CCPA Business Obligations
Beyond honoring consumer rights, CCPA imposes affirmative obligations on businesses: what you must tell people, what your vendor contracts must say, how much data you may collect and keep, and how you must secure it. These obligations are where regulators look first — an enforcement sweep does not begin with your request queue; it begins with your homepage footer, your privacy policy, your tags, and your contracts. The CPRA amendments also shifted CCPA from a pure transparency law toward substantive limits: purpose limitation, data minimization, and retention discipline are now legal duties, not best practices.
This lesson covers the obligations in the order a regulator would encounter them.
Notice Obligations
Privacy Policy
Your privacy policy must be updated at least every 12 months and must disclose, among other things:
- The categories of PI collected in the preceding 12 months, mapped to the statutory categories
- The purposes for collection, use, and (if applicable) sale or sharing
- The categories of sources and of third parties to whom PI is disclosed, sold, or shared
- Whether you sell or share PI — and if you knowingly sell/share PI of consumers under 16
- Whether you collect or use sensitive personal information and for what purposes
- Retention periods for each category of PI, or the criteria used to determine them (a CPRA addition many policies still miss)
- A description of all consumer rights and how to exercise them, including your verification process and authorized-agent procedures
- A statement that consumers who exercise rights will not be discriminated against
- The date the policy was last updated
Notice at Collection
Separately from the policy, consumers must receive a notice at or before the point of collection: the categories of PI collected (including SPI), the purposes, whether each category is sold or shared, retention periods or criteria, and a link to the full privacy policy. Online, this is typically a footer link or banner near collection points; offline collection (stores, phone lines, job applications) needs its own notice route. Employees and applicants must receive their own tailored notice at collection — a common gap since the HR exemption expired.
Required Links
Businesses that sell or share PI must post a "Do Not Sell or Share My Personal Information" link; businesses using SPI beyond permitted purposes must post "Limit the Use of My Sensitive Personal Information." These may be combined into a single "Your Privacy Choices" link with the standard opt-out icon. Links must be conspicuous — footer placement on every page is the norm — and functional. Dead or buried links are among the most-cited findings in enforcement sweeps.
Contract Obligations: Service Providers, Contractors, Third Parties
CCPA recognizes three recipient categories, and your contracts determine which one a vendor falls into — with very different consequences:
| Category | Relationship | Contract Must Include | Is Disclosure a Sale/Share? |
|---|---|---|---|
| Service provider | Processes PI on your behalf for business purposes | Specified purposes; no selling/sharing; no use or retention beyond the contract; no combining PI across customers (limited exceptions); compliance certification; cooperation on consumer requests; audit/remediation rights | No |
| Contractor | Receives PI for business purposes (CPRA-added, similar to service provider) | Same core restrictions plus certification of understanding | No |
| Third party | Everyone else — ad partners, data buyers | CPRA still requires terms: specified limited purposes, CCPA compliance obligations, oversight rights | Yes — triggers opt-out machinery |
The practical stakes: a disclosure to a properly papered service provider is not a sale or share; the identical disclosure under a defective contract can be. When the mandatory terms are missing, businesses have faced enforcement on exactly this theory — your data flows get reclassified as sales you never offered an opt-out for. Audit your vendor contracts against the required clauses, prioritize ad-tech and analytics vendors (many operate as third parties no matter what their marketing says), and re-paper anything signed before the CPRA regulations took effect.
Purpose Limitation, Minimization, and Retention
CPRA imported GDPR-style substantive limits:
- Purpose limitation: collection, use, retention, and sharing must be reasonably necessary and proportionate to the purposes disclosed to the consumer, or compatible with the context of collection. New, incompatible uses require fresh notice.
- Data minimization: do not collect more categories of PI, or hold them longer, than the disclosed purpose requires. The CPPA has signaled minimization as an enforcement priority, examining whether businesses actually need the data their forms and SDKs hoover up.
- Retention: you may not retain PI (including SPI) longer than reasonably necessary for the disclosed purpose — and you must disclose retention periods or criteria at collection. This effectively mandates a retention schedule with real deletion behind it.
Reasonable Security
CCPA's breach-related private right of action ($100–$750 statutory damages per consumer per incident) attaches when unencrypted, unredacted PI is exfiltrated due to failure to maintain reasonable security procedures and practices. California guidance has long pointed to the CIS Critical Security Controls as the benchmark for "reasonable." CPRA additionally imposes a general duty on businesses to implement reasonable security for PI, and forthcoming CPPA regulations add annual cybersecurity audits and risk assessments for higher-risk processing (detailed in the CPRA amendments lesson). For most companies, an ISO 27001 or SOC 2-grade control set — MFA, encryption, access reviews, logging, incident response — is the sensible floor.
Non-Discrimination and Financial Incentives
You cannot deny goods or services, charge different prices or rates, or provide a different level or quality of service because a consumer exercised a CCPA right — nor suggest you will. Loyalty and rewards programs that exchange value for data remain lawful as financial incentive programs if you disclose the material terms (including a good-faith estimate of the data's value and how it was calculated), obtain opt-in consent, and allow withdrawal at any time. CPRA also extended non-retaliation to employees and applicants exercising their rights.
Record-Keeping and Training
Maintain records of consumer requests and your responses for at least 24 months — request type, date, nature of response, and timing. Businesses that buy, sell, or share PI of 10 million or more consumers annually must additionally compile and disclose annual request metrics (received, complied with, denied, median/mean response times) in their privacy policy or website. All individuals handling consumer inquiries about privacy practices must be trained on CCPA requirements and how to direct consumers to exercise their rights — an explicit statutory obligation, so keep completion records.
Common Pitfalls in Practice
The obligations above fail in predictable ways:
- Policy-practice drift. The privacy policy describes last year's data practices; the tag audit shows this year's. Because the policy is a public representation, drift is simultaneously a CCPA violation and potential unfair-practices exposure. Tie the annual policy update to a fresh data-map review, not a copyedit.
- The missing HR notice. Employee and applicant notices at collection never got built because the program predates the exemption's expiry. Job application forms and HR onboarding are collection points like any other.
- The legacy DPA. Vendor contracts signed years ago lack the CPRA-mandated clauses, silently converting service providers into third parties — and disclosures into sales. Re-papering is tedious but mechanical; prioritize by data sensitivity and volume.
- Retention theater. A retention schedule exists as a document, but no system enforces it, and the "specific pieces" produced in access requests reveal decade-old records. Disclosure of retention periods creates an audit trail against yourself; make deletion real.
- The buried link. "Do Not Sell or Share" exists but only on the privacy policy page, or behind a cookie banner that disappears. The regulation expects homepage-footer conspicuousness.
- Incentive programs without paperwork. A loyalty program exchanges discounts for data with no disclosed terms, no value estimate, and no opt-in — a compliant program made non-compliant purely by missing documentation.
Business Obligations Checklist
- Privacy policy updated within the last 12 months with all required content, including retention disclosures
- Notice at collection presented at every collection point — web, mobile, offline, and HR/applicant flows
- "Do Not Sell or Share" / "Limit SPI" / "Your Privacy Choices" links posted, working, and tested (or documented rationale for omission)
- Every vendor classified as service provider, contractor, or third party — with the mandatory contract terms for each
- Ad-tech and analytics vendors specifically reviewed; opt-out signals propagate to them
- Data inventory supports purpose-limitation analysis: each PI category tied to a disclosed purpose
- Retention schedule defined per category, with deletion actually implemented
- Reasonable security controls benchmarked (CIS Controls / SOC 2 / ISO 27001) and breach response tested
- Financial incentive programs documented with disclosed terms and opt-in consent
- Request records retained 24 months; metrics reporting handled if at 10M+ scale
- Privacy training delivered and logged for consumer-facing and privacy-handling staff
Frequently Asked Questions
Our privacy policy is GDPR-compliant — does that cover CCPA?
Not fully. CCPA demands California-specific content: PI categories in statutory terms, sale/share disclosures, SPI usage, retention periods, the rights descriptions and metrics, and the required links. Most companies solve this with a California-specific section or addendum in a global policy. A pure GDPR policy typically misses a third of the CCPA-mandated disclosures.
What exactly makes a vendor a "service provider" instead of a "third party"?
The contract and the conduct. The agreement must limit processing to specified business purposes, prohibit selling/sharing and out-of-contract use, restrict combining PI across clients, and include certification and oversight terms — and the vendor must actually behave that way. A vendor that uses your data to improve its own ad products or enrich other clients' profiles is a third party regardless of what the contract says. Ad networks generally cannot qualify for behavioral advertising purposes, which is precisely why the "sharing" definition exists.
Do we need a Data Protection Agreement with every vendor?
Every vendor that receives PI, yes — the statutory terms are what keep the disclosure from being a sale or share. Most reputable SaaS vendors now offer a combined GDPR/CCPA DPA. Your job is verifying the CCPA clauses are actually present (many older DPAs predate the CPRA requirements) and keeping an inventory of who has signed what.
How do the rules apply to our employees' data?
Fully, since January 1, 2023. That means an HR-specific notice at collection, employee rights handling (know, delete, correct — with legal-obligation exceptions doing real work), retention schedules for personnel data, and non-retaliation protections. HR data is where many otherwise-compliant companies are most exposed.
What does "reasonable security" require, concretely?
There is no single certified standard, but California's long-standing position treats the CIS Critical Security Controls as the floor for reasonableness. Practically: encrypt PI at rest and in transit, enforce MFA, restrict and review access, patch, log and monitor, vet vendors, and maintain a tested incident response plan. Encryption matters doubly, because the private right of action only reaches unencrypted or unredacted data — encryption is both a control and a litigation shield.
We updated our policy last year — is annual review really enforced?
The 12-month update requirement is explicit, and stale policies are the easiest possible finding for a regulator or plaintiff's counsel because the "last updated" date is public. Calendar it, and treat the annual refresh as a forcing function to re-verify that your disclosed practices still match reality — drift between policy and practice is the actual risk.
In the next lesson, we will cover the CPRA amendments in detail — sensitive PI, the CPPA, and the audit and risk-assessment regime taking shape.
Keeping notices, contracts, and security controls in sync across dozens of vendors is a tooling problem as much as a legal one. AuditXYZ helps you compare compliance automation platforms and find auditors to operationalize it.