Skip to content

Infrastructure Engineering

CPRA / CCPA Compliance

CCPA and CPRA compliance means managing how your organization handles the personal information of California residents in line with the California Consumer Privacy Act, as amended by the California Privacy Rights Act: opt-out rights, data minimization, and risk assessments. Trellist audits and manages CCPA/CPRA compliance across your marketing technology and customer data operations for organizations serving California consumers.

Let’s Talk

What we do

CCPA/CPRA Compliance Audits

Assessing opt-out mechanisms, data minimization practices, and consumer rights workflows across your MarTech stack.

Tools we work with

  OneTrust for cookie scanning and personal data inventory

  Google Tag Manager for checking which tags still fire after an opt-out

CCPA/CPRA Compliance Audits

Assessing opt-out mechanisms, data minimization practices, and consumer rights workflows across your MarTech stack.

Tools we work with

  OneTrust for cookie scanning and personal data inventory

  Google Tag Manager for checking which tags still fire after an opt-out

Opt-Out & Preference Infrastructure

Building “Do Not Sell or Share” mechanisms and Global Privacy Control signal handling that actually work across every connected system.

Tools we work with

  OneTrust for “Do Not Sell or Share” links and Global Privacy Control handling

  Google Tag Manager for consent-aware tag firing

  Salesforce Marketing Cloud for preference centers that sync opt-outs

  HubSpot for subscription and consent preferences

Data Minimization Review

Identifying where you’re collecting or retaining more personal information than the law, or your own risk tolerance, supports.

Tools we work with

  Adobe Experience Platform for data usage labels and policy enforcement

  Salesforce for field-level reviews of what the CRM stores and why

Risk Assessment Support

Building the risk assessment documentation now required for businesses that sell or share personal information.

Tools we work with

  OneTrust for assessment templates and a record of each review

Ongoing Governance & Monitoring

Continuous compliance management as regulations, enforcement priorities, and your stack evolve.

Our approach

We start by auditing your opt-out mechanisms, data flows, and consumer rights workflows against current CCPA/CPRA requirements. From there we build or fix the infrastructure (preference centers, opt-out signal handling, data minimization) and document the risk assessments now required, then move into ongoing governance as enforcement and your stack both keep evolving.

Signs you need this

  • You’re not fully confident your opt-out and Global Privacy Control handling works consistently across every connected system.
  • You haven’t conducted the risk assessment now required for businesses that sell or share personal information.
  • Your compliance approach hasn’t been revisited since the CPRA amendments took effect.
  • You collect or retain more personal information than you have a clear, current business reason for.
Signs you need this
  • You’re not fully confident your opt-out and Global Privacy Control handling works consistently across every connected system.
  • You haven’t conducted the risk assessment now required for businesses that sell or share personal information.
  • Your compliance approach hasn’t been revisited since the CPRA amendments took effect.
  • You collect or retain more personal information than you have a clear, current business reason for.
What you’ll gain
  • Opt-out and preference infrastructure that actually works consistently, not just on paper.
  • Documented risk assessments that meet current requirements.
  • Reduced exposure to per-violation penalties that stack quickly across affected consumers.
  • Compliance that keeps pace with California’s continuing regulatory expansion, not a static one-time fix.
How it compares

Trellist audits and fixes CCPA/CPRA compliance specifically within your marketing technology, where opt-out mechanisms and data flows actually live. That’s different from a generic privacy policy review, which addresses documentation but not whether your systems actually behave the way the policy claims, and different from a one-time fix, given how quickly California’s enforcement priorities have continued to expand.

Why it matters

CCPA/CPRA penalties reach roughly $2,663 per unintentional violation and $7,988 per intentional violation in 2026, and because violations are counted per affected consumer, penalties escalate quickly in any real customer database. Recent settlements reflect that scale: General Motors paid $12.75 million in 2026, and Disney paid $2.75 million in a case centered specifically on opt-out mechanism failures.

FAQ

Does CCPA/CPRA apply to us if we’re not based in California?
It can. CCPA/CPRA applies based on whether you do business with California residents and meet certain thresholds, not where your company is headquartered.

What’s actually changed with the CPRA amendments?
Among other things, CPRA removed the automatic 30-day cure period, added new risk assessment requirements, and created the California Privacy Protection Agency as a dedicated enforcement body. Voluntary remediation is now a mitigating factor, not a guaranteed defense.

Is this the same work as GDPR compliance?
Related, but not identical. The specific rights, thresholds, and mechanisms differ, and we scope the audit to whichever regulations actually apply to you. See our GDPR compliance work for the EU side.

Why Trellist

We focus on whether your systems actually behave the way your privacy policy claims; that’s where most real CCPA/CPRA exposure actually lives.

Confident your opt-out mechanisms actually work the way you think they do?

Let’s Talk

Let’s talk

We’re ready to listen

Tell us a little about yourself and our team will reach out to schedule a call.

Looking for a job? Visit our Careers section to see open roles.

Required