The CCPA and its CPRA amendment apply to any for-profit business meeting one of three thresholds — extraterritorial in practice. We deliver the Notice at Collection, Do Not Sell or Share link, Limit Use of Sensitive Personal Information link, and 45-day SLA tooling that the California Privacy Protection Agency and the Attorney General expect.
The CCPA defines when it applies via three statutory thresholds. If your for-profit business does business in California and meets any one of these triggers, you are a business — even if your servers, headquarters, and staff are all outside the state.
CCPA/CPRA grants California consumers six distinct rights: Right to Know, Right to Delete, Right to Correct, Right to Limit Use of Sensitive PI, Right to Opt-Out of Sale or Sharing, and Right to Non-Discrimination. Each requires a workflow, an intake path, identity verification, and an audit trail — all inside the 45-day statutory response window.
Check Your Posture →Response covers categories collected, sources, purposes, recipients, and sale/sharing-for-value history. Free annual disclosure; structured, easily-digestible format required on request.
Deletion cascades to service providers. Enumerated exceptions: transaction completion, security/fraud, legal obligation, consumer-aligned internal uses, free speech, certain research.
Correction propagated across systems and downstream processors. Verification proportionate to sensitivity, no over-collection of verification data.
Restricts the business's use of §1798.140(ae) sensitive PI to enumerated §1798.121 purposes. Companion "Limit the Use of My Sensitive Personal Information" link.
"Do Not Sell or Share My Personal Information" link on every relevant page; opt-out propagates downstream within 15 business days. Mobile-app equivalent via settings menu.
Cannot condition pricing, tier, or service quality on the consumer's exercise of any other right. Permits §1798.125(b) financial-incentive programmes with Notice of Financial Incentive.
CCPA grants California consumers — or their counsel — a private right of action for breaches of non-encrypted personal information that result from a business's failure to maintain reasonable security procedures. Statutory damages of $100–$750 per consumer per incident aggregate quickly. Encryption-at-rest with controlled key custody is the architectural response.
Most US-headquartered companies face overlapping privacy obligations. CCPA/CPRA and GDPR both grant consumer rights, but the enforcement structures diverge — GDPR's administrative fines versus CCPA's §1798.150 private right of action. HIPAA, CCPA, and PCI-DSS overlap technically (encryption, audit, vendor due diligence) but govern different data and different enforcers.
CCPA/CPRA and GDPR grant consumers overlapping rights (access, deletion, opt-out), but they differ in three specific ways: (1) CCPA applies by revenue and volume thresholds, GDPR by territorial presence or offering to EU subjects; (2) CCPA enforcement is mixed — CPPA/AG enforcement plus a §1798.150 private right of action — while GDPR is enforcement-by-supervisory-authority; (3) CCPA deadlines are 45 days (extendable to 90), GDPR 30 days (extendable to 60).
HIPAA protects PHI of covered entities and business associates; CCPA/CPRA covers any consumer personal information of California residents. CCPA's §1798.150 attaches on the upper side of aggregate per-consumer damages, while HIPAA's 60-day breach clock attaches at any reasonable PHI exposure. Both have notification obligations but enforcement bodies and penalty structures differ materially.
CCPA/CPRA is a binding regulation enforced by the California Privacy Protection Agency and the Attorney General, plus a per-cause-of-action penalty channel. SOC 2 is a voluntary attestation commissioned to win enterprise SaaS deals. CCPA requires explicit controls (Notice at Collection, opt-out link, 45-day SLA); SOC 2 covers criteria a trust services evaluator can verify.
CCPA covers consumer personal information broadly; PCI-DSS covers cardholder data narrowly. CCPA enforcement is by CPPA/AG + private right of action; PCI-DSS enforcement is via the card brands (Visa/MasterCard/AmEx) and acquiring banks. Technical controls (encryption-at-rest, key management, audit logging, vendor due diligence) overlap materially between CCPA's "reasonable security" duty and PCI-DSS v4.0.
NIST CSF and CCPA share meaningful overlap on technical controls — access control, encryption, monitoring, incident response. But CCPA-specific obligations (Notice at Collection, opt-out links, sensitive-PI Limit-Use link, 45-day SLA, CPA/CPRA vendor contract structure) are not addressed by NIST and require dedicated work. Here is a realistic coverage estimate.
| NIST CSF Function | Description | Primary CCPA/CPRA Sections | Est. Coverage |
|---|---|---|---|
| GV — Govern | Organizational context, risk management strategy, supply chain | §1798.140(ag), (j) — Vendor / service provider contracts | |
| ID — Identify | Asset management, risk assessment, improvement planning | §1798.130 verification; §1798.185(a)(16) risk assessment rulemaking | |
| PR — Protect | Access control, awareness, data security, platform security | §1798.150 reasonable-security duty; §1798.140(ae) sensitive PI encryption | |
| DE — Detect | Continuous monitoring, anomaly detection | §1798.150 detection of unauthorised access; monitoring for exfiltration | |
| RS — Respond | Incident management, analysis, communication, mitigation | §1798.150 statutory damages exposure; consumer notification + AG notice | |
| RC — Recover | Recovery planning, communications | §1798.105 deletion propagation to service providers |
What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — roughly half of your CCPA technical-control work is already done. A cross-mapping assessment identifies exactly which CCPA sections your existing controls satisfy and which still need dedicated attention (Notice at Collection, Do Not Sell link, Limit Sensitive Use link, 45-day request SLA, §1798.140(ag) service-provider contract language, §1798.150 sensitive-PI encryption posture). See the NIST Policy Package →
CCPA/CPRA compliance is not a single project — it's an ongoing program. We follow a phased engagement model that ends with sustained operational coverage (Notice refresh, SLA monitoring, vendor-contract maintenance) rather than an open-ended consulting relationship.
Apply the three CCPA applicability thresholds (revenue ≥ $25M, sale/sharing volume ≥ 100,000, revenue-from-sale ≥ 50%) and document the result. Identify the categories of California consumer personal information processed, the categories of sensitive PI under §1798.140(ae) you may hold, and the candidate online/offline collection surfaces where the Notice at Collection must appear. The threshold conclusion drives whether we go to Phase 2 or pause here.
Systematic review against the full CCPA/CPRA accountability package: Notice at Collection, Privacy Policy disclosure, opt-out links, Limit-Use-of-Sensitive-PI links, request intake channels, identity verification framework, the 45-day SLA + extension framework, refusal grounds, and the §1798.140(ag) service-provider contract structure. Sensitive-PI stock inventory surfaces the §1798.150 exposure with specificity.
Close the gaps. This phase produces Notice at Collection copy, Do-Not-Sell-or-Share link wiring, Limit-Use-of-Sensitive-PI link wiring, the 45-day ticketing workflow with extension notice, refusal-and-appeal letter template, the §1798.140(ag) service-provider addendum, sensitive-PI encryption posture with §1798.150 reduction plan, and an updated Privacy Policy covering the §1798.100(e) elements.
Sustained coverage: Notice at Collection refresh on material-purpose changes, SLA monitoring with quarterly reporting, vendor-contract language maintenance and renewal, CPPA rulemaking monitoring (especially for the ADMT / automated decisionmaking regulations expected under §1798.185(a)(16)), and §1798.150 sensitive-PI stock audit. CCPA/CPRA doesn't end at enterprise certification — it requires continuous accountability.