New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Other frameworks

CCPA/CPRA: California consumer privacy

The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over the personal information businesses hold about them. EuroCompliant handles CCPA requests through the same pipeline as GDPR ones, with its own jurisdiction and deadline, which is the part of this framework most worth knowing well.

Transcript

The California Consumer Privacy Act gives California residents the right to know, delete, and correct their personal data, and to opt out of sale and sharing.

Open Settings and go to Compliance Frameworks. Unlike the AI Act and GDPR, CCPA is not locked on by default, so it needs to be switched on explicitly.

Turn CCPA on. Its obligations join your list: the right to know, the right to delete, and the verifiable consumer request process.

Now open the Trust & Privacy Hub and log a request. Choosing the CCPA jurisdiction applies its own forty-five day deadline instead of the GDPR's thirty, so the clock is always right.

The same consent records that support GDPR's lawful basis requirement also evidence CCPA compliance. Record consent under the right basis and it feeds both frameworks at once.

Choose the consent method: an opt-in checkbox, a cookie banner, or a signed form, and record what was agreed. The record is timestamped and auditable.

Because every framework shares the same obligations engine, CCPA's posture shows up on the dashboard alongside everything else, and your verifiable request handling is ready for inspection.

Why this is required

Section 1798.100 gives consumers the right to know what personal information is collected about them. Section 1798.105 gives the right to delete it. Section 1798.120 gives the right to opt out of the sale or sharing of personal information, including a requirement to honour the Global Privacy Control signal. Section 1798.125 prohibits discriminating against consumers who exercise these rights.

Unlike GDPR's uniform one-month response window, CCPA gives businesses 45 days to respond to a verified consumer request, extendable once by a further 45 days for complex cases.

What EuroCompliant does

CCPA requests go through the same Privacy Requests workspace as GDPR and UK GDPR ones, with CCPA / CPRA as a distinct jurisdiction option that automatically applies the 45-day countdown instead of the 30-day GDPR clock.

Consent records shared with the GDPR module double as evidence for CCPA's opt-in and disclosure requirements.

The opt-out-of-sale side of CCPA, tracking third parties you share or sell data to, is earlier-stage: a document type for the Opt-Out Register exists in the platform, but there's no dedicated workspace yet for logging individual third-party sales the way there is for requests and processors. If that applies to you, track it in your Vendors & Processors records for now.

Deadlines

45 daysThe standard CCPA response deadline, extendable once by a further 45 days for complex requests, longer than GDPR's 30-day window.

Walking through it

1

Enable CCPA/CPRA

Unlike EU AI Act and GDPR, this framework isn't locked on by default, so turn it on explicitly if California residents' data is in scope.

Open /settings/profile?tab=frameworks →
2

Log requests with the right jurisdiction

Select CCPA / CPRA when logging a request from a California resident, so the 45-day clock applies instead of GDPR's 30 days.

Open /privacy-hub →
3

Keep consent and disclosure records current

The same consent records that support GDPR Article 7 evidence CCPA's opt-in and disclosure obligations.

Open /privacy-hub →

The law

Frequently asked

Do we need this if we already comply with GDPR?

GDPR compliance covers most of the same ground in spirit, but CCPA has its own deadline, its own defined rights, and its own regulator (the California Privacy Protection Agency). If California residents' data is in scope, track it explicitly rather than assuming GDPR compliance is a substitute.

What's the Global Privacy Control?

A browser-level signal consumers can set to automatically communicate an opt-out-of-sale preference. Section 1798.135 requires businesses to honour it as a valid opt-out request, the same as if the consumer had submitted one manually.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial