Regulation · California

America's strictest consumer privacy law.

America's most comprehensive state privacy law, giving California consumers unprecedented control over their personal information. Neostra streamlines CCPA and CPRA compliance with automated opt-out management, data inventory and consumer request fulfilment.

2020
CCPA effective
40M+
Consumers protected
$7,500
Per intentional violation
6
Consumer rights

What is the CCPA and CPRA?

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state-level privacy law in the United States. Effective 1 January 2020, with CPRA amendments taking effect 1 January 2023.

The law gives California consumers significant rights over their personal information and imposes obligations on businesses that collect, sell or share consumer data, with enhanced protections for sensitive personal information under CPRA.

CACalifornia Consumer Privacy Act / CPRA

Who must comply?

The CCPA and CPRA apply to for-profit businesses that collect personal information of California residents and meet any one of the following thresholds.

  • Annual gross revenue exceeding $25 million
  • Buy, sell or share personal information of 100,000 or more consumers or households
  • Derive 50% or more of annual revenue from selling or sharing personal information
  • Businesses operating as joint ventures or partnerships
  • Service providers and contractors, with specific obligations
Revenue and data volume thresholds
Obligations

What the law requires.

Right to opt out
Businesses must provide a clear "Do Not Sell or Share My Personal Information" link and honour consumer opt-out requests for data selling and sharing.
Privacy policy
Maintain a comprehensive, updated privacy policy disclosing data categories collected, purposes, consumer rights and details about data selling or sharing practices.
Data minimisation
Under CPRA, businesses must limit collection and use of personal information to what is reasonably necessary and proportionate to the disclosed purposes.
Sensitive personal information
Provide consumers the right to limit the use of sensitive personal information to what is necessary. Display a "Limit the Use of My Sensitive Personal Information" link.
Service provider contracts
Include specific contractual provisions with service providers and contractors that restrict how they process personal information shared with them.
Risk assessments (CPRA)
Conduct regular cybersecurity audits and risk assessments for processing activities that present significant risk to consumer privacy or security.
Rights

Consumer rights under CCPA and CPRA

California consumers enjoy broad rights over their personal information.

  1. 1
    Right to know
    Consumers can request disclosure of what personal information a business has collected, the sources, purposes, and third parties with whom it has been shared.
  2. 2
    Right to delete
    Consumers can request deletion of their personal information held by a business, with the business required to direct service providers to do the same.
  3. 3
    Right to opt out of sale or sharing
    Consumers can direct businesses to stop selling or sharing their personal information with third parties for cross-context behavioural advertising.
  4. 4
    Right to correct (CPRA)
    Consumers can request that businesses correct inaccurate personal information maintained about them, with verification procedures.
  5. 5
    Right to limit use of sensitive data (CPRA)
    Consumers can direct businesses to limit the use and disclosure of their sensitive personal information to only what is necessary to perform services.
  6. 6
    Right to non-discrimination
    Businesses cannot discriminate against consumers for exercising their rights by denying services, charging different prices, or providing different quality.
The platform

How Neostra covers CCPA.

The platform automates the complex requirements of California's consumer privacy regulation.

Do Not Sell or Share
Compliant opt-out mechanisms with automated Global Privacy Control signal detection and universal opt-out preference management.
Consumer request automation
Automate intake, verification and fulfilment of Know, Delete, Correct and Opt-Out requests within the 45-day response window.
Data inventory
Discover and categorise personal information across all systems, map data flows to third parties, and maintain up-to-date inventories.
Privacy risk assessments
Conduct CPRA-mandated risk assessments for high-risk processing with built-in templates, scoring frameworks and remediation tracking.
Sensitive data controls
Identify and manage sensitive personal information with purpose limitation controls, preference management and Limit Use opt-out mechanisms.
Compliance reporting
Generate CCPA and CPRA reports on requests processed, response times, opt-out rates and data inventory completeness.
Other regulationsDPDPA 2023 → GDPR →

One platform, every regime.

DPDPA, GDPR and CCPA workflows run side by side on a single tenant, with one audit trail.