CCPA Compliance Tool & Platform
Link your California Consumer Privacy Act obligations to the controls you already maintain, on a platform built in France.
What the CCPA is and why it matters
The California Consumer Privacy Act (CCPA), strengthened by the CPRA, grants California residents broad rights over their personal data: access, deletion, opt-out of sale and correction. Any business handling the data of California consumers, wherever it is based, may fall within its scope. For European compliance teams, it is often an extraterritorial obligation to manage alongside the GDPR. Non-compliance exposes organizations to financial penalties and significant reputational risk.
How Vailor supports your CCPA compliance
The CCPA is not part of Vailor's catalogue of ready-to-use frameworks: the Vailor team adds it on request to the Vailor Control Framework (VCF). Its requirements are linked to the controls you already maintain, including those that answer the GDPR, which avoids duplicates. Each control carries its evidence and actions, and evidence collected once serves every framework. Vailor is not a consumer request handling tool: it gives you a unified view of your controls, evidence and actions across jurisdictions.
Why control over your data matters
The CCPA rests partly on the trust placed in how personal data is handled, so your compliance tool must be beyond reproach on that front. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice. Data is encrypted at rest and in transit, never used to train models, and every action is recorded in an audit log with no delete function. You pool your GDPR and CCPA efforts on a single control foundation.
A platform built for privacy
One control, many jurisdictions
CCPA requirements linked to the controls you already maintain for the GDPR and your other frameworks.
Reusable evidence
Evidence collected once serves the CCPA and your other frameworks, with no double entry.
Compliance evidence
Each piece of evidence is tied to its control and every action is traced, so you can demonstrate compliance during an inspection.
Data sovereignty
As SaaS, your compliance data is stored in France (AWS Paris region), or on your premises, even when handling a foreign obligation.
What you gain with Vailor
Frequently asked questions about the CCPA
Which businesses does the CCPA apply to?
The law targets for-profit organisations that do business in California, decide the purposes and means of the processing, and cross one of three thresholds: annual gross revenue above 25 million dollars (a figure adjusted periodically for inflation), buying, selling or sharing the personal information of 100,000 or more Californian consumers or households a year, or drawing half or more of annual revenue from selling or sharing that information. No physical presence in the United States is required.
Does GDPR compliance cover the CCPA?
No, though it takes you a long way. The two texts differ at the root: the GDPR requires a lawful basis before any processing, whereas the CCPA works mainly on an opt-out model, where the consumer must be able to object after the fact. The CCPA adds notions the GDPR does not carry, such as the household, sharing for cross-context behavioural advertising, and the right to limit the use of sensitive personal information. In return it imposes neither a DPO nor restrictions on international transfers. The record of processing built for the GDPR remains the best starting point.
What counts as selling data under the CCPA?
Many organisations are convinced they sell nothing and are wrong, because the definition is deliberately wide. Selling means disclosing personal information to a third party for monetary or any other valuable consideration. The CPRA added sharing, which covers disclosure for cross-context behavioural advertising even when no money changes hands. In practice most advertising trackers on a website fall into one category or the other, which triggers the duty to offer an opt-out and to honour opt-out preference signals sent by the visitor's browser, such as the Global Privacy Control.
How long do I have to answer a consumer request?
Three clocks, easily confused. A verifiable request (access, deletion, correction) has to be acknowledged within ten business days, with an explanation of how it will be handled, then answered within forty-five calendar days of receipt, extendable once by a further forty-five days where the complexity warrants it and the consumer is told. The count starts when the request arrives, not when it has been verified. A request to opt out of sale or sharing runs on its own clock: no verification, but action within fifteen business days.
Is there such a thing as CCPA certification?
No. The CCPA is a Californian state law, not a certifiable standard: no body issues a CCPA certificate. What gets examined is your actual practice, by the California Attorney General and by the California Privacy Protection Agency created by the CPRA. That agency has also adopted rules requiring risk assessments for processing that presents a significant risk to consumer privacy, and periodic cybersecurity audits for certain businesses, phased in over several years.
What penalties apply under the CCPA?
The fine can reach 2,500 dollars per violation, and 7,500 dollars where the violation is intentional or involves the personal information of a consumer the business knows to be under sixteen. Each affected consumer can count as a separate violation, which changes the scale on a mass incident. The CPRA removed the automatic cure period businesses used to enjoy before the regulator. On top of that sits a private right of action, limited to breaches of certain unencrypted personal information, with statutory damages of 100 to 750 dollars per consumer per incident.
Why use CCPA software rather than a spreadsheet?
Because a consumer request is not an isolated ticket: you need to know which systems hold the data, which recipients it went to, whether it is still being shared with advertising partners, and then prove the response went out on time. A spreadsheet loses those links the moment a processing activity changes, warns nobody while the clock runs, and keeps no timestamped record of what was done. A dedicated tool holds the counter, ties each request to the systems involved and keeps evidence that stands up to scrutiny. In Vailor, the CCPA is added on request: its requirements join the controls you already maintain.
Explore AI GRC with Vailor
Our resources on governance, risk and compliance assisted by artificial intelligence.
By role, and to go further
Pages to discover
Recommended articles
ANSSI-labelled EBIOS RM software: the 2026 overview
The EBIOS Risk Manager tools labelled by ANSSI as of 9 October 2026, what the label guarantees, what it does not, and how to check it.
Supply Chain Cyber Risk: How to Manage Your Suppliers
Supply chain cyber risk: what NIS2, DORA and EBIOS RM require, how to map your critical third parties, and what to ask your suppliers before and after signing.
Master your CCPA compliance
Book 30 minutes with us: we listen to your context and tell you concretely how Vailor can support your CCPA and GDPR obligations.