Asurvo
Privacy framework

Run CCPA/CPRA with
confidence.

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California consumers specific rights over their personal information and imposes obligations on businesses that collect, use, or sell it.

Who it's for

Businesses that handle the personal information of California residents.

Scope

Consumer-rights and business obligations

Category
Privacy

How Asurvo helps

What you get for CCPA/CPRA.

Consumer rights request workflows
Personal information inventory
Sale / sharing opt-out tracking
Cross-mapped to GDPR

California privacy

Turning CCPA and CPRA obligations into an operating program

The California Consumer Privacy Act (CCPA) took effect in 2020 and was substantially amended by the California Privacy Rights Act (CPRA), a ballot measure approved by voters in November 2020. Most CPRA amendments became operative on January 1, 2023. Unlike a certifiable standard, this is law: there is no certificate to earn, only obligations to meet and records that show you meet them when a regulator or plaintiff asks.

Does the law apply to you?

The CCPA applies to a for-profit "business" that does business in California, collects consumers' personal information (or has it collected on its behalf), determines the purposes and means of processing, and meets at least one of three thresholds. "Consumer" means any California resident, which since 2023 includes employees, job applicants, and business contacts.

Applicability thresholds (meet any one)

Applicability thresholds (meet any one)
Annual gross revenue above the statutory figureThe CPRA set this at $25 million and requires periodic adjustment for inflation. Confirm the current adjusted figure published by the CPPA.
Volume of consumersBuys, sells, or shares the personal information of 100,000 or more consumers or households per year
Revenue from dataDerives 50% or more of annual revenue from selling or sharing consumers' personal information

Who enforces it

The CPRA created the California Privacy Protection Agency (CPPA), a dedicated regulator with rulemaking, audit, and administrative enforcement powers. The California Attorney General retains civil enforcement authority. The CPRA also removed the automatic 30-day cure period businesses previously relied on. Consumers have a limited private right of action for data breaches caused by a failure to maintain reasonable security, which makes your security program part of your privacy exposure.

The rights you must operationalize

  • Right to know and access the categories and specific pieces of personal information collected, including in a portable format.
  • Right to delete personal information, subject to exceptions, and to pass deletion on to service providers and contractors.
  • Right to correct inaccurate personal information (added by the CPRA).
  • Right to opt out of sale or sharing, where "sharing" means disclosure for cross-context behavioral advertising (added by the CPRA). Opt-out preference signals such as Global Privacy Control must be honored.
  • Right to limit use and disclosure of sensitive personal information to purposes the regulations permit (added by the CPRA).
  • Right to non-discrimination and no retaliation for exercising these rights, including against employees and applicants.

Sensitive personal information is a defined category that includes government identifiers, account log-in credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of certain communications, genetic and biometric data, and health, sex life, or sexual orientation data. Tag these fields in your data inventory early, because they drive notice language, the limit-use right, and retention decisions.

Building the program in five workstreams

  1. Data inventory. Record categories of personal information, sources, purposes, recipients, retention periods, and whether each disclosure is a sale, a share, or a service provider transfer.
  2. Notices. Publish a notice at collection and a privacy policy reviewed at least every 12 months, including retention periods by category. Add the required opt-out links where you sell, share, or use sensitive data beyond permitted purposes.
  3. Request handling. Stand up intake methods, identity verification proportionate to the request, and tracking against regulatory response deadlines, which are set in the statute and CPPA regulations.
  4. Contracts. Update agreements with service providers, contractors, and third parties to include the terms the law requires, such as purpose limitations and restrictions on combining data. Your vendor risk program is the natural home for this.
  5. Security and assessments. Maintain reasonable security procedures and track the CPPA's regulations on cybersecurity audits, risk assessments, and automated decisionmaking technology, which phase in over several years.

Records that demonstrate compliance

Obligation, Record to keep, Owner comparison
TransparencyVersioned privacy policy and notices at collection with review datesLegal / privacy
Consumer requestsRequest log with dates received and closed, verification method, and outcomePrivacy operations
Opt-outsEvidence opt-out links and preference signals work, and downstream suppressionEngineering / marketing
Service providersExecuted contracts with required CCPA terms; vendor inventoryProcurement / security
TrainingRecords showing staff handling requests are trained on the requirementsPrivacy / HR
Reasonable securityRisk assessment, control evidence, incident recordsSecurity

Common gaps

  • Employee and applicant data left out of scope, even though the former exemptions expired on January 1, 2023
  • Advertising pixels and SDKs that constitute "sharing" but are not covered by the opt-out
  • Global Privacy Control signals detected in the browser but not applied to server-side data flows
  • Retention periods written in the policy that no deletion job actually enforces
  • Service provider agreements signed before 2023 that lack the CPRA-required contract terms

Overlap with GDPR and ISO 27701, and where Asurvo fits

If you already run a GDPR program, your records of processing, DSR workflow, and processor contracts carry over, although CCPA's sale and sharing concepts and opt-out model differ from GDPR's lawful bases. An ISO 27701 PIMS gives both laws a management system to live in. Asurvo cross-maps CCPA/CPRA with GDPR and ISO 27701 so shared controls are evidenced once, while Third Party tracks vendor contracts and questionnaires and the policy center versions your notices and records approvals.

FAQ

Frequently asked questions

Is CPRA a separate law from CCPA?

No. The CPRA amended and expanded the CCPA rather than replacing it. People often write CCPA/CPRA to refer to the law as amended. The CPRA added rights such as correction and limiting use of sensitive personal information, introduced the concept of sharing for cross-context behavioral advertising, and created the California Privacy Protection Agency.

Does the CCPA cover employee data?

Yes. Earlier temporary exemptions for employee, job applicant, and business-to-business contact information expired on January 1, 2023. Covered businesses now need to give these individuals notices and honor their rights, subject to the exceptions in the law. HR systems and recruiting tools should be included in your personal information inventory.

What counts as sharing under the CPRA?

Sharing means disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. Advertising cookies, pixels, and SDKs that pass identifiers to ad platforms commonly fall under this definition. Consumers can opt out of sharing, and businesses must honor opt-out preference signals like Global Privacy Control.

Can a company be certified as CCPA compliant?

There is no official CCPA certification issued by the state or the CPPA. Companies demonstrate compliance through documentation, working processes, and records such as request logs and vendor contracts. Frameworks like ISO 27701 can provide independently audited evidence of a privacy management system, but that is not a legal certification of CCPA compliance.

How does the CCPA relate to security controls?

The law requires businesses to implement reasonable security procedures appropriate to the nature of the personal information, and it gives consumers a private right of action for certain breaches resulting from a failure to do so. The CPPA has also finalized regulations requiring cybersecurity audits for some businesses, so a documented, evidenced security program directly reduces privacy exposure.

Ready to run CCPA/CPRA on Asurvo?

Book a walkthrough and see the framework live.