CCPA-CPRA Compliance

Having a Privacy Policy Isn’t CCPA-CPRA Compliance.

We help organisations understand their CCPA-CPRA obligations, map how California consumers’ personal information is collected and used, strengthen privacy controls, manage consumer rights and reduce regulatory risk — so privacy becomes an operational capability, not just a policy.

</SCOPE CHECK >

Does CCPA/CPRA apply to you?

CCPA/CPRA applies once you cross a revenue, data-volume, or data-sale threshold — regardless of where your company is based. A few quick questions, one clear answer.

01
Question 1 of 5
SECTOR

Which best describes your business?

Live readout
0% scope scan
  • Sector
  • Threshold met
  • Sale/share activity
  • Sensitive data
  • Existing program
// Preliminary indicator based on the CCPA as amended by the CPRA. Not legal advice, we confirm exact status in a formal assessment.
</ THE CCPA/CPRA GAP >

Most companies don’t fail CCPA/CPRA because they ignore California consumers. They fail because “we have a cookie banner” was never the same as honoring an opt-out.

CCPA/CPRA applies the moment you cross one of three thresholds — revenue, data volume, or data-sale revenue — regardless of where your company is based.

// PENALTY
$2,663–$7,988
per violation based on 2026 CPI-adjusted amounts for unintentional vs. intentional violations, plus $107–$799 per affected consumer in certain breach-related private actions.
// THRESHOLD
$25M+
revenue threshold, alongside thresholds for processing 100,000+ California consumers’ data or deriving 50%+ of revenue from selling personal information.
↳ regulatory exposure
// ENFORCEMENT BODY
CPPA
The California Privacy Protection Agency recalibrates CCPA/CPRA fine amounts every odd-numbered January.
// THIRD-PARTY RISK
60%
of enterprise buyers require security or compliance reviews before signing vendors.
WHAT CCPA/CPRA EXPECTS
Consumer privacy controls that actually work
A working “Do Not Sell or Share” mechanism, consumer requests for access, deletion and correction handled within statutory timelines, and documented disclosures covering the sale and sharing of personal information.
WHAT MOST COMPANIES HAVE
“We have a cookie banner”
A cookie banner that does not actually stop the sale or sharing it claims to gate, no structured consumer-request workflow, and no clear understanding of whether the organisation has crossed a CCPA/CPRA applicability threshold.

Most companies already have some privacy controls in place. The gap is knowing whether CCPA/CPRA applies, what personal information is being sold or shared, and whether consumer rights and opt-outs actually work across your systems and third parties. That’s where we help: turning CCPA/CPRA requirements into a practical privacy program that your organisation can actually operate and evidence.

</OUR APPROACH >

A Structured Approach to CCPA/CPRA Readiness.

We begin by assessing your current data practices against CCPA/CPRA’s consumer-rights requirements, identifying gaps in notice, opt-out, and data-sale disclosures, and prioritizing remediation. From implementing technical safeguards to documenting consumer-request workflows, we help you build an environment that is organized, defensible, and ready for regulatory scrutiny.

Map Requirements Stakeholder Interviews Consumer Rights & Sale/Share Mapping Current State Capture ▸ Scope Defined Plan to Close Gaps Action Plan Control Design Opt-Out & Notice Playbook ▸ Policy Drafts Test Before the Audit Mock Audit Evidence Validation Final Gap Closure ▸ Go / No-Go Assessment Stay Audit-Ready Ongoing Monitoring Annual Readiness Regulatory Updates ▸ Stay Compliant 01 Discover & Scope 02 Baseline Assessment 03 Remediation Roadmap 04 Implementation 05 Readiness Review 06 Audit Support 07 Continuous Compliance Find the Gaps Control Mapping Risk Prioritization Technical Review ▸ Gap Report Build & Deploy Technical Controls Process Rollout Policy Finalization ▸ Evidence Repository We Prep. You’re Ready. AG / CPPA Coordination Evidence Presentation Finding Response ▸ Inspection-Ready
</WHAT’S INCLUDED >

Everything You Need for CCPA-CPRA Readiness.

Every engagement produces practical, usable deliverables mapped to CCPA/CPRA requirements — from applicability and consumer rights to opt-out mechanisms, data mapping, privacy notices and ongoing compliance monitoring.

Assessment

CCPA/CPRA Applicability & Gap Assessment

Applicability thresholds, existing privacy practices and CCPA/CPRA control gaps assessed against your actual business and data environment.

Consumer Rights

Consumer Rights Request Process

Structured workflows for handling access, deletion, correction and opt-out requests within applicable CCPA/CPRA requirements and timelines.

Opt-Out Controls

Do Not Sell/Share Mechanism Implementation

Practical opt-out mechanisms implemented and aligned with requirements for the sale or sharing of consumers’ personal information.

Data Mapping

Data Inventory & Sale/Share Mapping

Personal information inventories mapped across systems, business processes, vendors and activities involving the sale or sharing of personal information.

Privacy Governance

Privacy Notice Rewrite

Privacy notices reviewed and rewritten to provide CCPA/CPRA-specific disclosures about collection, use, sale, sharing and consumer rights.

Sensitive Data

Sensitive Personal Information Controls

Controls and handling practices reviewed for sensitive personal information, including applicable use, disclosure, access and limitation requirements.

Third-Party Risk

Service Provider/Contractor Agreement Review

Service provider and contractor relationships reviewed for CCPA/CPRA obligations, data-handling responsibilities, restrictions and contractual safeguards.

Awareness

Employee Training

Practical training for employees on consumer-request handling, privacy responsibilities, escalation procedures and CCPA/CPRA obligations.

Ongoing

Ongoing Compliance Monitoring

Continuous monitoring of business growth, processing activities, privacy controls and applicability thresholds so emerging CCPA/CPRA obligations are identified early.

Typical engagement: scope and timeline depend on your business model, CCPA/CPRA applicability, consumer data volumes, sale or sharing activities, third-party ecosystem and current privacy maturity.
</BY THE NUMBERS >

Security work that shows up in the numbers.

Every engagement is measured, not just delivered.

0+
Security Engagements Delivered
0+
Vulnerabilities Identified
0+
Countries Served
0%
Client Satisfaction
</WHY BPDOXS >

The Right CCPA-CPRA Partner Makes All the Difference.

Recommended
Criteria
// Recommended BPDoxS
// In-house In-house team // Vendor Typical vendor
CCPA-CPRA Expertise
Practical expertise across CCPA/CPRA applicability, consumer rights, opt-outs, disclosures and operational privacy controls
Strong understanding of the business, but specialist California privacy expertise may depend on available internal resources
Specialist privacy firms may provide strong CCPA/CPRA knowledge where California privacy is part of their core service
Applicability & Threshold Assessment
Assesses revenue, consumer-data volume and sale/share activity to determine whether CCPA/CPRA obligations apply
Best visibility into company revenue, data volumes and business operations needed to assess applicability
Can assess thresholds when included in scope, but typically depends on information supplied by the client
Consumer Rights & Opt-Outs
Connects access, deletion, correction and opt-out workflows with the systems and teams responsible for fulfilling requests
Direct control over customer systems and internal teams makes ongoing request fulfilment highly manageable
Privacy specialists can design consumer-rights workflows and opt-out controls within the agreed engagement scope
Data Inventory & Sale/Share Mapping
Maps personal information across systems, business processes, vendors and activities involving sale or sharing
Strongest access to internal data sources, applications and operational knowledge needed for accurate inventory mapping
Can perform focused data-mapping exercises, but visibility is usually limited to the systems and scope defined by the client
Third-Party & Contract Risk
Reviews service providers, contractors, data-sharing relationships and contractual responsibilities across the privacy ecosystem
Strongest knowledge of existing vendors, contracts and operational relationships involving consumer information
Typically focuses on its own service or defined review scope rather than the client's complete third-party privacy ecosystem
Ongoing Compliance Readiness
Monitors business growth, processing changes, sale/share activities and applicability thresholds so emerging CCPA/CPRA gaps are identified early
Best positioned to own long-term privacy operations, provided sufficient internal resources and specialist knowledge remain available
Recurring support is possible, but a typical vendor cannot own the client's complete privacy posture across changing business activities
</TRUST & RECOGNITION >

Independently recognized.

Rated by clients on Clutch · GoodFirms · Sortlist · DesignRush · RightFirms

</Questions, answered >

Questions Worth Asking.

Everything you need to know before becoming CCPA-CPRA-ready with confidence.

CCPA/CPRA can apply to businesses that meet specific applicability thresholds relating to California consumers' personal information, including business revenue, the volume of consumers' information processed, or revenue derived from selling personal information. Applicability is not limited to companies physically located in California. We assess your business model, revenue, data volumes and processing activities to determine whether the law applies and which obligations are relevant.

If your business is subject to the applicable CCPA requirements and sells or shares personal information as defined by the law, consumers may have the right to opt out. Businesses also need to provide an appropriate mechanism for exercising that right and must properly honor valid opt-out requests. We help identify what constitutes sale or sharing in your environment and implement workflows and controls that make the opt-out effective across relevant systems and third parties.

Depending on the circumstances, California consumers have rights including access, deletion, correction, and opting out of the sale or sharing of personal information. The CPRA also provides additional protections concerning sensitive personal information. Organisations need practical processes for receiving, verifying, tracking and responding to applicable requests within the required timelines. We help build structured workflows that connect consumer requests to the systems and teams responsible for fulfilling them.

CCPA/CPRA uses specific definitions of "selling" and "sharing" that can cover more than a traditional exchange of customer data for money. Certain disclosures to advertising, analytics or other third parties may need to be assessed against these definitions. We map how personal information moves through your website, applications, advertising platforms, analytics tools, vendors and other third parties to identify relevant sale or sharing activities and the controls required for them.

Businesses subject to CCPA requirements need to provide specific disclosures about their collection and use of personal information, including information about categories of personal information collected, purposes of use and applicable consumer rights. The notice should accurately reflect the organisation's actual practices rather than simply copying a generic privacy template. We help review and rewrite privacy notices so the required CCPA/CPRA disclosures match your real data practices.

No. A privacy policy and cookie banner are only parts of a CCPA/CPRA compliance program. Organisations also need to understand applicability thresholds, map personal information, identify sale and sharing activities, provide and honor applicable consumer rights, manage service providers and contractors, address sensitive personal information requirements and maintain appropriate records and processes. We help turn these requirements into documented, operational controls that your teams can actually follow and evidence.

</LET'S GET YOU CCPA-CPRA-READY >

Know what data you collect and share. Know what needs to change.

Start with a practical assessment of your CCPA-CPRA applicability, personal information flows and existing privacy controls — then get a clear roadmap to close compliance gaps, strengthen consumer rights processes and build a privacy program your organisation can actually operate.

info@bpdoxs.com +91 77175 71863 Reply within 24 hours