CCPA/CPRA Compliance Verification

See where your site actually stands on CCPA.

We load your pages like a real visitor, watch what fires on the network, and hand you the specific issues along with the CCPA sections they fall under.

Independent of your consent vendorEvidence for every findingNo code changes
No card or account. Most scans finish in under 2 minutes. The full audit, all 55 checks, is free when you sign up.

Watch the scanner in action

A real scan, from URL entry to full compliance score. In minutes, not meetings.

Product demo showing compliance scan and scoring

Your compliance tool grades its own work

A consent platform enforces the rules it was given. Whether those rules still hold on your live site today is a separate question, and it needs a separate source.

Configuration drift and piggybacking

Tags get added, vendors piggyback on other vendors, and a script that behaved at setup ships on its own release schedule. What was verified when your consent tool was configured is not automatically still true this quarter.

No legal safe harbor

In 2026, “I thought I was compliant” is no longer a valid legal defense. The California Privacy Protection Agency is actively issuing fines, and your CMP vendor won't cover them.

Independent verification

You wouldn't let a student grade their own test. An outside scan has no stake in the answer: it reports what your pages actually send, whether or not that matches what your setup intends.

Regulators are issuing real penalties

These are not theoretical risks. California is actively enforcing privacy law. The three actions below alone add up to $15.87M.

General Motors (OnStar)
May 2026
$12.75M

Sold drivers' geolocation and behavior data to brokers despite a privacy policy saying otherwise — the largest CCPA penalty to date.

The Walt Disney Company
February 2026
$2.75M

Opt-out toggles covered only one streaming service at a time, and Global Privacy Control signals were honored per-device instead of account-wide.

Ford Motor Company
March 2026
$375K

Required email verification before honoring opt-outs and kept selling data after consumers opted out; must now audit its tracking for GPC compliance.

What's inside your audit report

30 discrete checks across four audit domains. A report your legal and engineering teams can act on immediately.

01

UI & page compliance

Surface-level disclosures and opt-out mechanisms a regulator reviews first

9 checks
Do Not Sell or Share LinkBusinesses that sell or share personal information (or use/disclose sensitive PI beyond § 1798.121(a) purposes) must provide a clear "Do Not Sell or Share My Personal Information" link, a § 7015 Alternative Opt-out Link, or frictionless opt-out preference signal processing with the § 7025(g)(2) policy disclosures.
§ 7013, § 7015, § 1798.135critical
Limit Use of Sensitive Personal Information Link§ 7014(a) requires a "Limit the Use of My Sensitive Personal Information" link in the header or footer of the homepage, but only when the business uses or discloses sensitive personal information for purposes beyond those listed in § 7027(m).
§ 7014, § 1798.121info
Privacy Policy LinkCCPA § 7011 requires the privacy policy to be posted online and reachable from a conspicuous link that uses the word "privacy".
§ 7011critical
Notice at CollectionCCPA § 7012 requires businesses to inform consumers, at or before the point of data collection, about the categories of PI collected, purposes of use, whether information is sold or shared, and retention periods.
§ 7012, § 1798.100high
Symmetry of ChoiceCCPA § 7004(a)(2) requires symmetry in choice: the path a consumer takes to the more privacy-protective option must not be longer, more difficult, or more time-consuming than the path to the less privacy-protective option.
§ 7004high
No Direct Accept/Reject ChoiceCCPA § 7004(a)(2) requires symmetry in choice: the path to the more privacy-protective option must not be longer, more difficult, or more time-consuming than the path to the less protective one.
§ 7004high
Alternative Opt-Out LinkCCPA § 7015 allows an Alternative Opt-out Link in lieu of the "Do Not Sell or Share" link.
§ 7015, § 7013info
Generic Privacy Controls LinkGeneric privacy-control links (e.g. "Cookie Preferences", "Privacy Preferences", "Ad Choices") do not satisfy the § 7013 opt-out link requirement or the § 7015(b) Alternative Opt-out Link title/icon requirements.
§ 7013, § 7015info
Consent Mechanism PresenceMarketing trackers evidence a sale or share of personal information, which obliges the business to offer a consumer-facing opt-out path: a consent banner, a "Do Not Sell or Share My Personal Information" link, or opt-out preference signal processing.
§ 7013, § 7025high

Scroll for all 9 checks

02

Tracker & network leak detection

Full network-layer scan of outbound requests during page load

3 checks
Third-Party Marketing TrackersMarketing and social media trackers are evidence of "selling" or "sharing" personal information.
§ 7013, § 7025high
Third-Party Request InventoryInventory of all third-party domains contacted during page load. Informational: it records how many distinct third-party domains loaded and how many of those are marketing or ad-tech, and warns above 20 domains as a data-exposure signal rather than as a statutory violation.
§ 7025, § 7013medium
Third-Party PII TransmissionThird-party request payloads must not carry personally identifiable information (email, phone, hashed identifiers, etc.) unless recipients are disclosed in the privacy policy and an opt-out mechanism is present.
§ 7011, § 7013high
03

Global Privacy Control (GPC) validation

Sends the GPC signal and verifies the site responds with opt-out behavior. Test your site with our free GPC checker.

12 checks
Pre-Consent TrackingMarketing trackers that load before the visitor answers the consent banner are reported as a best-practice concern, not a violation: CCPA is an opt-out regime and does not require prior consent from adults, but a banner whose choice arrives after the data has already left the page impairs that choice under § 7004(a).
§ 7004medium
Global Privacy Control (GPC) SignalCCPA requires businesses to honor the GPC signal as a valid opt-out of sale/sharing.
§ 7025, § 1798.135critical
GPC Status DisplayCCPA § 7025(c)(6) requires displaying opt-out status when GPC signal is active, and § 7026(g) requires a means for the consumer to confirm the opt-out was processed.
§ 7025(c)(6), § 7026(g)high
.well-known GPC DeclarationChecks whether the site publishes a valid `/.well-known/gpc.json` file containing `{ "gpc": true }`.
§ 7025info
USP API GPC TranslationWhen `__uspapi` is present, the GPC session should translate into an opt-out-aware US Privacy API response.
§ 7025medium
GPP API Signal ChangeWhen `__gpp` is present, the GPC session should produce a changed GPP API state or string compared with the control session.
§ 7025medium
GPC Consent Override (§ 7025(f)(3))CCPA § 7025(c)(3) permits notifying the consumer that a GPC signal conflicts with a business-specific privacy setting and offering an opportunity to consent, but the signal must still be processed as an opt-out.
§ 7025(f)(3), § 7025(c)(3)high
GPC Re-Opt-In Request (§ 1798.135(c)(4))Civil Code § 1798.135(c)(4) (echoed by reg § 7026(k)) requires a business to wait at least 12 months after an opt-out before requesting authorization to sell or share personal information.
§ 1798.135, § 7025(c)(4)high
Consent Mechanism EffectivenessCCPA § 7004(a)(2) requires the path to the more privacy-protective choice to be no longer or harder than the path to the less protective one, and § 7025 requires an opt-out to be actually effectuated rather than merely acknowledged.
§ 7004, § 7025critical
USP API Consent StringCCPA § 7025 requires a business to treat an opt-out as a valid request across the browser, device, and any associated consumer profile rather than merely acknowledging it.
§ 7025high
Google Consent Mode StateCCPA § 7025 requires an opt-out of sale/share (cross-context behavioral advertising) to be actually effectuated by the systems that act on it, not merely recorded in the interface.
§ 7025high
Marketing Cookies After Opt-OutMarketing cookies should be cleared or not set after the user opts out via the consent banner.
§ 7025high

Scroll for all 12 checks

04

Privacy policy substance review

Every required disclosure element checked against the 2026 CCPA/CPRA statute

31 checks
Privacy PolicyA comprehensive privacy policy is required under CCPA.
§ 7011critical
Policy: Data Categories DisclosureMust disclose categories of personal information collected.
§ 7011, § 1798.100critical
Policy: Collection PurposesMust disclose the business purposes for data collection.
§ 7011, § 1798.100critical
Policy: Right to KnowMust inform consumers of their right to know what data is collected.
§ 1798.100, § 7011high
Policy: Right to DeleteMust inform consumers of their right to request deletion of the personal information collected from them.
§ 1798.105, § 7011high
Policy: Right to CorrectMust inform consumers of their right to request correction of inaccurate personal information the business maintains about them.
§ 1798.106, § 7011high
Policy: Right to Opt-OutMust disclose the right to opt out of sale/sharing.
§ 1798.120, § 7013critical
Policy: 12-Month Lookback PeriodMust state that the collection, sale, and sharing disclosures cover the preceding 12 months.
§ 7011medium
Policy: Service Provider DisclosureMust identify the categories of persons to whom personal information is disclosed for a business purpose, such as service providers, contractors, and third parties.
§ 7011medium
Policy: Categories of SourcesMust identify categories of sources of personal information.
§ 7011critical
Policy: Categories of Third PartiesMust identify third party categories for sold/shared data.
§ 7011critical
Policy: ADMT Disclosure§ 7011(e)(2)(F)-(G) requires a privacy policy to disclose the right to opt out of ADMT and the right to access ADMT, but only for a business that uses ADMT to make a significant decision concerning a consumer (§ 7200(a)).
§ 7011, § 7200info
ADMT: Logic and Significance§ 7220(c)(5)(A): Must describe how the ADMT processes personal information to make a significant decision concerning the consumer.
§ 7220high
ADMT: Business Purpose§ 7220(c)(1): Must provide a plain-language explanation of the specific purpose for using ADMT.
§ 7220high
ADMT: Input Data Categories§ 7220(c)(5)(A): Must disclose the categories of personal information that affect the ADMT's output.
§ 7220high
ADMT: Right to Opt Out§ 7221: Must inform consumers of their right to opt-out of ADMT and how to submit the request (§ 7220(c)(2)).
§ 7220high
ADMT: Right to Human Review§ 7221(b)(1): Businesses relying on the human-appeal exception to the ADMT opt-out must disclose that consumers can appeal the decision to a qualified human reviewer (§ 7220(c)(2)(A)).
§ 7220high
ADMT: Right to Access§ 7222: Must inform consumers of their right to access information about the business's use of ADMT and how to submit the request (§ 7220(c)(3)).
§ 7222, § 7220high
ADMT: Output Type§ 7220(c)(5)(B): Must describe the type of output the ADMT generates and how the business uses it in the decision.
§ 7220high
Policy: Sensitive PI UsageMust state whether the business uses or discloses Sensitive Personal Information for purposes other than those permitted by § 7027(m).
§ 7011, § 1798.121high
Policy: Right to Limit Sensitive PIMust describe the consumer's right to limit the use or disclosure of sensitive personal information (§ 1798.121) if the business uses or discloses sensitive PI for reasons beyond the § 7027(m) purposes.
§ 1798.121, § 7014, § 7011high
Policy: Minors Under 16 SaleMust state whether the business has actual knowledge that it sells or shares the personal information of consumers under 16 years of age.
§ 7011, § 1798.120high
Policy: Non-Discrimination RightsMust disclose the right not to be retaliated or discriminated against for exercising CCPA rights.
§ 1798.125, § 7011high
Policy: Verification ProcessMust describe the process the business uses to verify a consumer request, including any information the consumer must provide.
§ 7011medium
Policy: Privacy Contact InformationMust provide a contact for questions or concerns about the privacy policy and information practices, using a method that reflects how the business primarily interacts with consumers.
§ 7011medium
Policy: Authorized Agent InstructionsMust explain how an authorized agent can submit a request on a consumer's behalf, including the written permission or identity verification the business requires of the agent.
§ 7011, § 1798.135medium
Policy: Last Updated DateMust state the date the privacy policy was last updated.
§ 7011medium
Policy: Financial Incentive NoticeMust disclose financial incentives tied to personal information if applicable.
§ 7011, § 1798.125medium
Policy: Opt-Out Preference Signal DisclosureMust disclose whether the business processes opt-out preference signals (e.g., GPC).
§ 1798.135, § 7025high
Policy Ownership / ApplicabilityThe privacy policy is hosted on an external domain; it must explicitly cover the scanned site's data practices.
§ 7011high
Privacy Request MechanismCCPA requires businesses to provide easy-to-use methods for consumers to submit requests to know, delete, correct, and opt-out.
§ 7004, § 7011high

Scroll for all 31 checks

This is a real report structure. Every audit includes compliance scoring, tracker mapping, GPC validation, and concrete remediation steps. Prefer to work through it yourself first? Check out our CCPA compliance checklist.

View a Sample Report

How it works

No SDK. No JavaScript snippet. No access to your codebase. We audit your site exactly like a regulator would.

Submit your URLs

Enter the pages that matter most: checkout flows, signup forms, anywhere users hand over data.

We run the audit engine

Our scanner loads each page like a real visitor and checks it against the 2026 CCPA/CPRA standards.

You get the report

A comprehensive risk report with clear, actionable remediation items for legal and engineering.

Pricing

First full audit free, then $29 for 50 scans.

Lite Checks
Free
On-demand public-facing audit

Run a free GPC check on any URL: verify Global Privacy Control is honored and see whether trackers respect it. No card or account required.

  • Sends a real Global Privacy Control opt-out signal
  • Verifies marketing trackers and cookies respect it
  • The full audit, all 55 checks, is free when you sign up
  • No credit card or account needed
Run a Free Scan
50 Scan CreditsRecommended
$29
First full audit free on sign-up

Get full network-layer scans to verify tracker blocking and audit privacy policy text against California regulations.

  • 50 audit credits (never expire)
  • First full audit free when you sign up
  • 1 credit = 1 URL audited (all 55 checks included)
  • Deep network-layer tracker analysis
  • Global Privacy Control (GPC) verification
  • Automated policy substance review
Sign Up & Get Started
FeatureLiteCredits
Compliance verdict + section scoresOverall verdict onlyVerdict + full section scores
UI & banner checks (§ 7013, § 7011)Detailed findings
Third-party trackersFull inventory
Network-layer tracker analysis
Global Privacy Control (GPC) validation
Privacy policy substance review (31 checks)
Unlocked report with remediation steps
Account requiredNoYes
1 credit = 1 URL audited (all 55 checks included)

Common questions

Patrick Daly, Founder of Privisy

Patrick Daly

Founder, Privisy. Marketing technologist.

I've spent my career at the intersection of marketing technology and business operations, helping companies move fast without losing control. I know firsthand how complex the modern martech stack gets: dozens of tags, pixels, and third-party scripts firing across your site, each one added with the best intentions but rarely audited end-to-end.

When CCPA enforcement ramped up in 2026, I started seeing a pattern: companies that thought they were compliant because they had a CMP were exposed in ways their tools never surfaced. I built Privisy to give businesses the independent, network-level view that their compliance vendors simply aren't.

Know exactly where your site stands.

Run one scan and see what a regulator would see, before they do.

Run a Free Scan

More from Privisy