Infrastructure Engineering
CPRA / CCPA Compliance
CCPA and CPRA compliance means managing how your organization handles the personal information of California residents in line with the California Consumer Privacy Act, as amended by the California Privacy Rights Act: opt-out rights, data minimization, and risk assessments. Trellist audits and manages CCPA/CPRA compliance across your marketing technology and customer data operations for organizations serving California consumers.
What we do
CCPA/CPRA Compliance Audits
Assessing opt-out mechanisms, data minimization practices, and consumer rights workflows across your MarTech stack.
Tools we work with
OneTrust for cookie scanning and personal data inventory
Google Tag Manager for checking which tags still fire after an opt-out
Opt-Out & Preference Infrastructure
Building “Do Not Sell or Share” mechanisms and Global Privacy Control signal handling that actually work across every connected system.
Tools we work with
OneTrust for “Do Not Sell or Share” links and Global Privacy Control handling
Google Tag Manager for consent-aware tag firing
Salesforce Marketing Cloud for preference centers that sync opt-outs
HubSpot for subscription and consent preferences
Data Minimization Review
Identifying where you’re collecting or retaining more personal information than the law, or your own risk tolerance, supports.
Tools we work with
Adobe Experience Platform for data usage labels and policy enforcement
Salesforce for field-level reviews of what the CRM stores and why
Risk Assessment Support
Building the risk assessment documentation now required for businesses that sell or share personal information.
Tools we work with
OneTrust for assessment templates and a record of each review
Ongoing Governance & Monitoring
Continuous compliance management as regulations, enforcement priorities, and your stack evolve.
CCPA/CPRA Compliance Audits
Assessing opt-out mechanisms, data minimization practices, and consumer rights workflows across your MarTech stack.
Tools we work with
OneTrust for cookie scanning and personal data inventory
Google Tag Manager for checking which tags still fire after an opt-out
Opt-Out & Preference Infrastructure
Building “Do Not Sell or Share” mechanisms and Global Privacy Control signal handling that actually work across every connected system.
Tools we work with
OneTrust for “Do Not Sell or Share” links and Global Privacy Control handling
Google Tag Manager for consent-aware tag firing
Salesforce Marketing Cloud for preference centers that sync opt-outs
HubSpot for subscription and consent preferences
Data Minimization Review
Identifying where you’re collecting or retaining more personal information than the law, or your own risk tolerance, supports.
Tools we work with
Adobe Experience Platform for data usage labels and policy enforcement
Salesforce for field-level reviews of what the CRM stores and why
Risk Assessment Support
Building the risk assessment documentation now required for businesses that sell or share personal information.
Tools we work with
OneTrust for assessment templates and a record of each review
Ongoing Governance & Monitoring
Continuous compliance management as regulations, enforcement priorities, and your stack evolve.
Our approach
We start by auditing your opt-out mechanisms, data flows, and consumer rights workflows against current CCPA/CPRA requirements. From there we build or fix the infrastructure (preference centers, opt-out signal handling, data minimization) and document the risk assessments now required, then move into ongoing governance as enforcement and your stack both keep evolving.
Signs you need this
- You’re not fully confident your opt-out and Global Privacy Control handling works consistently across every connected system.
- You haven’t conducted the risk assessment now required for businesses that sell or share personal information.
- Your compliance approach hasn’t been revisited since the CPRA amendments took effect.
- You collect or retain more personal information than you have a clear, current business reason for.
What you’ll gain
- Opt-out and preference infrastructure that actually works consistently, not just on paper.
- Documented risk assessments that meet current requirements.
- Reduced exposure to per-violation penalties that stack quickly across affected consumers.
- Compliance that keeps pace with California’s continuing regulatory expansion, not a static one-time fix.
How it compares
Trellist audits and fixes CCPA/CPRA compliance specifically within your marketing technology, where opt-out mechanisms and data flows actually live. That’s different from a generic privacy policy review, which addresses documentation but not whether your systems actually behave the way the policy claims, and different from a one-time fix, given how quickly California’s enforcement priorities have continued to expand.
Why it matters
CCPA/CPRA penalties reach roughly $2,663 per unintentional violation and $7,988 per intentional violation in 2026, and because violations are counted per affected consumer, penalties escalate quickly in any real customer database. Recent settlements reflect that scale: General Motors paid $12.75 million in 2026, and Disney paid $2.75 million in a case centered specifically on opt-out mechanism failures.
FAQ
Does CCPA/CPRA apply to us if we’re not based in California?
It can. CCPA/CPRA applies based on whether you do business with California residents and meet certain thresholds, not where your company is headquartered.
What’s actually changed with the CPRA amendments?
Among other things, CPRA removed the automatic 30-day cure period, added new risk assessment requirements, and created the California Privacy Protection Agency as a dedicated enforcement body. Voluntary remediation is now a mitigating factor, not a guaranteed defense.
Is this the same work as GDPR compliance?
Related, but not identical. The specific rights, thresholds, and mechanisms differ, and we scope the audit to whichever regulations actually apply to you. See our GDPR compliance work for the EU side.
Why Trellist
We focus on whether your systems actually behave the way your privacy policy claims; that’s where most real CCPA/CPRA exposure actually lives.
Signs you need this
- You’re not fully confident your opt-out and Global Privacy Control handling works consistently across every connected system.
- You haven’t conducted the risk assessment now required for businesses that sell or share personal information.
- Your compliance approach hasn’t been revisited since the CPRA amendments took effect.
- You collect or retain more personal information than you have a clear, current business reason for.
What you’ll gain
- Opt-out and preference infrastructure that actually works consistently, not just on paper.
- Documented risk assessments that meet current requirements.
- Reduced exposure to per-violation penalties that stack quickly across affected consumers.
- Compliance that keeps pace with California’s continuing regulatory expansion, not a static one-time fix.
How it compares
Trellist audits and fixes CCPA/CPRA compliance specifically within your marketing technology, where opt-out mechanisms and data flows actually live. That’s different from a generic privacy policy review, which addresses documentation but not whether your systems actually behave the way the policy claims, and different from a one-time fix, given how quickly California’s enforcement priorities have continued to expand.
Why it matters
CCPA/CPRA penalties reach roughly $2,663 per unintentional violation and $7,988 per intentional violation in 2026, and because violations are counted per affected consumer, penalties escalate quickly in any real customer database. Recent settlements reflect that scale: General Motors paid $12.75 million in 2026, and Disney paid $2.75 million in a case centered specifically on opt-out mechanism failures.
FAQ
Does CCPA/CPRA apply to us if we’re not based in California?
It can. CCPA/CPRA applies based on whether you do business with California residents and meet certain thresholds, not where your company is headquartered.
What’s actually changed with the CPRA amendments?
Among other things, CPRA removed the automatic 30-day cure period, added new risk assessment requirements, and created the California Privacy Protection Agency as a dedicated enforcement body. Voluntary remediation is now a mitigating factor, not a guaranteed defense.
Is this the same work as GDPR compliance?
Related, but not identical. The specific rights, thresholds, and mechanisms differ, and we scope the audit to whichever regulations actually apply to you. See our GDPR compliance work for the EU side.
Why Trellist
We focus on whether your systems actually behave the way your privacy policy claims; that’s where most real CCPA/CPRA exposure actually lives.
Confident your opt-out mechanisms actually work the way you think they do?
Let’s talk
We’re ready to listen
Tell us a little about yourself and our team will reach out to schedule a call.
Looking for a job? Visit our Careers section to see open roles.
Required
