Frameworks
California Consumer Privacy Act (as amended by CPRA)
America's de facto national privacy law — plus the growing pack of state laws behind it.
Book a demoThe CCPA, strengthened by the CPRA, gives California residents GDPR-like rights — access, deletion, correction, opt-out of sale/sharing — enforced by a dedicated agency. With a dozen-plus states following, building for California has become how US companies build for everyone.
Operational, not aspirational
The work is workflows: honoring rights requests within 45 days, a 'Do Not Sell or Share' mechanism including opt-out preference signals, purpose limitation on sensitive data, and contracts flowing obligations to service providers. Enforcement actions so far punish broken opt-outs and ignored requests — operational failures, not policy prose.
How Compriska helps
Compriska tracks rights-request workflows with deadlines, keeps processing purposes and vendor data-sharing documented, and maps CCPA controls alongside GDPR so multi-jurisdiction privacy is one program with two badge sets.
Frequently asked questions
Does CCPA apply to my company?
It applies to for-profit businesses meeting thresholds (roughly $25M+ revenue, or large-scale California data). But with many states enacting similar laws, treating CCPA as your baseline is the pragmatic play regardless of thresholds.
Other frameworks
Automate CCPA/CPRA with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo