California, US · Applies by law
CCPA / CPRA compliance
California Consumer Privacy Act, as amended
Companies over defined revenue or data-volume thresholds doing business with California residents.
The context
What it actually asks of you
CCPA, as amended by CPRA, is the most consequential US state privacy law simply because of California's size, but it is threshold-based, so the first question is whether you are in scope at all. Many early-stage SaaS companies are not, and finding that out is worth doing before building anything.
For companies that are in scope, the defined terms do most of the damage. 'Sale' and 'share' are drafted broadly enough that running third-party advertising or certain analytics constitutes one, which triggers opt-out obligations, a conspicuous link, and recognition of the Global Privacy Control browser signal.
Because a dozen other states have now passed similar laws, the efficient approach is to build to the strictest common denominator once rather than re-implementing per state as each takes effect.
The common mistake
What teams get wrong.
"Sale" and "share" are defined far more broadly than money changing hands. Running third-party advertising or analytics pixels usually triggers opt-out obligations you may not realise you have.
Our scope
What we do for CCPA / CPRA.
- 01Threshold assessment, whether you're actually in scope
- 02Consumer rights workflows: know, delete, correct, opt out
- 03"Do Not Sell or Share My Personal Information" implementation
- 04Global Privacy Control signal handling
- 05Service provider contract terms and vendor review
- 06Annual privacy policy disclosures
innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.
Questions
CCPA / CPRA FAQ
In broad terms: annual gross revenue above the statutory threshold, or buying/selling/sharing personal information of 100,000+ California consumers or households, or deriving 50% or more of revenue from selling or sharing personal information. The revenue figure is adjusted periodically, which is one reason to check rather than assume.
Possibly. If you run third-party advertising, or share identifiers with partners for cross-context behavioural advertising, that is 'sharing' under CPRA even with no money involved. This catches more companies than any other provision.
It gets you most of the way, data mapping, rights processes and vendor terms transfer well. What does not transfer is the sale/share opt-out machinery, the Global Privacy Control signal, and the specific notice-at-collection format California requires.
Find out whether CCPA / CPRA binds you.
Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.
No sales sequence. A scoping call and a written proposal cost nothing.