For organisations serving California residents

CCPA and CPRA — the signals a California resident can check themselves.

The law follows the residents whose data you handle, not where you are based. A UK organisation with California customers or donors can be in scope, and some of what it expects is visible on any public website.

The CCPA, as amended by the CPRA, gives California residents rights over how businesses handle their personal information. Some of what it expects is visible on any website that serves them — including sites based elsewhere. This page explains which signals an outside party can check and what usually needs fixing.

Who it applies to

The law reaches businesses that serve California residents and meet one of its thresholds, which are based on revenue, the volume of personal information handled, or how much revenue comes from sharing it. Being based outside the United States does not put you outside its reach — what matters is whose data you handle. A UK organisation with California customers or donors can be in scope.

  • Location of your customers matters more than your own
  • Thresholds are about revenue and data volume, not headcount
  • Selling and sharing are defined broadly, and include some advertising arrangements

What this check looks at

Everything below is read from the public website, and each maps to an expectation a California resident could reasonably test for themselves.

  • HTTPS enforcement — personal information submitted over plain HTTP is unprotected in transit
  • Privacy policy present and reachable — the law expects specific disclosures to be findable
  • A 'Do Not Sell or Share My Personal Information' route — required where a business sells or shares personal information
  • Cookie consent mechanism — the practical route through which most sharing is authorised or refused
  • Global Privacy Control support — a browser-level opt-out signal that businesses are increasingly expected to honour

Where sites usually fall short

The opt-out route is the most common gap: a privacy policy describes the right in text, but there is no actual link or control a visitor can use. Global Privacy Control is the second — it is a signal sent silently by the browser, so nothing on the page reveals whether it is being honoured unless you check.

  • Describing a right in a policy is not the same as providing a way to exercise it
  • An opt-out that is harder to use than opting in draws attention
  • Global Privacy Control is invisible to a casual review and easy to overlook

Common questions

We are a UK organisation. Can CCPA apply to us?

It can. The law follows the residents whose data is handled, not the location of the business. If you serve California residents and meet one of the thresholds, it can apply regardless of where you are based.

Is a privacy policy enough?

Not on its own. Where a business sells or shares personal information, the law expects a usable route to opt out, not only a description of the right. A visible, working control is the part that gets checked.

What is Global Privacy Control?

A signal a browser or extension sends on the visitor's behalf indicating they do not want their information sold or shared. Because it is sent silently, a site can appear compliant while ignoring it entirely, which is why it is worth checking directly.

Advisory only. This is an external check of publicly visible signals and is not a legal assessment of CCPA or CPRA compliance. Thresholds, definitions and obligations are matters for your own legal advice.

Start free — 5 domains, no card