CCPA enforced since 2020 · CPRA amendments enforceable Jan 1, 2023 · §1798.150 private right of action: $100–$750 per consumer per incident
California CCPA / CPRA Compliance Consulting

California consumer rights are real. Is your SaaS compliant for §1798.100 + §1798.120?

The CCPA and its CPRA amendment apply to any for-profit business meeting one of three thresholds — extraterritorial in practice. We deliver the Notice at Collection, Do Not Sell or Share link, Limit Use of Sensitive Personal Information link, and 45-day SLA tooling that the California Privacy Protection Agency and the Attorney General expect.

Compliance scope
CCPA §1798.100–.199 CPRA Amendments 2023 Notice at Collection 45-day Consumer SLA §1798.150 Awareness NIST CSF Mapping
Applicability threshold

CCPA's extraterritorial reach. Three triggers that pull you in.

The CCPA defines when it applies via three statutory thresholds. If your for-profit business does business in California and meets any one of these triggers, you are a business — even if your servers, headquarters, and staff are all outside the state.

Trigger 1 · Revenue
Annual Gross Revenue ≥ $25M
Applies to combined revenue of the business and its subsidiaries
Crosses the threshold regardless of how few California residents you actually serve
Implication: full Notice at Collection, opt-out link, 45-day SLA, vendor contracts required
Trigger 2 · Volume
100,000+ California Consumers/Households/Devices
Counts annual sale, sharing, or purchase of Californian consumer records
Devices counted under the original CCPA — the CPRA preserved the device prong
Implication: §1798.135 link engineering, two-channel intake, 45-day SLA enforcement
Trigger 3 · Revenue Mix
≥ 50% Revenue from Selling/Sharing Personal Information
Ad-tech, data broker, marketplace model fits here
"Selling/sharing" includes cross-context behavioural advertising
Implication: opt-out signalling must propagate downstream within 15 business days
Six consumer rights

Six rights. Six workflows. One 45-day clock.

CCPA/CPRA grants California consumers six distinct rights: Right to Know, Right to Delete, Right to Correct, Right to Limit Use of Sensitive PI, Right to Opt-Out of Sale or Sharing, and Right to Non-Discrimination. Each requires a workflow, an intake path, identity verification, and an audit trail — all inside the 45-day statutory response window.

Check Your Posture →
Know

§1798.110 — Right to Know (12-month lookback)

Response covers categories collected, sources, purposes, recipients, and sale/sharing-for-value history. Free annual disclosure; structured, easily-digestible format required on request.

Delete

§1798.105 — Right to Delete (with §1798.105(2) exceptions)

Deletion cascades to service providers. Enumerated exceptions: transaction completion, security/fraud, legal obligation, consumer-aligned internal uses, free speech, certain research.

Correct

§1798.106 — Right to Correct (CPRA-added)

Correction propagated across systems and downstream processors. Verification proportionate to sensitivity, no over-collection of verification data.

Limit

§1798.121 — Right to Limit Use of Sensitive PI

Restricts the business's use of §1798.140(ae) sensitive PI to enumerated §1798.121 purposes. Companion "Limit the Use of My Sensitive Personal Information" link.

Opt-Out

§1798.120 / §1798.135 — Right to Opt-Out of Sale or Sharing

"Do Not Sell or Share My Personal Information" link on every relevant page; opt-out propagates downstream within 15 business days. Mobile-app equivalent via settings menu.

Non-Discrimination

§1798.125 — Right to Non-Discrimination

Cannot condition pricing, tier, or service quality on the consumer's exercise of any other right. Permits §1798.125(b) financial-incentive programmes with Notice of Financial Incentive.

§1798.150 · Private right of action

The CCPA's most distinctive enforcement risk. Engineer for it.

CCPA grants California consumers — or their counsel — a private right of action for breaches of non-encrypted personal information that result from a business's failure to maintain reasonable security procedures. Statutory damages of $100–$750 per consumer per incident aggregate quickly. Encryption-at-rest with controlled key custody is the architectural response.

§1798.150
Statutory Damages — $100–$750 per Consumer
Per consumer, per incident — class aggregation is the norm
Actual damages, whichever is greater; plus injunctive relief
Triggers when the breach involved non-encrypted or insufficiently-redacted PI
Notice to AG required before filing suit (§1798.150(b))
§1798.121
Sensitive PI — Reduced Breach Surface
§1798.140(ae) catalog: SSN, account credentials, geolocation, race/ethnic, religious, union, communications contents, genetic, biometric, health, sex/orientation
Reduce stock via tokenisation, length reduction, minimum-necessary retention
Encryption-at-rest with sole-control keys for what must stay resident
Limit-Use link on every sensitive-PI collection surface
§1798.155
Per-Cause Action Penalties — Up to $7,500
Up to $7,500 per intentional violation; up to $2,500 per unintentional violation
Each violation plus a cure window — but cure is not unlimited
Triggers when the business fails to cure within 30 days after notice
Implication: track every consumer-right workflow with audit trail quality
Framework comparison

How CCPA/CPRA compares to GDPR, HIPAA, SOC 2, and PCI-DSS.

Most US-headquartered companies face overlapping privacy obligations. CCPA/CPRA and GDPR both grant consumer rights, but the enforcement structures diverge — GDPR's administrative fines versus CCPA's §1798.150 private right of action. HIPAA, CCPA, and PCI-DSS overlap technically (encryption, audit, vendor due diligence) but govern different data and different enforcers.

vs GDPR

Same rights DNA, very different enforcement

CCPA/CPRA and GDPR grant consumers overlapping rights (access, deletion, opt-out), but they differ in three specific ways: (1) CCPA applies by revenue and volume thresholds, GDPR by territorial presence or offering to EU subjects; (2) CCPA enforcement is mixed — CPPA/AG enforcement plus a §1798.150 private right of action — while GDPR is enforcement-by-supervisory-authority; (3) CCPA deadlines are 45 days (extendable to 90), GDPR 30 days (extendable to 60).

vs HIPAA

Narrower scope, harder breach trigger

HIPAA protects PHI of covered entities and business associates; CCPA/CPRA covers any consumer personal information of California residents. CCPA's §1798.150 attaches on the upper side of aggregate per-consumer damages, while HIPAA's 60-day breach clock attaches at any reasonable PHI exposure. Both have notification obligations but enforcement bodies and penalty structures differ materially.

vs SOC 2

Mandatory regulation vs voluntary attestation

CCPA/CPRA is a binding regulation enforced by the California Privacy Protection Agency and the Attorney General, plus a per-cause-of-action penalty channel. SOC 2 is a voluntary attestation commissioned to win enterprise SaaS deals. CCPA requires explicit controls (Notice at Collection, opt-out link, 45-day SLA); SOC 2 covers criteria a trust services evaluator can verify.

vs PCI-DSS

Different data, different enforcer

CCPA covers consumer personal information broadly; PCI-DSS covers cardholder data narrowly. CCPA enforcement is by CPPA/AG + private right of action; PCI-DSS enforcement is via the card brands (Visa/MasterCard/AmEx) and acquiring banks. Technical controls (encryption-at-rest, key management, audit logging, vendor due diligence) overlap materially between CCPA's "reasonable security" duty and PCI-DSS v4.0.

Cross-framework mapping

Already working on NIST CSF? You have a foundation — but not full coverage.

NIST CSF and CCPA share meaningful overlap on technical controls — access control, encryption, monitoring, incident response. But CCPA-specific obligations (Notice at Collection, opt-out links, sensitive-PI Limit-Use link, 45-day SLA, CPA/CPRA vendor contract structure) are not addressed by NIST and require dedicated work. Here is a realistic coverage estimate.

NIST CSF Function Description Primary CCPA/CPRA Sections Est. Coverage
GV — Govern Organizational context, risk management strategy, supply chain §1798.140(ag), (j) — Vendor / service provider contracts
~45%
ID — Identify Asset management, risk assessment, improvement planning §1798.130 verification; §1798.185(a)(16) risk assessment rulemaking
~50%
PR — Protect Access control, awareness, data security, platform security §1798.150 reasonable-security duty; §1798.140(ae) sensitive PI encryption
~60%
DE — Detect Continuous monitoring, anomaly detection §1798.150 detection of unauthorised access; monitoring for exfiltration
~55%
RS — Respond Incident management, analysis, communication, mitigation §1798.150 statutory damages exposure; consumer notification + AG notice
~55%
RC — Recover Recovery planning, communications §1798.105 deletion propagation to service providers
~40%

What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — roughly half of your CCPA technical-control work is already done. A cross-mapping assessment identifies exactly which CCPA sections your existing controls satisfy and which still need dedicated attention (Notice at Collection, Do Not Sell link, Limit Sensitive Use link, 45-day request SLA, §1798.140(ag) service-provider contract language, §1798.150 sensitive-PI encryption posture). See the NIST Policy Package →

How we work

From CCPA/CPRA readiness assessment to ongoing privacy operations.

CCPA/CPRA compliance is not a single project — it's an ongoing program. We follow a phased engagement model that ends with sustained operational coverage (Notice refresh, SLA monitoring, vendor-contract maintenance) rather than an open-ended consulting relationship.

01
Phase 1 · Week 1–2
Scoping & Threshold Analysis

Apply the three CCPA applicability thresholds (revenue ≥ $25M, sale/sharing volume ≥ 100,000, revenue-from-sale ≥ 50%) and document the result. Identify the categories of California consumer personal information processed, the categories of sensitive PI under §1798.140(ae) you may hold, and the candidate online/offline collection surfaces where the Notice at Collection must appear. The threshold conclusion drives whether we go to Phase 2 or pause here.

02
Phase 2 · Week 2–5
Gap Analysis & Inventory

Systematic review against the full CCPA/CPRA accountability package: Notice at Collection, Privacy Policy disclosure, opt-out links, Limit-Use-of-Sensitive-PI links, request intake channels, identity verification framework, the 45-day SLA + extension framework, refusal grounds, and the §1798.140(ag) service-provider contract structure. Sensitive-PI stock inventory surfaces the §1798.150 exposure with specificity.

03
Phase 3 · Week 5–10
Remediation & Documentation

Close the gaps. This phase produces Notice at Collection copy, Do-Not-Sell-or-Share link wiring, Limit-Use-of-Sensitive-PI link wiring, the 45-day ticketing workflow with extension notice, refusal-and-appeal letter template, the §1798.140(ag) service-provider addendum, sensitive-PI encryption posture with §1798.150 reduction plan, and an updated Privacy Policy covering the §1798.100(e) elements.

04
Phase 4 · Ongoing
Ongoing Privacy Operations

Sustained coverage: Notice at Collection refresh on material-purpose changes, SLA monitoring with quarterly reporting, vendor-contract language maintenance and renewal, CPPA rulemaking monitoring (especially for the ADMT / automated decisionmaking regulations expected under §1798.185(a)(16)), and §1798.150 sensitive-PI stock audit. CCPA/CPRA doesn't end at enterprise certification — it requires continuous accountability.

Priv