purposes (for example, CUS/safety), at the request of the consumer - "limit use of sensitive PI."
- 7. Non-discrimination: services cannot be degraded for exercising rights (fair price programs are permissible if they comply with the law).
4) Notices and Privacy Policy
Notice at collection point: PI/SPI categories, goals, retention, sale/share status, links to opt-out.
Privacy Policy: rights, request methods (phone/web form/mail), recipient categories, retention period, sell/share PI, GPC support, verification/appeal procedures, date of last update.
5) Cookies, adtech и «sharing»
Any behavioral advertising in different contexts = "sharing" requires opt-out and GPC compliance.
For children <16: opt-in (up to 13 years - only with the consent of the parent/guardian).
Do not hide the refusal: banner/preference control center, understandable categories and a unified button "Do Not Sell or Share...."
Ensure that third-party SDKs/pixels comply with PI reuse bans after opt-out (through contracts and technical settings).
6) Contracts with suppliers and contractors
Contracts shall:- Prohibit secondary use of PIs other than as instructed by the controller.
- require security and incident notification;
- oblige to support consumer requests (delete/correct/opt-out) and pass them down the chain;
- grant audit/evaluation authority;
- identify sub-processors and their terms of engagement.
7) Child/youth data
13-16: the teenager's own opt-in.
Approved mechanisms for obtaining and storing evidence of consent, understandable interfaces for recall.
8) Security and incident liability
Duty to implement reasonable safety measures based on PI scope/sensitivity.
The private right to claim is limited to leaks caused by violation of security duties for certain categories of data: $100- $750 per user/incident (or actual damage).
Administrative supervision fines: up to $2,500 for violation and up to $7,500 for intentional violations and violations related to children.
An automatic "correction period" is no longer guaranteed (possible at the discretion of the regulator).
9) Storage and minimization
You want to publish retention periods by PI/SPI category or criteria for their definition.
It is forbidden to store longer than necessary for the stated purposes (data minimization).
Embed "Retention Schedule" + deletion/anonymization processes, cascade in backups.
10) Verification and DSR Appeals
Before issuing/deleting data - verification of the applicant (the level of verification depends on the sensitivity).
There should be a procedure for appealing refusals to the DSR with an understandable explanation.
11) Inquiry Register, Training and Documentation
Keep records of DSRs, SLA indicators/results, store justification of failures;
Annual training of personnel working with PI/DSR/advertising;
Data map: sources of PI, flows to suppliers/third parties, goals, legal grounds and sale/share statuses.
12) How CCPA/CPRA relates to GDPR (brief)
GDPR is broader in subjects and grounds, CCPA focuses on consumer rights and sales/sharing.
CCPA requires a GPC signal, a separate opt-out for sharing (behavioral advertising).
The SPI (CPRA) category is conceptually closer to the GDPR "special categories," but the regime is different: restriction of use/disclosure and a separate link/process.
GDPR has DPA/controller-processor and global legality; CCPA has strict service provider/contractor/third party contracts and sale/share management.
13) Implementation checklist (operational)
Policies and interfaces
- Update Privacy Policy and Notice at collection (PI/SPI categories, targets, retention, sale/share).
- Place "Do Not Sell or Share My PI" + "Limit Use of My SPI" where applicable.
- Enable GPC support; describe the behavior in politics.
- Separate processes for <13 and 13-16 (opt-in).
DSR Processes
- Request channels (web form/phone/mail), SLA 45 days, verification, appeals.
- Logging, reporting, response templates; accounting for a 12-month window for access.
Adtech и SDK
- Third party tag/pixel/SDK inventory, sale/share classification.
- Transfer of opt-out/GPC statuses down the chain; idioms restricted data processing.
- Test: No behavioral targeting after opt-out.
Contracts and Vendors
- DPA/contracts with service provider/contractor/third party with the necessary reservations.
- Sub-Processor Registry, Audit Privilege, No Recycling.
Storage and security
- Retention Schedule by PI/SPI Category, Deletion/Anonymization Plan.
- "Reasonable security measures": encryption, RBAC/ABAC, DLP, logs, IR plan tests.
- Procedure for recording/investigating incidents and notifications.
14) Category → action → interface matrix
15) Metrics and quality control
DSR SLAs:% closed on time; middle/95th percentile.
GPC Honor Rate: the proportion of sessions where the signal is correctly taken into account.
Opt-out Efficiency: percentage of adtech events after failure (should tend to 0).
Retention Adherence% of records deleted on schedule.
Incident MTTR/MTTD and repeatability.
Vendor Compliance: results of inspections/audits of counterparties.
16) Implementation Roadmap (6 steps)
1. Data mapping: sources, streams, tags/SDK, categories PI/SPI, sale/share.
2. Policies: Notice/Privacy Policy, DSR procedures, children's data, GPC.
3. UI and technical contours: links "Do Not Sell or Share...," "Limit SPI," banner, preference center, GPC.
4. Contracts: update the statuses of counterparties (service provider/contractor/third party), prohibitions on secondary use, subprocessors.
5. Retention & Security: storage schedules, deletion/anonymization, IR playbook.
6. Training and monitoring: trainings, metrics, regular audits/scoreboards for management.
17) Frequent mistakes and how to avoid them
To assume that "we are not selling data, then CCPA is not about us" is ignored by sharing.
Ignoring GPC is a violation, even if you have your own banner.
It is wrong to classify a contractor as a "service provider," allowing them to use PI for their own purposes.
Do not specify retention and criteria - required transparently.
Lack of evidence of applicant verification and DSR logs.
Total
CCPA/CPRA compliance is not one banner, but a system: transparent notifications and UI for rights, technical support for GPC and opt-out, correct contracts with suppliers, a data card with retention, and reliable DSR and security processes. By embedding these elements in architecture and operations, you reduce legal and reputational risks and maintain user trust without sacrificing product speed.