CCPA / CPRA-compliant AI vendors
AI vendors that publicly attest to CCPA/CPRA compliance, with documented opt-out, deletion, and limit-use mechanisms for California residents.
The California Consumer Privacy Act and its 2020 amendment (CPRA) impose specific obligations on businesses processing personal information of California residents — opt-out of sale or sharing, deletion rights, the right to limit use of sensitive personal information, and disclosure obligations. The California Privacy Protection Agency enforces these requirements. The vendors below have publicly attested to CCPA/CPRA compliance.
Vendors with CCPA / CPRA
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Adobe
Score 13.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
SAP
Score 16.63 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Nuance (Microsoft)
Score 20.86 · moderate
Writer
Score 20.93 · moderate
Mistral AI
Score 21.81 · moderate
AI21 Labs
Score 22.34 · moderate
Workday
Score 22.45 · moderate
Mosaic (Databricks)
Score 22.6 · moderate
Nvidia
Score 22.63 · moderate
SentinelOne
Score 22.96 · moderate
Scale AI
Score 23.3 · moderate
Hugging Face
Score 24.05 · moderate
Snowflake
Score 24.36 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
SambaNova
Score 24.5 · moderate
PolyAI
Score 24.72 · moderate
Palantir
Score 25.09 · moderate
Databricks
Score 25.4 · moderate
Cloudflare
Score 25.89 · moderate
Slack
Score 26.47 · moderate
GitHub Copilot
Score 27.12 · moderate
Vanta
Score 27.24 · moderate
Zoom
Score 27.35 · moderate
Atlassian
Score 28.51 · moderate
Synthesia
Score 29.28 · moderate
Kensho (S&P Global)
Score 29.4 · moderate
Khanmigo (Khan Academy)
Score 29.49 · moderate
Casetext
Score 29.77 · moderate
CoreWeave
Score 29.93 · moderate
Stripe
Score 29.97 · moderate
Harvey
Score 30.27 · moderate
LexisNexis
Score 30.29 · moderate
Arize AI
Score 30.6 · moderate
Grammarly
Score 30.74 · moderate
Moveworks
Score 30.84 · moderate
Zendesk
Score 30.94 · moderate
Galileo
Score 30.97 · moderate
Bloomberg
Score 31.1 · moderate
Weights & Biases
Score 31.11 · moderate
Buyer checklist
- Verify the vendor's privacy policy includes the CCPA-required disclosures (categories collected, sources, business purposes, third-party sharing).
- Confirm a working "Do Not Sell or Share My Personal Information" mechanism exists.
- Ask how the vendor handles requests to limit use of sensitive personal information for AI training.
- For data brokers, verify registration with the California Privacy Protection Agency.
- Map your own CCPA exposure — if you're B2B, employee and contact data are now in scope.
Compliance is necessary, not sufficient. Holding CCPA / CPRA is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.