CCPA (California Consumer Privacy Act) website screenshot

CCPA (California Consumer Privacy Act)

The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), is a state statute that grants California residents rights over their personal information: the right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, and non-discrimination for exercising privacy rights. It is enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General. Technical interoperability mechanisms include the Global Privacy Control (GPC) browser signal and the IAB Tech Lab US Privacy (USP) / Global Privacy Platform (GPP) signals for advertising technology. This index tracks the official regulatory resources, technical privacy signals, and commercial APIs that help businesses comply with CCPA/CPRA obligations.

CCPA (California Consumer Privacy Act) publishes 1 API on the APIs.io network: CalPrivacy DROP Data Broker API. Tagged areas include CPRA, California, Compliance, Data Protection, and Data Subject Rights.

The CCPA (California Consumer Privacy Act) catalog on APIs.io includes 1 event-driven AsyncAPI specification.

CCPA (California Consumer Privacy Act)’s developer surface includes documentation, FAQ, authentication, changelog, sandbox, API reference, getting-started guide, and 38 more developer resources.

59.1/100 strong ▬ flat Agent 37/100 agent ready Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemium
5 APIs 13 Features 9 Use Cases
CPRACaliforniaComplianceData ProtectionData Subject RightsLegalPrivacyRegulations

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/ccpa: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Global Privacy Control (GPC) Specification

Global Privacy Control is a browser-level signal that communicates a user's opt-out preference to websites. The California Attorney General has affirmed that GPC must be treated...

IAB Tech Lab Global Privacy Platform (GPP)

The IAB Tech Lab Global Privacy Platform (GPP) is the successor to the US Privacy (USP) string. It provides a standardized way to communicate user consent and opt-out signals be...

California Privacy Protection Agency (CPPA) Resources

Official resources from the California Privacy Protection Agency, the body empowered by CPRA to implement, enforce, and publish regulations under the CCPA.

California Data Broker Registry

Official California Attorney General registry of data brokers required to register under Civil Code section 1798.99.80, providing a public list that consumers can use to submit ...

CalPrivacy DROP Data Broker API

The Delete Request and Opt-out Platform (DROP) Data Broker API is the statutory integration surface California's Delete Act requires of every registered data broker. Brokers cal...

Pricing Plans 1

Published pricing tiers and plan structures.

Ccpa Plans Pricing

2 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Ccpa Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Ccpa Finops

FINOPS

Features 13

Notable capabilities this provider offers.

Notice at Collection

Privacy Policy Disclosure

Do Not Sell or Share Link

Limit Use of Sensitive PI Link

Verifiable Consumer Requests

Authorized Agent Requests

Opt-Out Preference Signal (GPC)

Service Provider / Contractor Contracts

Data Processing Addendum

Data Retention Disclosure

Risk Assessments (CPRA)

Cybersecurity Audits (CPRA)

Automated Decision-Making Disclosures (CPRA)

Scroll for all 13

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Ccpa Authentication

apiKey · 1 scheme

SECURITY

Ccpa Domain Security

TLSv1.2 · HSTS · DNSSEC · DMARC

SECURITY

Ccpa Vulnerability Disclosure

security.txt · contact published

SECURITY

Use Cases 9

What developers build with this provider.

DSAR (Data Subject Access Request) Automation

Consent Management Platform (CMP)

Cookie Banner and Preference Center

Data Inventory and Mapping

Vendor Risk Management

Privacy Impact Assessments

Audit and Reporting

Global Privacy Control Handling

Data Broker Registration

Scroll for all 9

Resources

Get Started 6

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 5

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 11

Properties that don't map to a standard resource type

Scroll for all 11

Source (apis.yml)

apis.yml Raw ↑
aid: ccpa
url: https://raw.githubusercontent.com/api-evangelist/ccpa/refs/heads/main/apis.yml
name: CCPA (California Consumer Privacy Act)
tags:
- CPRA
- California
- Compliance
- Data Protection
- Data Subject Rights
- Legal
- Privacy
- Regulations
tags_raw:
- CPRA
- California
- Compliance
- Data Protection
- Data Subject Rights
- Legal
- Privacy
- Regulation
type: Index
deliveryModel:
  model: unknown
  open_source: unknown
  commercial: false
  callable_host: false
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - repository-unlicensed
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/ccpa.png
access: 3rd-Party
created: '2025-01-01'
modified: '2026-09-05'
position: Consuming
description: 'The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), is a state
  statute that grants California residents rights over their personal information: the right to know, delete, correct, opt-out
  of sale/sharing, limit use of sensitive personal information, and non-discrimination for exercising privacy rights. It is
  enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General. Technical interoperability
  mechanisms include the Global Privacy Control (GPC) browser signal and the IAB Tech Lab US Privacy (USP) / Global Privacy
  Platform (GPP) signals for advertising technology. This index tracks the official regulatory resources, technical privacy
  signals, and commercial APIs that help businesses comply with CCPA/CPRA obligations.'
apis:
- aid: ccpa:global-privacy-control
  name: Global Privacy Control (GPC) Specification
  tags:
  - Browser Signal
  - Opt-Out
  - Standard
  humanURL: https://globalprivacycontrol.org/
  properties:
  - url: https://globalprivacycontrol.org/
    type: Website
  - url: https://privacycg.github.io/gpc-spec/
    type: Specification
  - url: https://github.com/privacycg/gpc-spec
    type: SourceCode
  description: Global Privacy Control is a browser-level signal that communicates a user's opt-out preference to websites.
    The California Attorney General has affirmed that GPC must be treated as a valid CCPA "Do Not Sell or Share" opt-out request.
- aid: ccpa:iab-gpp
  name: IAB Tech Lab Global Privacy Platform (GPP)
  tags:
  - AdTech
  - Consent
  - IAB
  - Signals
  humanURL: https://iabtechlab.com/gpp/
  properties:
  - url: https://iabtechlab.com/gpp/
    type: Documentation
  - url: https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform
    type: SourceCode
  - url: https://github.com/InteractiveAdvertisingBureau/USPrivacy
    type: LegacySpec
  - url: packages/ccpa-packages.yml
    type: Packages
  - url: packages/ccpa-packages.yml
    type: SDKs
  description: The IAB Tech Lab Global Privacy Platform (GPP) is the successor to the US Privacy (USP) string. It provides
    a standardized way to communicate user consent and opt-out signals between publishers, consent management platforms, and
    adtech vendors for CCPA, CPRA, and other jurisdictions.
- aid: ccpa:cppa-enforcement-resources
  name: California Privacy Protection Agency (CPPA) Resources
  tags:
  - Enforcement
  - Regulations
  - Rulemaking
  tags_raw:
  - Enforcement
  - Regulation
  - Rulemaking
  humanURL: https://cppa.ca.gov/
  properties:
  - url: https://cppa.ca.gov/
    type: Website
  - url: https://cppa.ca.gov/regulations/
    type: Regulations
  description: Official resources from the California Privacy Protection Agency, the body empowered by CPRA to implement,
    enforce, and publish regulations under the CCPA.
- aid: ccpa:ca-data-broker-registry
  name: California Data Broker Registry
  tags:
  - Data Brokers
  - Registry
  humanURL: https://oag.ca.gov/data-brokers
  properties:
  - url: https://oag.ca.gov/data-brokers
    type: Registry
  - url: https://privacy.ca.gov/drop-for-data-brokers/account-creation-fees-and-annual-registration/
    type: Registration
  description: Official California Attorney General registry of data brokers required to register under Civil Code section
    1798.99.80, providing a public list that consumers can use to submit opt-out requests.
- aid: ccpa:drop-data-broker-api
  name: CalPrivacy DROP Data Broker API
  tags:
  - Data Brokers
  - Delete Act
  - Deletion Requests
  - DROP
  - Regulator API
  humanURL: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/
  baseURL: https://api.drop.privacy.ca.gov
  properties:
  - url: openapi/ccpa-drop-databroker-api.yml
    type: OpenAPI
  - url: https://dropresources.blob.core.windows.net/apidocs/databroker_api.yaml
    type: Specification
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/
    type: Documentation
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/api-operations/
    type: APIReference
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/getting-started/
    type: GettingStarted
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/integration-workflow/
    type: Documentation
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/working-with-data/
    type: Documentation
  - url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/reference/
    type: Reference
  - url: https://databroker.drop.privacy.ca.gov/
    type: Portal
  description: The Delete Request and Opt-out Platform (DROP) Data Broker API is the statutory integration surface California's
    Delete Act requires of every registered data broker. Brokers call GET /data/download to retrieve a ZIP of CSV files holding
    SHA-256 hashed consumer deletion identifiers, match those hashes against their own records, act, then report a status
    per work item with POST /data/upload (2 Exempted, 3 Deleted, 4 Opted out, 5 Not found), correcting a prior filing with
    POST /data/amend. Operated by the California Privacy Protection Agency (CalPrivacy), authenticated with an X-API-KEY issued
    in the Data Broker Portal after annual registration and fee payment. OpenAPI 3.1.0, description version 1.2.0. Processing
    became mandatory for registered brokers on 2026-08-01.
common:
- type: VulnerabilityDisclosure
  url: security/ccpa-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/ccpa-domain-security.yml
- type: Website
  url: https://oag.ca.gov/privacy/ccpa
- type: Documentation
  url: https://oag.ca.gov/privacy/ccpa
- type: Regulator
  url: https://cppa.ca.gov/
- type: StatuteText
  url: https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&chapter=&article=
- type: Regulations
  url: https://cppa.ca.gov/regulations/
- type: FAQ
  url: https://oag.ca.gov/privacy/ccpa
- type: DataBrokerRegistry
  url: https://oag.ca.gov/data-brokers
- type: GPC
  url: https://globalprivacycontrol.org/
- type: GPP
  url: https://iabtechlab.com/gpp/
- name: Rights
  type: Rights
  data:
  - name: Right to Know
  - name: Right to Delete
  - name: Right to Correct
  - name: Right to Opt-Out of Sale
  - name: Right to Opt-Out of Sharing (Cross-Context Behavioral Advertising)
  - name: Right to Limit Use of Sensitive Personal Information
  - name: Right to Data Portability
  - name: Right to Non-Discrimination
- name: Applicability
  type: Applicability
  data:
  - name: Gross Annual Revenue > $25M
  - name: Personal Information of 100k+ California Residents
  - name: 50%+ Revenue From Sale of Personal Information
- name: Features
  type: Features
  data:
  - name: Notice at Collection
  - name: Privacy Policy Disclosure
  - name: Do Not Sell or Share Link
  - name: Limit Use of Sensitive PI Link
  - name: Verifiable Consumer Requests
  - name: Authorized Agent Requests
  - name: Opt-Out Preference Signal (GPC)
  - name: Service Provider / Contractor Contracts
  - name: Data Processing Addendum
  - name: Data Retention Disclosure
  - name: Risk Assessments (CPRA)
  - name: Cybersecurity Audits (CPRA)
  - name: Automated Decision-Making Disclosures (CPRA)
- name: UseCases
  type: UseCases
  data:
  - name: DSAR (Data Subject Access Request) Automation
  - name: Consent Management Platform (CMP)
  - name: Cookie Banner and Preference Center
  - name: Data Inventory and Mapping
  - name: Vendor Risk Management
  - name: Privacy Impact Assessments
  - name: Audit and Reporting
  - name: Global Privacy Control Handling
  - name: Data Broker Registration
- type: Authentication
  url: authentication/ccpa-authentication.yml
- type: OpenAPI
  url: openapi/ccpa-drop-databroker-api.yml
- type: Overlay
  url: overlays/ccpa-drop-databroker-api-overlay.yaml
- type: WellKnown
  url: well-known/ccpa-well-known.yml
- type: SecurityTxt
  url: well-known/ccpa-security.txt
- type: Security
  url: security/ccpa-vulnerability-disclosure.yml
- type: Conventions
  url: conventions/ccpa-conventions.yml
- type: Conformance
  url: conformance/ccpa-conformance.yml
- type: ErrorCatalog
  url: errors/ccpa-problem-types.yml
- type: Lifecycle
  url: lifecycle/ccpa-lifecycle.yml
- type: ChangeLog
  url: changelog/ccpa-changelog.yml
- type: Sandbox
  url: sandbox/ccpa-sandbox.yml
- type: Webhooks
  url: asyncapi/ccpa-drop-webhooks.yml
- type: DataModel
  url: data-model/ccpa-data-model.yml
- type: Packages
  url: packages/ccpa-packages.yml
- type: SDKs
  url: packages/ccpa-packages.yml
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/ccpa-llms.txt
- type: RateLimits
  url: rate-limits/ccpa-rate-limits.yml
- type: Plans
  url: plans/ccpa-plans-pricing.yml
- type: FinOps
  url: finops/ccpa-finops.yml
- type: DeveloperPortal
  url: https://privacy.ca.gov/drop-for-data-brokers/
- type: APIReference
  url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/api-operations/
- type: GettingStarted
  url: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/getting-started/
- type: Support
  url: https://privacy.ca.gov/drop-for-data-brokers/help/
- type: Blog
  url: https://privacy.ca.gov/about-us/blog/
- type: Pricing
  url: https://privacy.ca.gov/drop-for-data-brokers/account-creation-fees-and-annual-registration/
- type: SignUp
  url: https://databroker.drop.privacy.ca.gov/
- type: TermsOfService
  url: https://privacy.ca.gov/conditions-of-use/
- type: PrivacyPolicy
  url: https://privacy.ca.gov/privacy-policy/
- type: Complaints
  url: https://privacy.ca.gov/submit-a-complaint/ccpa-complaints/
- type: LawsAndRegulations
  url: https://privacy.ca.gov/laws-and-regulations/
- type: Announcements
  url: https://cppa.ca.gov/announcements/
- type: DataBrokerRegistryData
  url: https://cppa.ca.gov/data_broker_registry/complete-reg-data-brokers.csv
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
specificationVersion: '0.23'
x-enrichment:
  date: '2026-09-05'
  status: enriched
  artifacts_added: 20
  pass: local-v3

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/ccpa"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/ccpa/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/ccpa/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.