Get Demo
CCPA / CPRA · California Privacy · CPPA Enforced

CCPA / CPRA Compliance Hub

The California Consumer Privacy Act and California Privacy Rights Act impose notice, consumer rights, opt-out of sale/sharing, and reasonable security expectations on businesses that meet statutory thresholds. Use this hub for current thresholds, clocks, and CyberSilo product links.

Who Must Comply — Current Business Thresholds

CCPA/CPRA apply to for-profit entities that do business in California, collect California consumers’ personal information, and meet one or more of the following (Civil Code §1798.140(d)(1)):

The older pre-CPRA “50,000 consumers/households/devices” threshold is no longer the current statutory test.

Consumer Request Clocks

Respond to verifiable requests to know, delete, or correct within 45 days; one extension of an additional 45 days when reasonably necessary with notice in the first period (§1798.130). Regulations also expect acknowledgment within 10 business days.

California security breach notice to residents is under Civil Code §1798.82 (most expedient time / without unreasonable delay) — distinct from CCPA consumer rights. See the breach notification matrix.

Key Explainers & Tools

CyberSilo’s Compliance Standards Automation platform handles DSAR workflows, data mapping evidence, and security control monitoring from a unified dashboard shared with SOC 2 Privacy criteria and GDPR Article 32 obligations.