US · CALIFORNIA · CCPA / CPRA
Consumer rights intake, opt-out workflows, consent records, and audit proof — everything needed to meet CCPA and CPRA obligations.
No credit card required. Privacy Center live in 15 minutes.
CCPA / CPRA PENALTIES
Unlike GDPR's aggregate cap, CCPA fines are per consumer per incident. A breach affecting 10,000 Californians could mean $75 million in intentional-violation penalties.
| Violation type | Penalty | Scope |
|---|---|---|
| Unintentional violation | $2,500 | Per violation, per consumer |
| Intentional violation | $7,500 | Per violation, per consumer |
| Children's data (under 16) | $7,500 | Per intentional violation involving minors |
| Data breach (failure to implement security) | $100–$750 | Per consumer per incident — or actual damages if higher |
YOUR OBLIGATIONS
§ 1798.100, 1798.110
Businesses must disclose categories of personal information collected, purposes, and third parties it is shared with.
§ 1798.100, 1798.110
Consumers can request the categories and specific pieces of personal information a business has collected about them.
§ 1798.105
Consumers can request deletion of personal information. Businesses must notify service providers to delete as well.
§ 1798.120 (CPRA)
Consumers can opt out of the sale or sharing of their personal information at any time.
§ 1798.106 (CPRA)
Consumers can request correction of inaccurate personal information. Added by CPRA in 2023.
§ 1798.125
Businesses cannot discriminate against consumers who exercise CCPA rights — no different pricing or service quality.
§ 1798.100(a)(3)
Businesses must not collect more personal information than is reasonably necessary for the disclosed purpose.
§ 1798.121 (CPRA)
Consumers can limit the use of sensitive PI (SSN, financial, biometric, geolocation). Separate opt-out required.
HOW CONDUIT COVERS EACH OBLIGATION
| CCPA Obligation | How Privacy Conduit covers it |
|---|---|
| Privacy notice | Privacy Center with CCPA-specific disclosures and right descriptions. |
| Right to know & access | DSR inbox with 45-day SLA clock, response templates, and case evidence trail. |
| Right to delete | Fulfillment playbooks track deletion across systems and vendors with evidence. |
| Right to opt out of sale/sharing | Consent records module tracks opt-out status and links to case workflow. |
| Right to correct | Correction request handling with playbook and 45-day response SLA. |
| Non-discrimination | Audit trail ensures every rights request is fulfilled regardless of consumer segment. |
| Data minimization (CPRA) | Data inventory maps collection purpose per system and vendor. |
| Sensitive personal information | Sensitive PI flags on consent records and playbook steps for limited use. |
GET STARTED
Privacy Center live in 15 minutes. Full CCPA/CPRA compliance toolkit included.