CCPA Compliance

CCPA Compliance Tool & Platform

Link your California Consumer Privacy Act obligations to the controls you already maintain, on a platform built in France.

What the CCPA is and why it matters

The California Consumer Privacy Act (CCPA), strengthened by the CPRA, grants California residents broad rights over their personal data: access, deletion, opt-out of sale and correction. Any business handling the data of California consumers, wherever it is based, may fall within its scope. For European compliance teams, it is often an extraterritorial obligation to manage alongside the GDPR. Non-compliance exposes organizations to financial penalties and significant reputational risk.

How Vailor supports your CCPA compliance

The CCPA is not part of Vailor's catalogue of ready-to-use frameworks: the Vailor team adds it on request to the Vailor Control Framework (VCF). Its requirements are linked to the controls you already maintain, including those that answer the GDPR, which avoids duplicates. Each control carries its evidence and actions, and evidence collected once serves every framework. Vailor is not a consumer request handling tool: it gives you a unified view of your controls, evidence and actions across jurisdictions.

Why control over your data matters

The CCPA rests partly on the trust placed in how personal data is handled, so your compliance tool must be beyond reproach on that front. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice. Data is encrypted at rest and in transit, never used to train models, and every action is recorded in an audit log with no delete function. You pool your GDPR and CCPA efforts on a single control foundation.

A platform built for privacy

One control, many jurisdictions

CCPA requirements linked to the controls you already maintain for the GDPR and your other frameworks.

Reusable evidence

Evidence collected once serves the CCPA and your other frameworks, with no double entry.

Compliance evidence

Each piece of evidence is tied to its control and every action is traced, so you can demonstrate compliance during an inspection.

Data sovereignty

As SaaS, your compliance data is stored in France (AWS Paris region), or on your premises, even when handling a foreign obligation.

What you gain with Vailor

CCPA requirements added on request by the Vailor team to your controls
Reuse of your GDPR controls for the CCPA
Evidence collected once, reused everywhere
Gaps turned into actions tracked in the action plan
An audit log with no delete function for inspections
A consolidated view of your privacy compliance

Frequently asked questions about the CCPA

Which businesses does the CCPA apply to?

The law targets for-profit organisations that do business in California, decide the purposes and means of the processing, and cross one of three thresholds: annual gross revenue above 25 million dollars (a figure adjusted periodically for inflation), buying, selling or sharing the personal information of 100,000 or more Californian consumers or households a year, or drawing half or more of annual revenue from selling or sharing that information. No physical presence in the United States is required.

Does GDPR compliance cover the CCPA?

No, though it takes you a long way. The two texts differ at the root: the GDPR requires a lawful basis before any processing, whereas the CCPA works mainly on an opt-out model, where the consumer must be able to object after the fact. The CCPA adds notions the GDPR does not carry, such as the household, sharing for cross-context behavioural advertising, and the right to limit the use of sensitive personal information. In return it imposes neither a DPO nor restrictions on international transfers. The record of processing built for the GDPR remains the best starting point.

What counts as selling data under the CCPA?

Many organisations are convinced they sell nothing and are wrong, because the definition is deliberately wide. Selling means disclosing personal information to a third party for monetary or any other valuable consideration. The CPRA added sharing, which covers disclosure for cross-context behavioural advertising even when no money changes hands. In practice most advertising trackers on a website fall into one category or the other, which triggers the duty to offer an opt-out and to honour opt-out preference signals sent by the visitor's browser, such as the Global Privacy Control.

How long do I have to answer a consumer request?

Three clocks, easily confused. A verifiable request (access, deletion, correction) has to be acknowledged within ten business days, with an explanation of how it will be handled, then answered within forty-five calendar days of receipt, extendable once by a further forty-five days where the complexity warrants it and the consumer is told. The count starts when the request arrives, not when it has been verified. A request to opt out of sale or sharing runs on its own clock: no verification, but action within fifteen business days.

Is there such a thing as CCPA certification?

No. The CCPA is a Californian state law, not a certifiable standard: no body issues a CCPA certificate. What gets examined is your actual practice, by the California Attorney General and by the California Privacy Protection Agency created by the CPRA. That agency has also adopted rules requiring risk assessments for processing that presents a significant risk to consumer privacy, and periodic cybersecurity audits for certain businesses, phased in over several years.

What penalties apply under the CCPA?

The fine can reach 2,500 dollars per violation, and 7,500 dollars where the violation is intentional or involves the personal information of a consumer the business knows to be under sixteen. Each affected consumer can count as a separate violation, which changes the scale on a mass incident. The CPRA removed the automatic cure period businesses used to enjoy before the regulator. On top of that sits a private right of action, limited to breaches of certain unencrypted personal information, with statutory damages of 100 to 750 dollars per consumer per incident.

Why use CCPA software rather than a spreadsheet?

Because a consumer request is not an isolated ticket: you need to know which systems hold the data, which recipients it went to, whether it is still being shared with advertising partners, and then prove the response went out on time. A spreadsheet loses those links the moment a processing activity changes, warns nobody while the clock runs, and keeps no timestamped record of what was done. A dedicated tool holds the counter, ties each request to the systems involved and keeps evidence that stands up to scrutiny. In Vailor, the CCPA is added on request: its requirements join the controls you already maintain.

Master your CCPA compliance

Book 30 minutes with us: we listen to your context and tell you concretely how Vailor can support your CCPA and GDPR obligations.

Book a demo