The California AG's office just announced another round of CCPA enforcement sweep letters, this time targeting data brokers and large advertisers. The fines are getting real, and "we're working on it" isn't a defense anymore.
This isn't just a legal checkbox. If your martech stack leaks data to non-compliant vendors, you're holding the bag. I'm talking about:
* Third-party pixels and tags from your social/ad platforms
* Analytics tools that export raw PII without proper controls
* CDPs or data warehouses with poor access logging and data lineage
* ESPs and marketing automation platforms that don't handle deletion requests properly
So, what's your actual verification process? Before you trust a vendor's "CCPA-ready" claim:
* What specific data processing addendum (DPA) are you using? The IAB's? A custom one?
* Have you audited their subprocessor list in the last quarter?
* Can they provide a written attestation of their compliance, not just a marketing page?
For context, my recommendations shift based on your business model and scale. A B2B SaaS with 50k known contacts has different risks and tool requirements than a 10M-visitor/month DTC e-commerce site running dozens of third-party scripts.
What benchmarks or audit steps are you running on your key tools (think: your CDP, CRM, analytics suite) right now? I'm less interested in theory and more in the specific clauses you're demanding in contracts and the technical checks you've implemented.
Totally agree on auditing subprocessors. That's the trapdoor most companies miss. I've seen a "CCPA-compliant" CDP vendor whose data warehouse subprocessor (a major cloud provider) was logging all query results, including full PII rows, to an unsecured bucket for "debugging" - which counted as an unauthorized sale because that bucket was accessed by their support engineers.
My verification gotcha: don't just look at their *current* subprocessor list. Ask for their *change notification process*. If they can add a new data processor with 30 days notice to you, you're back to square one every month. We now mandate a 90-day heads-up and the right to terminate.
The written attestation is key. We got burned early on by accepting a signed DPA as proof. It wasn't. We now require a separate SOC 2 Type II report that specifically includes the CCPA control criteria, or a certification from a third party audit firm. Marketing pages are fiction.
Backup twice, migrate once.