CCPA/CPRA Compliance Check
Phase 1: Applicability Assessment
- Determine CCPA/CPRA applicability
- Annual gross revenue > $25 million
- Buy/sell/share personal info of 100,000+ consumers/households
- Derive 50%+ of revenue from selling/sharing personal info
- Identify all business entities in scope
- Determine if acting as business, service provider, or contractor
- Identify any exemptions applicable (employee data, B2B, etc.)
Phase 2: Data Inventory & Mapping
- Catalog personal information collected
- Identifiers (name, email, SSN, IP address)
- Commercial information (purchase history)
- Internet/network activity (browsing, search history)
- Geolocation data
- Professional/employment information
- Education information
- Inferences drawn from above
- Sensitive personal information
- Document data sources, purposes, and retention periods
- Map data flows to third parties and service providers
- Identify data sold or shared for cross-context behavioral advertising
Data Mapping Summary
| Category | Sources | Purpose | Shared With | Sold | Retention |
|---|---|---|---|---|---|
| Identifiers | Yes/No | ||||
| Commercial | Yes/No | ||||
| Internet activity | Yes/No | ||||
| Geolocation | Yes/No | ||||
| Sensitive PI | Yes/No |
Phase 3: Consumer Rights Implementation
- Assess consumer rights mechanisms
- Right to Know (access requests)
- Right to Delete
- Right to Correct
- Right to Opt-Out of Sale/Sharing
- Right to Limit Use of Sensitive PI
- Right to Non-Discrimination
- Right to data portability
- Verify request submission methods (minimum 2 methods required)
- Test request fulfillment within 45-day timeline
- Verify identity verification procedures
- Assess authorized agent request handling
Rights Compliance Matrix
| Right | Mechanism Exists | Process Documented | Tested | Timeline Met | Compliant |
|---|---|---|---|---|---|
| Know/Access | [ ] | [ ] | [ ] | [ ] | [ ] |
| Delete | [ ] | [ ] | [ ] | [ ] | [ ] |
| Correct | [ ] | [ ] | [ ] | [ ] | [ ] |
| Opt-Out Sale/Share | [ ] | [ ] | [ ] | [ ] | [ ] |
| Limit Sensitive PI | [ ] | [ ] | [ ] | [ ] | [ ] |
Phase 4: Privacy Notice Review
- Review privacy policy for required disclosures
- Categories of PI collected in past 12 months
- Purposes for each category
- Categories of third parties PI shared with
- Consumer rights description
- "Do Not Sell or Share My Personal Information" link
- "Limit the Use of My Sensitive Personal Information" link
- Updated within past 12 months
- Verify notice at collection is provided
- Review financial incentive notices if applicable
- Assess cookie banner and GPC signal handling
Phase 5: Vendor & Service Provider Management
- Review service provider and contractor agreements
- Written contract with CCPA-required terms
- Purpose limitations specified
- Prohibition on selling/sharing received PI
- Obligation to assist with consumer requests
- Right to audit compliance
- Assess third-party data sharing agreements
- Verify data processing agreements are current
Phase 6: Data Protection Assessment
- Evaluate security measures for personal information
- Assess data minimization practices
- Review data retention and deletion schedules
- Verify breach notification procedures
- Conduct risk assessment for high-risk processing (CPRA requirement)
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
- Applicability Determination: Criteria met and entities in scope
- Data Inventory: Complete PI catalog with flows and purposes
- Rights Assessment: Compliance status per consumer right
- Privacy Notice Gap Analysis: Required vs. current disclosures
- Remediation Plan: Prioritized actions with timelines
Action Items
- Complete personal information data mapping
- Implement missing consumer rights mechanisms
- Update privacy policy with all required disclosures
- Review and update service provider agreements
- Implement opt-out signal handling (GPC)
- Conduct annual data protection assessment
- Train staff on CCPA request handling procedures