CPA · CISA · CISM · CDPSE · CCSE · MBA
Privacy officer reviewing a personal data inventory and consumer rights request log for CCPA compliance

Data Privacy Compliance. CCPA, CPRA, GDPR and HIPAA

Data mapping, consumer rights processes, vendor terms and privacy programme design across California, EU and health-sector requirements.

Where does a CCPA compliance consultant in California start?

With the inventory, and it is harder than it sounds. The first question is what personal information the business holds, where it is, and who it has been given to. Almost no company can answer that at the start. Privacy programmes fail on the inventory long before they fail on the legal analysis, because data mapping is the foundation for consumer rights processes, vendor terms and every other part of the programme.

A CCPA compliance consultant in California is usually engaged once a consumer rights request has arrived and the business has discovered it has no dependable way to answer one.

Most programmes get built in the wrong order, starting with policy language and a privacy notice because those are the visible deliverables and the ones a customer or a prospect asks to see. The notice then describes practices nobody has verified, which is a written representation the business may later have to stand behind.

What a CCPA compliance consultant in California establishes first

Not to every California business. The thresholds are specific, annual gross revenue above a defined level, buying, selling or sharing the personal information of a defined number of California consumers or households, or deriving a defined share of annual revenue from selling or sharing personal information. Meeting any one brings you in scope.

Three things catch companies out. The revenue threshold is total annual revenue, not California revenue, a company with modest California activity can be in scope on the strength of its overall size. "Personal information" under California law is broad, reaching device identifiers, IP addresses, geolocation, browsing history and inferences drawn about a consumer. And since CPRA, employee and job applicant data is fully in scope, which is the point at which most B2B companies discover the law applies to them after all.

What compliance actually requires

Beyond the privacy notice; which is the part everyone does and the least of it:

  • A verifiable consumer request process covering access, deletion, correction, opt-out of sale or sharing, and limitation of sensitive personal information use, with defined response timeframes and an identity verification method proportionate to the sensitivity of what is requested
  • Data minimisation and purpose limitation, collecting and retaining only what is necessary for a disclosed purpose, which conflicts directly with most companies' default of keeping everything indefinitely
  • Defined retention periods, disclosed and actually enforced in the systems
  • Contractual terms with service providers and contractors that meet the statutory requirements. Standard vendor agreements do not, and this is the most common gap found
  • Opt-out mechanisms, including recognition of opt-out preference signals
  • Risk assessments for processing presenting significant risk
  • Reasonable security, the private right of action for breaches of unencrypted, unredacted personal information attaches to the failure to maintain it, which is what turns a privacy programme into a litigation-exposure question

GDPR for US companies

GDPR reaches US companies offering goods or services to people in the EU or monitoring their behaviour, no European establishment is required. Companies typically discover this through a customer's data processing agreement rather than through their own analysis.

Practical scope: establishing a lawful basis for each processing activity, which is more demanding than the consent-focused summary suggests; the Article 30 record of processing activities; data subject rights with a one-month response clock; international transfer mechanisms, which have been through repeated legal upheaval and need current rather than legacy documentation; Data Protection Impact Assessments for high-risk processing; a 72-hour breach notification obligation to the supervisory authority; and whether an EU representative or Data Protection Officer is required.

Overlap with CCPA is substantial in mechanism (inventory, rights handling, vendor terms) and materially different in legal structure. Building one programme that satisfies both is achievable and considerably cheaper than running two.

HIPAA and HITECH

Relevant to covered entities and, increasingly, to the business associates serving them, a category that catches many technology companies who did not consider themselves healthcare businesses until a health system sent them a business associate agreement.

The Security Rule requires a documented risk analysis, and its absence is among the most frequently cited findings in OCR enforcement. Also in scope: administrative, physical and technical safeguards; the breach notification rule with its own timelines and thresholds; business associate agreements down the chain to subcontractors; and the minimum necessary standard applied to access.

The medical device and health technology concentration around Thousand Oaks and Camarillo means this frequently arrives alongside 21 CFR Part 11 obligations, and the two are worth mapping together rather than running as separate programmes.

Data mapping, where the work actually is

Every obligation above depends on knowing what you hold. Building that inventory is unglamorous and takes longer than clients expect.

It runs through systems and databases, SaaS applications (discovered through expense analysis and SSO logs rather than by asking, because the answer to asking is always incomplete), marketing and analytics tooling (a persistent source of undisclosed data sharing) HR and payroll systems, support ticketing, backups and archives, and the spreadsheets and exports sitting on individual laptops that no formal inventory ever captures.

For each: what is collected, why, on what basis, how long it is kept, who it is disclosed to, and where it physically resides. Companies routinely discover during this exercise that they are sharing data with advertising platforms in ways that meet the statutory definition of "selling" or "sharing", which triggers opt-out obligations nobody had implemented.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Applicability analysis across CCPA, CPRA, GDPR, HIPAA and other state privacy laws
  • Personal data inventory and data flow mapping
  • Gap assessment against each applicable regime
  • Privacy notice drafting aligned to actual practice rather than to a template
  • Consumer and data subject rights process design with verification methodology
  • Retention schedule development and enforcement planning
  • Service provider and processor contract term review and remediation
  • Article 30 records of processing activities
  • Data Protection Impact Assessments and CPRA risk assessments
  • HIPAA Security Rule risk analysis and safeguard assessment
  • Breach response procedures aligned to each applicable notification clock

How a typical engagement runs

  1. Establish applicability

    Which regimes apply, on what basis, and to which parts of the business. Companies are frequently in scope of laws they had not considered and out of scope of ones they were preparing for.

  2. Map the data

    The inventory across systems, SaaS, marketing tooling, HR, backups and endpoints. This is the longest phase and everything else depends on it.

  3. Assess and design

    Gap analysis against each regime, then a single programme designed to satisfy all of them rather than separate parallel efforts.

  4. Operationalise

    Rights request handling, retention enforcement, vendor terms and breach procedures put into operation with named owners, because a privacy programme that exists only as documents fails at its first request.

Data Privacy (CCPA, GDPR, HIPAA) across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

Data Privacy (CCPA, GDPR, HIPAA): questions we are asked

Not answered here? Ask Javed directly

Does CCPA apply to our small California business?

Only if you meet one of the statutory thresholds, annual gross revenue above the defined level, handling the personal information of a defined number of California consumers or households, or deriving a defined proportion of revenue from selling or sharing it.

Check total revenue rather than California revenue, and remember that since CPRA employee and applicant data counts. A B2B company with few consumer customers can still be in scope through its own workforce data.

We do not sell data. Do the opt-out rules still apply?

Frequently yes, and this is the single most common misunderstanding in California privacy work. "Sale" and "share" are defined broadly enough to capture disclosures for cross-context behavioural advertising, even where no money changes hands.

Standard advertising and analytics implementations (pixels, conversion tracking, audience matching) routinely meet the definition. Companies that were confident they do not sell data discover during data mapping that their marketing stack does, and that an opt-out mechanism should have been in place.

How do we handle a deletion request when the data is in twelve systems?

You cannot, until the inventory exists; which is why data mapping precedes rights process design rather than following it.

Once mapped, the process needs a named owner per system, a defined method for each (some support deletion via API, some require manual action, some cannot delete without breaking referential integrity and require anonymisation instead), a documented position on backups and archives, and a record of what was done. Statutory exceptions permit retention for specific purposes such as legal obligation or fraud prevention, but those must be documented rather than assumed.

Our vendor contracts are standard. Is that a problem?

Usually, yes; and it is the most common gap found. CCPA imposes specific contractual requirements on agreements with service providers and contractors, and GDPR imposes its own under Article 28. Standard commercial terms almost never contain them.

Absent the required terms, a disclosure to that vendor may be treated as a sale rather than a service provider relationship, with the opt-out and disclosure consequences that follow. Remediation is a contract amendment exercise across the material vendor population, prioritised by data sensitivity.

What is the real exposure if we do nothing?

Three distinct routes. Regulatory enforcement by the California Privacy Protection Agency and the Attorney General, with per-violation penalties that multiply across affected consumers. A private right of action for breaches of unencrypted, unredacted personal information caused by failure to maintain reasonable security; which is the route that produces class actions.

And the commercial one, which arrives first in practice: enterprise customers and health systems now include privacy terms in vendor agreements and ask for evidence during procurement. Companies typically encounter the cost of non-compliance as a lost or delayed deal well before any regulator makes contact.

Related services

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about data privacy (ccpa, gdpr, hipaa)

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a data privacy (ccpa, gdpr, hipaa) engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now