The Art of CTO CCPA/CPRA Compliance tool evaluates organizational readiness for California privacy law requirements including consumer data rights, opt-out mechanisms, and data handling practices.
Do we meet CCPA and CPRA?
Applicability from your revenue and data volume, a score across consumer rights, and the gaps.
About 15 min · Assessment · Free
About this toolWhy it matters, common mistakes, FAQ
Do You Meet CCPA And CPRA, Or Just GDPR?
Teams that did GDPR often assume California is covered. CPRA added obligations GDPR does not have — sensitive personal information handling, a Do Not Sell or Share signal, and contractual terms with every recipient — and enforcement has focused on exactly those.
The Global Privacy Control gets ignored because it is a browser signal rather than a form submission. Regulators have treated failure to honour it as a straightforward violation, and it is one of the few things that can be checked from outside your company.
Questions CTOs ask
- What is the difference between CCPA and CPRA?
- CPRA (California Privacy Rights Act) amended and expanded the original CCPA, taking full effect in 2023. Key additions include a new category of "sensitive personal information" with opt-out rights, expanded consumer rights (correction, limited use of sensitive data), stricter requirements for data sharing (not just selling), and the creation of the California Privacy Protection Agency for enforcement. Companies compliant with CCPA need to update their practices to meet the additional CPRA requirements.
- Does CCPA/CPRA apply to my business?
- CCPA/CPRA applies to for-profit businesses that collect California residents' personal information AND meet any one of three thresholds: annual gross revenue over $25 million, buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Service providers and contractors also face obligations through their contracts with covered businesses. Note that this tool tests only the first two thresholds — it asks for revenue and data volume, not revenue mix — so if you sell or share personal information at scale, treat yourself as covered regardless of what the applicability card says.
Related Reading
GDPR Compliance Checklist for Startups: Turn a Readiness Assessment Into a 90-Day Plan
GDPR compliance checklist: a GDPR readiness assessment companion guide for CTOs
guidesCCPA/CPRA Compliance Guide: A CTO Companion to a CCPA Compliance Checklist and Readiness Assessment
CCPA compliance checklist and CPRA readiness assessment: a CTO companion guide
guidesDORA Compliance Checklist: A CTO Companion Guide to Digital Operational Resilience Act Assessment
DORA compliance checklist: a CTO companion guide to Digital Operational Resilience Act assessment