Overview
This Framework provides a structured approach to validate your organization's compliance with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Getting CCPA right is crucial for avoiding regulatory fines, protecting consumer trust, and ensuring your marketing and analytics programs can operate without interruption.
Each Framework aligns with ObservePoint capabilities, but it will also include recommended processes, documents, and policies that we recommend an organization consider in their pursuit of a defensible privacy program.
Disclaimer: This Framework is provided for informational purposes only and does not constitute legal advice. We recommend consulting with qualified legal counsel regarding your specific compliance obligations.
Framework
This Framework is organized into the following Policies:
Notice at Collection
Consent & Opt-Out Management
Global Privacy Control (GPC)
Cookie Governance
Tag Behavior Under Opt-Out
Data Minimization & Security
Third-Party Vendors & Service Providers
Consumer Rights Accessibility
Documentation & Processes
Each policy contains individual Checks.
For each Check, we will include links to pre-built reports (when possible) in the ObservePoint Platform and an implementation & remediation guide.
Each check will be accompanied with an icon.
The ✅ icon represents a Check is out of the box available by just running an Audit.
The 🛠️ ✅ icons represent a Check that requires additional configuration.
In addition to checks, there are recommended documents (📄) and processes (⚖️) we encourage you to maintain as they are part of an effective privacy governance program.
Scope & Frequency
Before diving into specifics of each policy, we want to provide our recommendation around scope and frequency of validating your CCPA compliance posture.
Frequency | Scope | Goal |
Daily | 10-100 most critical pages (highest traffic / forms that collect personal information) | Confirm opt-out mechanisms and consent controls remain functional on the pages most likely to collect personal information |
Every Deployment | 10-15% of pages/templates or 100% of templates | Ensure new website code or TMS deployment hasn't introduced unapproved tags, broken the CMP, begun dropping unexpected cookies, or removed other privacy compliance elements |
Quarterly | 100% of pages | Catch "long tail" pages where privacy controls may have drifted and surface any rogue tags or trackers across the entire property |
If you find that you are having trouble determining how many pages exist on a domain, talk to your Success Manager or our Support Team and ask about running a Site Census scan.
If you have additional questions regarding our recommendation, contact our team.
Notice at Collection
This policy represents checks that pertain to the "Notice at Collection" requirement — the obligation to inform consumers, at or before the point of data collection, about the categories of personal information collected and the purposes for which the information will be used.
🛠️✅ Privacy Policy link is present on every page
CCPA requires businesses to conspicuously post a privacy policy that is accessible from every page where personal information is collected. A missing or orphaned privacy policy link is one of the most commonly cited CCPA violations and is easy for a regulator or plaintiff's attorney to screenshot.
Report in ObservePoint: Pages missing Privacy Policy links (English)
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.130(a)(5)
✅ "Notice at Collection" is present on pages that collect personal information
Any page that collects personal information (forms, account creation, newsletter signups, checkout flows) must surface a Notice at Collection that describes the categories of information being collected and the purposes. Without it, the collection itself is considered unlawful under the CCPA.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.100(a)(1)
🛠️ ✅ Do Not Sell or Alternative Opt-Out link is present on every page
If your business sells or shares personal information (including for cross-context behavioral advertising), the CCPA and CPRA require a clear and conspicuous "Do Not Sell or Share My Personal Information" link, or an acceptable Alternative Opt-Out Link, on the homepage and every page where personal information is collected. Missing this link is a per-page violation.
The only two acceptable Alternative Opt-Out Link labels provided are “Your Privacy Choices” or “Your California Privacy Choices”.
Exception: If your website appropriately handles GPC Signals as opt out requests, this link is not required per California Civil Code § 1798.135(b)(1).
Report in ObservePoint: Pages missing Do Not Sell or Alternative Opt Out Links
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.135(a)(1), CPPA Regulations 7015(a,b)
🛠️ ✅ "Limit the Use of My Sensitive Personal Information" link is present where required
If your business uses or discloses sensitive personal information (SPI) for purposes beyond what is necessary to provide the requested service, the CPRA requires a separate "Limit the Use of My Sensitive Personal Information" link. This check helps confirm the link is deployed on the pages where it is expected.
Exception: When websites provide a “Your Privacy Choices” link, the “Limit the Use of My Sensitive Personal Information” link is not required.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.135(a)(2)
Consent & Opt-Out Management
This policy represents checks that pertain to the behavior of your Consent Management Platform (CMP), often called "cookie banner", and the mechanisms a consumer uses to opt out of the sale or sharing of their personal information.
🛠️ ✅ Consent Management Platform (CMP) loads on every page
The CMP, or cookie banner, is the control surface for every downstream privacy decision on your site. If it fails to load, even on a small percentage of pages, opt-out signals will not be captured, unapproved tags will fire unchecked, and consent records will be incomplete. A CMP present on 99% of pages is still a gap that regulators treat as non-compliance.
Exceptions: First, an organization can develop and use their own first-party CMP. Second, not all pages collect data that would substantiate needing a CMP. The report below doesn’t account for these 2 exceptions, but additional filters can be applied as needed.
Report in ObservePoint: Pages missing a 3rd Party CMP
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.130(a)(1)(A)
🛠️ ✅ Non-essential tags cease firing after opt out
When a consumer exercises their right to opt out of non-essential tracking (such as advertising, sharing, or analytics), corresponding tags must immediately stop sending network requests on current and subsequent page views. Continued tag activity after an opt-out choice is made is an easily detectable compliance failure that exposes businesses to regulatory enforcement and class-action litigation.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.120
🛠️ ✅ Opt-out choice is honored across the full consumer journey
An opt-out is not a "per-page" signal — once selected, it must persist across the entire session and across subsequent visits from the same browser. This check validates that the opt-out state holds from the landing page through a representative user journey (e.g., landing → category → product → cart).
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.135(c)(4)
Global Privacy Control (GPC)
This policy represents checks that pertain to the recognition and honoring of browser-level opt-out signals. Under current California regulatory guidance, GPC must be treated as a valid "Do Not Sell or Share" request.
🛠️ ✅ Global Privacy Control (GPC) signal is recognized
California's AG and the CPPA have publicly confirmed that GPC is a required opt-out signal under CCPA/CPRA. When a browser sends a GPC signal, your site must treat the visitor as having opted out of sale and sharing — without requiring them to click the "Do Not Sell or Share" link manually. Sites that ignore GPC have been the subject of public enforcement actions.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.135(b)(1), California AG GPC Enforcement Advisory
🛠️ ✅ GPC state is reflected in the CMP User Interface
When GPC is detected, the CMP should visibly reflect that the consumer has been opted out (for example, by showing the toggle in its "off" state). Hidden or silent honoring of GPC creates ambiguity for the consumer and risk for the business. This check confirms the CMP updates its displayed state when GPC is present.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: CPPA Regulations § 7025(c)(6)
Cookie Governance
This policy represents checks that pertain to the creation, categorization, and lifetime of cookies set by your property.
🛠️ ✅ No unapproved cookies fire on any page
Manual review required.
An "unknown" or uncategorized cookie is a compliance landmine — regulators and consumers both assume the worst. Every cookie set by your property should map to a category (Strictly Necessary, Functional, Performance/Analytics, Advertising/Sharing) in a documented inventory so you can defend its presence and its duration.
Report in ObservePoint: Cookie Inventory report compared against your approved cookie list
Implementation & Remediation Guide: Link + manual review required.
Source Citation: CPPA Regulations § 7012, California Civil Code § 1798.100(a)
✅ Cookie lifetimes do not exceed the documented retention period or 400 Days
CCPA requires disclosure of retention periods for each category of personal information. Cookies with unexpectedly long expirations (e.g., a "session" cookie that persists for 13+ months) contradict your disclosures and extend your exposure window for any given consumer.
Report in ObservePoint: Cookies Expiring After 400 Days
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.100(a)(3), CPPA Regulations § 7011
Tag Behavior Under Opt-Out
This policy represents checks that pertain to how marketing, analytics, and advertising tags behave once a consumer has exercised their CCPA rights.
🛠️ ✅ Advertising tags send the correct downstream opt-out signal (GPP / IAB US National)
There is an exception where advertising tags are still permissible after opt-out if they are firing under a limited use context. When an advertising tag does still fire under a limited-use context, it must pass the correct downstream consent string — typically the IAB Global Privacy Platform (GPP) string with the US National section, or the legacy US Privacy String — so that the receiving vendor also honors the opt-out.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: IAB Tech Lab — Global Privacy Platform, CPPA Regulations § 7026
🛠️ ✅ No unapproved tags fire on any page
Rogue tags, introduced by a marketing team member through a TMS, a vendor pixel, or a piggyback from another tag, are one of the most common sources of unintentional CCPA violations. A tag that isn't on your approved inventory hasn't been reviewed for data-sharing implications and, by definition, cannot be covered by your privacy disclosures.
Report in ObservePoint: Pages with Unapproved Tags
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.100, CPPA Regulations § 7053 (Service Provider / Contractor requirements)
Data Minimization & Security
This policy represents checks that pertain to the principle of collecting only what is necessary, transmitting it securely, and avoiding categories of data that are either sensitive or strictly off-limits.
✅ No personal information appears in URL query parameters
Email addresses, phone numbers, or account identifiers passed in query strings are written to server logs, browser history, referrer headers, and every third-party analytics tool that sees the URL. This is a silent but serious form of personal information leakage and is one of the easiest things for a regulator or researcher to spot.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
🛠️ ✅ Tag payloads do not contain personal information (PI) or sensitive personal information (SPI)
CCPA treats any outbound transmission of identifiers (email, phone, precise geolocation, government ID, health or financial account numbers) as regulated activity. Analytics and advertising tags should not be carrying this data in their variables — whether intentionally or as a side effect of a mis-bound data layer.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.140(v) (definition of PI), § 1798.140(ae) (definition of SPI)
✅ All tag requests are made over HTTPS
A tag firing over plain HTTP exposes any personal information in the payload (including identifiers) to passive network observers. Beyond CCPA's "reasonable security" requirement, an HTTP tag is a trivially exploitable weakness that also triggers mixed-content warnings and browser blocking.
Report in ObservePoint: Pages with Tag requests not made over HTTPS
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.100(e) (reasonable security)
✅ No mixed-content or insecure resource loads on pages that collect personal information
Forms that collect personal information must be served and submitted over HTTPS end-to-end. Mixed-content resources (an HTTP image or script on an HTTPS form page) undermine the integrity of the page and, under California's "reasonable security" standard, can be treated as a failure to safeguard the data collected.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.100(e), CPPA Cybersecurity Audit Regulations
Third-Party Vendors & Service Providers
This policy represents checks that pertain to the third parties, service providers, and contractors that receive data via your property.
🛠️ ✅ Every third-party tag maps to a documented vendor with a CCPA contract type
Under CCPA, every external data recipient must be an approved vendor categorized with a valid contract type (Service Provider, Contractor, or Third Party). Tags directing traffic to unapproved domains or undocumented vendors—frequently introduced via tag piggybacking or ungoverned TMS updates—expose your organization to unauthorized data transfers, missing privacy disclosures, and contractual non-compliance.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.140(ag), § 1798.140(j), § 1798.140(ai); CPPA Regulations § 7051 & § 7053
Consumer Rights Accessibility
This policy represents checks that pertain to the consumer's ability to exercise the rights granted to them under CCPA/CPRA.
✅ Privacy Request (DSAR) page is reachable and returns a 200 status
Under CCPA, businesses must provide at least two designated methods for submitting consumer rights requests (access, deletion, correction, opt-out, etc.), and at minimum a web form is typically required. A 404 or 500 on the privacy request page is not just a broken link, it is a direct failure to provide a legally required method.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.130(a)(1), CPPA Regulations § 7020
✅ "Do Not Sell or Share" opt-out link routes to a functional opt-out mechanism
It is not enough for the link to be present, the link must actually lead to a working opt-out. A broken link, an endless redirect loop, or a link that leads to a form that doesn't submit is treated the same as no opt-out at all.
Report in ObservePoint: See Implementation & Remediation Guide
Implementation & Remediation Guide: Link
Source Citation: California Civil Code § 1798.135, CPPA Regulations § 7026
Documentation & Processes
This policy represents recommended documents and processes pertaining to CCPA compliance.
📄 Create and maintain a Privacy Policy aligned to CCPA disclosures
The Privacy Policy is the primary public artifact of your privacy program. Under CCPA, it must describe the categories of personal information collected, the sources, the purposes, the recipients, the retention periods, and the consumer rights available — and it must be refreshed at least every 12 months. A stale privacy policy is one of the first things a regulator reviews.
📄 Create and maintain a Data Inventory / Record of Processing Activities (ROPA)
You cannot honor access, deletion, or correction requests for data you don't know you have. A Data Inventory catalogs every category of personal information collected, where it lives, how long it's retained, and which vendors touch it. It is the foundation of every other CCPA obligation.
📄 Create and maintain a Vendor / Service Provider Register
Every vendor that touches personal information — tags, pixels, SaaS tools, offline processors — must be classified as a Service Provider, Contractor, or Third Party, and be covered by the appropriate contractual clauses. The Vendor Register is what you'll be asked to produce during any regulatory inquiry.
📄 Create and maintain a Cookie & Tag Inventory
This inventory documents every cookie and tag approved to run on your property, its purpose, its category (Strictly Necessary / Functional / Performance / Advertising-Sharing), its retention, and the vendor that owns it. It is the ground truth against which ObservePoint reconciles every Audit.
⚖️ Implement a "No Vendor, No Tag" Policy
This policy is the governance firewall for your CCPA program. It is important because it prevents rogue tags, uncontracted vendors, and unreviewed data sharing. By rejecting any tag request that lacks a documented vendor, a contract type, and a privacy-policy entry, you ensure that:
Opt-outs are honored: No tag is implemented without first being classified against your consent categories.
Disclosures stay accurate: Every data recipient is reflected in the privacy policy before data starts flowing.
Contracts exist: Service Provider / Contractor terms are in place before, not after, the tag goes live.
⚖️ Implement a quarterly CCPA posture review
A standing quarterly review — run by Privacy, Marketing, and Engineering together — that walks through each policy in this framework and confirms each check is green. ObservePoint provides the evidence; this process turns that evidence into a reviewed, signed-off record that a regulator can be shown on request.
Conclusion
This framework is not a comprehensive guide to everything that can or should be done to validate your CCPA compliance posture, but it is a solid foundation.
As ObservePoint unlocks more data and enhances its platform, we will support more checks to be fully automated. Expect this framework to evolve in time and talk to our Customer Success if you have other checks you want to implement.

