UprootSecurity
Book a demo

California · CPRA-amended · CPPA-enforced

FRAMEWORK

Consumer privacyyou can actually evidence.

CCPA gives Californians real rights to know, delete, correct, and opt out. Uproot wires them to your systems: requests tracked to the 45-day clock, opt-out and GPC honored.

Start CCPATalk to a privacy lead

Requests tracked to 45 days

·

One program covers the sibling state laws

app.uproot.security · /framework/ccpa
CCPACPRA

acme-inc · CCPA / CPRA

business · CA consumers in scope

84%

in good standing

18 met3 in progress1 open

Obligation areas

22 controls

RTS

Consumer rights

know · delete · correct

90%

OPT

Opt-out & GPC

sale / sharing

82%

NOT

Notice & policy

at collection

95%

SPI

Sensitive PI limits

limit use & disclosure

76%

SP

Service providers · contracts

required terms

71%

Open requests

4 · within SLA

GPC honored

auto

Response SLA

45 days

Opt-out signal honored automatically

A browser sent GPC. Sharing was disabled and the preference recorded across destinations.

Consumer rights

7

Know, delete, correct, opt-out of sale/sharing, limit sensitive PI, portability, and non-discrimination.

Who it applies to

$25M+ rev

For-profits over $25M revenue, or 100k+ consumers/households, or 50%+ revenue from selling PI.

Response window

45days

Verifiable consumer requests must be answered within 45 days, extendable once when necessary.

Authority

CPPA

The California Privacy Protection Agency and the state Attorney General enforce it. No certificate exists.

Penalty

$7,500/ violation

Up to $2,500 per violation, $7,500 if intentional or involving a minor counted per consumer.

What CCPA asks of you

Five obligations that decide whether you're defensible.

CPRA expanded CCPA into a full consumer-privacy regime. For a product team it concentrates into honoring rights, respecting opt-outs, telling people what you collect, protecting sensitive data, and governing who you share it with. Uproot proves each from your real stack.

1798.100
RTS

Consumer rights

Honor requests to know, delete, and correct personal info across every system that holds it.

Know & access · Delete · Correct · 45-day response
Basis 1798.100–106
OPT

Opt-out & GPC

A clear "Do Not Sell or Share" path, plus automatic recognition of the Global Privacy Control signal.

Opt-out link · GPC honored · sharing disabled
Basis 1798.120 · 135
NOT

Notice & policy

A notice at collection and a privacy policy covering what you collect, why, and for how long.

Notice at collection · privacy policy · retention disclosed
Basis 1798.130 · 100
SPI

Sensitive PI limits

Let consumers limit use of sensitive info government IDs, precise geolocation, health, and more.

Limit use link · categories mapped · purpose-bound
Basis 1798.121
SP

Service providers

Contracts with every service provider and third party carrying the terms CPRA requires.

Required terms · inventory · contractor vs third party
Basis 1798.140 · 100(d)
One obligation, end to end

The CPPA's favorite test: send a GPC signal and watch. Opt-out is where Uproot proves you honored it.

Recognizing the Global Privacy Control is now an enforcement focus. Here's how Uproot turns "we honor opt-outs" into evidence that actually shows it happening.

1798.135 Opt-out of sale & sharing

Businesses must give consumers a clear way to opt out of the sale or sharing of their personal information, and must treat an opt-out preference signal like the Global Privacy Control as a valid request. Regulators have already fined companies for ignoring it.

"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."

— Hiren Hasmukh, Co-Founder & CEO

1798.135 · OPT-OUT & GPC

Opt-out of sale & sharing honored

Last evidenced 09:14:02 UTC · all CA traffic · sha256 verified

Honored
01

The requirement

What 1798.135 asks for

“A business shall provide a clear and conspicuous link… to opt out of the sale or sharing… and shall treat an opt-out preference signal as a valid request to opt out for that consumer.”
02

Your real surface

What we read from your systems

Uproot inspects the consent platform, tag manager, and ad destinations that actually decide whether data is shared.

osano ·consent.stategtm ·tag.triggerssegment ·destinationssite ·opt-out.link
03

Evidence collected

Signal in, sharing off, preference stored

Uproot verifies the GPC signal is recognized, the opt-out propagates to every destination, and the preference persists captured, hashed, and timestamped.

GPC ·recognizedad tags ·suppressedopt-out link ·present0 leaking destinations
04

For the regulator

Proof the signal was honored

If the CPPA tests your site or a consumer complains, you have a timestamped record that the opt-out path works and sharing actually stopped.

Scope · CA traffic  ·  Owner· Privacy  ·  Leaks · 0

GDPR Art. 21VCDPA opt-outCPA universal
Path to good standing

From data map to a defensible privacy program.

CCPA has no certificate enforcement is complaint- and sweep-driven. The goal is a program that holds up the day the CPPA, or a consumer, comes knocking.

Day 0

Map personal info

Uproot discovers where personal information lives and which categories you collect the basis for notice, rights, and opt-out.

Day 1–3

Wire the rights

Request intake, verification, and a 45-day workflow stood up across the systems that hold consumer data.

Day 4–18

Opt-out & contracts

GPC recognition verified, opt-out path tested, notices published, and service-provider contracts inventoried for required terms.

Day 19–30

Defensible

Program documented and evidenced. Able to answer a CPPA inquiry, a consumer complaint, or a customer's privacy review.

5

Ongoing

Stay current

New trackers, vendors, or data categories surface as tickets. Opt-out coverage is monitored continuously, not spot-checked.

The template way
  • ×

    A privacy policy copied from a generator that doesn’t match what you actually collect

  • ×

    A “Do Not Sell” link that looks compliant but still leaks to ad destinations

  • ×

    GPC signals ignored now a documented enforcement target

  • ×

    Consumer requests handled ad hoc over email, with no proof you met the 45-day clock

With Uproot
  • Notices generated from your real data map and kept in sync as it changes

  • The opt-out path verified end-to-end signal in, sharing off, preference stored

  • GPC honored automatically, with timestamped proof for every request

  • Consumer requests tracked to the 45-day SLA across every system that holds their data

Evidence map

Where your CCPA posture actually lives. Uproot reads it there.

A partial map of the obligations Uproot evidences from source data inventory, consent, requests, and vendor contracts.

RTS

Rights & data

  • Postgres · PI inventory

    tagged

  • Request workflow

    ≤45d

  • Identity verification

    on

  • Deletion propagation

    tracked

OPT

Opt-out & GPC

  • Osano · consent state

    live

  • GTM · tag suppression

    verified

  • GPC recognition

    auto

  • Opt-out link present

    all CA

NOT

Notice

  • Privacy policy

    versioned

  • Notice at collection

    live

  • Retention disclosed

    per cat

  • Categories mapped

    12

SP

Service providers

  • Vendor inventory

    34

  • CPRA terms in contract

    29 / 34

  • Contractor vs 3rd-party

    classified

  • Sensitive-PI flows

    mapped

One program, many states

CCPA is the strictest. Run it well and the sibling state laws come along.

A dozen-plus US states now have CCPA-style privacy laws with overlapping rights and opt-out duties. Uproot maps your CCPA program to each, so one data map and one rights workflow cover most of the country.

CCPA / CPRA

california

VCDPA

virginia

CPA

colorado

CTDPA

connecticut

UCPA

utah

TDPSA

texas

OCPA

oregon

MCDPA

montana

MODPA

maryland

DPDPA

delaware

NJDPA

new jersey

+ more

2025–26

CCPA, plainly

Questions we get every week. Answered the way an engineer would.

What's the difference between CCPA and CPRA?+

CPRA is the 2020 amendment that expanded CCPA adding the right to correct, the sensitive-PI category, the concept of "sharing," and the CPPA enforcement agency. People say "CCPA" but almost always mean the CPRA-amended version in force today.

Does CCPA apply to my business?+

If you're a for-profit doing business in California and meet one threshold: $25M+ annual revenue, personal info on 100,000+ consumers or households, or 50%+ of revenue from selling/sharing personal info. Uproot helps you confirm scope from real data volumes.

What is GPC and do I have to honor it?+

The Global Privacy Control is a browser signal that communicates an opt-out. California treats it as a valid opt-out request you must honor and regulators have already enforced against businesses that ignored it. Uproot verifies you recognize and act on it.

How fast must I respond to requests?+

Within 45 days of a verifiable consumer request, with a single 45-day extension when reasonably necessary. Uproot tracks every request against the clock across all systems holding that consumer's data.

What's a "service provider" vs a "third party"?+

A service provider processes data on your behalf under a contract with specific CPRA terms; a third party is anyone else you share with. The distinction drives your opt-out obligations. Uproot classifies your vendors and checks the contract terms.

How does CCPA relate to GDPR?+

They share a spine data inventory, consumer/data-subject rights, vendor governance with different mechanics. If you run GDPR with Uproot, most of CCPA falls out of the same data map, rights workflow, and processor tracking.

Honor the rights. Prove you did.

Map your consumer data, wire the 45-day request workflow, and verify opt-out and GPC end-to-end. When the CPPA or a consumer asks, the evidence is already there and it covers the other states too.

Start CCPATalk to a privacy lead
$uproot init --framework ccpa
mapping consumer personal infook
verifying opt-out + GPC pathok
18 of 22 controls met · 34 vendors mapped84%
program ready in 3m 39slive