Your Salesforce Org Has Three CCPA/CPRA Gaps
average cost per manually processed DSAR in Salesforce
Section 1798.105 requires deletion within 45 days. Most Salesforce orgs handle delete requests manually: SOQL queries to find related records, legal review of running contracts, cascade deletion in the right order. At 50+ requests/month, manual processing consumes weeks of admin time. A missed record means you have not honored the deletion request.
“It's been a long project for me. It's taken me two years. I'm looking forward to getting this done. Go live this quarter hopefully.”
Salesforce Admin
of Salesforce data is obsolete and creating unnecessary CCPA retention liability
CPRA requires data minimization: don't keep what you no longer need. Your org likely has no automated retention policy. Data from closed deals, expired contacts, and lapsed customers accumulates indefinitely. Every obsolete record is an unnecessary CCPA obligation. When California AG audits your retention practices, 'we had no system' is not a defense.
“Obsolete records pile up because nobody owns the delete button. When the AG asks how you minimize data, spreadsheets are not an answer.”
Compliance Lead
per intentional CPRA violation. California AG enforcement actively fines companies.
CCPA/CPRA enforcement is active. The California Privacy Protection Agency (CPPA) issued enforcement actions in 2023 and 2024. Doordash: $375K. Sephora: $1.2M. Honda: $632K. These are not edge cases. They are the cost of normal non-compliance. Your Salesforce org with California consumer records and no deletion automation has real exposure on every unfulfilled request.
“Taking data out is always something that makes me anxious - I want to do it right.”
Data Operations Lead
Three Obligations Every California-Touching Salesforce Org Must Meet
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to businesses meeting revenue or data volume thresholds that collect personal data from California residents. Three rights create specific Salesforce obligations:
Section 1798.105
Right to Delete
California consumers can demand deletion of their personal data. Your team must delete within 45 days, including related records. In Salesforce, this means cascade deletes that don't break Opportunities, Cases, or active Contracts.
Privacy Rights AutomationSection 1798.120
Right to Opt-Out of Sale/Sharing
Consumers can opt-out of data sale or sharing for cross-context behavioral advertising. Your team must honor opt-outs within 15 business days and maintain suppression lists. In Salesforce, this means marking records and suppressing them from marketing workflows.
Consent ManagementSection 1798.100
Right to Know + Data Minimization
Your org must disclose what data it collects, why, and for how long. CPRA adds data minimization: don't retain personal data beyond its purpose. Retention schedules per object type with automated deletion are required.
Data Retention ManagerCivil Code §1798.155, §1798.150
CCPA / CPRA penalties, 2025 figures
The California Privacy Protection Agency adjusts these amounts for inflation every two years. The figures below took effect on 1 January 2025 and apply per violation — a single incident can involve thousands of violations.
| Breach | Section | Maximum |
|---|---|---|
| Any violation of the CCPA (administrative fine or civil penalty) | §1798.155(a), §1798.199.90(a) | $2,663 per violation |
| Intentional violation, or any violation involving the personal information of a consumer under 16 | §1798.155(a), §1798.199.90(a) | $7,988 per violation |
| Private right of action after a data breach caused by failure to maintain reasonable security — statutory damages | §1798.150(a)(1)(A) | $107 to $799 per consumer per incident, or actual damages |
Source: California Privacy Protection Agency — 2025 increases for CCPA fines and penalties (17 December 2024). Figures last checked . Base statutory amounts were $2,500, $7,500 and $100–$750. The next CPI adjustment is due January 2027.
Three Products. Three Rights. One Platform.
Section 1798.105: Right to Delete
Privacy Rights Automation1-Click Deletion With Cascade Logic
Fulfills deletion requests in 1 click. Handles cascade deletes (Contacts, Cases, Contracts, Opportunities) without breaking data integrity. Respects running contracts: won't delete what you can't legally delete yet. Generates audit trail proving the deletion.
Section 1798.100: Data Minimization
Data Retention ManagerAutomated Retention Schedules Per Object Per Jurisdiction
Set CCPA-compliant retention rules once. Manager runs automated deletion jobs on schedule with complete audit trail. Handles multi-state complexity (CCPA + GDPR + HIPAA) simultaneously. No manual scripts, no admin overhead.
Section 1798.120: Right to Opt-Out
Consent ManagementOpt-Out Suppression Lists Across Salesforce
Marks records with consent status and suppresses them from marketing campaigns and data sharing workflows. Integrates with existing Salesforce marketing automations. Maintains complete consent history for audit purposes.
Key Takeaways
CCPA 45-day deletion window met with automated cascade deletion across all Salesforce objects
CPRA data minimization: automated retention policies delete obsolete California consumer records
Opt-out of sale and sharing automated, consent records enforce downstream data processing
DSAR portability fulfilled as PDF, CSV, JSON, or Excel, configurable per request type
California Privacy Protection Agency enforcement is active, automated compliance reduces exposure
Works across multiple Salesforce orgs, multi-org enterprise support built-in
Frequently Asked Questions
CCPA Section 1798.105 requires businesses to delete a California consumer's personal data on request within 45 days (extendable to 90 with notice). In Salesforce, this means finding all records tied to that consumer and deleting them in the correct order, without breaking Opportunities, Cases, or active Contracts. Privacy Rights Automation handles the cascade delete logic and generates an audit trail proving the deletion was completed.
CPRA (effective January 2023) amends and strengthens CCPA. Key additions: data minimization requirements (delete data you no longer need), a new right to correct inaccurate data, stricter rules on sensitive personal information, and creation of the California Privacy Protection Agency (CPPA) as a dedicated enforcement authority. If you were compliant with original CCPA, you still need to address data minimization and sensitive data rules added by CPRA.
CCPA applies to for-profit businesses that do business in California AND meet at least one threshold: (1) $25M+ annual gross revenue, (2) buy/sell/receive/share personal data of 100,000+ California consumers or households annually, or (3) derive 50%+ of annual revenue from selling personal data. If you have a Salesforce org with California customer data and meet any threshold, CCPA applies.
GDPR covers EU/UK residents; CCPA covers California residents. Both require deletion on request and data minimization, but with different timelines (GDPR: 30 days; CCPA: 45 days) and different exemptions (GDPR has broader legitimate interest; CCPA has specific business purpose exemptions). Privacy Rights Automation and Data Retention Manager handle both simultaneously. You set the rules per jurisdiction and the platform applies them correctly.
Privacy Rights Automation: 3-4 weeks. Data Retention Manager: 2-3 weeks. These are clicks-not-code implementations, no Apex development required. Cloud Compliance guides you through the configuration over Zoom. We never need direct access to your data.
The California Privacy Protection Agency (CPPA) and California AG have issued enforcement actions in 2023-2024: Doordash ($375K for data broker violations), Sephora ($1.2M for opt-out failures), Honda ($632K for CCPA violations). These fines are based on willful violations, not technical errors. Organizations with no deletion automation, no opt-out mechanism, and no data minimization policy are at the highest risk.
Related Compliance Solutions
GDPR Compliance for Salesforce
EU/UK privacy regulation automation for Salesforce.
Privacy Rights Automation
1-click DSAR fulfillment with cascade-delete logic.
Data Retention Manager
Automated retention schedules per object per jurisdiction.
For Data Privacy Officers
How Cloud Compliance helps DPOs meet cross-regulation mandates.


