The CCPA took effect in 2020 and the CPRA amended it three years later, adding sensitive personal information, correction, the limit right and a dedicated privacy regulator. People say CCPA and mean both, and they are right to: it is one regime written in two layers of drafting.
A CCPA programme built for 2020? The ladder runs to 2030.
Risk assessments are already live under the CCPA regulations. The automated decision-making (ADMT) duties land on 1 January 2027.
Our promise
“A notice is a page. The response log is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditCalifornia privacy, in three chapters
Most programmes were built to the 2020 line and stopped there. What has arrived since is the part with operational weight - risk assessments from 2026, ADMT duties from 2027, audit certifications to 2030 - and none of it was in scope when any one of those programmes was first written down.
We score every finding against the date it is owed from, so an older programme shows its own gap rather than being told it has one. Then the forty-five-day path gets walked against your own intake route, and the ADMT duty is answered as the process question that it actually is.
Whose information, not where you sit.
Personal information of Californians, held by a for-profit business doing business there - wherever you are incorporated.
- Businesses meeting any one of three tests
- 100,000 California consumers or households
- Half or more of revenue from selling data
- Service providers, bound by contract instead
- At or before the point of collection, for notice
- Within 45 days for know, delete and correct
- Within 15 business days for an opt-out
- Before disclosure, for the contract terms
The duty is yours. So is the machine’s.
Whoever meets a threshold
A for-profit business doing business in California that meets any one of the three tests. Every duty on this page lands on you - the notices, the rights machinery, the retention limits, the registers and the training data behind them - and being incorporated somewhere else changes none of it.
The people who process for you
Service providers and contractors are bound by the contract rather than by the thresholds, and the statutory terms are what keep a disclosure from being a sale. Increasingly it is a customer's procurement team, not the regulator, that asks them to prove it, and asks you to prove that you checked it.
A machine decision owes a person
Automated decision-making technology used in a significant decision carries a pre-use notice, an opt-out and an access right. A human reviewer only takes it out of scope where they can interpret the output, analyse it, and change the decision - which is a job description, not a checkbox on a form.
“We did our CCPA work back in 2020.”
Three more rungs have landed since.
It is the first thing we have to correct.
- Who it is for
- Retail & e-commerce
- Banks & lenders
- Ad tech & publishers
- SaaS serving California
- Hiring & credit teams
Violations are generally counted per consumer, which is what turns a single systemic notice failure into a very large number rather than one.
A private right of action attaches to certain breaches. That route needs no regulator to bring it at all - only a plaintiff and a law firm.
The inventory and the rights machinery carry into the other state laws and into the GDPR. Most of the work there is mapping, not rebuilding.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Not one deadline, but a ladder.
Four rungs to act on. The dates are how you find which duties an older programme was written before.
-
The Act in force
1 January 2020Notice at collection, the core rights and the Do Not Sell link date from here. Most programmes stopped here too.
-
The amendments
1 January 2023Sensitive personal information, correction, the limit right and sharing - plus a dedicated regulator to enforce it.
-
Risk assessments
1 January 2026Required for high-risk processing: selling or sharing, sensitive data, and training the technology itself.
-
ADMT duties
1 January 2027Pre-use notice, an opt-out and an access right - including for technology deployed before that date.
A programme built for 2020 was written when only the original Act was live. It will have a notice set and a Do Not Sell link and no ADMT position at all - and the opt-out signal will be logged somewhere without ever being acted on.
What the law says, what we ship
12 duties: six consumer rights, then the six obligations that make them work.
- Right to know 45 days
- Categories and specific pieces collected, the sources, the business purpose and the third parties it reached - on a twelve-month look-back, twice a year, free.
- Right to delete 45 days
- Deletion of information collected from the consumer, with the statutory exceptions applied and recorded per request rather than assumed, and service providers instructed too.
- Right to correct 45 days
- Inaccurate personal information corrected on a commercially reasonable effort standard, propagated downstream, with the reasoning documented where it is refused.
- Right to opt out of sale or sharing 15 business days
- A conspicuous link, cross-context behavioural advertising treated as sharing, downstream recipients told, and a universal opt-out signal honoured as a request.
- Right to limit sensitive data 15 business days
- Use of sensitive personal information held to what the service the consumer asked for actually needs, with the necessary-use boundary written down and inferences inside it.
- Right to non-discrimination Continuous
- No denial, different price or lower quality for exercising a right - with any financial incentive disclosed, justified and its value calculation shown.
- Notice at collection At or before
- Categories and purposes given at or before the point of collection, including for information gathered offline and from sources other than the consumer.
- Complete privacy policy Reviewed yearly
- The full disclosure set: what is sold or shared, the retention period stated per category rather than implied, and how each right is actually exercised.
- Request verification Before responding
- A documented method proportionate to the sensitivity of the request - and one that does not itself collect more personal information than it needs to.
- Retention limits Stated in policy
- A stated period per category, and nothing kept longer than is reasonably necessary for the disclosed purpose - which is a deletion schedule, not a sentence.
- Contracts with recipients Before disclosure
- Service provider, contractor and third-party terms carrying the statutory clauses - the difference between a disclosure and a sale often lives in this document.
- Assessments and certification Filings from 2028
- Risk assessments conducted from 2026 are filed with the regulator from 2028, and cybersecurity audit certifications follow by revenue band through to 2030.
Personal information, independently reviewed
From the CRM to the model in the decision path.
-
Intake
Which systems hold California personal information, and what each is for.
-
Test
Every duty on the ladder against the estate as it actually runs.
-
Sign off and evidence
You see the draft first. Then the notices, registers and drills - dated.
Why teams choose iDharma for their CCPA review
Scored by rung
Every finding carries the date it is owed from, so an older programme shows its gaps plainly.
ADMT, answered
The automated-decision duty tested as a process running end to end, which is what it actually is.
The clock, rehearsed
The 45-day response path walked against your own intake route, and not a generic template.
It carries to other laws
The inventory and rights machinery map onto the other state privacy laws, and onto the GDPR.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
CCPA and CPRA review report
The full review: what you collect, what counts as selling or sharing, and where every duty is evidenced or is not - written rung by rung so a programme built for 2020 shows its own gap. The automated-decision position and the assessment and certification schedule out to 2030 are stated separately.
Data inventory and map
Categories, sources, business purposes, recipients and retention - built from the systems inwards rather than from a questionnaire sent round the business.
Rights request runbook
One intake route, verification proportionate to the request, and a search that reaches the backups and the ticketing system - against the clock, rehearsed once.
Notice and policy set
Notice at or before collection per channel, the full policy with its look-back, and the retention period stated per category rather than left to be implied.
Opt-out and signal wiring
The Do Not Sell and Limit the Use links placed, a universal opt-out signal honoured automatically, and downstream recipients told rather than left to notice.
Automated decision register
Every significant decision the technology touches: the pre-use notice, the opt-out route, and what the named human reviewer is actually able to change.
Policy template pack
The notice set, the rights and contracts set and the assessment set - written to California rather than handed over as a generic privacy pack.
Real numbers, upfront.
- Scope
- Set by the statute
- Inputs
- Your systems and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The statute fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Findings scored by rung
- Rights request runbook
- The 45-day path, walked once
- 26 policy templates, tailored
Four things you have to be able to produce
California is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The inventory,
current
Categories, sources, purposes, recipients and retention. Every notice, every rights response and every risk assessment is built from it, so it is the first thing to be short.
The clock,
tracked
Forty-five days for the core rights and fifteen business days for an opt-out, tracked rather than remembered, with the permitted extension recorded and reasoned.
The signal,
honoured
A universal opt-out signal is an opt-out request, applied automatically and passed downstream. Treating it as advisory is the most reliably found failure in this regime.
The human,
empowered
For a significant decision made by machine: a reviewer who can interpret the output, analyse it against everything else, and actually change the answer.
Four cards, and the clock on each one is part of the card.
Plain answers
What the law is, whether it reaches you, the clock, and where AI lands. Answered straight.
Request this reviewDoes CCPA apply to my business?
If you are a for-profit business doing business in California and you meet any one of three tests - a gross annual revenue threshold, buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving half or more of your revenue from selling or sharing it.
What is the difference between CCPA and CPRA?
CPRA amended the CCPA rather than replacing it. It added sensitive personal information, the rights to correct and to limit, the concept of sharing for cross-context behavioural advertising, and a dedicated privacy regulator with rulemaking and enforcement powers.
What are the response deadlines for consumer rights requests?
Forty-five days for the core rights, with one permitted extension recorded and reasoned, and acknowledgement well inside that. Opt-out of sale or sharing and limiting sensitive data run on a shorter fifteen-business-day clock.
What are automated decision-making technology requirements?
Where the technology is used in a significant decision - financial services, housing, education, employment or healthcare - a consumer gets a pre-use notice, an opportunity to opt out, and a right to information about how it was used. The duties apply from 1 January 2027, including to technology already deployed.
What does an iDharma CCPA review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the data inventory and map, the rights request runbook, the notice and policy set, the opt-out and signal wiring, the automated decision register and the policy template pack.
Request your CCPA review
Tell us where the California information lives and we come back in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.
- Which systems hold California personal information
- When your CCPA programme was last scoped
- Your current notice at collection and privacy policy
- Where a significant decision runs on automated technology
- Who you disclose to, and on what contract terms
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The Act as amended by the CPRA, and the regulations
- The California Privacy Protection Agency, on its guidance
- Risk assessments
- 1 January 2026
- ADMT duties
- 1 January 2027
What it means
- General information about what the statute requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- No penalty figure appears here. Our own source and the reference this page was written against state the administrative and penal ceilings the other way round from each other — so for a number, go to the Commission.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom