Regulatory & Privacy · California Consumer Privacy Act

CCPA and CPRA compliance you can actually operate.

We assess how your business collects, sells, and shares California consumers’ personal information, then hand you a prioritized plan to close the gaps before a consumer request or the state agency finds them first.

CCPA compliance means honoring California consumers’ rights over their personal information under the California Consumer Privacy Act, as amended by the CPRA. FinAudit CPA reviews your data practices, notices, and vendor contracts against the law, then gives you a practical remediation plan. We assess and fix; your legal counsel issues any formal opinion.

Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)

Last updated July 2026

What CCPA and CPRA compliance actually require

The California Consumer Privacy Act took effect in 2020 and gave residents of California real, enforceable control over the personal information businesses collect about them. In 2023 the California Privacy Rights Act, which voters passed as Proposition 24, amended and expanded that law. People often talk about the CCPA and the CPRA as if they were two separate statutes. They are not. The CPRA is a set of amendments folded into the CCPA, so the operative law today is the CCPA as amended. When a security team or a regulator asks about your "CCPA compliance," they mean the whole amended framework.

At its core, California privacy law does two things. It tells consumers what rights they hold over their own data, and it tells businesses what they must do to honor those rights and to be transparent about their practices. That means posting a compliant privacy notice, giving consumers working ways to exercise their rights, respecting opt-out signals, limiting how you use the most sensitive categories of data, and putting the right contract terms in place with every vendor that touches California personal information.

None of that happens by accident. A privacy policy copied from a template does not make you compliant, and neither does a "Do Not Sell" link that leads nowhere. Real compliance is an operational program: you know what data you hold, why you hold it, who you share it with, and how you would respond if a consumer or the state agency asked you to prove it. That is the program we help you build.

California privacy law does not reward a polished policy page. It rewards the business that can receive a deletion request on a Monday and prove, weeks later, that the data actually left every system and every vendor it had reached.
— FinAudit CPA

Does CCPA apply to my business?

The law reaches for-profit businesses that collect California consumers’ personal information, do business in California, and meet at least one of three thresholds. You are in scope if you have annual gross revenue above 25 million dollars; or you buy, sell, or share the personal information of 100,000 or more California consumers or households in a year; or you derive 50 percent or more of your annual revenue from selling or sharing consumers’ personal information. Meeting any one of the three is enough.

Two points surprise people. First, you do not need an office or a single employee in California to qualify. Serving California consumers over the internet is enough to be "doing business" there, which is why so many companies far outside the state fall under the law. Second, the 100,000 threshold counts households, not just individuals, and it is easier to reach than it looks once you count website visitors, app users, and leads.

The CPRA also created rules for entities that do not meet the thresholds on their own but voluntarily certify compliance, and it carved out specific handling for employee and business-to-business data that earlier versions had exempted. If you are close to a threshold, or unsure whether your consumer counts include the right categories, that ambiguity is exactly the kind of question our assessment resolves before it becomes an enforcement problem.

The consumer rights you have to honor

California privacy law grants consumers a defined set of rights, and each one creates an obligation you have to be able to meet on demand. The right to know lets a consumer ask what personal information you collected, where it came from, why you collected it, and who you disclosed it to. The right to delete lets them ask you to erase the data you hold, and to pass that request to your service providers. The right to correct, added by the CPRA, lets them fix inaccurate information.

The rights that draw the most enforcement attention concern selling and sharing. The right to opt out of sale or sharing lets a consumer tell you to stop selling their data or sharing it for cross-context behavioral advertising. The CPRA added the right to limit the use of sensitive personal information — data such as Social Security numbers, precise geolocation, health details, race, or the contents of private messages — so a consumer can restrict you to using it only for the narrow purposes the law permits.

Two mechanics matter here. You must honor the Global Privacy Control, a browser signal that communicates an opt-out automatically, as a valid request. And you cannot retaliate: charging a higher price or degrading service because someone exercised a right is unlawful discrimination under the statute. We test whether your systems actually deliver each of these rights, not just whether your policy claims to.

CCPA/CPRA vs GDPR: how they differ

Teams that already handle European data assume the CCPA is just a lighter GDPR. The overlap is real, but the mechanics differ in ways that change how you build the program. If you operate under both, map them together rather than assuming one covers the other.

CCPA / CPRA (California) GDPR (EU/EEA)
Who is protected California residents, including households Individuals in the EU and EEA
Legal basis to process No prior legal basis required; consumer rights apply after collection Requires a lawful basis, often consent, before processing
Core opt-out Opt out of sale or sharing; opt in to sell data of minors Consent to process is generally opt-in from the start
Sensitive data Right to limit use of sensitive personal information Special categories need explicit consent or another condition
Enforcer California Privacy Protection Agency and the Attorney General National data protection authorities
Threshold to apply Revenue or volume thresholds must be met Applies broadly, with no revenue threshold

How our CCPA/CPRA engagement runs

You always know where you stand and what comes next. The work is practical, evidence-based, and built to hand off to your team.

  1. 01

    Scoping and applicability

    We confirm whether and how the law applies to you, which thresholds you meet, and which business units and systems fall in scope. You get a fixed fee before we start.

  2. 02

    Data mapping

    We trace what personal information you collect, where it lives, why you hold it, and every vendor you disclose it to — the foundation every other obligation rests on.

  3. 03

    Gap assessment

    We measure your notices, rights processes, opt-out mechanics, and contracts against the amended CCPA and flag exactly where you fall short.

  4. 04

    Sale and share analysis

    We examine your ad tech, analytics, and data flows to determine what counts as selling or sharing, and where a "Do Not Sell or Share" obligation is triggered.

  5. 05

    Remediation roadmap

    You get a prioritized, plain-language plan: what to fix first, what each fix involves, and which items need your legal counsel rather than us.

  6. 06

    Validation and handoff

    We help you test that rights requests, opt-out signals, and deletion flows work end to end, then hand your team a program it can run and defend.

Service provider, contractor, or third party — and why it matters

Every vendor that receives California personal information from you falls into one of three roles, and the label decides your contract terms and your exposure. A service provider processes data on your behalf for a business purpose you set, under a contract that bars them from using it for their own ends. A contractor is similar — a party you make personal information available to for a business purpose, again under restrictive terms. Both are, in effect, extensions of your operation, and disclosing data to them is not treated as a sale.

A third party is anyone who is neither. When you hand data to a third party for their own use, or in exchange for value, you are very likely selling or sharing it, which triggers opt-out obligations, disclosure requirements, and the "Do Not Sell or Share My Personal Information" link. Many companies think they only use service providers, then discover during data mapping that an analytics or advertising partner is actually acting as a third party. That single misclassification is one of the most common and most costly gaps we find.

Getting these relationships right is both a contract exercise and an operational one. The written terms have to include the specific commitments the law requires, and the real data flows have to match what those contracts say. We check both, because a compliant contract over a non-compliant data flow protects no one.

Who enforces the law, and what an assessment gets you

The CPRA created a dedicated regulator, the California Privacy Protection Agency, which now enforces the law alongside the California Attorney General. The agency writes regulations, investigates, and can bring administrative actions with penalties per violation — and the automatic 30-day cure period that softened the original CCPA is gone, so a gap can become a finding without a grace window. Separately, consumers can sue directly when certain unencrypted personal information is exposed in a breach caused by inadequate security.

Our engagement gives you a clear read of where you actually stand and a roadmap to close the distance. You receive a data map, a documented gap assessment against the amended CCPA, an analysis of your selling and sharing activity, vendor-contract findings, and a prioritized remediation plan written in language your team can act on. We are a licensed CPA firm doing practical privacy assessment and remediation work. We do not issue legal opinions — your counsel does that — and we will tell you plainly which items belong on their desk rather than ours.

What actually drives the cost

We quote a fixed engagement fee, so you will not see a surprise hourly bill. The number depends on real factors, not guesswork:

Data footprint

The more systems, products, and categories of personal information you hold, the more there is to map and assess.

Number of vendors

Every service provider, contractor, and third party means another data flow and another contract to review against the law.

Selling and sharing complexity

Heavy use of advertising and analytics tools makes the sale-and-share analysis more involved than a simple internal-use operation.

Current program maturity

If you already have notices, rights processes, and data inventories in place, we validate and refine. If not, more of the work is building from the ground up.

Why run your CCPA/CPRA work with FinAudit CPA

Privacy compliance is not only a legal question. It is an operational and controls question, and that is where a licensed CPA firm earns its place. We build audit-grade evidence for a living, so when we map your data and test your rights processes, we do it the way an examiner would — tracing claims to proof, not taking a policy page at its word. That discipline is exactly what stands up if the California Privacy Protection Agency ever asks you to show your work.

You get senior attention that does not fade as the engagement grows, a fixed scope you can budget around, and findings written in plain English rather than statute-speak. Because we also handle GDPR, ISO 27701, and HIPAA work, we map overlapping obligations once instead of billing you to rebuild the same data inventory for each framework. And we stay in our lane honestly: we assess and remediate, and we point the legal-opinion questions to your counsel rather than pretending they are ours to answer.

Pair your CCPA/CPRA work with

  • GDPR assessment, when you also serve customers in the EU and want both privacy regimes mapped together
  • ISO 27701, when you want a certifiable privacy management system layered on top of your compliance program
  • HIPAA compliance assessment, when you handle protected health information alongside California consumer data
  • A data mapping refresh, so every framework you follow reads from one accurate inventory instead of several

CCPA / CPRA Compliance · questions buyers ask

Answers before you ever fill in a form.

More across our FAQs and glossary.

It applies if you are a for-profit business that does business in California, collects California consumers’ personal information, and meets one of three thresholds: over 25 million dollars in annual revenue, data on 100,000 or more consumers or households a year, or 50 percent or more of revenue from selling or sharing personal information. You do not need a California office to qualify — serving California consumers online is enough. Our assessment confirms exactly where you stand.

They are not two separate laws. The CPRA, passed by California voters in 2020 and effective in 2023, amended and expanded the original CCPA. The operative statute today is the CCPA as amended. The CPRA added the rights to correct data and to limit sensitive personal information, created the "sharing" concept for behavioral advertising, and established the California Privacy Protection Agency as a dedicated enforcer.

Selling means disclosing personal information to a third party for money or other value. Sharing, a CPRA concept, means disclosing it for cross-context behavioral advertising even when no money changes hands. Both trigger opt-out rights and the "Do Not Sell or Share My Personal Information" link. Many companies assume they do not sell data, then find during data mapping that an advertising or analytics partner qualifies as a third party.

A service provider processes personal information on your behalf, for purposes you set, under a contract that bars other uses; disclosing data to one is not a sale. A contractor is similar. A third party is anyone who is neither, and handing data to a third party for their own use generally counts as selling or sharing. The label decides your contract terms and your opt-out obligations, so getting it right matters.

Two bodies enforce it: the California Privacy Protection Agency, which the CPRA created specifically for this purpose, and the California Attorney General. The agency can investigate, write regulations, and bring administrative penalties per violation. The automatic 30-day cure period from the original CCPA is gone. Consumers can also sue directly when certain unencrypted personal information is exposed in a breach caused by inadequate security.

No. FinAudit CPA is a licensed US CPA firm, and we deliver a practical assessment and remediation program: data mapping, a gap analysis against the amended CCPA, a sale-and-share review, vendor-contract findings, and a prioritized plan. Formal legal opinions on your obligations come from your attorneys. We tell you clearly which items belong with counsel, so nothing important falls between us.

The GDPR generally requires a lawful basis, often opt-in consent, before you process data, and it applies with no revenue threshold. The CCPA lets you collect first but gives consumers rights afterward, including the right to opt out of sale or sharing, and it applies only once you meet a revenue or volume threshold. The two overlap enough to map together but differ enough that one does not cover the other.

The right to know lets a California consumer ask what personal information you collected, its sources, your purposes, and who you disclosed it to. The right to delete lets them ask you to erase the data and pass that request to your service providers. The right to correct, added by the CPRA, lets them fix inaccurate information. You must give consumers working ways to exercise each one and respond within the law’s timelines.

FINAUDIT CPA · ASSURANCE · VERIFIED · INDEPENDENT ·

Ready when you are

Ready to make trust your competitive advantage?

One licensed CPA firm for your SOC, ISO, HIPAA, and VAPT programs — and the financial audits behind them. Talk to a senior auditor, not a sales rep.

Call Book a Consultation