California · CPRA-amended · CPPA-enforced
FRAMEWORKCCPA gives Californians real rights to know, delete, correct, and opt out. Uproot wires them to your systems: requests tracked to the 45-day clock, opt-out and GPC honored.
Requests tracked to 45 days
One program covers the sibling state laws
acme-inc · CCPA / CPRA
business · CA consumers in scope
84%
in good standing
Obligation areas
22 controls
Consumer rights
know · delete · correct
90%
Opt-out & GPC
sale / sharing
82%
Notice & policy
at collection
95%
Sensitive PI limits
limit use & disclosure
76%
Service providers · contracts
required terms
71%
Open requests
4 · within SLA
GPC honored
auto
Response SLA
45 days
Opt-out signal honored automatically
A browser sent GPC. Sharing was disabled and the preference recorded across destinations.
Consumer rights
7Know, delete, correct, opt-out of sale/sharing, limit sensitive PI, portability, and non-discrimination.
Who it applies to
$25M+ revFor-profits over $25M revenue, or 100k+ consumers/households, or 50%+ revenue from selling PI.
Response window
45daysVerifiable consumer requests must be answered within 45 days, extendable once when necessary.
Authority
CPPAThe California Privacy Protection Agency and the state Attorney General enforce it. No certificate exists.
Penalty
$7,500/ violationUp to $2,500 per violation, $7,500 if intentional or involving a minor counted per consumer.
CPRA expanded CCPA into a full consumer-privacy regime. For a product team it concentrates into honoring rights, respecting opt-outs, telling people what you collect, protecting sensitive data, and governing who you share it with. Uproot proves each from your real stack.
Consumer rights
Honor requests to know, delete, and correct personal info across every system that holds it.
Opt-out & GPC
A clear "Do Not Sell or Share" path, plus automatic recognition of the Global Privacy Control signal.
Notice & policy
A notice at collection and a privacy policy covering what you collect, why, and for how long.
Sensitive PI limits
Let consumers limit use of sensitive info government IDs, precise geolocation, health, and more.
Service providers
Contracts with every service provider and third party carrying the terms CPRA requires.
Recognizing the Global Privacy Control is now an enforcement focus. Here's how Uproot turns "we honor opt-outs" into evidence that actually shows it happening.
Businesses must give consumers a clear way to opt out of the sale or sharing of their personal information, and must treat an opt-out preference signal like the Global Privacy Control as a valid request. Regulators have already fined companies for ignoring it.
"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."
1798.135 · OPT-OUT & GPC
Opt-out of sale & sharing honored
Last evidenced 09:14:02 UTC · all CA traffic · sha256 verified
The requirement
What 1798.135 asks for
Your real surface
What we read from your systems
Uproot inspects the consent platform, tag manager, and ad destinations that actually decide whether data is shared.
Evidence collected
Signal in, sharing off, preference stored
Uproot verifies the GPC signal is recognized, the opt-out propagates to every destination, and the preference persists captured, hashed, and timestamped.
For the regulator
Proof the signal was honored
If the CPPA tests your site or a consumer complains, you have a timestamped record that the opt-out path works and sharing actually stopped.
Scope · CA traffic · Owner· Privacy · Leaks · 0
CCPA has no certificate enforcement is complaint- and sweep-driven. The goal is a program that holds up the day the CPPA, or a consumer, comes knocking.
Day 0
Map personal info
Uproot discovers where personal information lives and which categories you collect the basis for notice, rights, and opt-out.
Day 1–3
Wire the rights
Request intake, verification, and a 45-day workflow stood up across the systems that hold consumer data.
Day 4–18
Opt-out & contracts
GPC recognition verified, opt-out path tested, notices published, and service-provider contracts inventoried for required terms.
Day 19–30
Defensible
Program documented and evidenced. Able to answer a CPPA inquiry, a consumer complaint, or a customer's privacy review.
Ongoing
Stay current
New trackers, vendors, or data categories surface as tickets. Opt-out coverage is monitored continuously, not spot-checked.
A privacy policy copied from a generator that doesn’t match what you actually collect
A “Do Not Sell” link that looks compliant but still leaks to ad destinations
GPC signals ignored now a documented enforcement target
Consumer requests handled ad hoc over email, with no proof you met the 45-day clock
Notices generated from your real data map and kept in sync as it changes
The opt-out path verified end-to-end signal in, sharing off, preference stored
GPC honored automatically, with timestamped proof for every request
Consumer requests tracked to the 45-day SLA across every system that holds their data
A partial map of the obligations Uproot evidences from source data inventory, consent, requests, and vendor contracts.
Rights & data
Postgres · PI inventory
tagged
Request workflow
≤45d
Identity verification
on
Deletion propagation
tracked
Opt-out & GPC
Osano · consent state
live
GTM · tag suppression
verified
GPC recognition
auto
Opt-out link present
all CA
Notice
Privacy policy
versioned
Notice at collection
live
Retention disclosed
per cat
Categories mapped
12
Service providers
Vendor inventory
34
CPRA terms in contract
29 / 34
Contractor vs 3rd-party
classified
Sensitive-PI flows
mapped
A dozen-plus US states now have CCPA-style privacy laws with overlapping rights and opt-out duties. Uproot maps your CCPA program to each, so one data map and one rights workflow cover most of the country.
CCPA / CPRA
california
VCDPA
virginia
CPA
colorado
CTDPA
connecticut
UCPA
utah
TDPSA
texas
OCPA
oregon
MCDPA
montana
MODPA
maryland
DPDPA
delaware
NJDPA
new jersey
+ more
2025–26
CPRA is the 2020 amendment that expanded CCPA adding the right to correct, the sensitive-PI category, the concept of "sharing," and the CPPA enforcement agency. People say "CCPA" but almost always mean the CPRA-amended version in force today.
If you're a for-profit doing business in California and meet one threshold: $25M+ annual revenue, personal info on 100,000+ consumers or households, or 50%+ of revenue from selling/sharing personal info. Uproot helps you confirm scope from real data volumes.
The Global Privacy Control is a browser signal that communicates an opt-out. California treats it as a valid opt-out request you must honor and regulators have already enforced against businesses that ignored it. Uproot verifies you recognize and act on it.
Within 45 days of a verifiable consumer request, with a single 45-day extension when reasonably necessary. Uproot tracks every request against the clock across all systems holding that consumer's data.
A service provider processes data on your behalf under a contract with specific CPRA terms; a third party is anyone else you share with. The distinction drives your opt-out obligations. Uproot classifies your vendors and checks the contract terms.
They share a spine data inventory, consumer/data-subject rights, vendor governance with different mechanics. If you run GDPR with Uproot, most of CCPA falls out of the same data map, rights workflow, and processor tracking.
Map your consumer data, wire the 45-day request workflow, and verify opt-out and GPC end-to-end. When the CPPA or a consumer asks, the evidence is already there and it covers the other states too.