Skip to main content

The Art of CTO CCPA/CPRA Compliance tool evaluates organizational readiness for California privacy law requirements including consumer data rights, opt-out mechanisms, and data handling practices.

Do we meet CCPA and CPRA?

Applicability from your revenue and data volume, a score across consumer rights, and the gaps.

About 15 min · Assessment · Free

About this toolWhy it matters, common mistakes, FAQ

Do You Meet CCPA And CPRA, Or Just GDPR?

Teams that did GDPR often assume California is covered. CPRA added obligations GDPR does not have — sensitive personal information handling, a Do Not Sell or Share signal, and contractual terms with every recipient — and enforcement has focused on exactly those.

The Global Privacy Control gets ignored because it is a browser signal rather than a form submission. Regulators have treated failure to honour it as a straightforward violation, and it is one of the few things that can be checked from outside your company.

Questions CTOs ask

What is the difference between CCPA and CPRA?
CPRA (California Privacy Rights Act) amended and expanded the original CCPA, taking full effect in 2023. Key additions include a new category of "sensitive personal information" with opt-out rights, expanded consumer rights (correction, limited use of sensitive data), stricter requirements for data sharing (not just selling), and the creation of the California Privacy Protection Agency for enforcement. Companies compliant with CCPA need to update their practices to meet the additional CPRA requirements.
Does CCPA/CPRA apply to my business?
CCPA/CPRA applies to for-profit businesses that collect California residents' personal information AND meet any one of three thresholds: annual gross revenue over $25 million, buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Service providers and contractors also face obligations through their contracts with covered businesses. Note that this tool tests only the first two thresholds — it asks for revenue and data volume, not revenue mix — so if you sell or share personal information at scale, treat yourself as covered regardless of what the applicability card says.

Related Reading