Skip to main content

Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal

You've clearly built for GDPR and you talk about India. What about California — does CCPA even apply to you, and are you ready for the US state-law patchwork?

The question a Chief Privacy Officer / DPO asks.

The short answer

CCPA likely doesn't bite us directly yet, but as your service provider we'll sign its terms today — no data sales exist to prohibit, and the GDPR rights machinery discharges California requests identically. The state patchwork is contract deltas on plumbing we've already built.

The full executive answer

Candid scoping first: CCPA's thresholds (revenue, volume of California consumers) mean it likely doesn't apply to us directly today as a pre-launch B2B company — but that's the wrong comfort to rely on, for two reasons. First, our customers may be covered businesses, making us their "service provider" under CCPA's terms — the analogue of a GDPR processor — and service-provider contracts require specific commitments: process only for the business purpose, no selling or sharing of personal information, support consumer rights requests. We can sign those today because the machinery already exists: we sell no data to anyone (the business model is subscription software, full stop), and the access/deletion pipelines built for GDPR Articles 15/17 discharge CCPA §1798.100/§1798.105 requests identically — rights plumbing, once genuinely built, is regime-portable.

Second, the patchwork point: Virginia, Colorado, Connecticut, Texas and a dozen more state laws all riff on the same chassis — access, deletion, correction, opt-outs, processor contracts. Our approach is the same one that carried GDPR-to-DPDP: implement the strictest common denominator in code (executable rights, minimisation, no data sales, named sub-processors) and treat per-state deltas as contract-schedule and configuration work tracked by the regulatory-horizon monitoring, rather than re-engineering per statute. B2B SaaS has a structural advantage here — most state-law complexity (targeted advertising opt-outs, dark patterns, sensitive-data sales) concerns consumer data economies we simply don't participate in.

The honest boundary: we haven't engaged US privacy counsel for a state-by-state opinion yet — that's sequenced with US go-to-market, not before it — and if your operations make CCPA service-provider terms a signing requirement, that's a contract schedule we'd adopt now, since nothing in it conflicts with how the platform already behaves.

Grounded in: CCPA/CPRA §1798.100 (access), §1798.105 (deletion), §1798.140 (service provider definition); GDPR Art. 28 (portable processor posture); Colorado/Virginia CDPA analogues.

Want this answered live, on your data?