Test your website for CCPA compliance
Enter your domain to start a free scan and open an account - no integration required.
Overview
The California Consumer Privacy Act (CCPA) is a state statute that enhances privacy rights and consumer protection for residents of California. It applies to businesses that collect personal information from California residents and meet certain thresholds.
Penalties
$2,500 per unintentional violation, $7,500 per intentional violation
What Complyy checks
6 automated tests — 3 passive, 3 active
Passive (instant scan)
"Do Not Sell or Share My Personal Information" link present
Cal. Civ. Code §1798.135 requires a clear and conspicuous "Do Not Sell or Share My Personal Information" link on the homepage when the business sells or shares data. Missing link is the single most-cited CCPA violation by the CA AG.
Privacy policy includes CCPA-required disclosures
§1798.130 requires a privacy policy listing categories collected, sources, purposes, third parties, retention, and consumer rights. The policy must be updated at least every 12 months.
Categories of personal data collected are disclosed
§1798.110 requires disclosure of the specific categories of personal information collected in the past 12 months. Generic statements like "we collect information about you" are non-compliant.
Active (synthetic identity tests)
Opt-out of sale/sharing request honored within 15 days(waits up to 15d for response)
Once a consumer opts out of sale/sharing, the business must comply within 15 business days (CCPA Regs §7026). Continued targeted ads after opt-out is a documented enforcement priority.
Right to delete fulfilled within 45 days(waits up to 45d for response)
§1798.105 requires deletion within 45 days, with exceptions documented. Partial deletion or "soft delete" that leaves marketing profiles intact is a finding.
Right to know fulfilled within 45 days(waits up to 45d for response)
§1798.130 requires fulfilling right-to-know requests within 45 days (extendable to 90). Slow or incomplete responses trigger AG enforcement and the private right of action under CPRA.
Learn More About California Consumer Privacy Act
Overview of the California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA) was enacted to give California residents greater control over their personal information. It establishes specific rights for consumers and imposes obligations on businesses that collect and process personal data.
Who It Applies To
The CCPA applies to any for-profit business that:
Collects personal information from California residents.
Has annual gross revenues exceeding $25 million.
Buys, receives, sells, or shares the personal information of 50,000 or more consumers, households, or devices.
Derives 50% or more of its annual revenues from selling consumers' personal information.
Key Requirements
Under the CCPA, businesses must:
Inform consumers about the categories of personal information collected and the purposes for which it is used.
Provide consumers with the right to access their personal information and request its deletion.
Allow consumers to opt-out of the sale of their personal information.
Implement reasonable security measures to protect personal information.
Penalties
Non-compliance with the CCPA can result in:
Fines of up to $2,500 for each unintentional violation.
Fines of up to $7,500 for each intentional violation.
Consumers have the right to sue for damages in the event of a data breach.
Compliance Tips
To comply with the CCPA, businesses should:
Conduct a data inventory to understand what personal information is collected and processed.
Update privacy policies to reflect CCPA requirements.
Implement processes to handle consumer requests regarding their personal information.
Train employees on CCPA compliance and data protection best practices.
Recently Scanned Websites
Live compliance reports from Complyy's public directory.
The Platform
How Complyy enforces CCPA compliance
Complyy continuously tests your site against California Consumer Privacy Act using synthetic identities that behave exactly like regulators — and your customers.
Discover
We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.
Scan & Test
Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.
Score & Evidence
Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.
Why Complyy
The only platform that tests compliance the way regulators do
Real synthetic identities
We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.
Active + passive tests
Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.
Court-admissible artifacts
Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.
3
Regulations monitored
18
Compliance tests
∞
Agentic identities
3 min
Avg. first evidence artifact
Is your company CCPA-compliant?
Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.