Skip to main content

CCPA·California Consumer Privacy Act

US-CA

Test your website for CCPA compliance

Enter your domain to start a free scan and open an account - no integration required.

Overview

The California Consumer Privacy Act (CCPA) is a state statute that enhances privacy rights and consumer protection for residents of California. It applies to businesses that collect personal information from California residents and meet certain thresholds.

Penalties

$2,500 per unintentional violation, $7,500 per intentional violation

What Complyy checks

6 automated tests 3 passive, 3 active

Passive (instant scan)

critical

"Do Not Sell or Share My Personal Information" link present

Cal. Civ. Code §1798.135 requires a clear and conspicuous "Do Not Sell or Share My Personal Information" link on the homepage when the business sells or shares data. Missing link is the single most-cited CCPA violation by the CA AG.

high

Privacy policy includes CCPA-required disclosures

§1798.130 requires a privacy policy listing categories collected, sources, purposes, third parties, retention, and consumer rights. The policy must be updated at least every 12 months.

medium

Categories of personal data collected are disclosed

§1798.110 requires disclosure of the specific categories of personal information collected in the past 12 months. Generic statements like "we collect information about you" are non-compliant.

Active (synthetic identity tests)

critical

Opt-out of sale/sharing request honored within 15 days(waits up to 15d for response)

Once a consumer opts out of sale/sharing, the business must comply within 15 business days (CCPA Regs §7026). Continued targeted ads after opt-out is a documented enforcement priority.

high

Right to delete fulfilled within 45 days(waits up to 45d for response)

§1798.105 requires deletion within 45 days, with exceptions documented. Partial deletion or "soft delete" that leaves marketing profiles intact is a finding.

high

Right to know fulfilled within 45 days(waits up to 45d for response)

§1798.130 requires fulfilling right-to-know requests within 45 days (extendable to 90). Slow or incomplete responses trigger AG enforcement and the private right of action under CPRA.

Learn More About California Consumer Privacy Act

Overview of the California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA) was enacted to give California residents greater control over their personal information. It establishes specific rights for consumers and imposes obligations on businesses that collect and process personal data.

Who It Applies To

The CCPA applies to any for-profit business that:

  • Collects personal information from California residents.

  • Has annual gross revenues exceeding $25 million.

  • Buys, receives, sells, or shares the personal information of 50,000 or more consumers, households, or devices.

  • Derives 50% or more of its annual revenues from selling consumers' personal information.

Key Requirements

Under the CCPA, businesses must:

  • Inform consumers about the categories of personal information collected and the purposes for which it is used.

  • Provide consumers with the right to access their personal information and request its deletion.

  • Allow consumers to opt-out of the sale of their personal information.

  • Implement reasonable security measures to protect personal information.

Penalties

Non-compliance with the CCPA can result in:

  • Fines of up to $2,500 for each unintentional violation.

  • Fines of up to $7,500 for each intentional violation.

  • Consumers have the right to sue for damages in the event of a data breach.

Compliance Tips

To comply with the CCPA, businesses should:

  • Conduct a data inventory to understand what personal information is collected and processed.

  • Update privacy policies to reflect CCPA requirements.

  • Implement processes to handle consumer requests regarding their personal information.

  • Train employees on CCPA compliance and data protection best practices.

Recently Scanned Websites

Live compliance reports from Complyy's public directory.

Browse the full directory →

The Platform

How Complyy enforces CCPA compliance

Complyy continuously tests your site against California Consumer Privacy Act using synthetic identities that behave exactly like regulators — and your customers.

01

Discover

We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.

02

Scan & Test

Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.

03

Score & Evidence

Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.

Why Complyy

The only platform that tests compliance the way regulators do

Real synthetic identities

We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.

Active + passive tests

Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.

Court-admissible artifacts

Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.

3

Regulations monitored

18

Compliance tests

Agentic identities

3 min

Avg. first evidence artifact

Is your company CCPA-compliant?

Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.