California Consumer Privacy

    CCPA & CPRA ComplianceConsulting

    California's privacy laws, the CCPA and its successor CPRA, establish comprehensive consumer privacy rights and business obligations. Crestpoint Strategic helps organizations build practical compliance programs that balance consumer privacy with business operations.

    From opt-out mechanisms to consumer rights fulfillment, we build the infrastructure for sustainable California privacy compliance.

    What Are the CCPA and CPRA?

    The California Consumer Privacy Act (CCPA) was signed into law on June 28, 2018, and became effective on January 1, 2020. It was the first comprehensive state-level privacy law in the United States, granting California residents specific rights over their personal information and imposing obligations on businesses that collect or process that data.

    The California Privacy Rights Act (CPRA), approved by California voters in November 2020, significantly amends and expands the CCPA. CPRA provisions took effect on January 1, 2023, with a lookback period to January 1, 2022. Key additions include the creation of the California Privacy Protection Agency (CPPA), the first dedicated privacy enforcement agency in the U.S., and new concepts including sensitive personal information, cross-context behavioral advertising, and mandatory cybersecurity audits.

    Together, CCPA/CPRA apply to for-profit businesses meeting specific revenue, data volume, or revenue-derivation thresholds. The law has extraterritorial reach, meaning it applies to any qualifying business that collects personal information of California residents, regardless of where the business is headquartered.

    Consumer Rights Under CCPA/CPRA

    The CCPA and CPRA establish specific rights that California consumers can exercise with respect to their personal information.

    Right to Know

    Consumers have the right to request that businesses disclose what personal information they collect, the sources, the business purposes, the categories of third parties with whom data is shared, and the specific pieces of personal information collected.

    Right to Delete

    Consumers can request deletion of their personal information held by a business. Businesses must also direct service providers and contractors to delete the consumer's personal information.

    Right to Opt-Out of Sale/Sharing

    Consumers can opt out of the sale of their personal information and, under CPRA, the sharing of personal information for cross-context behavioral advertising purposes.

    Right to Correct

    Under CPRA, consumers have the right to request correction of inaccurate personal information that a business maintains about them.

    Right to Limit Use of Sensitive PI

    CPRA grants consumers the right to limit a business's use and disclosure of their sensitive personal information to purposes necessary for providing the requested goods or services.

    Right to Non-Discrimination

    Businesses cannot discriminate against consumers for exercising their CCPA/CPRA rights through denial of services, different pricing, different quality, or suggesting different treatment.

    Our CCPA/CPRA Compliance Services

    End-to-end consulting to achieve and maintain compliance with California's consumer privacy laws.

    CCPA/CPRA Compliance Audit

    Comprehensive assessment of data collection, sharing, and selling practices against CCPA and CPRA requirements. Identifies compliance gaps across your digital properties, marketing systems, and data processing operations.

    Do Not Sell/Share Implementation

    Technical implementation of 'Do Not Sell or Share My Personal Information' mechanisms including opt-out signals, Global Privacy Control (GPC) recognition, and opt-out preference management.

    Data Inventory & Mapping

    Systematic cataloging of all personal information collected, the sources of collection, business purposes, categories of third parties with whom data is shared or sold, and data retention practices.

    Privacy Notice & Disclosure Design

    Creation of CCPA-compliant privacy notices including required disclosures about data collection categories, purposes, consumer rights, and financial incentive programs.

    Consumer Rights Fulfillment

    Design and implementation of systems to handle consumer requests for access (right to know), deletion, correction, and opt-out of sale/sharing within the 45-day response window.

    Risk Assessment & DPIA

    Cybersecurity audits and risk assessments required under CPRA for processing that presents significant risk to consumer privacy, including automated decision-making and profiling.

    Vendor & Service Provider Management

    Contractual framework design for service providers, contractors, and third parties to ensure downstream compliance with CCPA/CPRA data processing limitations.

    Ongoing Compliance Advisory

    Retained advisory support for evolving CPPA regulations, AG enforcement actions, and CPRA rulemaking updates. Includes periodic compliance reviews and readiness assessments.

    CCPA/CPRA Penalties & Enforcement

    $2,500 per violation

    Unintentional violations: civil penalties imposed by the AG or CPPA.

    $7,500 per violation

    Intentional violations and violations involving minors' data.

    $100 to $750 per consumer

    Private right of action for data breaches due to failure to implement reasonable security.

    Why Choose Crestpoint Strategic for CCPA/CPRA Compliance

    Practitioner-led consulting with deep expertise in consent management, opt-out mechanisms, and privacy-first tracking

    Hands-on experience implementing GPC signal recognition and Do Not Sell/Share technical controls

    Cross-industry experience across e-commerce, SaaS, adtech, and digital media

    Implementation-focused: we build the technical systems that operationalize compliance

    Integrated approach connecting analytics, martech, advertising systems, and privacy compliance

    Ongoing advisory for CPPA rulemaking, AG enforcement actions, and evolving regulatory guidance

    Frequently Asked Questions About CCPA/CPRA

    What is the CCPA?

    The California Consumer Privacy Act (CCPA) is a state-level privacy law enacted in 2018 and effective from January 1, 2020. It grants California residents rights over their personal information and imposes obligations on businesses that collect, sell, or share personal information of California consumers. The CCPA was significantly amended and expanded by the California Privacy Rights Act (CPRA) in 2020, with CPRA provisions taking effect on January 1, 2023.

    What is the difference between CCPA and CPRA?

    CPRA (California Privacy Rights Act) is an amendment and expansion of the CCPA passed by California voters in November 2020. Key additions include: creation of the California Privacy Protection Agency (CPPA) for enforcement, new consumer rights (correction, limiting use of sensitive PI), expanded 'sharing' concept for cross-context behavioral advertising, mandatory risk assessments, and contractor-level obligations. CPRA provisions are generally effective from January 1, 2023.

    Who must comply with the CCPA/CPRA?

    CCPA/CPRA applies to for-profit businesses that collect California consumers' personal information AND meet at least one threshold: (1) annual gross revenue exceeding $25 million, (2) buy, sell, or share personal information of 100,000 or more consumers or households, or (3) derive 50% or more of annual revenue from selling or sharing consumers' personal information. The law applies regardless of where the business is physically located.

    What are the penalties for CCPA/CPRA violations?

    The California Attorney General can impose civil penalties of up to $2,500 per unintentional violation and up to $7,500 per intentional violation. CPRA also grants the CPPA enforcement authority. Consumers have a private right of action for data breaches resulting from a business's failure to implement reasonable security, with statutory damages of $100 to $750 per consumer per incident.

    What is the Global Privacy Control (GPC)?

    The Global Privacy Control (GPC) is a browser-level signal that communicates a consumer's opt-out preference for the sale or sharing of personal information. Under CPRA regulations, businesses must treat a GPC signal as a valid opt-out request. The California Attorney General has confirmed that failing to honor GPC signals constitutes a CCPA violation.

    What qualifies as 'selling' personal information under CCPA?

    Under CCPA, 'selling' means making personal information available to a third party for monetary or other valuable consideration. CPRA expands this with the concept of 'sharing,' which includes making personal information available for cross-context behavioral advertising, regardless of whether monetary consideration is exchanged. This broader definition captures many common digital advertising practices.

    Start Your CCPA/CPRA Compliance Journey

    Schedule a consultation to assess your California privacy compliance posture and build a practical compliance program.