CCPA/CPRA Compliance
The California Consumer Privacy Act (CCPA), as amended by the CPRA, grants California consumers rights over their personal information. Businesses must honor rights to know, delete, correct, and opt out of the sale or sharing of personal data.
Who Needs CCPA/CPRA?
Businesses collecting personal data from California residents meeting certain revenue or data volume thresholds.
Key Benefits
- Operate legally in the California market
- Build consumer trust through transparent data practices
- Avoid Attorney General enforcement actions and fines
- Prepare for broader US state privacy law compliance
Key Requirements
- 1Privacy notice disclosing categories and purposes of data collection
- 2Consumer rights requests (know, delete, correct, opt-out)
- 3Do Not Sell or Share My Personal Information mechanism
- 4Data inventory and records of processing activities
- 5Vendor contracts with data protection provisions
- 6Security measures appropriate to the risk
Required Policy Templates
8 policies required for CCPA/CPRA compliance, organized by category.
Privacy
Privacy Notice / Privacy Policy
Consumer-facing privacy notice disclosing data collection, use, sharing practices, and consumer rights under CCPA/CPRA.
Consumer Rights Procedures
Internal procedures for handling consumer rights requests including access, deletion, correction, opt-out, and portability.
Data Inventory & Mapping Policy
Policy for maintaining an inventory of personal information collected, used, shared, and deleted across the organization.
Opt-Out & Do Not Sell/Share Policy
Procedures for honoring consumer opt-out requests from sale and sharing of personal information under CCPA/CPRA.
Data Retention & Deletion Policy
Retention schedules and secure deletion procedures for personal information under CCPA/CPRA data minimization principles.
Generate CCPA/CPRA Documentation
Answer questions about your infrastructure and PoliWriter generates all 8 CCPA/CPRA policies customized to your organization. Audit-ready in hours, not months.
Get Started FreeNo credit card required. 3 documents free.
Other Compliance Frameworks
SOC 2 Type II
Service Organization Control 2 - Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Requires an observation period of 3-12 months demonstrating controls operate effectively over time.
20 templatesGDPR
General Data Protection Regulation - EU data protection and privacy regulation.
3 templatesHIPAA
Health Insurance Portability and Accountability Act - US healthcare data protection.
3 templatesISO 27001
International standard for information security management systems (ISMS).
3 templatesPCI DSS v4.0
Payment Card Industry Data Security Standard — security controls for organizations that store, process, or transmit payment cardholder data.
12 templatesNIST CSF 2.0
NIST Cybersecurity Framework — voluntary guidance for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
10 templatesSOC 2 Type I
SOC 2 Type I — Point-in-time assessment of your security controls design. Ideal for first-time certification before progressing to Type II.
0 templatesISO 42001
ISO/IEC 42001 — International standard for Artificial Intelligence Management Systems (AIMS), covering responsible AI development, deployment, and governance.
0 templatesNIS 2 Directive
NIS 2 Directive (EU 2022/2555) — EU-wide cybersecurity legislation requiring essential and important entities to implement comprehensive risk management and incident reporting.
0 templatesNIST SP 800-53
NIST SP 800-53 — Comprehensive catalog of security and privacy controls for federal information systems, widely adopted by private sector organizations.
0 templates