Tested tool guide
Tested browser tools
Checked August 16, 2026
What CCPA / CPRA Compliance Checker does, with a checked example
You answer a short questionnaire about your business - annual revenue, how many California consumers' personal information you buy, sell, or share per year, whether you post a privacy notice at or before collection, and how you handle consumer requests - and the tool maps your answers against the CCPA as amended by the CPRA, telling you whether the law applies to you and which obligations are unmet. Everything runs in your browser; nothing you enter is uploaded. The surprise for most people: being under $25 million in revenue does not automatically exempt a business.
Worked example
A concrete input and expected output from the current implementation.
Input
Revenue: $12 million per year. Personal information bought from 200,000 California consumers per year. Sells or shares personal information: no. Revenue from selling or sharing: 0%.
->
Expected output
Covered. Prong 1 (revenue over $25 million): not met. Prong 3 (50% of revenue from selling or sharing): not met. Prong 2: met - the business annually buys personal information of 100,000 or more California consumers (200,000), which qualifies it under Civil Code section 1798.140. Result: notice at collection, access, deletion, and correction requirements apply; the 'Do Not Sell or Share' opt-out requirement does not, because the business neither sells nor shares.
The three prongs of the business definition are alternatives, so coverage does not require $25 million in revenue. Because 200,000 exceeds the 100,000-consumer threshold, the business qualifies, while the opt-out duty drops out since it applies only to selling or sharing.