Privacy Law

CCPA / CPRA Compliance Checklist for SaaS Startups (2025)

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is now enforced by an independent agency with $7,500-per-violation fine authority. CPRA removed the 30-day automatic cure period as of January 1, 2023. If your SaaS company has crossed $25M in revenue or 100,000 California users, this checklist covers every compliance obligation you need to address.


CCPA / CPRA Applicability Thresholds

CCPA/CPRA applies to for-profit businesses that do business in California AND meet ANY ONE of these thresholds:

ThresholdTestSaaS Notes
Revenue thresholdAnnual gross revenues > $25M (preceding calendar year)
Applies once $25M ARR is crossed — regardless of California data volume
Most growth-stage SaaS crosses this by Series B
Data volume thresholdBuys, sells, or shares personal info of ≥ 100K CA consumers or households annually
Counts individual consumer records — user signups count
Popular SaaS products reach 100K California users faster than expected
Revenue-from-data threshold≥ 50% of annual revenue from selling California consumers' personal information
Applies to data broker, ad-supported, and data resale businesses
Rarely applies to pure B2B SaaS; applies to consumer ad-tech

6 Consumer Rights You Must Support

RightResponse TimeScope
Right to Know45 days (+ 45 extension)Categories, specific pieces, sources, purposes, third-party sharing
Right to Delete45 days (+ 45 extension)All personal info (with enumerated exceptions); must flow to service providers
Right to Correct (CPRA)45 days (+ 45 extension)Inaccurate personal information — commercially reasonable efforts
Right to Opt-Out of Sale/Sharing15 business days to implementSale to 3rd parties; sharing for cross-context behavioral advertising; honor GPC signals
Right to Limit SPI Use (CPRA)15 business daysSensitive PI: SSN, financial, geolocation, health, biometric, racial/ethnic, sexual orientation
Right to Non-DiscriminationOngoing obligationCannot deny service, charge more, or degrade service for exercising rights

CCPA / CPRA Compliance Checklist

Privacy notice at collection
Disclose categories collected, purposes, whether sold/shared, link to full policy — at or before collection.
Full CCPA/CPRA privacy policy
All required disclosures including retention periods, third-party categories, and consumer rights summary. Update annually.
Consumer rights intake mechanism
"Do Not Sell or Share" link on homepage; webform or email address for rights requests; identity verification process.
Global Privacy Control (GPC) signals
Technical implementation to recognize and honor GPC browser signals as opt-out of sale/sharing. Required since 2023 CPPA enforcement.
Service provider agreements (DPAs)
CCPA-compliant DPA with all service providers processing California consumer data. Required terms listed in FAQ above.
Employee / applicant privacy notice
Separate at-collection notice for employees and job applicants effective January 1, 2023 (CPRA removed employment exemption).
Sensitive personal information (SPI) controls
If you process SPI categories: purpose limitation, "Limit Use of My Sensitive Personal Information" link on homepage.
Annual privacy training
Employees who handle consumer inquiries and personal information must receive annual privacy training.
Data retention schedule
Document retention periods for each category of personal information (CPRA-required disclosure in privacy policy).
Security measures
Reasonable security measures for personal information. CPPA has authority to mandate cybersecurity audits for high-risk businesses.

Contract Risk — $97

Scan Your Privacy Policy or DPA for CCPA / CPRA Compliance Gaps

Upload your Privacy Policy or Data Processing Agreement and BizLegal AI checks for missing CPRA-required disclosures (retention periods, SPI categories, GPC compliance), service provider agreement gaps, outdated employee data exemption language, and opt-out mechanism compliance — with specific remediation guidance for each finding.

Scan for CCPA/CPRA Gaps →

Frequently Asked Questions

Does CCPA / CPRA apply to my SaaS company?

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to for-profit businesses that: (1) do business in California; AND (2) meet ANY ONE of the following three thresholds: (a) annual gross revenues over $25 million in the preceding calendar year; (b) annually buy, sell, or share the personal information of 100,000 or more California consumers or households; or (c) derive 50% or more of annual revenues from selling California consumers' personal information. "Doing business in California" is interpreted broadly — it includes online businesses with California-resident customers, even if the company has no physical presence in the state. The $25M revenue threshold catches most growth-stage SaaS companies earlier than founders expect. Once a company crosses $25M in ARR, CCPA/CPRA compliance is mandatory regardless of data volume. Important nuances: (1) The "selling or sharing" threshold: even if you never sell data, if your SaaS product reaches 100,000+ California consumer accounts through organic growth, you trigger the threshold. (2) Employee data: from January 1, 2023, CCPA/CPRA applies to employee personal information, job applicant data, and business contact data — removing the prior B2B and employee exemptions. (3) B2B SaaS: your SaaS product may process personal data of your business customers' employees and end-users — you may be acting as a "service provider" (the CCPA equivalent of a data processor) on behalf of your customer. In that case, your Data Processing Agreement (DPA) or Service Provider Agreement needs CCPA-compliant terms. (4) Territorial scope: the CCPA/CPRA applies to personal information of California residents regardless of where that data is processed, stored, or accessed.

What are the 6 consumer rights under CCPA / CPRA that SaaS companies must support?

California residents (consumers) have the following rights under CCPA as amended by CPRA, effective January 1, 2023: (1) Right to Know — consumers can request disclosure of: what categories of personal information the business collects; the specific pieces of personal information held about them; the categories of sources from which information was collected; the business purpose for collection; and the categories of third parties with whom information is shared. Response deadline: 45 days (extendable once by another 45 days with notice). (2) Right to Delete — consumers can request deletion of personal information. Businesses must also direct service providers to delete the information. Exceptions: information necessary for completing a transaction; detecting security incidents; complying with a legal obligation; or otherwise exercising free speech. Response deadline: 45 days. (3) Right to Correct — CPRA added this right (not in original CCPA). Consumers can request correction of inaccurate personal information. Businesses must use commercially reasonable efforts to correct. (4) Right to Opt-Out of Sale/Sharing — consumers can opt out of: the sale of their personal information to third parties; and (CPRA expansion) the sharing of personal information for cross-context behavioral advertising. Businesses must honor opt-out signals from global privacy controls (GPCs) like browser extensions — this is the most operationally complex requirement for SaaS companies with advertising technology. Must provide a "Do Not Sell or Share My Personal Information" link on the homepage. (5) Right to Limit Use of Sensitive Personal Information — CPRA created a new right to limit the use and disclosure of sensitive personal information (SPI) to purposes necessary for providing the service. SPI categories: social security number; financial account numbers; precise geolocation; racial/ethnic origin; religious or philosophical beliefs; union membership; contents of mail/email/text messages; genetic data; biometric data; health data; sex life or sexual orientation data. (6) Right to Non-Discrimination — businesses cannot discriminate against consumers who exercise their CCPA/CPRA rights (denying services, charging higher prices, providing lower quality service). Businesses CAN offer financial incentives for providing data, if disclosed and not so disproportionate as to constitute a penalty for opting out.

What is required in a CCPA-compliant privacy notice?

CCPA/CPRA requires two types of privacy disclosures, with specific required content: (1) Privacy Notice at Collection (at-collection notice): Required at or before collecting personal information. Must disclose: categories of personal information to be collected; the purposes for which it will be used; whether any category is sold or shared (and if so, to whom); and a link to the full privacy policy. For online businesses, this notice is typically embedded in a "cookie consent" banner or just-in-time notice when a user starts a sign-up flow. (2) Full Privacy Policy: Must include all CCPA/CPRA required disclosures and be accessible via a link on the homepage. Required contents: the 11 categories of personal information under CCPA; specific categories the business collects; purposes for collection; how long personal information is retained (or criteria used to determine retention period — this is a CPRA addition); categories of third parties with whom information is shared; whether personal information is sold or shared for behavioral advertising; consumer rights summary and how to exercise them; contact information for submitting requests; date of last update. The CPRA added a requirement to disclose retention periods (or criteria) — many SaaS privacy policies do not include this and are therefore non-compliant with CPRA as of January 1, 2023.

What are the CCPA / CPRA service provider agreement requirements for B2B SaaS?

If your SaaS product processes personal information on behalf of a business customer (as opposed to collecting it in your own right), you are likely a "service provider" under CCPA/CPRA — roughly equivalent to a "data processor" under GDPR. This matters because CCPA/CPRA imposes specific contractual requirements on service provider relationships: Required service provider agreement terms: (1) Business purposes for which personal information is disclosed (limited list — service providers cannot use the data for any other purpose); (2) Prohibition on selling or sharing personal information received from the business; (3) Prohibition on collecting, using, retaining, or disclosing personal information outside the specified business purposes; (4) Obligation to assist the business in responding to consumer rights requests (right to know, delete, correct); (5) Obligation to assist the business in meeting its CCPA/CPRA obligations; (6) Obligation to provide same level of privacy protection as required by CCPA; (7) Right for the business to audit the service provider's compliance; (8) Obligation to notify the business if service provider can no longer comply; and (9) Obligation to pass-through CCPA requirements to any sub-service providers ("subprocessors" in GDPR terminology). Without a CCPA-compliant service provider agreement, the disclosure of personal information from your SaaS customer to you may constitute a "sale" of personal information — subjecting your customer to CCPA opt-out requirements and exposure. Most SaaS companies need to update their DPA or online service terms to include these elements if they have California-based business customers.

What are the CPRA enforcement powers and fine amounts?

The California Privacy Protection Agency (CPPA), created by CPRA and operational since 2023, has independent enforcement authority separate from the California Attorney General. CPPA enforcement: The CPPA can: conduct investigations and issue subpoenas; hold adjudicatory hearings; impose administrative fines; refer cases to the Attorney General for civil enforcement. CPPA rulemaking: The CPPA has authority to create new regulations implementing CCPA/CPRA — including additional consumer rights, new categories of sensitive data, and cybersecurity audit requirements. The CPPA has been active in issuing regulations on automated decision-making technology (ADMT) and data broker registration. Fine amounts: $2,500 per violation for unintentional violations; $7,500 per violation for intentional violations or violations involving children's data. "Per violation" is interpreted as per consumer per violation — a data breach exposing records of 50,000 California consumers, if found to involve a CCPA failure, could theoretically be calculated as up to $375M in fines ($7,500 × 50,000). The Attorney General and CPPA have discretion in how violations are counted, and to date enforcement actions have resulted in consent decrees rather than maximum theoretical penalties. Attorney General enforcement: the California AG can also bring CCPA enforcement actions. AG enforcement focuses on: failure to implement required privacy practices; failure to respond to consumer rights requests; unlawful selling/sharing of personal information without disclosures; and failure to maintain DPAs with service providers. 30-day cure period (eliminated by CPRA for most violations as of January 1, 2023 — businesses no longer have an automatic right to cure before fines are imposed).

How does CCPA / CPRA interact with GDPR for SaaS companies processing California and EU data?

SaaS companies with both California consumers and EU customers face a dual compliance obligation. The regimes overlap in significant ways and diverge in others: Key similarities (making dual compliance more efficient): (1) Both require a detailed privacy notice at collection; (2) Both require a legal basis or disclosed purpose for data processing; (3) Both grant rights to access, delete, and port data; (4) Both require data processing agreements with service providers/processors; (5) Both require security measures proportionate to the risk of the data processed. Key differences (requiring separate compliance measures): (1) Legal bases: GDPR requires one of six legal bases (consent, legitimate interests, contract, legal obligation, vital interests, public task). CCPA/CPRA does not require a legal basis — it focuses on disclosure and opt-out rights rather than pre-authorization requirements; (2) Children's data: GDPR requires explicit consent from parents for children under 13 (or 16 in some EU countries). CCPA requires opt-in consent from consumers under 16 for the sale of their data, and parental consent under 13. CPRA creates enhanced protections for minors' data with higher fines; (3) Retention: GDPR requires a specific retention period or criteria. CPRA added a similar disclosure requirement but does not mandate a specific period; (4) Data transfer mechanisms: GDPR requires SCCs, adequacy decisions, or other transfer mechanisms for EU personal data flows outside the EEA. CCPA/CPRA has no equivalent international transfer restriction; (5) Enforcement model: GDPR enforcement through national Data Protection Authorities (DPAs) with EU-wide coordination. CCPA through California AG + CPPA. Practical dual-compliance approach: a GDPR-compliant privacy program is generally more stringent and will satisfy most CCPA/CPRA obligations as a floor — but CPRA-specific requirements (opt-out of sharing for behavioral advertising, GPC signal compliance, service provider contract terms) must be addressed separately.

Related compliance resources

CCPA Regulation Hub →GDPR Compliance Checklist →Privacy Policy Guide →GDPR DPA Guide →Startup Compliance Program →All Guides →