This website uses cookies to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
READ MORE
OKAY, I AGREE

CCPA Compliance Services and CPRA Consulting

The California Consumer Privacy Act (CCPA) and its CPRA amendment give California consumers rights over the personal information a business holds about them, and they put the work of honoring those rights on the business. CyberCrest's CCPA compliance consulting services cover that work end to end: mapping what you hold and where it sits, building the consumer request and opt-out paths that act on it, and closing the gaps the mapping exposes.

METHODOLOGY

Our CCPA Compliance Methodology

Achieving CCPA compliance is a sequence, not a single project. Our CCPA consultants take you through four steps, from finding out what personal information the business holds to the ongoing work that keeps the program current as California's rules change.

Gap Assessment

We assess your privacy program against the CCPA as amended by the CPRA, identify your CCPA compliance gaps and set the order in which they have to be closed.

01

Remediation Support

CyberCrest will assist in developing documentation and support control implementation to achieve compliance.

02

Readiness Review

We re-test the program once the gaps are closed, from consumer request handling to the opt-out path, so the business can show how each requirement is met.

03

Compliance Maintenance

CyberCrest will provide maintenance and ongoing compliance activity support.

04

SERVICES

Our CCPA Consulting Services

No two CCPA engagements start in the same place. Some businesses have never mapped the personal information they hold; others published a privacy policy years ago that no longer matches what the business does. Our CCPA consultancy starts from what you already have. Each service below can be bought on its own or run as part of one engagement.

Data Inventory and Data Mapping

We identify the systems, vendors and processes that hold consumer data, then map what personal information is collected, where it came from, what it is used for and who it is disclosed to. That mapping is the data inventory the rest of the program is built on.

Privacy Notice and Policy Development

We draft the notice at collection, the privacy policy and the internal procedures behind them, so what your business publishes matches its actual data collection, use and disclosure. The notices are written from your data map rather than from a template.

Ongoing CCPA Compliance Support

Products change, vendors change and California's rules change with them. We keep the notices, the contracts and the record of requests current, and revisit them whenever you add a data flow or a new vendor.

HOW WE HELP

How a CCPA Compliance Company Supports Your Privacy Program

CCPA requirements turn into daily operations: requests arrive and have to be answered, opt-out signals have to be honored, vendors come and go. This is what working with a CCPA consultant at CyberCrest looks like once the engagement is under way.

Consumer Request Handling

We build the path that consumer rights requests travel: how consumers submit requests, who verifies identity, which systems hold the data collected about the person asking, who approves the response and how the record is kept. Then we run test consumer requests through it before real ones arrive.

Opt-Out Paths, Built and Tested

We exercise the opt-out mechanisms your site publishes, from the "Do Not Sell or Share My Personal Information" link to the opt-out preference signals your servers receive, such as Global Privacy Control, and we test them across every service and every device in scope. An opt-out that stops at one app, or at one device, is not an opt-out of sale or sharing.

Reasonable Security, with Your Team

Where the assessment finds weak access controls, forgotten data stores or no plan for security incidents, a CyberCrest consultant works alongside your IT team on the fix. The CCPA puts a business under a duty to implement and maintain reasonable security procedures and practices appropriate to the personal information it holds, which makes data security part of the privacy work rather than a separate project.

Service Provider Contracts

We review the contracts behind the personal information you disclose to service providers and contractors, and the business purposes those contracts name. The regulations require each purpose to be described specifically rather than in generic terms, which is where most existing agreements fall short.

DELIVERABLES

What You Receive from Our CCPA-CPRA Compliance Services

Our CCPA professional services produce documents your team can work from and a regulator or an enterprise customer can read. How many of them you need depends on how much of the privacy program already exists.

Data Inventory and Data Map

A record of the personal information the business collects, the sources it comes from, the systems that hold it, the purposes it is used for and the parties it is disclosed to, in a form your team can keep up to date.

CCPA Gap Assessment Report

Where your privacy program stands against the CCPA as amended, gap by gap, each one tied to the requirement behind it and ordered by what has to be closed first.

Privacy Notice and Privacy Policy

The notice at collection and the published privacy policy, drafted against your own data map so that the document and the business describe the same thing.

Consumer Request Procedure

The written procedure your team follows when a request arrives, covering identity verification, the systems in scope, the response deadline and the record you keep of each request.

Prioritized Remediation Plan

A dated plan for the gaps that are still open, with an owner and a target date against each one, so the work can be tracked after the engagement ends.

Choose a CCPA Compliance Vendor That Stays Through Remediation

An assessment is easy to buy and hard to act on. The CyberCrest consultants who deliver our CCPA compliance services and CPRA consulting stay on after the report and work the findings through with your team, from the data map to the opt-out path, so what changes is the program and not the paperwork.

TALK TO AN EXPERT

WHY US

Why Work with CyberCrest's CCPA Experts

CyberCrest is a licensed CPA firm registered with the American Institute of Certified Public Accountants (AICPA), and that assurance discipline shapes how our CCPA compliance consultants work: evidence over assertion, testing over assumption. Privacy compliance is security work as much as documentation work, so an engagement improves your security posture, not just the notices on your website.

Ready to Start

Some CCPA compliance providers cannot put a team on a new engagement for several months. CyberCrest staffs up ahead of time and is ready to begin when you are.

Client-First Strategies

CyberCrest will always put your organization's needs first, making your priorities central to our strategy without sacrificing quality.

Technology Enabled

CyberCrest leverages state-of-the-art compliance software to streamline and enhance the compliance journey. Our consultants are also trained and have hands-on experience with the top compliance platform vendors.

Hands-On Remediation

We support information security implementation and remediation work, from technical tasks to administrative ones, so our clients reach compliance without compromising best practices and requirements.

TESTIMONIALS

Hear from Our Clients

01
/
03

I have worked with CyberCrest on multiple compliance engagements over the past several years including HITRUST, NIS 2 and ISO 27001. Without exception, CyberCrest has consistently exceeded expectations for my clients through a combination of highly experienced consultants, and a practical approach to achieving compliance. They are willing to roll up their sleeves and help organizations fully understand and address their compliance challenges, not just function as external auditors.

Paul Lucidi

Founder and President, CyberAge Consulting LLC

“I have used the CyberCrest team for a variety of critical information security compliance engagements over the years including successfully attaining ISO 27001 and HITRUST certifications. All of our engagements have exceeded expectations!”

Craig Guinasso

Senior Director, Technology & CyberSecurity, Alector

"We have worked with CyberCrest on multiple penetration testing and cybersecurity risk and maturity assessments. The CyberCrest team has consistently produced high quality deliverables at fair prices. We give their client prospects our strongest recommendation."

David Wise

Managing Partner, Aberdeen Advisors

ABOUT CCPA

About the CCPA and CPRA

The California Consumer Privacy Act (CCPA) has been operative since January 1, 2020. In November 2020 California voters approved Proposition 24, the California Privacy Rights Act (CPRA), which amended the CCPA and added protections that began on January 1, 2023. What a business collects has to be disclosed to California consumers at or before the point of collection, the published privacy policy has to describe the business's data practices and the rights consumers have over them, and the law treats data sharing for cross-context behavioral advertising much as it treats a sale. The CCPA requires businesses to make what they publish match what they hold, and closing the distance between the two is most of the work. The consumer rights the law creates are specific, and California consumers can:

  • Know what personal information a business has collected about them, the sources it came from and the parties it was disclosed to
  • Delete the personal information collected from them, and correct it when it is inaccurate
  • Opt out of the sale or sharing of their personal information, including cross-context behavioral advertising, the targeted advertising built from their activity across other sites and apps
  • Limit how a business uses and discloses their sensitive personal information
  • Receive the same goods, services and prices after exercising any of these rights

WHO IT APPLIES TO

Does the CCPA Apply to Your Business?

The CCPA reaches for-profit businesses that do business in California, collect the personal information of California residents and meet at least one of three thresholds. Your industry does not decide coverage: the thresholds below do, and meeting any one of them brings the same legal obligations.

Businesses Above the Revenue Threshold

A business with annual gross revenue above $26,625,000 in the preceding calendar year is covered. That is the adjusted threshold in force since January 1, 2025, not the $25,000,000 printed in the statute.

Businesses Handling Personal Information at Volume

A business that buys, sells or shares the personal information of 100,000 or more consumers or households in a year is covered, whatever its revenue. The count is of California residents, not of every customer on the books.

Businesses That Monetize Personal Information

A business that derives 50 percent or more of its annual revenue from selling or sharing consumers' personal information is covered at any size. A business in that position also carries duties the CCPA does not place on every covered business: a privacy risk assessment before the selling or sharing begins, and an annual cybersecurity audit.

2026 OBLIGATIONS

What the 2026 California Privacy Regulations Add

The Agency's regulations on cybersecurity audits, privacy risk assessments and automated decisionmaking took effect on January 1, 2026. Each obligation has its own trigger and its own deadline, and the audit has to be performed by someone who did not develop, recommend or implement the program being examined.

Annual Cybersecurity Audits

The audit applies to a business that derives 50 percent or more of its annual revenue from selling or sharing personal information. It also applies to a business that meets the revenue threshold and, in the preceding calendar year, processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers. The first report is due April 1, 2028, if 2026 annual gross revenue was above $100,000,000; April 1, 2029, if 2027 revenue was between $50,000,000 and $100,000,000; and April 1, 2030, if 2028 revenue was below $50,000,000.

Privacy Risk Assessments

A privacy risk assessment has to be completed before the business begins any data processing that presents significant risk to consumers' privacy, and the regulations name selling or sharing personal information and processing sensitive personal information among the activities that qualify. Assessments conducted in 2026 and 2027 have to be submitted to the Agency by April 1, 2028.

Automated Decisionmaking Technology

A business that uses automated decisionmaking technology (ADMT) to make a significant decision about a consumer has to be in compliance with the ADMT rules by January 1, 2027. Working out which of your systems meet that definition is a scoping exercise, and it is worth running before the date, not after.

Frequently asked questions

What is the difference between the CCPA and the CPRA?

The CPRA is not a second law: it amended the CCPA, created the California Privacy Protection Agency as a dedicated regulator and widened what a consumer can ask a business to do. That is why the Attorney General's office refers to the result as the CCPA, or the CCPA as amended. Everything on this page describes the amended law, and our CCPA vs CPRA comparison walks through the changes one by one.

What are the penalties for violating the CCPA?

Three routes apply, carrying two sets of figures between them: an administrative fine from the regulator, a civil penalty recovered in court and damages in a consumer's own lawsuit. In an administrative enforcement action the California Privacy Protection Agency can impose a fine of not more than $2,663 per violation, or $7,988 for an intentional violation or one involving the personal information of a consumer the business knows is under 16. Civil Code 1798.199.90 sets the civil penalties the Attorney General recovers in court at those same two amounts. A consumer can sue on their own only over certain data breaches, where nonencrypted and nonredacted personal information is taken because the business failed to maintain reasonable security procedures and practices. Statutory damages in such a suit run from $107 to $799 per consumer per incident, or actual damages if those are greater. A consumer has to give the business 30 days' written notice before suing for statutory damages, and a cure inside that window ends the claim; that notice belongs to the private action and has nothing to do with regulator enforcement. Every figure here is the amount in force rather than the one printed in the statute, because Civil Code 1798.199.95(d) has them adjusted for the Consumer Price Index every odd-numbered year. Beyond the money, non-compliance costs time: an enforcement inquiry asks for the same records a working privacy program keeps anyway, and a business that does not keep them has to build them to the regulator's deadline.

What is a consumer request, and how long does a business have to respond?

A consumer request is how a California resident exercises a CCPA right: to know what personal information you hold about them, to delete it, to correct it or to opt out of its sale or sharing. Once you receive a verifiable consumer request, you have 45 days to respond, and that period can be extended once by another 45 days where it is reasonably necessary, provided you tell the consumer inside the first 45 days. The deadline is rarely the hard part; finding every copy of the personal information across your systems is. That search is privacy operations as much as policy, and it is the part CyberCrest's CCPA privacy consultants work through with your team.

How is the CCPA enforced?

By the California Privacy Protection Agency through administrative actions, and by the Attorney General through civil actions in court. Consumers cannot bring most CCPA claims themselves, although consumer complaints are one of the ways patterns of misconduct reach the Attorney General, and the Agency can investigate on a sworn complaint or on its own initiative. Enforcement carries no cure period: since January 1, 2023, the CCPA no longer requires notice of a violation or an opportunity to cure before an enforcement action is filed, though the Agency may decide not to investigate a complaint, or to give the business a period to cure the alleged violation. In February 2026 the Attorney General announced a $2.75 million settlement with the Walt Disney Company, the largest under the CCPA to date, over opt-out requests that were applied only to the streaming service the consumer was using and often only to the device in front of them.

Does the CCPA apply to employee data and B2B contact data?

Yes. The carve-outs that once kept employment records and business-to-business contacts outside most of the law became inoperative on January 1, 2023. Data about job applicants, employees, owners, directors, officers and contractors is subject to the same consumer rights and the same notice duties as any other personal information the business collects, and so is the personal information exchanged with contacts at other companies.

Does the CCPA apply to businesses outside California?

It can. The test is not where the business sits but whether it does business in California and meets one of the thresholds. A consumer under the CCPA is a natural person who is a California resident, so a company headquartered in another state, or another country, can be covered by what it does with the data of Californians.