Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

US Privacy Laws (CCPA / CPRA)

There is no single United States privacy law, which is exactly the problem. California came first and remains the reference point, and a Malaysian company serving US consumers or acting as a service provider to a US business usually meets California's regime before any other. This day covers the California Consumer Privacy Act as amended by the California Privacy Rights Act, sets out what a service provider contract has to say, and then places the other state laws around it so you can see what generalises and what does not.

Programme Agenda

Does It Apply to You?

The applicability thresholds for a business, and the separate position of a service provider or contractor processing on behalf of one. Why many Malaysian companies are caught contractually rather than directly.

The Vocabulary That Trips People Up

Consumer, business, service provider, contractor and third party. Personal information as defined in California, which is broader than most teams expect, and the sensitive personal information category added by the CPRA.

Selling and Sharing

Why analytics tags and advertising pixels can constitute a sale or a share even with no money involved, and what that triggers. The Do Not Sell or Share link and where it has to appear.

Consumer Rights and Response Mechanics

Know, delete, correct, opt out, and limit the use of sensitive personal information. Verification, the 45-day response window and its extension, and the two required submission methods.

Opt-Out Preference Signals

Global Privacy Control and the obligation to honour a browser-level signal. What that means for a website operated from Malaysia serving Californian visitors.

Service Provider Contract Terms

The specific clauses California requires in a contract for a recipient to qualify as a service provider rather than a third party, and the consequences of falling outside that definition.

The Wider State Landscape

Virginia, Colorado, Connecticut, Texas and the others: the common structure most of them share, the points where California remains an outlier, and a practical strategy for covering several states without running several programmes.

Request Handling Workshop

Participants build a consumer rights request workflow covering intake, verification, search, response and record keeping, sized for their own organisation.

Learning Outcomes:
Determine whether you are caught as a business, a service provider, or neither
Apply California's definitions of personal information and sensitive personal information correctly
Recognise when advertising and analytics activity constitutes a sale or a share
Handle the full set of consumer rights within the statutory timeline
Honour opt-out preference signals on a website serving Californian consumers
Review a service provider contract for the clauses California requires
Position the other state privacy laws against California and plan multi-state coverage

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Compliance and legal staff, digital marketing and web teams, and account managers at Malaysian companies selling to US consumers or providing outsourced services to US businesses. Ecommerce operators and technology service providers make up most attendees.

Signing it is necessary but not sufficient. The addendum imposes obligations you then have to be able to meet, particularly on deletion, retention limits and onward transfer. The programme covers what those commitments require operationally.

One module places them against California, covering the structure most of them share and where California diverges. The depth is on California because it is both the strictest in several respects and the one most Malaysian companies meet first.

No. It is compliance training. Questions about your specific applicability, and any question touching enforcement or litigation risk, should go to US-qualified counsel.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Data Protection and Privacy Law