Evidence standards

CCPA website evidence review: tracking, disclosures, and GPC

A website scan can help identify tracking vendors, public disclosures, opt-out surfaces, and observable GPC behavior for CCPA review. It cannot establish whether the law applies to a business, determine every downstream data use, or certify compliance.

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

Start with applicability and context

California’s Attorney General describes consumer rights under the CCPA, including opting out of sale or sharing and using a user-enabled GPC signal. A qualified reviewer must assess applicability and obligations in the business’s actual context.

Keep the site, visitor region, scan time, and public-page coverage attached to the evidence. A result from one page or region cannot stand in for all visitor journeys.

Primary sources:California Attorney General: CCPA

Review observable tracking and disclosures

Identify the retained vendor requests, cookies or storage, and relevant policy excerpts. Ask the implementation and privacy owners to reconcile observed activity with intended purposes, vendor arrangements, and public descriptions.

A vendor’s presence does not independently prove a sale or sharing of personal information. Missing or inaccessible policy evidence is a coverage limitation, not automatic proof of a disclosure failure.

Test GPC separately from banner choices

Compare equivalent fresh passive sessions with and without GPC. Verify actual signal delivery before interpreting response. Keep a visible Reject control, a completed click, a confirmed refusal, and an observable GPC response as distinct facts.

No observable response describes the evidence within a bounded test. Indeterminate delivery or incomplete comparison must stay unknown. Neither result alone establishes a legal conclusion.

Primary sources:GPC testing walkthrough

Build an evidence packet for review

Include the target and region, retained requests or storage identities with sensitive values removed, policy references, control observations, GPC proof, contract version, and coverage limitations. Assign follow-up questions to the responsible owner.

Review authenticated experiences, server-side handling, consumer request workflows, contracts, and other regions separately. They are beyond what an unauthenticated public-page scan can establish.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.