Other frameworks
CCPA/CPRA: California consumer privacy
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over the personal information businesses hold about them. EuroCompliant handles CCPA requests through the same pipeline as GDPR ones, with its own jurisdiction and deadline, which is the part of this framework most worth knowing well.
Transcript
The California Consumer Privacy Act gives California residents the right to know, delete, and correct their personal data, and to opt out of sale and sharing.
Open Settings and go to Compliance Frameworks. Unlike the AI Act and GDPR, CCPA is not locked on by default, so it needs to be switched on explicitly.
Turn CCPA on. Its obligations join your list: the right to know, the right to delete, and the verifiable consumer request process.
Now open the Trust & Privacy Hub and log a request. Choosing the CCPA jurisdiction applies its own forty-five day deadline instead of the GDPR's thirty, so the clock is always right.
The same consent records that support GDPR's lawful basis requirement also evidence CCPA compliance. Record consent under the right basis and it feeds both frameworks at once.
Choose the consent method: an opt-in checkbox, a cookie banner, or a signed form, and record what was agreed. The record is timestamped and auditable.
Because every framework shares the same obligations engine, CCPA's posture shows up on the dashboard alongside everything else, and your verifiable request handling is ready for inspection.
Why this is required
Section 1798.100 gives consumers the right to know what personal information is collected about them. Section 1798.105 gives the right to delete it. Section 1798.120 gives the right to opt out of the sale or sharing of personal information, including a requirement to honour the Global Privacy Control signal. Section 1798.125 prohibits discriminating against consumers who exercise these rights.
Unlike GDPR's uniform one-month response window, CCPA gives businesses 45 days to respond to a verified consumer request, extendable once by a further 45 days for complex cases.
What EuroCompliant does
CCPA requests go through the same Privacy Requests workspace as GDPR and UK GDPR ones, with CCPA / CPRA as a distinct jurisdiction option that automatically applies the 45-day countdown instead of the 30-day GDPR clock.
Consent records shared with the GDPR module double as evidence for CCPA's opt-in and disclosure requirements.
The opt-out-of-sale side of CCPA, tracking third parties you share or sell data to, is earlier-stage: a document type for the Opt-Out Register exists in the platform, but there's no dedicated workspace yet for logging individual third-party sales the way there is for requests and processors. If that applies to you, track it in your Vendors & Processors records for now.
Deadlines
Walking through it
Enable CCPA/CPRA
Unlike EU AI Act and GDPR, this framework isn't locked on by default, so turn it on explicitly if California residents' data is in scope.
Open /settings/profile?tab=frameworks →Log requests with the right jurisdiction
Select CCPA / CPRA when logging a request from a California resident, so the 45-day clock applies instead of GDPR's 30 days.
Open /privacy-hub →Keep consent and disclosure records current
The same consent records that support GDPR Article 7 evidence CCPA's opt-in and disclosure obligations.
Open /privacy-hub →The law
Right to know
Consumers have the right to know what personal information a business collects, and why.
Right to delete
Consumers may request deletion of personal information collected about them, subject to exceptions.
Right to opt out
Consumers may opt out of the sale or sharing of their personal information, including via the Global Privacy Control signal.
Non-discrimination
Businesses may not discriminate against consumers for exercising their CCPA rights.
Frequently asked
Do we need this if we already comply with GDPR?
GDPR compliance covers most of the same ground in spirit, but CCPA has its own deadline, its own defined rights, and its own regulator (the California Privacy Protection Agency). If California residents' data is in scope, track it explicitly rather than assuming GDPR compliance is a substitute.
What's the Global Privacy Control?
A browser-level signal consumers can set to automatically communicate an opt-out-of-sale preference. Section 1798.135 requires businesses to honour it as a valid opt-out request, the same as if the consumer had submitted one manually.
Related guides
GDPR & privacy
How data protection obligations run alongside the AI Act, and the parts of the GDPR that carry operational consequences.
Data subject requests (DSARs)
Tracking Articles 15 to 22 requests against the one-month statutory clock, including the automated-decision right that bites hardest on AI.
Records of processing (RoPA)
The Article 30 record: the foundational GDPR document, and usually the first thing requested in an investigation.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial