Regulation

California Consumer Privacy Act (CCPA/CPRA)

America's most comprehensive state privacy law, giving California consumers unprecedented control over their personal information. Neostra streamlines CCPA/CPRA compliance with automated opt-out management, data inventory, and consumer request fulfillment.

Explore Our Platform →
2020
CCPA Effective
40M+
Consumers Protected
$7,500
Per Violation (Intentional)
6
Consumer Rights

What is the CCPA/CPRA?

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state-level privacy law in the United States. Effective January 1, 2020, with CPRA amendments taking effect January 1, 2023.

The law gives California consumers significant rights over their personal information and imposes obligations on businesses that collect, sell, or share consumer data, with enhanced protections for sensitive personal information under CPRA.

CA
California Consumer
Privacy Act / CPRA

Who Must Comply?

The CCPA/CPRA applies to for-profit businesses that collect personal information of California residents and meet any one of the following thresholds:

  • Annual gross revenue exceeding $25 million
  • Buy, sell, or share personal information of 100,000+ consumers or households
  • Derive 50% or more of annual revenue from selling or sharing personal information
  • Businesses operating as joint ventures or partnerships
  • Service providers and contractors with specific obligations
Revenue & Data
Volume Thresholds

Key CCPA/CPRA Requirements

Understanding the core obligations under California's consumer privacy framework

Right to Opt-Out

Businesses must provide a clear "Do Not Sell or Share My Personal Information" link and honor consumer opt-out requests for data selling and sharing.

Privacy Policy

Maintain a comprehensive, updated privacy policy disclosing data categories collected, purposes, consumer rights, and details about data selling or sharing practices.

Data Minimization

Under CPRA, businesses must limit collection and use of personal information to what is reasonably necessary and proportionate to the disclosed purposes.

Sensitive Personal Information

Provide consumers the right to limit the use of sensitive personal information to what is necessary. Display a "Limit the Use of My Sensitive Personal Information" link.

Service Provider Contracts

Include specific contractual provisions with service providers and contractors that restrict how they process personal information shared with them.

Risk Assessments (CPRA)

Conduct regular cybersecurity audits and risk assessments for processing activities that present significant risk to consumer privacy or security.

Consumer Rights Under CCPA/CPRA

California consumers enjoy broad rights over their personal information

1

Right to Know

Consumers can request disclosure of what personal information a business has collected, the sources, purposes, and third parties with whom it has been shared.

2

Right to Delete

Consumers can request deletion of their personal information held by a business, with the business required to direct service providers to do the same.

3

Right to Opt-Out of Sale/Sharing

Consumers can direct businesses to stop selling or sharing their personal information with third parties for cross-context behavioral advertising.

4

Right to Correct (CPRA)

Consumers can request that businesses correct inaccurate personal information maintained about them, with verification procedures.

5

Right to Limit Use of Sensitive Data (CPRA)

Consumers can direct businesses to limit the use and disclosure of their sensitive personal information to only what is necessary to perform services.

6

Right to Non-Discrimination

Businesses cannot discriminate against consumers for exercising their CCPA rights through denying services, charging different prices, or providing different quality.

How Neostra Ensures CCPA/CPRA Compliance

Our platform automates the complex requirements of California's consumer privacy regulation

Do Not Sell or Share

Deploy compliant opt-out mechanisms with automated Global Privacy Control (GPC) signal detection and universal opt-out preference management.

Consumer Request Automation

Automate the intake, verification, and fulfillment of consumer requests — Know, Delete, Correct, and Opt-Out — within the 45-day response window.

Data Inventory

Automatically discover and categorize personal information across all systems, map data flows to third parties, and maintain up-to-date data inventories.

Privacy Risk Assessments

Conduct CPRA-mandated risk assessments for high-risk processing activities with built-in templates, scoring frameworks, and remediation tracking.

Sensitive Data Controls

Identify and manage sensitive personal information with purpose limitation controls, consumer preference management, and "Limit Use" opt-out mechanisms.

Compliance Reporting

Generate CCPA/CPRA compliance reports with metrics on consumer requests processed, response times, opt-out rates, and data inventory completeness.

Simplify CCPA/CPRA Compliance Today

Join businesses across the United States using Neostra to manage California privacy requirements and build consumer trust.

Get Started →