Kuulo
← Trust Centre
CCPA / CPRA mark

Data protection

California Consumer Privacy Act and CPRA amendments

A credible review needs to follow the actual collection and sharing model. It should be possible to explain what information is collected, why it is used, which vendors receive it and how a rights request is handled.

Client-specific assessmentCalifornia Attorney General overview

The framework

What CCPA / CPRA is for.

The CCPA, as amended by the California Privacy Rights Act, gives California residents rights over personal information and places obligations on businesses around notice, access, deletion, correction, opting out and the handling of sensitive information.

How we work with it

Make the obligation usable.

  • Map collection, disclosure, sale or sharing, retention and consumer-rights workflows.
  • Review vendor and contract language against the actual system behaviour.
  • Create a practical evidence pack for procurement, privacy review and operational handover.

What we can leave behind

Evidence a reviewer can follow.

  • Data inventory and sharing map
  • Vendor questionnaire support
  • Consumer-rights workflow review
Request documentation →

Concrete delivery evidence

How this showed up in client work.

The current public project and case-study material does not attribute a CCPA/CPRA-specific client engagement. We therefore present this page as a capability and assessment route, not as a claim that a named client completed a California privacy programme with us.

Current public evidence

Documentation route

A vendor questionnaire, data map and rights-handling review can be scoped to the system and the organisation's role.

Keep the map connected

Need this mapped to your system?

Start with the evidence your review needs.

Talk to us →