Privacy operations engineered for California compliance
CCPA/CPRA & Data Privacy Compliance
Privacy teams and founders often have the same problem: the California Consumer Privacy Act (CCPA) rules are clear in principle, but hard to translate into repeatable workflows across web, mobile, and offline channels. The most common operational exposure is misclassifying cookies, analytics, and ad-tech as not involving a sale or sharing, then missing required opt-out notice and link mechanics. California requires notice at collection at or before the point of collection, including retention disclosures and links to the relevant rights pathways, under Cal. Civ. Code § 1798.100(a). Law Laguna builds a maintainable privacy compliance system, including data mapping, notices, consumer-request operations, and vendor contracting that matches your actual data flows. The goal is a program leadership can keep current every 12 months without rework.
Prevent accidental “sale” or “sharing” classifications
The CCPA, as amended by the California Privacy Rights Act (CPRA), functions like an operating system: the law sets rights and definitions, and your business must implement controls that work in production. Coverage can turn on revenue and data-volume thresholds, common branding across affiliates, joint venture structure, or even a voluntary election into California Privacy Protection Agency (CPPA) jurisdiction. The primary “business” definition and thresholds sit in Cal. Civ. Code § 1798.140(d)(1), with related coverage rules in Cal. Civ. Code § 1798.140(d)(2) to (4). Even when a team thinks it is outside scope, marketing pixels, analytics, and partner integrations can create a “sharing” profile for cross-context behavioral advertising. The resulting fix is rarely just updating a privacy policy, it is re-papering vendors, rebuilding request workflows, and correcting notices across every intake channel.
Law Laguna approaches CCPA compliance as an implementation project with legal checkpoints. We map personal information (PI) and sensitive personal information (SPI) through collection, use, retention, and disclosure, then tie each flow to a notice, contract role, and consumer-right mechanism. We document decisions so internal teams can update the program as tools and vendors change.
-
Classify cookies and ad-tech as cross-context behavioral advertising, then align opt-out workflows to the actual sharing pathways.
-
Draft and deploy a notice at collection that matches every channel, including offline collection and passive observation.
-
Scope sensitive personal information (SPI) to Permitted SPI Purposes, then implement limitation controls when the use goes beyond those purposes.
This work reduces rework by aligning definitions, disclosures, and technical implementation. It also creates an auditable record of why your program decisions fit the CCPA framework.
Counsel for privacy programs that must run
Law Laguna is based in Laguna Beach and serves privacy and compliance teams across Southern California. We also support California businesses statewide through remote engagement.
General Counsel (or Fractional GC)
You need a clean answer on whether the company is a covered “business,” including affiliates under common branding and joint venture relationships. You also need notices and vendor contracts that match your actual roles, so teams do not create a “sale” or “sharing” problem through cross-context behavioral advertising tools.
-
Support an acquisition diligence request by classifying PI transfers under the merger and acquisition exception and documenting post-close use constraints.
-
Negotiate service provider and contractor terms so commercial teams can deploy tools without creating third party disclosures.
-
Align retention disclosures and purpose limitations so product teams can ship without incompatible-purpose re-noticing.
Chief Privacy Officer / Privacy Program Manager
You are managing notice at collection content, consumer-request workflows, and internal governance, while business units keep adding data sources. You also need consistent “Do Not Sell or Share My Personal Information” handling for cookies and ad-tech so opt-outs work across domains, devices, and household identifiers.
-
Implement a verification and response workflow for access, delete, correct, and portability requests with consistent logs.
-
Standardize intake methods across web forms, phone scripts, and offline collection points without breaking the user journey.
-
Rebuild data maps when a new analytics vendor changes whether disclosures qualify as sharing.
Head of Marketing / Growth (owns cookies, analytics, ad-tech stack)
Your tools can trigger “sharing” even when no money changes hands, and the classification depends on configuration, contracts, and actual use. You also need a choice architecture that is simple, clear, and symmetrical so opt-out flows work without degrading measurement beyond what is required.
-
Audit the pixel and tag manager to identify transfers that qualify as sharing for cross-context behavioral advertising.
-
Coordinate with engineering to deploy the “Your Privacy Choices” link and icon in the header or footer with minimal steps.
-
Paper ad-tech vendors correctly so “service provider” claims match operational purpose limitations.
General Counsel (or Fractional GC)
You need a clean answer on whether the company is a covered “business,” including affiliates under common branding and joint venture relationships. You also need notices and vendor contracts that match your actual roles, so teams do not create a “sale” or “sharing” problem through cross-context behavioral advertising tools.
-
Support an acquisition diligence request by classifying PI transfers under the merger and acquisition exception and documenting post-close use constraints.
-
Negotiate service provider and contractor terms so commercial teams can deploy tools without creating third party disclosures.
-
Align retention disclosures and purpose limitations so product teams can ship without incompatible-purpose re-noticing.
Chief Privacy Officer / Privacy Program Manager
You are managing notice at collection content, consumer-request workflows, and internal governance, while business units keep adding data sources. You also need consistent “Do Not Sell or Share My Personal Information” handling for cookies and ad-tech so opt-outs work across domains, devices, and household identifiers.
-
Implement a verification and response workflow for access, delete, correct, and portability requests with consistent logs.
-
Standardize intake methods across web forms, phone scripts, and offline collection points without breaking the user journey.
-
Rebuild data maps when a new analytics vendor changes whether disclosures qualify as sharing.
Head of Marketing / Growth (owns cookies, analytics, ad-tech stack)
Your tools can trigger “sharing” even when no money changes hands, and the classification depends on configuration, contracts, and actual use. You also need a choice architecture that is simple, clear, and symmetrical so opt-out flows work without degrading measurement beyond what is required.
-
Audit the pixel and tag manager to identify transfers that qualify as sharing for cross-context behavioral advertising.
-
Coordinate with engineering to deploy the “Your Privacy Choices” link and icon in the header or footer with minimal steps.
-
Paper ad-tech vendors correctly so “service provider” claims match operational purpose limitations.
Privacy Compliance System Buildout
These services convert CCPA requirements into concrete operating procedures and documentation. The deliverables are designed to stay usable as your business, vendors, and product flows change.
Coverage and data-flow engineering
-
CCPA/CPRA Applicability & Threshold Analysis (Strategic Assessment). We determine whether your organization is a covered “business,” including affiliate and common-branding analysis, joint venture treatment, and voluntary CPPA jurisdiction options. We document the reasoning against the CCPA definitions so leadership can defend the scope decision under Cal. Civ. Code § 1798.140(d)(1) to (4).
-
Data Inventory & Transfer Classification Map. We build a data map that ties each PI disclosure to “sale,” “sharing,” or “business purpose,” including cookie, analytics, and advertising flows. The output becomes the backbone for notices, request workflows, and vendor contracts by aligning disclosures to Cal. Civ. Code §§ 1798.140(ad), 1798.140(ah), and 1798.140(e).
-
Sensitive Personal Information (SPI) Governance. We identify SPI, define Permitted SPI Purposes, and set limitation controls and disclosures when use goes beyond permitted purposes. We align the program to Cal. Civ. Code §§ 1798.121(a) and (d) and Cal. Code Regs. Title 11, § 7027(m) so teams do not over-collect or over-use SPI.
-
Vendor & Ad-Tech Contracting Support via Data Processing & Security Addenda (DPAs) and commercial terms. We paper “service provider,” “contractor,” and “third party” relationships with the required data use restrictions and operational purpose limitations. We also address ad-tech realities, including that cross-context behavioral advertising services are treated as third party activity under Cal. Code Regs. Title 11, § 7050(b).
Notices and consumer-facing implementation
-
Notices Package Implementation. We draft and deploy the Notice at Collection, Privacy Policy, Opt-Out Right Notice, Right to Limit Notice, and Financial Incentive Notice when applicable, following the six-notice framework in Cal. Code Regs. Title 11, § 7010. We also align placement, accessibility, and channel-specific presentation requirements across web, mobile, and offline collection under Cal. Code Regs. Title 11, §§ 7003(a) to (b) and 7012(c) to (d).
-
Consumer Rights Request Operations. We design intake, verification, response steps, and documentation for access or know, delete, correct, and portability rights. We build a workflow that is operationally realistic for teams while supporting consistent responses and recordkeeping under the CCPA framework in Cal. Civ. Code §§ 1798.100 to 1798.199.100.
-
CCPA/CPRA Applicability & Threshold Analysis (Strategic Assessment). We clarify the coverage decision so your notices and workflows match the correct scope, including consumer meaning a California resident under Cal. Civ. Code § 1798.140(i) and Cal. Code Regs. Title 18, § 17014. That avoids building a program based on incorrect assumptions about who qualifies for rights handling.
-
Notices Package Implementation. We ensure the privacy policy is conspicuously linked, printable as a single document, and updated at least every 12 months, consistent with Cal. Civ. Code § 1798.130(a)(5) and Cal. Code Regs. Title 11, § 7011. We also plan for mobile app settings menu requirements effective January 1, 2026, under Cal. Code Regs. Title 11, § 7011(d).
Rights execution and choice architecture
-
Consumer Rights Request Operations. We build a request program that works across account holders and non-account holders, and across online and offline intake. We also align choice architecture with the CCPA requirement set, including opt-out methods that map to the data flow rather than a single web-only solution.
-
Notices Package Implementation. We implement opt-out and right-to-limit link mechanics, including “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information,” under Cal. Civ. Code § 1798.135 and Cal. Code Regs. Title 11, §§ 7013 and 7014. Where appropriate, we implement the alternative combined “Your Privacy Choices” link and required icon under Cal. Code Regs. Title 11, § 7015.
-
Sensitive Personal Information (SPI) Governance. We define when SPI can be treated as non-sensitive under the SPI inference exception, then document why, based on Cal. Civ. Code § 1798.121(d) and Cal. Code Regs. Title 11, §§ 7014(g) and 7027(m)(8). That reduces unnecessary right-to-limit workflows without expanding SPI use beyond permitted purposes.
-
Data Inventory & Transfer Classification Map. We identify when disclosures are “sharing” for cross-context behavioral advertising even without valuable consideration, under Cal. Civ. Code § 1798.140(ah). This informs whether you must provide opt-out notice and links and how to operationalize those controls.
Governance and contracting controls
-
Vendor & Ad-Tech Contracting Support via Data Processing & Security Addenda (DPAs) and commercial terms. We draft and negotiate the clauses that allow you to classify recipients correctly and restrict downstream use. We align the contract framework to service provider and contractor limitations, including that cross-context behavioral advertising is not a business purpose for service providers or contractors under Cal. Civ. Code § 1798.140(e)(6).
-
Data Inventory & Transfer Classification Map. We tie each use and retention period to a stated purpose and reasonable expectations framework, which supports minimization and proportionality. This reduces incompatible-purpose repurposing under Cal. Code Regs. Title 11, § 7002(b).
-
CCPA/CPRA Applicability & Threshold Analysis (Strategic Assessment). We review exceptions and boundary conditions, including coverage exceptions categories under Cal. Civ. Code §§ 1798.145 and 1798.146. We also confirm anti-avoidance constraints so transactions are not structured fictionally to bypass obligations under Cal. Civ. Code § 1798.190.
-
Notices Package Implementation. We support financial incentive programs, such as loyalty discounts, with the notice required by Cal. Civ. Code § 1798.125(b) and Cal. Code Regs. Title 11, § 7016. We align the value-of-data and good-faith estimate methodology so marketing programs are supportable and consistent with disclosures.
Sale versus sharing, and why cookies change the analysis
Under the CCPA, “sale” can include transferring personal information for monetary or other valuable consideration, by any means, under Cal. Civ. Code § 1798.140(ad)(1). “Sharing” is distinct: it covers disclosing personal information for cross-context behavioral advertising, and it does not require valuable consideration, under Cal. Civ. Code § 1798.140(ah). This matters because common cookie and ad-tech configurations can qualify as sharing even when the vendor contract is labeled as a “service provider” arrangement. If the program misclassifies the disclosure, the business can miss opt-out notices, links, and downstream controls.
California treats cross-context behavioral advertising services as third party activity in the regulations, even where teams assume a processor-style relationship. Cal. Code Regs. Title 11, § 7050(b) states that any person performing cross-context behavioral advertising services is treated as a third party. That makes opt-out of sharing a core operational requirement for many California-facing websites and mobile apps.
-
Map each tag, pixel, SDK, and server-side event to the recipient and purpose, then classify the disclosure as sale, sharing, or business purpose.
-
Confirm whether the transfer fits a statutory exception, including consumer-directed transfer logic under Cal. Civ. Code § 1798.140(ad)(2)(A) and “intentional interaction” limits in Cal. Civ. Code § 1798.140(s).
-
Validate that “service provider” and “contractor” contracts contain enforceable data use restrictions tied to specified business purposes and operational purposes.
-
Implement opt-out notice and link mechanics that allow minimal-step exercise, including “Do Not Sell or Share My Personal Information,” under Cal. Civ. Code §§ 1798.120(b) and 1798.135 and Cal. Code Regs. Title 11, § 7013.
-
Coordinate notice at collection content with cookie banner or equivalent presentation so you do not collect undisclosed categories or repurpose for incompatible purposes under Cal. Code Regs. Title 11, §§ 7002(f) and 7012(d).
-
Document how opt-out signals and requests apply across devices and households using unique identifiers under Cal. Civ. Code § 1798.140(aj) and related household concepts in Cal. Civ. Code § 1798.140(q).
Law Laguna implements these controls in written notices, technical workflows, and vendor contracts so the classification matches the real data flow.
California Regulatory Compliance
The CCPA, located at Cal. Civ. Code §§ 1798.100 to 1798.199.100, and the implementing regulations at Cal. Code Regs. Title 11, §§ 7000 to 7304, require businesses to manage privacy as an operational system. A compliant program starts with data minimization and purpose limitation, meaning collection, use, retention, and sharing must be reasonably necessary and proportionate, and aligned to average consumer expectations or compatible disclosed purposes, under Cal. Civ. Code § 1798.100(c) and Cal. Code Regs. Title 11, § 7002(b). These standards influence what you collect, how long you retain it, and what you can do with it after collection. Notice obligations drive much of the implementation work. Notice at collection must be provided at or before the point of collection and must include categories collected, purposes, retention period or criteria, whether information is sold or shared, and links to the privacy policy and rights pathways, under Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012. If you sell or share, you must provide opt-out notice and the required link titles under Cal. Civ. Code § 1798.135 and Cal. Code Regs. Title 11, § 7013. For sensitive personal information, right-to-limit notice and link mechanics apply under Cal. Civ. Code § 1798.121(a) and Cal. Code Regs. Title 11, § 7014.
Flexible Legal Counsel
Ongoing privacy program counsel
-
Maintain a rolling privacy operations backlog, including quarterly data-flow reviews, notice updates, and vendor contract triage.
-
Standardize internal decision records so updates remain consistent with Cal. Civ. Code § 1798.130(a)(5) annual policy review cycles.
-
Coordinate privacy, marketing, product, and human resources stakeholders so deployment decisions match the published notice at collection.
Fixed-scope implementation project
-
Deliver a defined set of artifacts, including data maps, notices package, request workflows, and contract templates within an agreed timeline.
-
Run stakeholder workshops to inventory systems and confirm how personal information moves across web, mobile, and offline channels.
-
Provide launch support for link placement, interactive forms, and escalation paths for complex consumer requests.
Targeted contracting and ad-tech support
-
Negotiate Data Processing & Security Addenda (DPAs) and advertising terms to align service provider, contractor, and third party roles.
-
Classify cookie and analytics disclosures and document the control plan for opt-out of sharing for cross-context behavioral advertising.
-
Support procurement and renewal cycles with contract language that limits use to specified business purposes and operational purposes.
Each engagement model is designed to produce operational outputs, not only legal memos. Law Laguna keeps the program usable for internal teams and aligned to statutory and regulatory requirements.
California Privacy and Contracts Network
Build a unified compliance and contracting stack
CCPA/CPRA & Data Privacy Compliance FAQs
Do we qualify as a California Consumer Privacy Act (CCPA) covered business in 2026 if revenue is around the $26.625 million threshold?
It depends, the analysis turns on annual gross revenues, the volume of personal information (PI) bought, sold, or shared, and whether the business derives 50 percent or more of annual revenues from selling or sharing PI. Operationally, the scope also includes whether affiliates share common branding and whether a joint venture structure triggers separate “business” treatment. The hidden risk is treating the inquiry as only a revenue question and missing affiliate, joint venture, or common-branding coverage under Cal. Civ. Code § 1798.140(d)(1) to (3). Law Laguna documents the threshold analysis and ties it to data maps, notices, and contracts so your program scope matches Cal. Civ. Code § 1798.140(d)(1) and related coverage rules.
What must a CCPA notice at collection include, and do we need to disclose a retention period?
A notice at collection must identify categories of personal information (PI) and sensitive personal information (SPI) collected, the purposes for collection or use, whether the information is sold or shared, and the retention period or the criteria used to determine it. Operationally, this controls what your teams can collect, what they can do with it, and how long systems may keep it across web, mobile, and offline channels. The hidden risk is publishing a privacy policy but failing to provide notice at or before collection everywhere data is collected, including offline collection and passive observation, under Cal. Code Regs. Title 11, § 7012(c) to (d). Law Laguna builds channel-specific notices and retention disclosures aligned to Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012.
Do we need a “Do Not Sell or Share My Personal Information” link, and where does it have to appear?
It depends, you need the link if your business sells or shares personal information (PI), including through cookie and advertising disclosures that qualify as sharing for cross-context behavioral advertising. Operationally, this controls link placement, the opt-out right notice content, and the interactive form or offline method that allows consumers to exercise the right under Cal. Code Regs. Title 11, § 7013(f). The hidden risk is assuming you do not sell or share because no money changes hands, even though “sharing” under Cal. Civ. Code § 1798.140(ah) does not require valuable consideration. Law Laguna classifies your disclosures and implements the required opt-out notice and link mechanics under Cal. Civ. Code § 1798.135 and Cal. Code Regs. Title 11, § 7013.
Can we use the “Your Privacy Choices” link and icon instead of separate links, and what changes in 2026?
Yes, you can use an alternative combined link titled “Your Privacy Choices” or “Your California Privacy Choices” with the required icon to provide both opt-out of sale or sharing and right-to-limit sensitive personal information (SPI) where applicable. Operationally, this controls header and footer placement, minimal-step exercise, and whether the user lands on a page that contains the right notice and an interactive form. The hidden risk is implementing the combined link but not meeting the specific mechanics in Cal. Code Regs. Title 11, § 7015, including icon rules that receive clarification effective January 1, 2026 under Cal. Code Regs. Title 11, § 7015(b)(3). Law Laguna designs the combined link path so it satisfies Cal. Civ. Code § 1798.185(a)(4)(C) and the implementation details in Cal. Code Regs. Title 11, § 7015.
If we use analytics and marketing pixels, are we “sharing” personal information for cross-context behavioral advertising?
It depends, analytics and marketing pixels can qualify as “sharing” when the disclosure supports cross-context behavioral advertising, including transfers of identifiers, cookie data, device IDs, and browsing activity. Operationally, this controls how you configure tags, whether you must provide opt-out of sharing, and how you route opt-out signals through your advertising and analytics stack. The hidden risk is treating the tools as a pure “business purpose” disclosure even though cross-context behavioral advertising services are treated as third party activity under Cal. Code Regs. Title 11, § 7050(b), which can trigger opt-out notice and link duties under Cal. Civ. Code § 1798.135. Law Laguna maps the transfer, classifies the disclosure under Cal. Civ. Code § 1798.140(ah), and implements the opt-out workflow and notices required by Cal. Code Regs. Title 11, § 7013.
Do we have to provide notice at collection for offline collection and passive observation, such as in-store signups or in-app telemetry?
Yes, notice at collection applies wherever personal information (PI) is collected, including offline collection and situations where the business passively observes consumers, such as analytics events and device identifiers. Operationally, this controls scripts, signage, point-of-sale workflows, app disclosures, and any intake mechanism that triggers collection. The hidden risk is collecting categories not disclosed in the notice at collection or repurposing for incompatible purposes without a new notice, which Cal. Code Regs. Title 11, §§ 7002(f) and 7012(d) restrict. Law Laguna designs channel-specific notices and controls under Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012(c) to (d) so collection matches disclosures.
How should we govern sensitive personal information (SPI), and when can we avoid the “Limit the Use of My Sensitive Personal Information” link?
It depends, sensitive personal information (SPI) includes certain categories of personal information (PI) and triggers a right to limit when you use or disclose SPI beyond Permitted SPI Purposes. Operationally, this controls SPI identification, use scoping, limitation workflows, and whether you must present the “Limit the Use of My Sensitive Personal Information” link under Cal. Civ. Code § 1798.121(a) and Cal. Code Regs. Title 11, § 7014. The hidden risk is assuming you can avoid the link without documenting that you only use SPI for Permitted SPI Purposes, or that SPI is treated as non-sensitive under the SPI inference exception in Cal. Civ. Code § 1798.121(d) and Cal. Code Regs. Title 11, §§ 7014(g) and 7027(m)(8). Law Laguna builds SPI governance and disclosures that align to Cal. Code Regs. Title 11, § 7027(m) and the minimization and proportionality framework in Cal. Civ. Code §§ 1798.100(c) and 1798.121(a).
Stop “sale” or “sharing” exposure at the source
When privacy operations do not match the CCPA definitions, teams end up rebuilding notices, reclassifying vendors, and reworking opt-out and request workflows after launch. Cookie and ad-tech sharing is a recurring trigger because it crosses product, marketing, and vendor boundaries. A structured compliance system reduces operational churn by making the data map, notices, and contracts work together.
We start with a scoping call to identify your collection channels, ad-tech stack, and current notices and contracts. Then we propose a phased implementation plan tied to specific deliverables and owners.