CCPA/CPRA Compliance
Protect California consumer privacy with automated compliance
Evidr automates CCPA consumer rights management, data inventory mapping, and DSAR fulfillment. Respond to access requests in days instead of weeks and avoid penalties up to $7,500 per violation.
Inside the product
CCPA in the console, control by control.

01CCPA
Consumer rights
What a California resident can ask of you, and how long you have to answer.
- 0145 days
Right to Know
Consumers can request what personal information you collect, use, and share about them
- 0245 days
Right to Delete
Consumers can request deletion of their personal information with limited exceptions
- 0345 days
Right to Correct
Consumers can request correction of inaccurate personal information (CPRA)
- 04Immediate
Right to Opt-Out
Consumers can opt-out of sale or sharing of their personal information
- 05Immediate
Right to Limit Use
Consumers can limit use of sensitive personal information to necessary purposes (CPRA)
- 06Ongoing
Right to Non-Discrimination
Businesses cannot discriminate against consumers who exercise their rights
02CCPA
Categories of personal information
The categories the statute names, with the kind of data each one covers.
- IdentifiersName, email, SSN, driver's license, passport
- Commercial InformationPurchase history, products/services obtained
- Internet ActivityBrowsing history, search history, interactions
- Geolocation DataPrecise location data from devices
- Biometric InformationFingerprints, face geometry, voiceprints
- Professional InformationEmployment history, employer information
- Education InformationStudent records, educational history
- InferencesProfiles reflecting preferences, behavior, attitudes
- Sensitive Personal InfoSSN, financial accounts, precise geolocation, racial/ethnic origin, health data
03What Evidr does
Everything CCPA asks for, handled.
- 01
Consumer Rights Management
Track and respond to all CCPA consumer rights: right to know, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information.
- 02
Data Inventory Mapping
Automatically map personal information collection, storage, and sharing across your systems. Document data categories, purposes, and retention periods.
- 03
DSAR Workflow Automation
Streamline Data Subject Access Requests with automated intake, verification, fulfillment tracking, and response within the 45-day deadline.
- 04
Opt-Out Preference Center
Implement compliant "Do Not Sell/Share My Personal Information" mechanisms with Global Privacy Control (GPC) signal recognition.
- 05
Service Provider Oversight
Manage data processing agreements, track third-party data sharing, and ensure service providers meet CCPA contractual requirements.
- 06
Sensitive Information Controls
Identify and protect sensitive personal information (SPI) categories including SSN, financial data, geolocation, biometrics, and health information.
04The path
CCPA readiness, step by step.
- 01Week 1-2
Data Inventory & Mapping
Document all personal information collection points, storage systems, and third-party sharing. Categorize data per CCPA definitions including sensitive personal information.
- 02Week 2-3
Privacy Policy & Notices
Update privacy policy with required disclosures: data categories, purposes, retention periods, consumer rights, and contact methods. Add required notices at collection points.
- 03Week 3-5
Consumer Rights Infrastructure
Implement DSAR intake forms, verification processes, and fulfillment workflows. Set up opt-out mechanisms with GPC signal recognition.
- 04Week 5-6
Service Provider Agreements
Review and update contracts with service providers and third parties. Ensure required CCPA contractual provisions are in place.
- 05Week 6-8
Training & Ongoing Compliance
Train staff on CCPA requirements and DSAR handling. Implement ongoing monitoring, record-keeping, and annual policy reviews.
05Questions
CCPA, answered.
Related
Often paired with CCPA.
Ready for CCPA?
Start on the free Starter plan, or talk to us and see CCPA set up on your own stack.