CCPA Compliant Consumer Data Platform: What It Covers
A vendor's CCPA compliance covers its own systems. Once you export an audience, keeping that file compliant is your job.
A CCPA compliant consumer data platform handles California consumers' personal information the way the California Consumer Privacy Act (as amended by the CPRA) requires: it registers as a data broker where the law calls for it, gives consumers a working way to opt out and request deletion, honors Global Privacy Control signals, and keeps people who opted out out of future data. The little-known part is where that compliance ends. It covers the vendor's own systems. The moment you export an audience, keeping that file compliant becomes your job, and that's where most teams get caught.
What CCPA actually requires, in plain terms
The CCPA gives California residents a set of rights over their personal information. The CPRA, approved by voters in 2020, expanded them and created the California Privacy Protection Agency to enforce them. Together they give consumers the right to:
- Know what personal information a business collects about them, and get access to it
- Request deletion
- Correct inaccurate information
- Opt out of the sale or sharing of their information (sharing means cross-context behavioral advertising)
- Limit how sensitive personal information is used
- Not be discriminated against for using any of those rights
For a consumer data platform, almost all of that lands on two verbs: opt out and delete. A data provider's whole product is personal information collected from sources other than the consumer, which is why California treats many of them as data brokers with extra obligations on top of the CCPA.
None of this is legal advice. State privacy laws keep changing, the CCPA has its own thresholds for which businesses it covers, and your counsel should decide how it applies to you. What follows is the practical side: what to check on a vendor, and what stays on your desk.
What to check on the vendor side
A badge on a pricing page doesn't tell you much. Published documents do. Here's what to look for before signing with any consumer data provider:
A public opt-out route a real person can use. A web form, an email address, ideally a phone number. If you can't find it in two clicks from the footer, consumers can't either.
Global Privacy Control support. GPC is a browser signal that California treats as a valid opt-out request. A compliant provider says plainly that it recognizes it.
Data broker registration and DROP. California's Delete Request and Opt-out Platform (DROP), run by the California Privacy Protection Agency, lets a resident send one deletion request to every registered data broker. Ask any vendor whether it's registered and how it processes DROP requests.
Suppression, not just deletion. When someone opts out, a good provider keeps a do-not-serve record so that person doesn't reappear in the next refresh. Without that, a deleted record can quietly come back.
Prohibited uses in writing. Look for an acceptable use policy that names what you can't do with the data, especially around sensitive information and eligibility decisions.
Exact Match publishes each of these. Its Consumer Privacy Rights Notice lists an online request form, a privacy email and a toll-free number, says it recognizes legally required universal opt-out signals including Global Privacy Control, and explains that it may keep opted-out people on a suppression or do-not-serve list. It also states that, beginning August 1, 2026, California data brokers must process DROP deletion requests and check the platform at least every 45 days, and that it processes valid DROP requests that match its records.
The part that stays with you
A vendor being CCPA compliant doesn't make your campaigns compliant. It means the data was handled correctly up to the point you received it.
Most people don't realize how literal that is. After that, you're the one holding a file of people. If one of them opts out next week, the vendor can suppress them in its own graph, but it can't reach into your CRM, your ad account or the client's email platform. You have to.
Exact Match's Acceptable Use Policy spells this out more directly than most. Section 12 requires customers to:
- Honor suppression lists, do-not-contact lists, do-not-sell-or-share lists and Global Privacy Control signals on an ongoing basis
- Stop using a person's data for anything the law doesn't allow after a deletion request, remove them from every audience, segment and model built from it, and push that suppression to every connected system
- Never re-target, re-enrich or re-append anyone who has opted out
- Act on suppression instructions Exact Match sends, within the time the law requires, and confirm it when asked
- Pass those same obligations down to downstream customers and agents
That last point matters most for agencies. If you build audiences for clients, their systems are downstream of yours. A suppression that stops at your account isn't a suppression.
Exact Match's subaccounts help on the organizational side: each client gets its own scoped identity with isolated data under one parent API key, and the platform keeps usage history and audit logs. That keeps one client's audiences apart from another's. It doesn't propagate an opt-out into a client's CRM for you. Nothing does that automatically, so build it into your process.
Sensitive information and prohibited uses
The CPRA added a separate category for sensitive personal information, and this is where a compliant vendor's rules get strict. Exact Match's AUP bars using its data around sensitive categories altogether, and says consent doesn't change that.
The same policy says its services aren't designed or authorized for advertising, targeting or audience building around housing, employment, credit or insurance opportunities, and prohibits that use unless Exact Match has authorized it in writing. If you work in a regulated vertical such as real estate, read those sections before you build a single segment.
Minimize what you upload
One habit that cuts risk on the input side: don't send more than you need. When you upload a list to enrich it, Exact Match accepts email and phone either in plaintext or hashed as MD5, SHA-1 or SHA-256, so your team doesn't have to pass raw contact details around to get a match. Names and addresses are plaintext only. Run a small test batch first to confirm your hashing matches. The what is a hashed email guide covers how to normalize before you hash.
How this differs from GDPR
People often lump the two together. They're different laws for different people. CCPA covers California residents, while GDPR covers people in the EU and EEA. Exact Match is a U.S. consumer data platform, CCPA compliant, with U.S. data only, and it doesn't claim GDPR compliance. If your audiences are European, the gdpr compliant consumer data platform guide covers what to look for instead.
The bottom line
A long, dull privacy notice is worth more than a shiny compliance badge. The notice tells you how opt-outs flow, what gets suppressed and what you've agreed to. The badge tells you nothing you can check. And price shouldn't be the filter that decides it; if you're comparing options on cost, the cheapest consumer data api breakdown is worth reading alongside this one.
Exact Match runs its four products (Audience ID, Clean ID, Predict ID and Site ID) on one consumer data graph of 250M+ verified U.S. consumer profiles, refreshed daily. Pricing is shared in a consultation, so the next step is to book a demo and walk through how suppression would work with your own stack.
Frequently Asked Questions
What makes a consumer data platform CCPA compliant?
It gives California consumers a working way to know about, delete, correct and opt out of the sale or sharing of their data, honors Global Privacy Control signals, registers as a data broker where required, and keeps opted-out people suppressed so they don't return in later refreshes. It should also publish an acceptable use policy that restricts sensitive and eligibility-related uses.
If my data vendor is CCPA compliant, am I compliant too?
Not automatically. The vendor's compliance covers its own systems. Once you export an audience, you're responsible for honoring opt-outs, deletion requests and suppression instructions in your CRM, ad accounts and email tools. Agencies also need to pass those obligations to client systems. This isn't legal advice, so confirm your own obligations with counsel.
Is Exact Match CCPA compliant?
Yes. Exact Match is a CCPA compliant U.S. consumer data platform with U.S. data only. It publishes a Consumer Privacy Rights Notice with an opt-out form, privacy email and toll-free number, recognizes Global Privacy Control signals where the law requires, and processes valid California DROP deletion requests that match its records. Its Acceptable Use Policy sets out the suppression duties customers take on.
What happens when someone opts out after I've exported their data?
Under Exact Match's Acceptable Use Policy, you must stop using that person's data for anything the law doesn't allow, remove them from every audience and segment built from it, and never re-target or re-enrich them. Exact Match may also send suppression instructions, which you need to apply within the time the law requires and confirm when asked.
Walk Through Suppression With Your Stack
One Unlimited plan: every product, every feature, unlimited credits, no per-seat fees. Book a short consultation to get your pricing.