- Official Attorney General guidance explaining GPC as a method for submitting a CCPA sale-or-sharing opt-out request.
"One acceptable method for consumers to opt-out of sales or sharing is via a user-enabled global privacy control, like the GPC."
Build one CCPA operating model linking entity scope, data inventory, notices, rights, GPC and opt-outs, recipient contracts, retention, security, risk assessments, cybersecurity audits, automated decisionmaking technology (ADMT), and enforcement evidence.
Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.
Structured answer sets in this page tree.
Cited legal and guidance references.
CCPA compliance starts with a per-entity scope decision and a current data inventory. Connect every collection point, use, disclosure, request, and consumer choice to an owner, control, deadline, and evidence record; a privacy policy alone does not prove that the control operates.
Divide the program into six connected workstreams: scope and governance; data mapping and minimization; notices and consumer choices; rights operations; recipient contracts and oversight; and security, risk assessments, cybersecurity audits, and (ADMT).
Each workstream needs a decision register. For every control, record the legal trigger, affected entities and systems, accountable owner, implementation evidence, exception, deadline, and event that requires reassessment.
The team able to change a process should own its control. Privacy or legal interprets ambiguous triggers, but product owns interface behavior, engineering owns signal and request propagation, procurement owns contract completion, security owns safeguards and audits, and support owns intake execution.
Evidence must show what operated, not only what policy said. Preserve dated notices, deployed interface captures, test results, request logs, vendor instructions, contract versions, retention jobs, assessment approvals, audit reports, and remediation records.
The regulations effective January 1, 2026 added risk-assessment, annual cybersecurity-audit, and ADMT requirements. General CCPA coverage does not trigger all three automatically; each article has its own processing, revenue, or risk criteria.
Covered risk assessments began for new processing on January 1, 2026. Continuing pre-2026 processing must be assessed by December 31, 2027, and the first required submission for 2026-2027 assessments is due April 1, 2028. ADMT obligations for significant decisions begin January 1, 2027. Initial cybersecurity-audit certification deadlines are phased by revenue on April 1 of 2028, 2029, or 2030.
Review core scope, inventory, privacy policy, request methods, and evidence at least annually. Review a specific control sooner when its facts change.
Open a change review before a new collection purpose, recipient, ad-tech tag, financial incentive, sensitive-information use, significant-decision ADMT, acquisition, or data-broker activity goes live.
Connect each CCPA trigger to the team that can change the process, the evidence showing it operated, and the event that reopens the decision.
Turn Compliance into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next Compliance actions with Sorena.
"One acceptable method for consumers to opt-out of sales or sharing is via a user-enabled global privacy control, like the GPC."
"A business that uses ADMT for a significant decision prior to January 1, 2027, must be in compliance with the requirements of this Article no later than January 1, 2027."
"Applying Data Minimization to Consumer Requests"
"In doing so, the regulations make it easier for consumers to exercise their CCPA rights"
"The GPP is the only privacy signaling mechanism available to signal consumer privacy choices for all US states"