Loading
Home / CCPA Compliance Software for Websites

CCPA Compliance Software for Websites

CCPA compliance requires covered businesses to explain how they collect, use, disclose, sell or share California consumers’ personal information and to provide practical ways to exercise applicable privacy rights. Okito supports the website layer by identifying cookies and trackers, presenting clear notices and opt-out controls, honoring valid preference signals and maintaining records of consumer choices.

Get Started
Powering we provide the latest solutions for website privacy compliance
garcia.png
suaryapi.png
blackstate.png
gulbenergen.png
reportage.png
tecnhifue.png
sulax.png (1)
barbertrade.png
naksanyapi.png
byonhotels.png
atlastek.png
nexonya.png
uiduk.png
endemik.png
sms.png
yediiklim.png
envatarim.png
scotty.png
baru.png
pehlivan.png
mintek.png
ader.png

Key Website Controls for CCPA Compliance

Clear Notice at Collection

Explain what categories of personal information your website collects, why they are collected and whether they are sold or shared. Make this information available at or before collection and connect it to your privacy policy.

Clear Notice at Collection

Sale and Sharing Opt-Outs

Provide California consumers with a clear way to opt out where personal information is sold or shared. Apply their choices to the relevant advertising, analytics and third-party technologies.

Sale and Sharing Opt-Outs

Preference Signals and Accountability

Recognize valid browser-based opt-out signals, record consumer choices and review your configuration as your website, vendors and data practices change.

Preference Signals and Accountability

Four Steps to Stronger CCPA Compliance

01

Identify personal information, cookies, trackers and third-party technologies on your website.

02

Explain what you collect, why it is used and whether it is sold or shared.

03

Provide applicable opt-out controls and honor valid preference signals.

04

Record consumer choices and review your setup as data practices change.

Four Steps to Stronger CCPA Compliance
margin: 0 !important; padding: 0 !important; } .design-project-content > ul + p br { display: none !important; } .design-project-content > ul + p span:not(:last-child)::after { content: " "; }

Core Website Requirements for CCPA Compliance

Notice at Collection and Privacy Transparency

Covered businesses must provide clear information at or before collecting personal information. Consumers should be able to understand what is collected, why it is used and how they can exercise their rights.

  • Identify the categories of personal information collected

  • Explain the purposes for collecting or using each category

  • State whether personal information is sold or shared

  • Provide access to the privacy policy and consumer rights information

  • Update notices when collection practices or purposes change

Notice at Collection and Privacy Transparency

Sale and Sharing Opt-Out Controls

Businesses that sell or share personal information must provide an accessible way for consumers to opt out. The process should be clear, easy to use and reflected in the business’s data practices.

  • Provide a “Do Not Sell or Share My Personal Information” mechanism where required

  • Recognize and honor valid signals such as Global Privacy Control

  • Process opt-out requests as soon as feasibly possible and within the applicable deadline

  • Avoid requiring an account or full identity verification for an opt-out

  • Obtain the required opt-in before selling or sharing the personal information of consumers known to be under 16

Okito helps apply opt-out choices and supported preference signals to advertising tags, pixels and third-party technologies configured within the platform.

Consumer Privacy Rights

California consumers have specific rights concerning their personal information under the CCPA, as amended by the CPRA. Businesses must provide suitable request methods and follow the applicable verification, response and non-discrimination requirements.

  • Support applicable requests to know, access, delete and correct personal information

  • Allow consumers to opt out of sale or sharing

  • Apply appropriate verification to requests that require it

  • Confirm and respond to requests within the applicable CCPA timelines

  • Maintain records of requests and responses for the required period

  • Avoid discriminatory treatment when consumers exercise their rights

Some of these rights were introduced or expanded by the CPRA and can be addressed in greater detail on the CPRA compliance page. Official guidance is available from the California Attorney General.

Website Tracking and Preference Management

Cookies, pixels and similar technologies may collect personal information or enable its sale or sharing. Businesses should understand how these technologies operate and ensure that applicable consumer choices affect their technical behavior.

  • Scan digital properties for cookies, pixels and third-party scripts

  • Classify technologies according to their purposes and data practices

  • Identify advertising or tracking activities that may involve sale or sharing

  • Apply opt-out requests and supported preference signals to relevant technologies

  • Maintain records showing how website privacy choices were received and applied

  • Review configurations when vendors or tracking technologies change

Okito supports this digital layer through website scanning, configurable privacy controls, Global Privacy Control recognition, preference enforcement and structured records of consumer choices.

Simplify CCPA Privacy Management with Okito

1

Share Your Requirements

Tell us about your organisation, websites and third-party technologies. Our team will help you choose the right Okito configuration for your CCPA website controls.

2

Configure CCPA Controls

Set up applicable notices, “Do Not Sell or Share” choices, California-specific display rules and supported opt-out preference signal handling.

3

Deploy, Test and Maintain

Install Okito through Google Tag Manager, direct script or a supported integration. Test opt-out links, preference signals and tracking behaviour, then review the setup as your website changes.

Please use an email address that is not associated with an existing Okito account.

FAQ

Frequently Asked Questions

CCPA compliance means meeting the transparency, consumer rights, opt-out, data governance and security requirements that apply to a covered business.

Businesses must explain their data practices, provide required notices, respond to consumer requests, honor sale and sharing opt-outs and protect personal information. Compliance is an ongoing process that should be reviewed as data practices, vendors and technologies change.

The CCPA generally applies to a for-profit business that does business in California, determines how and why personal information is processed and meets at least one threshold:

  • Gross annual revenue above $26.625 million

  • Buys, sells or shares personal information of 100,000 or more California consumers or households

  • Receives at least 50% of annual revenue from selling or sharing California consumers’ personal information

No. The CCPA protects California consumers, but covered businesses can be located elsewhere. A business in another US state, the UK or another country may fall within scope if it does business in California, determines how and why personal information is processed and meets an applicable threshold. It does not automatically apply to every business serving US customers.

Website requirements depend on the business’s activities, but commonly include:

  • Providing a Notice at Collection

  • Maintaining an accurate privacy policy

  • Explaining the personal information collected and its purposes

  • Offering a sale and sharing opt-out where required

  • Honoring Global Privacy Control signals

  • Providing suitable consumer request methods

  • Reviewing cookies, pixels and third-party tracking technologies

These controls must reflect the website’s actual data practices.

Start by confirming whether the CCPA applies to your business. Map the personal information you collect, where it goes and how it is used. Update your notices, establish processes for consumer requests, implement required opt-outs and review contracts with service providers and third parties.

For websites, assess cookies and tracking technologies and ensure applicable consumer choices are reflected in their technical behavior.

Personal information is information that can identify, describe, relate to or reasonably be linked with a consumer or household. Examples include names, contact details, IP addresses, online identifiers, browsing activity, purchase history, geolocation and consumer profiles. Properly deidentified or aggregated information and certain publicly available information may fall outside the definition.

They can be. Cookies, pixels and similar technologies may qualify as personal information when they identify or can reasonably be linked to a consumer, household or device. The answer depends on what the technology collects, how it is used and whether the information is disclosed to other parties. Okito’s Cookie Checker can help identify cookies and trackers requiring further review.

Not generally. Unlike the GDPR model, the CCPA does not require prior consent for every non-essential cookie. Its website requirements usually focus on transparency and the ability to opt out when personal information is sold or shared. Prior authorization can still be required in specific situations, including the sale or sharing of personal information belonging to consumers known to be under 16.

Yes, when a covered business sells or shares personal information. Consumers must be given an accessible way to stop those activities, and valid browser-based preference signals must be honored. This is not a general opt-out from every type of data processing; it applies specifically to activities covered by the relevant CCPA rights.

Global Privacy Control, or GPC, is a browser or device-based signal indicating that a consumer wants to opt out of the sale or sharing of personal information. Covered businesses must treat a valid GPC signal as an opt-out request. It should be applied without requiring the consumer to create an account or repeat the same choice through unnecessary steps. See the official GPC guidance.

A sale is not limited to receiving money for personal information. It may also involve making personal information available to a third party in exchange for another form of valuable consideration. However, not every disclosure is a sale. Exceptions may apply to consumer-directed transfers, qualifying service provider arrangements and certain business transactions.

Depending on the circumstances and applicable exceptions, California consumers may have rights to:

  • Know and access personal information

  • Delete personal information

  • Correct inaccurate information

  • Opt out of its sale or sharing

  • Limit certain uses of sensitive personal information

  • Receive equal treatment when exercising their rights

Businesses must provide suitable request methods and follow the applicable verification and response requirements.

No. A banner is only the visible interface. The website must also provide accurate disclosures, honor applicable opt-outs and GPC signals, control relevant advertising and tracking technologies and maintain records of consumer choices. A cookie consent management platform can coordinate these website controls, but it does not replace the business’s wider legal, security and governance responsibilities.

The CPRA did not replace the CCPA with a separate law. It amended and expanded the CCPA by strengthening rights concerning correction, sensitive personal information, data sharing and enforcement. References to the current CCPA generally mean the CCPA as amended by the CPRA. The expanded requirements can be covered in more detail on the CPRA compliance page.

CPPA regulations took effect on 1 January 2026, but some deadlines are phased. The main developments include:

  • Risk assessment requirements for certain high-risk processing

  • Phased cybersecurity audit obligations for qualifying businesses

  • New requirements concerning qualifying automated decision-making technology from 2027

  • Clarifications affecting insurance companies and existing CCPA rules

The official dates and scope are available on the CPPA regulations page.

A practical CCPA compliance checklist should cover:

  1. CCPA applicability: Confirm whether the business meets the law’s scope and thresholds

  2. Personal information inventory: Map what information is collected, why it is used and who receives it

  3. Privacy notices: Maintain an accurate privacy policy and provide a Notice at Collection

  4. Consumer privacy rights: Establish processes for access, deletion, correction and other applicable requests

  5. Sale and sharing opt-outs: Provide a clear “Do Not Sell or Share” mechanism where required

  6. Global Privacy Control: Recognize and apply valid GPC and other supported preference signals

  7. Service provider contracts: Review contractual terms with service providers, contractors and third parties

  8. Data security and records: Apply reasonable safeguards and document compliance activity

  9. Ongoing CCPA review: Reassess notices, vendors and technologies when data practices change