
CCPA Compliance Services and CPRA Consulting
The California Consumer Privacy Act (CCPA) and its CPRA amendment give California consumers rights over the personal information a business holds about them, and they put the work of honoring those rights on the business. CyberCrest's CCPA compliance consulting services cover that work end to end: mapping what you hold and where it sits, building the consumer request and opt-out paths that act on it, and closing the gaps the mapping exposes.

METHODOLOGY
Our CCPA Compliance Methodology
Achieving CCPA compliance is a sequence, not a single project. Our CCPA consultants take you through four steps, from finding out what personal information the business holds to the ongoing work that keeps the program current as California's rules change.

Gap Assessment
We assess your privacy program against the CCPA as amended by the CPRA, identify your CCPA compliance gaps and set the order in which they have to be closed.
Remediation Support
CyberCrest will assist in developing documentation and support control implementation to achieve compliance.
Readiness Review
We re-test the program once the gaps are closed, from consumer request handling to the opt-out path, so the business can show how each requirement is met.
Compliance Maintenance
CyberCrest will provide maintenance and ongoing compliance activity support.
SERVICES
Our CCPA Consulting Services
No two CCPA engagements start in the same place. Some businesses have never mapped the personal information they hold; others published a privacy policy years ago that no longer matches what the business does. Our CCPA consultancy starts from what you already have. Each service below can be bought on its own or run as part of one engagement.
Data Inventory and Data Mapping
We identify the systems, vendors and processes that hold consumer data, then map what personal information is collected, where it came from, what it is used for and who it is disclosed to. That mapping is the data inventory the rest of the program is built on.
Privacy Notice and Policy Development
We draft the notice at collection, the privacy policy and the internal procedures behind them, so what your business publishes matches its actual data collection, use and disclosure. The notices are written from your data map rather than from a template.
Ongoing CCPA Compliance Support
Products change, vendors change and California's rules change with them. We keep the notices, the contracts and the record of requests current, and revisit them whenever you add a data flow or a new vendor.
DELIVERABLES
What You Receive from Our CCPA-CPRA Compliance Services
Our CCPA professional services produce documents your team can work from and a regulator or an enterprise customer can read. How many of them you need depends on how much of the privacy program already exists.
Data Inventory and Data Map
A record of the personal information the business collects, the sources it comes from, the systems that hold it, the purposes it is used for and the parties it is disclosed to, in a form your team can keep up to date.
CCPA Gap Assessment Report
Where your privacy program stands against the CCPA as amended, gap by gap, each one tied to the requirement behind it and ordered by what has to be closed first.
Privacy Notice and Privacy Policy
The notice at collection and the published privacy policy, drafted against your own data map so that the document and the business describe the same thing.
Consumer Request Procedure
The written procedure your team follows when a request arrives, covering identity verification, the systems in scope, the response deadline and the record you keep of each request.
Prioritized Remediation Plan
A dated plan for the gaps that are still open, with an owner and a target date against each one, so the work can be tracked after the engagement ends.


Choose a CCPA Compliance Vendor That Stays Through Remediation
An assessment is easy to buy and hard to act on. The CyberCrest consultants who deliver our CCPA compliance services and CPRA consulting stay on after the report and work the findings through with your team, from the data map to the opt-out path, so what changes is the program and not the paperwork.




WHY US
Why Work with CyberCrest's CCPA Experts
CyberCrest is a licensed CPA firm registered with the American Institute of Certified Public Accountants (AICPA), and that assurance discipline shapes how our CCPA compliance consultants work: evidence over assertion, testing over assumption. Privacy compliance is security work as much as documentation work, so an engagement improves your security posture, not just the notices on your website.
Ready to Start
Some CCPA compliance providers cannot put a team on a new engagement for several months. CyberCrest staffs up ahead of time and is ready to begin when you are.
Client-First Strategies
CyberCrest will always put your organization's needs first, making your priorities central to our strategy without sacrificing quality.
Technology Enabled
CyberCrest leverages state-of-the-art compliance software to streamline and enhance the compliance journey. Our consultants are also trained and have hands-on experience with the top compliance platform vendors.
Hands-On Remediation
We support information security implementation and remediation work, from technical tasks to administrative ones, so our clients reach compliance without compromising best practices and requirements.
TESTIMONIALS
Hear from Our Clients

ABOUT CCPA
About the CCPA and CPRA
The California Consumer Privacy Act (CCPA) has been operative since January 1, 2020. In November 2020 California voters approved Proposition 24, the California Privacy Rights Act (CPRA), which amended the CCPA and added protections that began on January 1, 2023. What a business collects has to be disclosed to California consumers at or before the point of collection, the published privacy policy has to describe the business's data practices and the rights consumers have over them, and the law treats data sharing for cross-context behavioral advertising much as it treats a sale. The CCPA requires businesses to make what they publish match what they hold, and closing the distance between the two is most of the work. The consumer rights the law creates are specific, and California consumers can:
- Know what personal information a business has collected about them, the sources it came from and the parties it was disclosed to
- Delete the personal information collected from them, and correct it when it is inaccurate
- Opt out of the sale or sharing of their personal information, including cross-context behavioral advertising, the targeted advertising built from their activity across other sites and apps
- Limit how a business uses and discloses their sensitive personal information
- Receive the same goods, services and prices after exercising any of these rights
WHO IT APPLIES TO
Does the CCPA Apply to Your Business?
The CCPA reaches for-profit businesses that do business in California, collect the personal information of California residents and meet at least one of three thresholds. Your industry does not decide coverage: the thresholds below do, and meeting any one of them brings the same legal obligations.
Businesses Above the Revenue Threshold
A business with annual gross revenue above $26,625,000 in the preceding calendar year is covered. That is the adjusted threshold in force since January 1, 2025, not the $25,000,000 printed in the statute.
Businesses Handling Personal Information at Volume
A business that buys, sells or shares the personal information of 100,000 or more consumers or households in a year is covered, whatever its revenue. The count is of California residents, not of every customer on the books.
Businesses That Monetize Personal Information
A business that derives 50 percent or more of its annual revenue from selling or sharing consumers' personal information is covered at any size. A business in that position also carries duties the CCPA does not place on every covered business: a privacy risk assessment before the selling or sharing begins, and an annual cybersecurity audit.
Frequently asked questions
What is the difference between the CCPA and the CPRA?
The CPRA is not a second law: it amended the CCPA, created the California Privacy Protection Agency as a dedicated regulator and widened what a consumer can ask a business to do. That is why the Attorney General's office refers to the result as the CCPA, or the CCPA as amended. Everything on this page describes the amended law, and our CCPA vs CPRA comparison walks through the changes one by one.
What are the penalties for violating the CCPA?
Three routes apply, carrying two sets of figures between them: an administrative fine from the regulator, a civil penalty recovered in court and damages in a consumer's own lawsuit. In an administrative enforcement action the California Privacy Protection Agency can impose a fine of not more than $2,663 per violation, or $7,988 for an intentional violation or one involving the personal information of a consumer the business knows is under 16. Civil Code 1798.199.90 sets the civil penalties the Attorney General recovers in court at those same two amounts. A consumer can sue on their own only over certain data breaches, where nonencrypted and nonredacted personal information is taken because the business failed to maintain reasonable security procedures and practices. Statutory damages in such a suit run from $107 to $799 per consumer per incident, or actual damages if those are greater. A consumer has to give the business 30 days' written notice before suing for statutory damages, and a cure inside that window ends the claim; that notice belongs to the private action and has nothing to do with regulator enforcement. Every figure here is the amount in force rather than the one printed in the statute, because Civil Code 1798.199.95(d) has them adjusted for the Consumer Price Index every odd-numbered year. Beyond the money, non-compliance costs time: an enforcement inquiry asks for the same records a working privacy program keeps anyway, and a business that does not keep them has to build them to the regulator's deadline.
What is a consumer request, and how long does a business have to respond?
A consumer request is how a California resident exercises a CCPA right: to know what personal information you hold about them, to delete it, to correct it or to opt out of its sale or sharing. Once you receive a verifiable consumer request, you have 45 days to respond, and that period can be extended once by another 45 days where it is reasonably necessary, provided you tell the consumer inside the first 45 days. The deadline is rarely the hard part; finding every copy of the personal information across your systems is. That search is privacy operations as much as policy, and it is the part CyberCrest's CCPA privacy consultants work through with your team.
How is the CCPA enforced?
By the California Privacy Protection Agency through administrative actions, and by the Attorney General through civil actions in court. Consumers cannot bring most CCPA claims themselves, although consumer complaints are one of the ways patterns of misconduct reach the Attorney General, and the Agency can investigate on a sworn complaint or on its own initiative. Enforcement carries no cure period: since January 1, 2023, the CCPA no longer requires notice of a violation or an opportunity to cure before an enforcement action is filed, though the Agency may decide not to investigate a complaint, or to give the business a period to cure the alleged violation. In February 2026 the Attorney General announced a $2.75 million settlement with the Walt Disney Company, the largest under the CCPA to date, over opt-out requests that were applied only to the streaming service the consumer was using and often only to the device in front of them.
Does the CCPA apply to employee data and B2B contact data?
Yes. The carve-outs that once kept employment records and business-to-business contacts outside most of the law became inoperative on January 1, 2023. Data about job applicants, employees, owners, directors, officers and contractors is subject to the same consumer rights and the same notice duties as any other personal information the business collects, and so is the personal information exchanged with contacts at other companies.
Does the CCPA apply to businesses outside California?
It can. The test is not where the business sits but whether it does business in California and meets one of the thresholds. A consumer under the CCPA is a natural person who is a California resident, so a company headquartered in another state, or another country, can be covered by what it does with the data of Californians.



