Tell us about your organisation, websites and third-party technologies. Our team will help you choose the right Okito configuration for your CCPA website controls.
CCPA Compliance Software for Websites
CCPA compliance requires covered businesses to explain how they collect, use, disclose, sell or share California consumers’ personal information and to provide practical ways to exercise applicable privacy rights. Okito supports the website layer by identifying cookies and trackers, presenting clear notices and opt-out controls, honoring valid preference signals and maintaining records of consumer choices.
Key Website Controls for CCPA Compliance
Clear Notice at Collection
Explain what categories of personal information your website collects, why they are collected and whether they are sold or shared. Make this information available at or before collection and connect it to your privacy policy.
Sale and Sharing Opt-Outs
Provide California consumers with a clear way to opt out where personal information is sold or shared. Apply their choices to the relevant advertising, analytics and third-party technologies.
Preference Signals and Accountability
Recognize valid browser-based opt-out signals, record consumer choices and review your configuration as your website, vendors and data practices change.
Four Steps to Stronger CCPA Compliance
Identify personal information, cookies, trackers and third-party technologies on your website.
Explain what you collect, why it is used and whether it is sold or shared.
Provide applicable opt-out controls and honor valid preference signals.
Record consumer choices and review your setup as data practices change.
Core Website Requirements for CCPA Compliance
Notice at Collection and Privacy Transparency
Covered businesses must provide clear information at or before collecting personal information. Consumers should be able to understand what is collected, why it is used and how they can exercise their rights.
Identify the categories of personal information collected
Explain the purposes for collecting or using each category
State whether personal information is sold or shared
Provide access to the privacy policy and consumer rights information
Update notices when collection practices or purposes change
Sale and Sharing Opt-Out Controls
Businesses that sell or share personal information must provide an accessible way for consumers to opt out. The process should be clear, easy to use and reflected in the business’s data practices.
Provide a “Do Not Sell or Share My Personal Information” mechanism where required
Recognize and honor valid signals such as Global Privacy Control
Process opt-out requests as soon as feasibly possible and within the applicable deadline
Avoid requiring an account or full identity verification for an opt-out
Obtain the required opt-in before selling or sharing the personal information of consumers known to be under 16
Okito helps apply opt-out choices and supported preference signals to advertising tags, pixels and third-party technologies configured within the platform.
Consumer Privacy Rights
California consumers have specific rights concerning their personal information under the CCPA, as amended by the CPRA. Businesses must provide suitable request methods and follow the applicable verification, response and non-discrimination requirements.
Support applicable requests to know, access, delete and correct personal information
Allow consumers to opt out of sale or sharing
Apply appropriate verification to requests that require it
Confirm and respond to requests within the applicable CCPA timelines
Maintain records of requests and responses for the required period
Avoid discriminatory treatment when consumers exercise their rights
Some of these rights were introduced or expanded by the CPRA and can be addressed in greater detail on the CPRA compliance page. Official guidance is available from the California Attorney General.
Website Tracking and Preference Management
Cookies, pixels and similar technologies may collect personal information or enable its sale or sharing. Businesses should understand how these technologies operate and ensure that applicable consumer choices affect their technical behavior.
Scan digital properties for cookies, pixels and third-party scripts
Classify technologies according to their purposes and data practices
Identify advertising or tracking activities that may involve sale or sharing
Apply opt-out requests and supported preference signals to relevant technologies
Maintain records showing how website privacy choices were received and applied
Review configurations when vendors or tracking technologies change
Okito supports this digital layer through website scanning, configurable privacy controls, Global Privacy Control recognition, preference enforcement and structured records of consumer choices.
Simplify CCPA Privacy Management with Okito
Frequently Asked Questions
CCPA compliance means meeting the transparency, consumer rights, opt-out, data governance and security requirements that apply to a covered business.
Businesses must explain their data practices, provide required notices, respond to consumer requests, honor sale and sharing opt-outs and protect personal information. Compliance is an ongoing process that should be reviewed as data practices, vendors and technologies change.
The CCPA generally applies to a for-profit business that does business in California, determines how and why personal information is processed and meets at least one threshold:
Gross annual revenue above $26.625 million
Buys, sells or shares personal information of 100,000 or more California consumers or households
Receives at least 50% of annual revenue from selling or sharing California consumers’ personal information
No. The CCPA protects California consumers, but covered businesses can be located elsewhere. A business in another US state, the UK or another country may fall within scope if it does business in California, determines how and why personal information is processed and meets an applicable threshold. It does not automatically apply to every business serving US customers.
Website requirements depend on the business’s activities, but commonly include:
Providing a Notice at Collection
Maintaining an accurate privacy policy
Explaining the personal information collected and its purposes
Offering a sale and sharing opt-out where required
Honoring Global Privacy Control signals
Providing suitable consumer request methods
Reviewing cookies, pixels and third-party tracking technologies
These controls must reflect the website’s actual data practices.
Start by confirming whether the CCPA applies to your business. Map the personal information you collect, where it goes and how it is used. Update your notices, establish processes for consumer requests, implement required opt-outs and review contracts with service providers and third parties.
For websites, assess cookies and tracking technologies and ensure applicable consumer choices are reflected in their technical behavior.
Personal information is information that can identify, describe, relate to or reasonably be linked with a consumer or household. Examples include names, contact details, IP addresses, online identifiers, browsing activity, purchase history, geolocation and consumer profiles. Properly deidentified or aggregated information and certain publicly available information may fall outside the definition.
They can be. Cookies, pixels and similar technologies may qualify as personal information when they identify or can reasonably be linked to a consumer, household or device. The answer depends on what the technology collects, how it is used and whether the information is disclosed to other parties. Okito’s Cookie Checker can help identify cookies and trackers requiring further review.
Not generally. Unlike the GDPR model, the CCPA does not require prior consent for every non-essential cookie. Its website requirements usually focus on transparency and the ability to opt out when personal information is sold or shared. Prior authorization can still be required in specific situations, including the sale or sharing of personal information belonging to consumers known to be under 16.
Yes, when a covered business sells or shares personal information. Consumers must be given an accessible way to stop those activities, and valid browser-based preference signals must be honored. This is not a general opt-out from every type of data processing; it applies specifically to activities covered by the relevant CCPA rights.
Global Privacy Control, or GPC, is a browser or device-based signal indicating that a consumer wants to opt out of the sale or sharing of personal information. Covered businesses must treat a valid GPC signal as an opt-out request. It should be applied without requiring the consumer to create an account or repeat the same choice through unnecessary steps. See the official GPC guidance.
A sale is not limited to receiving money for personal information. It may also involve making personal information available to a third party in exchange for another form of valuable consideration. However, not every disclosure is a sale. Exceptions may apply to consumer-directed transfers, qualifying service provider arrangements and certain business transactions.
Depending on the circumstances and applicable exceptions, California consumers may have rights to:
Know and access personal information
Delete personal information
Correct inaccurate information
Opt out of its sale or sharing
Limit certain uses of sensitive personal information
Receive equal treatment when exercising their rights
Businesses must provide suitable request methods and follow the applicable verification and response requirements.
No. A banner is only the visible interface. The website must also provide accurate disclosures, honor applicable opt-outs and GPC signals, control relevant advertising and tracking technologies and maintain records of consumer choices. A cookie consent management platform can coordinate these website controls, but it does not replace the business’s wider legal, security and governance responsibilities.
The CPRA did not replace the CCPA with a separate law. It amended and expanded the CCPA by strengthening rights concerning correction, sensitive personal information, data sharing and enforcement. References to the current CCPA generally mean the CCPA as amended by the CPRA. The expanded requirements can be covered in more detail on the CPRA compliance page.
CPPA regulations took effect on 1 January 2026, but some deadlines are phased. The main developments include:
Risk assessment requirements for certain high-risk processing
Phased cybersecurity audit obligations for qualifying businesses
New requirements concerning qualifying automated decision-making technology from 2027
Clarifications affecting insurance companies and existing CCPA rules
The official dates and scope are available on the CPPA regulations page.
A practical CCPA compliance checklist should cover:
CCPA applicability: Confirm whether the business meets the law’s scope and thresholds
Personal information inventory: Map what information is collected, why it is used and who receives it
Privacy notices: Maintain an accurate privacy policy and provide a Notice at Collection
Consumer privacy rights: Establish processes for access, deletion, correction and other applicable requests
Sale and sharing opt-outs: Provide a clear “Do Not Sell or Share” mechanism where required
Global Privacy Control: Recognize and apply valid GPC and other supported preference signals
Service provider contracts: Review contractual terms with service providers, contractors and third parties
Data security and records: Apply reasonable safeguards and document compliance activity
Ongoing CCPA review: Reassess notices, vendors and technologies when data practices change
Türkçe
English