CCPA/CPRA Compliance Verification

See where your site actually stands on CCPA.

We load your pages like a visitor, record what fires on the network, and cite the CCPA section behind every issue.

View sample report →
No card or account. Most scans finish in under 2 minutes. The grade and all 56 checks are free; the evidence and fixes unlock for $49.
A Privisy audit report for shop.example.com: a score of 63 (grade D), five pages scanned, and a critical finding that no Do Not Sell or Share link was found, with the evidence, the fix, and the §§ 7013, 7015 and 1798.135 citations.
A sample audit of a fictional storefront. Every finding carries its evidence, the fix, and the CCPA section it falls under.
checks in every full audit
56
audit domains: UI, trackers, GPC, and policy
4
lines of code to install on your site
0
to run the full audit, no account needed
$0

Your compliance tool grades its own work

A consent platform enforces the rules it was given. Whether those rules still hold on your live site today is a separate question, and it needs a separate source.

Configuration drift and piggybacking

Tags get added, vendors piggyback on other vendors, and a script that behaved at setup ships on its own release schedule. What was verified when your consent tool was configured is not automatically still true this quarter.

No legal safe harbor

In 2026, “I thought I was compliant” is no longer a valid legal defense. The California Privacy Protection Agency is actively issuing fines, and your CMP vendor won't cover them.

Independent verification

You wouldn't let a student grade their own test. An outside scan has no stake in the answer: it reports what your pages actually send, whether or not that matches what your setup intends.

What's inside your audit report

56 checks across four audit domains. Each tab shows its highest-severity checks; every full audit evaluates all of them.

Surface-level disclosures and opt-out mechanisms a regulator reviews first.

Do Not Sell or Share LinkBusinesses that sell or share personal information (or use/disclose sensitive PI beyond § 1798.121(a) purposes) must provide a clear "Do Not Sell or Share My Personal Information" link, a § 7015 Alternative Opt-out Link, or frictionless opt-out preference signal processing with the § 7025(g)(2) policy disclosures.
§ 7013, § 7015, § 1798.135critical
Privacy Policy LinkCCPA § 7011 requires the privacy policy to be posted online and reachable from a conspicuous link that uses the word "privacy".
§ 7011critical
Notice at CollectionCCPA § 7012 requires businesses to inform consumers, at or before the point of data collection, about the categories of PI collected, purposes of use, whether information is sold or shared, and retention periods.
§ 7012, § 1798.100high

+ 6 more UI checks in every full audit

View sample report

Prefer to work through it yourself first? Use the CCPA compliance checklist.

How it works

No SDK, no snippet, no access to your codebase. We audit your site from the outside, the way a regulator would. Most scans finish in under 2 minutes.

  1. Submit your URLs

    Enter the pages that matter most: checkout flows, signup forms, anywhere users hand over data.

  2. We run the audit engine

    Our scanner loads each page like a real visitor and checks it against the 2026 CCPA/CPRA standards.

  3. You get the report

    A comprehensive risk report with clear, actionable remediation items for legal and engineering.

Regulators are issuing real penalties

California is actively enforcing privacy law. The three actions below alone add up to $15.87M.

General Motors (OnStar)
May 2026
$12.75M

Sold drivers' geolocation and behavior data to brokers despite a privacy policy saying otherwise — the largest CCPA penalty to date.

The Walt Disney Company
February 2026
$2.75M

Opt-out toggles covered only one streaming service at a time, and Global Privacy Control signals were honored per-device instead of account-wide.

Ford Motor Company
March 2026
$375K

Required email verification before honoring opt-outs and kept selling data after consumers opted out; must now audit its tracking for GPC compliance.

Pricing

Every free scan is the full audit. Unlock the evidence and fixes for $49, or $348 a year for weekly monitoring.

Free Audit

Not ready to buy? Run the full audit on any URL for free and see the grade, the section scores and every check's name and severity. The evidence, tracker names and fixes unlock for $49. No card or account required.

Run a Free Scan
Single Audit
$49
One-time, per audit · unlocks this report

Know exactly where one site stands today: every tracker it loads, whether it honors GPC, and which policy disclosures are missing.

  • Unlocks the report you already ran: evidence, tracker names and fixes
  • 1 credit = 1 full audit of one URL (all 56 checks included)
  • Pay per audit. Unused credits never expire
  • Deep network-layer tracker analysis
  • Global Privacy Control (GPC) verification
  • Automated policy substance review
Run an Audit
Continuous MonitoringRecommended
$348
Per year · renews automatically until cancelled

Catch the tag that shipped last Tuesday. Your site is re-audited every week, so a new vendor or a broken opt-out shows up in days, not at the next annual review.

  • Automatic weekly re-audit of 1 domain
  • Every run is the full audit, all 56 checks
  • A dated report for every weekly run
  • Starting monitoring unlocks the report you already ran
  • Audits of other URLs use credits as usual
  • Cancel online any time from the billing portal; it stops the next renewal
Start Monitoring
Agency
Contact us
For teams auditing client sites

Auditing privacy compliance for several clients? Tell us how many sites you manage and we will put together a plan that fits.

  • Built for agencies and consultancies
  • Every audit is the same full 56-check engine
  • Volume pricing for multiple client sites. Tell us what you need
Talk to Us
FeatureFree AuditSingle AuditMonitoring
Compliance verdict + section scores
UI & banner checks (§ 7013, § 7011)Names + severityDetailed findingsDetailed findings
Third-party trackersLockedFull inventoryFull inventory
Network-layer tracker analysisLocked
Global Privacy Control (GPC) validation
Privacy policy substance review (31 checks)Names + severity
Unlocked report with remediation steps
Automatic weekly re-audit1 domain
Account requiredNoYesYes
1 credit = 1 full audit of one URL (all 56 checks included)

Common questions

Something else? Contact us.

Patrick Daly, Founder of Privisy
“I kept meeting companies that believed a CMP meant they were compliant. I built Privisy to give them an outside, network-level view of what their site actually sends.”
Patrick Daly, Founder of Privisy and marketing technologist

Know exactly where your site stands.

Run one scan and see what a regulator would see, before they do.

Run a Free Scan

More from Privisy