US · CALIFORNIA · CCPA / CPRA

CCPA compliance for companies with California customers.

Consumer rights intake, opt-out workflows, consent records, and audit proof — everything needed to meet CCPA and CPRA obligations.

No credit card required. Privacy Center live in 15 minutes.

CCPA / CPRA PENALTIES

Per-consumer penalties add up fast.

Unlike GDPR's aggregate cap, CCPA fines are per consumer per incident. A breach affecting 10,000 Californians could mean $75 million in intentional-violation penalties.

Violation typePenaltyScope
Unintentional violation$2,500Per violation, per consumer
Intentional violation$7,500Per violation, per consumer
Children's data (under 16)$7,500Per intentional violation involving minors
Data breach (failure to implement security)$100–$750Per consumer per incident — or actual damages if higher

YOUR OBLIGATIONS

Eight things CCPA / CPRA requires.

Privacy notice

§ 1798.100, 1798.110

Businesses must disclose categories of personal information collected, purposes, and third parties it is shared with.

Right to know & access

§ 1798.100, 1798.110

Consumers can request the categories and specific pieces of personal information a business has collected about them.

Right to delete

§ 1798.105

Consumers can request deletion of personal information. Businesses must notify service providers to delete as well.

Right to opt out of sale/sharing

§ 1798.120 (CPRA)

Consumers can opt out of the sale or sharing of their personal information at any time.

Right to correct

§ 1798.106 (CPRA)

Consumers can request correction of inaccurate personal information. Added by CPRA in 2023.

Non-discrimination

§ 1798.125

Businesses cannot discriminate against consumers who exercise CCPA rights — no different pricing or service quality.

Data minimization (CPRA)

§ 1798.100(a)(3)

Businesses must not collect more personal information than is reasonably necessary for the disclosed purpose.

Sensitive personal information

§ 1798.121 (CPRA)

Consumers can limit the use of sensitive PI (SSN, financial, biometric, geolocation). Separate opt-out required.

HOW CONDUIT COVERS EACH OBLIGATION

One workspace. Every CCPA requirement.

CCPA ObligationHow Privacy Conduit covers it
Privacy noticePrivacy Center with CCPA-specific disclosures and right descriptions.
Right to know & accessDSR inbox with 45-day SLA clock, response templates, and case evidence trail.
Right to deleteFulfillment playbooks track deletion across systems and vendors with evidence.
Right to opt out of sale/sharingConsent records module tracks opt-out status and links to case workflow.
Right to correctCorrection request handling with playbook and 45-day response SLA.
Non-discriminationAudit trail ensures every rights request is fulfilled regardless of consumer segment.
Data minimization (CPRA)Data inventory maps collection purpose per system and vendor.
Sensitive personal informationSensitive PI flags on consent records and playbook steps for limited use.

FREQUENTLY ASKED

CCPA & CPRA, answered.

What are the CCPA and CPRA?
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is California’s data protection law. It gives California consumers rights over the personal information that businesses collect about them.
What rights do California consumers have?
Consumers have the right to know what personal information is collected, the right to delete it, the right to correct inaccurate information, the right to opt out of the sale or sharing of their data, and the right to limit the use of sensitive personal information.
How long does a business have to respond to a CCPA request?
Businesses must respond to a verifiable consumer request within 45 days. This can be extended by an additional 45 days (90 days total) when reasonably necessary, with notice to the consumer.
What are the penalties for CCPA non-compliance?
The California Privacy Protection Agency and Attorney General can levy civil penalties of up to $2,500 per violation, or $7,500 per intentional violation or violation involving the data of minors.
Which businesses must comply with the CCPA?
The CCPA applies to for-profit businesses serving California residents that meet at least one threshold: over $25 million in annual revenue, buying or selling the personal information of 100,000+ consumers or households, or deriving 50% or more of revenue from selling consumers’ personal information.

GET STARTED

Start your CCPA workspace today.

Privacy Center live in 15 minutes. Full CCPA/CPRA compliance toolkit included.