Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...

California Privacy Compliance

Operationalize California Privacy Requirements (CCPA & CPRA) 

California privacy law has evolved significantly from its initial introduction of establishing privacy notices and consumer rights, including opt-out. The 2025 CCPA final regulation text codified CPRA amendments of 2023 and expanded requirements for mandatory risk assessments across high-risk activities and instituted privacy and cyber audits to demonstrate the protections across information systems processing sensitive data. The new set of requirements is pushing organizations to adopt a higher level of rigor and implement defensible evidence-backed programs. OneTrust gives privacy teams that foundation so they can proactively assess risk, honor opt-out choices, process requests faster, apply decisions consistently, and stay audit-ready.

CCPA OneTrust Workflow CCPA OneTrust Workflow

Automate a frictionless consumer and employee rights requests 

California privacy rights apply to both consumers and employees. OneTrust handles the full request lifecycle for both in one operational flow: intake, identity verification, data discovery, redaction, deletion, and secure response. Teams can process requests consistently, shorten turnaround time, and maintain a documented record of how each request was handled.

Consumer and employee rights request widgets

Enable opt-out of sale and sharing across digital experiences 

California privacy law gives residents meaningful control over how their personal information is used and shared, including the right to opt out of both sale and broader sharing with third parties. OneTrust operationalizes those opt-out choices across web, mobile, and connected platforms. Consumer decisions are captured, enforced, and communicated to downstream systems and third parties so organizations can apply them consistently rather than tracking them manually.

The image shows a grid of six user interface card layout styles on a light background. Each card contains a simple browser window mockup with green content blocks and different positioning and corner treatments. The styles are labeled Center Rounded, Flat, Floating Rounded Icon, Floating Rounded Corner, Floating Flat, and Floating Rounded. One card, Floating Rounded Corner, is highlighted with a yellow border to emphasize selection.

Classify and manage sensitive personal information 

California privacy law provides a definition for sensitive personal information, which includes Social Security numbers, biometric data, precise geolocation, and financial account credentials, with additional rights and handling requirements attached. OneTrust helps organizations identify, label, and apply appropriate controls to sensitive personal information across data sources. Automated discovery and California-specific classifiers give teams a clearer picture of where sensitive data lives and how it moves.

Misc logos around the onetrust monogram

Map data flows and high-risk processing activities to support risk and audit readiness 

California privacy requirements include risk assessments and audits for high-risk data processing activities, both of which depend on knowing where personal information resides. OneTrust maps systems, business processes, and third parties so teams can scope consumer and employee requests accurately, keep the data inventory current as systems change, and maintain the documentation needed to manage assessments, consolidate findings, and demonstrate accountability to regulators over time.

Diagram illustrating data consumers connected to an Adobe Analytics source or collection. The left side shows two stylized user icons labeled Customer and Contractor. A line connects these consumer roles to a rectangular panel on the right labeled Source/Collection and Adobe Analytics. The design uses simple flat icons with green and blue accents on a light background, conveying a clean, modern interface concept.

Meet California breach notification requirements 

When incidents occur, teams need a structured response process that meets California's notification timelines. OneTrust centralizes incident intake and analysis across reporting channels, with repeatable workflows for investigation and response. Connecting incident activity to privacy operations helps organizations document what happened, coordinate across teams, and notify affected parties within the required timeframe.

The image displays a data dashboard summarizing incidents across an organization. A card on the left shows 13 open incidents, while a central donut chart visualizes incidents by type. Below, a horizontal bar chart compares incidents by organization units labeled EU, Corporate, Legal, and HR, with a numeric axis from 0 to 40. The design uses green, blue, and purple bars and segments on a light background for clear visualization.

You May Also Like

Frequently Asked Questions

ADMT applies to technologies (including AI) for "significant decisions" affecting a consumer's life. ADMT is pre-classified as a high-risk processing activity, and the CCPA update explicitly applies requirements for proactive consent, notice, opt out, data access, and risk assessments 

The California Consumer Privacy Act gives California residents rights over their personal information, including the right to know how data is collected and used, request access or deletion, and opt out of the sale of their data. OneTrust helps organizations operationalize each of those obligations through automated workflows for rights requests, opt-out enforcement, and consumer-facing privacy experiences.

CalPrivacy is California’s dedicated privacy regulator, formerly known as the California Privacy Protection Agency (CPPA). It implements and enforces the CCPA, adopts privacy regulations, and investigates and audits businesses for compliance.

The California Consumer Privacy Act (CCPA) went into effect in 2020 and was amended by  the California Privacy Rights Act (CPRA) in 2023, the now-codified expansion of requirements with 2025 update amended the CCPA effective January 1,. It expanded consumer rights, added protections for sensitive personal information, extended privacy rights to employees, broadened opt-out requirements from sale to include sharing, and established the California Privacy Protection Agency to enforce the law. OneTrust supports the full scope of both laws in a single platform, so organizations do not need separate tools to manage CCPA and CPRA obligations.

For-profit organizations that do business in California and meet at least one threshold: annual gross revenues over $25 million; buying, selling, or receiving the personal information of 100,000 or more consumers or households per year; or deriving 50% or more of annual revenue from selling personal information. OneTrust helps organizations assess their obligations and build the operational workflows needed to meet them.

Qualifying businesses must complete an annual, independent cybersecurity audit focused on the controls and evidence used to protect consumers’ personal information, with certification deadlines phased through 2030.

California privacy law defines sensitive personal information to include Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, health information, and the contents of private communications. California residents have additional rights over how organizations use and disclose this data. OneTrust helps organizations identify and classify sensitive personal information across data sources and apply appropriate handling controls so those additional obligations can be met consistently.

OneTrust provides a connected platform for managing California privacy operations, including automated workflows for consumer and employee rights requests, Do-Not-Sell and Do-Not-Share enforcement across web and mobile, sensitive personal information classification, data mapping, privacy audits and risk assessments, breach notification, and regulatory monitoring. Organizations can manage each of those obligations in one place rather than coordinating across disconnected tools.

Operationalize CCPA & CPRA Compliance with OneTrust

OneTrust is the AI-Ready Governance Platform™ that helps organizations manage California privacy obligations across consumer and employee rights, opt-out enforcement, sensitive data classification, and privacy audits.