Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » CCPA » CCPA Compliance

CCPA Compliance

CCPA, or California Consumer Privacy Act, is a set of compliance guidelines aimed at protecting data belonging to residents of the state of California. It came into effect on January 1, 2020, and is considered one of the most stringent privacy laws in the United States. It applies to all organizations, regardless of where the business is located, that:

  • Process more than 100,000 personal data (B2B data included) of California citizens annually
  • Have more than $25 million in revenue annually
  • Earn more than 50% of revenue from selling California residents’ data

According to the CCPA guidelines, personal data can include details such as names, Social Security numbers, email addresses, birthdates, passport numbers, IP addresses, phone numbers, driver’s license numbers, residential addresses, and bank account details.

The CCPA protects the customers for their right to choose not to sell their data and the right of access and deletion of the data collected. Organizations that violate the CCPA may face fines of $7,500 per violation and $750 per user affected in civil damages.

The CCPA compliance requires an organization to have a process for responding to customer privacy rights exercise requests. In addition, businesses should collect less personal information except when it is absolutely necessary.

An inventory of all the data collected by an organization is set up, and customers are given notice of the collection of data. A data privacy policy is established, the employees are trained, and requests from customers are handled effectively.

Additional reading

SOC 2 Audit: The Ultimate Guide (Scopes, Process & Tips)

According to the AICPA, demand for SOC 2 reports is up nearly 50%, and more companies are taking a hard line: no report, no deal. Consequently, risk teams have tightened their vendor-assessment checklists. Buyers also want a fresh PDF certifying that your services are secure, not promises that the audit is “in progress.” If you’re…

COSO ERM Framework: Key Components and Implementation Guide

In March 2024, cloud service giant Microsoft had their head hung in shame after the Cyber Safety Review Board (CSRB) provided a 30-page review of its inadequate security culture.  The CSRP report read “..troubling examples of decision-making processes within the company that did not prioritize security risk management at a level commensurate with the threat.”…

Top 6 Anecdotes Alternatives for 2026 and Beyond

TL; DR This guide compares six top Anecdotes alternatives. We evaluate automation depth, integration coverage, multi-framework mapping, workflow customization, audit collaboration, and pricing transparency to help you choose the right platform for your 2026 compliance needs. Top 6 Anecdoes alternatives in 2026: 1. Sprinto2. Drata3. Vanta4. Secureframe5. Hyperproof6. Scytale If you run security or compliance…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.