Meet CCPA and CPRA without a separate program
What is CCPA / CPRA?
The California Consumer Privacy Act (CCPA) was the first comprehensive US state privacy law, taking effect January 1, 2020. It was substantially amended by the California Privacy Rights Act (CPRA) — passed by ballot initiative in 2020 and effective January 1, 2023 — which established the California Privacy Protection Agency (CPPA), created the new category of Sensitive Personal Information (SPI), added a right to correction, and broadened "sale" opt-outs to "sale or share" opt-outs.
The combined CCPA/CPRA gives California consumers a set of rights resembling but not identical to GDPR: the right to know what personal information is collected, the right to delete it, the right to correct it, the right to opt out of sale or sharing, the right to limit the use of SPI, and the right to non-discrimination for exercising rights.
Who is subject
For-profit businesses doing business in California that meet at least one threshold: $25M+ annual gross revenue, processing personal information of 100,000+ consumers or households, or deriving 50%+ of annual revenue from selling or sharing personal information. The law also creates obligations for service providers and contractors processing personal information on behalf of businesses.
How episki helps
episki tracks CCPA and CPRA obligations as structured records with owners and due dates — consumer requests, opt-out handling, and service provider agreements — alongside technical controls that are evaluated continuously. Service providers and their subprocessors live on vendor records with review cadences. Start a free trial or book a demo.
CCPA / CPRA outcomes with episki
Why teams choose episki for CCPA / CPRA
- Right to know, delete, correct, opt-out, limit
- Identity verification flows
- 45-day SLA timers with extension workflow
- GPC signal honored
- Do Not Sell or Share My Personal Information
- Sensitive PI use-limitation log
- DSAR types crosswalked to GDPR rights
- SPI categories mapped to GDPR special-category data
- ISO 27701 control mapping
CCPA / CPRA readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ Personal Information inventory (categories collected, sources, purposes)
- ✓ Notice at collection language and triggers
- ✓ DSAR intake portal with verification
- ✓ Opt-out of sale/share workflows (including GPC)
- ✓ Sensitive PI use-limitation requests
- ✓ 12-month look-back for "right to know" requests