CCPA compliance discussions tend to focus on the consumer-facing side, opt-out links and privacy policies, while the data collection side – where personal information actually enters an organization’s systems – gets less attention despite being where several of the law’s obligations attach directly. The California Attorney General’s CCPA page confirms businesses have up to 15 business days to respond to a consumer opt-out request, a timeline that depends on being able to actually locate and act on the data a specific consumer’s forms have generated.
Does CCPA Apply to Your Organization?
CCPA generally applies to for-profit businesses collecting California residents’ personal information once they cross a size or data-volume threshold, roughly $25 million in annual gross revenue, handling data belonging to 50,000 or more consumers, households, or devices in a year, or earning at least half of annual revenue from selling personal information. Data collection teams at qualifying businesses need to treat every form that captures California residents’ personal information as in scope, not just forms explicitly labeled as collecting sensitive data.
What This Means at the Point of Collection
A few specific things need to be true about a data collection process for CCPA compliance to hold up. Notice at or before collection, meaning the respondent needs to know what categories of personal information are being collected and why before they submit the form, not buried in a separate privacy policy they were never directed to. The ability to locate a specific consumer’s data quickly, which depends on how well-organized and retrievable form submissions are, not just whether the data exists somewhere in the system. And a working, easy-to-find method for consumers to submit opt-out, access, or deletion requests, which the AG’s office has specifically flagged as a common point of business non-compliance.
Building Response Capability Into the Collection Process
The 15-business-day response window for opt-out requests, and similar timelines for access and deletion requests, means data collection teams need to be able to retrieve a specific individual’s records quickly, not run a manual search across scattered spreadsheets and disconnected tools. Role-based permissions that control who can access personal information, combined with a searchable, centralized record of submissions, are what actually make these response timelines achievable in practice.
Where FormAssembly Fits
FormAssembly gives data collection teams the infrastructure CCPA compliance depends on at the point of collection: role-based permissions that control access to personal information, a complete audit trail showing what was collected and when, and forms that connect directly to Salesforce so a specific consumer’s data is retrievable quickly rather than scattered across disconnected exports. For organizations building or auditing a CCPA-compliant data collection process, that combination of access control, retrievability, and audit depth is what turns a written policy into something the team can actually execute against a 15-business-day deadline.
This overview is provided for general informational purposes and is not legal advice; organizations should consult qualified counsel to confirm CCPA obligations specific to their business.
Review FormAssembly’s Compliance Certifications
FormAssembly is built for organizations that operate under regulatory scrutiny.