Privacy regulations give individuals a chance to exercise privacy rights over how their data is used and stored. Compliance with privacy regulations such as California Consumer Protection Act (CCPA) are best met by following strategic, targeted operational processes (privacy operations) and technological processes (privacy engineering) in tandem. But there’s still a lot to unpack in there.
This free ebook gives a high-level overview of the CCPA to help you get familiar with the requirements, such as:
- Opt-out options and personal data processing restrictions
- Penalties for non-compliance
- How to solve for critical technology gaps
Which Companies the CCPA Applies To
The CCPA reaches any company doing business in California that meets one of three tests: annual gross revenue above $25 million, buying selling or sharing the personal information of 50,000 or more consumers, households or devices in a year, or deriving half or more of its revenue from selling consumers’ personal data.
It covers the full life of that data, from collection through use, processing, sharing and sale, and it applies to customers, employees and other individuals alike.
The Opt-Out Requirement
Companies must carry a “Do Not Sell My Info” link, and sale is defined broadly. Any exchange of personal information for value with a third party counts, including data captured by cookies and similar technologies.
The mechanism has to be easy. A business may not design an opt-out process whose effect is to discourage or obstruct the decision, and requests must be honored within 15 business days. Opting out stops the selling; it does not restrict other uses.
Responding to a Data Subject Access Request
Right to know and right to be forgotten requests must be answered within 45 business days. The exceptions are narrow: where the identity of the requester cannot be verified, or where a request concerns a child under 13 and the requester cannot be verified as the parent or guardian.
What Non-Compliance Costs
Penalties run from $2,500 for an unintentional violation to $7,500 for an intentional one, and violations involving children’s data carry the same fines as those involving adults. A company that cures the problem within 30 days of being notified is not liable.
The clause worth reading twice concerns private action. An individual can sue only where there has been a breach of unencrypted and unredacted personal data, which makes encryption and redaction the difference between a regulatory matter and a litigation exposure.
You Cannot Sell, Delete or Report What You Cannot Find
Every obligation above assumes the company knows what it holds and where. In practice that is the hard part, because personal data arrives from several directions, some collected directly, some sourced from third parties, some shared internally as services grew.
Traditional database searches fail here. Column headers and formats differ between departments and between external sources, so the same kind of information is labeled inconsistently or unrecognizably. Personal data also sits in unstructured and semi-structured files, across on-premises systems, Azure, AWS and Google environments, and on the laptops and shared folders people use every day.
Operations and Engineering Together
Meeting the CCPA works best as two efforts running in parallel. Privacy operations put governance policy in front of the whole organization and make protection a stated commitment. Privacy engineering makes that policy executable, through discovery, classification and automated protection that produce evidence as a by-product of running.
The timelines make that concrete. Fifteen business days to honor an opt-out and 45 to answer an access request are short intervals if the search has to be designed each time one arrives, and entirely routine if the inventory already exists and is current.

