California · CCPA as amended by the CPRA

Run California consumer privacy rights on one clock

For organizations subject to the CCPA — AccessPoint manages requests to know, delete, correct, and port, opt-outs of sale and sharing, the risk assessments the CPPA regime contemplates, and § 1798.82 breach duties, inside your own Microsoft 365 tenant.

California — CCPA/CPRA at a glance

Rights deadline
45 days, extendable once by a further 45 days on notice
Acknowledgment
Within 10 business days of receiving a request
Rights covered
Know, delete, correct, port, opt out of sale/sharing, limit sensitive personal information
Breach notice
§ 1798.82 — the most expedient time possible and without unreasonable delay
Oversight
California Privacy Protection Agency and the Attorney General
Languages
English

Built for California — CCPA/CPRA

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Every right on one clock

Know, delete, correct, and port all run on the 45-day clock with the single 45-day extension, with the 10-business-day acknowledgment tracked separately so it is never the step that slips.

Verification, proportionate to the request

California asks for verification scaled to the sensitivity of what is being requested. Record the method used and the evidence relied on, so a deletion of sensitive data and a routine right-to-know are not verified the same way by accident.

Opt-outs of sale and sharing

Track opt-out requests, including those arriving through an opt-out preference signal, and record when and how the request was honoured downstream.

Risk assessments

Run the risk assessments the California regime contemplates for higher-risk processing as full assessment cases — questionnaire, risks with owners, mitigations, and a dated sign-off.

Breach notification

Log an incident, assess it, and work the § 1798.82 notification to affected residents on a live checklist with the reasoning recorded.

In your own tenant

Consumer personal information stays inside your own Microsoft 365 and Azure tenant — no third-party privacy cloud holding the very data the requests are about.

A regulator that audits

California gave itself an agency. That changes what a compliance record has to survive.

For most of the United States, privacy enforcement means an attorney general acting on a complaint. California built a standing regulator with rulemaking and audit authority, and the practical consequence is that a California program can be examined rather than merely challenged. An examination does not ask whether you believe you complied; it asks to see the requests you received, how each was verified, when each was answered, what was disclosed or deleted, and what you decided about the ones you refused. Programs run out of a shared mailbox cannot produce that. AccessPoint keeps every consumer request as a case with its clock, its verification record, its outcome, and its reasoning — and lets you report across all of them at once.

45 + 45 The rights clock and its extension, computed and visible.
Verification on record The method and evidence kept with each request.
Reportable at once Metrics across the whole request population, not per file.

Configured out of the box

Installing the us-ca-ccpa jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The CCPA as amended by the CPRA as the legal-authority spine
  • The 45-day rights clock with its single 45-day extension and the 10-business-day acknowledgment
  • Request types for know, delete, correct, port, opt out of sale/sharing, and limit sensitive personal information
  • Verification methods scaled to request sensitivity, recorded on each request
  • Exceptions and refusal grounds, cited on the response
  • Risk assessments for higher-risk processing, with risks, mitigations, and sign-off
  • § 1798.82 breach assessment and consumer notification workflows
  • Consumer-facing response templates carrying the statutory disclosures

California — CCPA/CPRA Questions

Who is subject to the CCPA?

The Act applies to for-profit businesses doing business in California that meet its thresholds for revenue, volume of consumers' personal information, or revenue derived from selling or sharing personal information, and it reaches service providers and contractors through required contract terms. Whether a particular organization is covered is a legal question for its own counsel — AccessPoint runs the regime for organizations that are.

How long do we have to respond?

45 days from receipt, extendable once by a further 45 days where reasonably necessary with notice to the consumer, and a request must be acknowledged within 10 business days. AccessPoint computes all three dates and shows whichever falls next.

Can privacy consultancies run this for clients?

Yes. A consultancy can host AccessPoint in its own tenant, tag each case with a Customer field, and use case-matched roles so a client sees exactly its own cases and reports and nothing else. See the managed service provider page for how that model works in practice.

Where does consumer personal information reside?

Entirely within your own Microsoft 365 and Azure tenant. Requests, the personal information gathered to answer them, and the audit history never leave your control — no third-party cloud and no vendor access.

Run CCPA/CPRA in Your Own Tenant

Try AccessPoint free for 30 days, configured for California consumer privacy. No credit card required.

Start Free Trial