CCPA/CPRA Compliance

Protect California consumer privacy with automated compliance

Evidr automates CCPA consumer rights management, data inventory mapping, and DSAR fulfillment. Respond to access requests in days instead of weeks and avoid penalties up to $7,500 per violation.

CCPACCPA
CCPACalifornia Consumer Privacy Act, as amended by the CPRAOn every plan
  • Controls and evidence requirements mapped in advance
  • Every upload read and scored by the AI reviewer
  • Policies, monitoring and the auditor portal included
Shares evidence withGDPRSOC 2HIPAA
40M+California residents protected
$7,500Max penalty per violation
45Days to respond to DSARs
4-8Weeks to compliance

Inside the product

CCPA in the console, control by control.

The Evidr dashboard in a live workspace: SOC 2 Type II at 100% with 68 of 68 controls, 68 approved evidence items, a 99% pass rate on 103 checks, and quick actions beside them.

01CCPA

Consumer rights

What a California resident can ask of you, and how long you have to answer.

  • 0145 days

    Right to Know

    Consumers can request what personal information you collect, use, and share about them

  • 0245 days

    Right to Delete

    Consumers can request deletion of their personal information with limited exceptions

  • 0345 days

    Right to Correct

    Consumers can request correction of inaccurate personal information (CPRA)

  • 04Immediate

    Right to Opt-Out

    Consumers can opt-out of sale or sharing of their personal information

  • 05Immediate

    Right to Limit Use

    Consumers can limit use of sensitive personal information to necessary purposes (CPRA)

  • 06Ongoing

    Right to Non-Discrimination

    Businesses cannot discriminate against consumers who exercise their rights

02CCPA

Categories of personal information

The categories the statute names, with the kind of data each one covers.

  • IdentifiersName, email, SSN, driver's license, passport
  • Commercial InformationPurchase history, products/services obtained
  • Internet ActivityBrowsing history, search history, interactions
  • Geolocation DataPrecise location data from devices
  • Biometric InformationFingerprints, face geometry, voiceprints
  • Professional InformationEmployment history, employer information
  • Education InformationStudent records, educational history
  • InferencesProfiles reflecting preferences, behavior, attitudes
  • Sensitive Personal InfoSSN, financial accounts, precise geolocation, racial/ethnic origin, health data

03What Evidr does

Everything CCPA asks for, handled.

  • 01

    Consumer Rights Management

    Track and respond to all CCPA consumer rights: right to know, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information.

  • 02

    Data Inventory Mapping

    Automatically map personal information collection, storage, and sharing across your systems. Document data categories, purposes, and retention periods.

  • 03

    DSAR Workflow Automation

    Streamline Data Subject Access Requests with automated intake, verification, fulfillment tracking, and response within the 45-day deadline.

  • 04

    Opt-Out Preference Center

    Implement compliant "Do Not Sell/Share My Personal Information" mechanisms with Global Privacy Control (GPC) signal recognition.

  • 05

    Service Provider Oversight

    Manage data processing agreements, track third-party data sharing, and ensure service providers meet CCPA contractual requirements.

  • 06

    Sensitive Information Controls

    Identify and protect sensitive personal information (SPI) categories including SSN, financial data, geolocation, biometrics, and health information.

04The path

CCPA readiness, step by step.

  1. 01Week 1-2

    Data Inventory & Mapping

    Document all personal information collection points, storage systems, and third-party sharing. Categorize data per CCPA definitions including sensitive personal information.

  2. 02Week 2-3

    Privacy Policy & Notices

    Update privacy policy with required disclosures: data categories, purposes, retention periods, consumer rights, and contact methods. Add required notices at collection points.

  3. 03Week 3-5

    Consumer Rights Infrastructure

    Implement DSAR intake forms, verification processes, and fulfillment workflows. Set up opt-out mechanisms with GPC signal recognition.

  4. 04Week 5-6

    Service Provider Agreements

    Review and update contracts with service providers and third parties. Ensure required CCPA contractual provisions are in place.

  5. 05Week 6-8

    Training & Ongoing Compliance

    Train staff on CCPA requirements and DSAR handling. Implement ongoing monitoring, record-keeping, and annual policy reviews.

05Questions

CCPA, answered.

Ready for CCPA?

Start on the free Starter plan, or talk to us and see CCPA set up on your own stack.