CCPA/CPRA compliance for a SaaS
California Consumer Privacy Act, as amended by the CPRA. This page applies it to one kind of product (SaaS), so you get the obligations that are actually yours instead of a summary of the whole statute.
Does it apply to you?
For-profit businesses with over $25M revenue, or handling personal data of 100,000+ California consumers, or deriving 50%+ of revenue from selling data.
What a SaaS typically processes
- account creation and authentication
- subscription billing through a payment processor
- product analytics and session tracking
- transactional and marketing email
Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.
Documents you need
The intersection of what CCPA/CPRA requires and what a SaaS actually does:
- Privacy policy
- Cookie policy and consent banner
Rights you must honour
CCPA/CPRA gives people in California the right to:
- Access a copy of their data
- Correct inaccurate data
- Have their data deleted
- Receive their data in a portable format
- Opt out of the sale or sharing of their data
- Opt out of profiling and targeted advertising
- Not be discriminated against for exercising a right
Cookies and trackers
Trackers may load by default, but the visitor needs a working way to opt out, and you must honour it.
CCPA/CPRA also requires you to honour a universal opt-out signal, so a browser sending Global Privacy Control must be treated as having opted out — without the visitor clicking anything.
See what your site is actually missing
Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.
No signup · result in seconds
Primary sources
- CCPA/CPRA — California Consumer Privacy Act, as amended by the CPRA · official text · California Privacy Protection Agency (CPPA)
- §1798.100 — Right to know what is collected
- §1798.120 — Right to opt out of sale or sharing
- §1798.135 — Do Not Sell or Share link and opt-out signals
CCPA/CPRA for other kinds of product
Other frameworks for a SaaS
This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.