WebinarPix Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?Explore Now WebinarPix Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?Explore Now Pix Fraud 2026 — Are Your Fraud Controls Ready?Explore Gavel on AMLR rule bookAMLR applies 10 July 2027. See your stack against every obligationBook a Demo AMLR applies 10 July 2027. See your stack against every obligationBook A Demo AMLR applies 10 July 2027 — see your stackBook Demo Globe with pKYC, Onboarding, Screening and Transactions labelsShufti’s Glocal PlatformGlobal Coverage. Local Depth. Full Compliance Lifecycle.Explore More Global Coverage. Local Depth. Full Compliance Lifecycle.Explore More Glocal Platform — Global Coverage. Local Depth.Explore Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
Gavel on AMLR rule bookAMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027 — Find the GapsConsult Bank card and cashBank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification — Secure PayoutsSee How Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance — Verified Location, Verified IdentityBook Demo Journey Builder dot gridConfigure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Configure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Journey Builder — Configure Verification FlowsSee How Shufti MCP toggle with ChatGPT and ClaudeShufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP — Verification Tools Inside Claude or ChatGPTExplore

CCPA / CPRA

Shufti is a compliant service provider under California law

Under CCPA/CPRA, your verification provider is either a service provider operating under strict contractual restrictions, or a third party with rights to use your users' data broadly. Shufti is a service provider and uses identity verification data solely to provide the verification service, not for any secondary purpose, and never sold or shared. Shufti service provider agreement is included in every enterprise contract.

CCPA / CPRA certification badge

Certification Overview

What CCPA / CPRA Covers

CCPA (2018)

The California Consumer Privacy Act established consumer rights over personal information: the right to know what data is collected, the right to delete it, the right to opt out of its sale, and the right to non-discrimination. It created the service provider classification, a vendor who uses data only for the contracted service.

CPRA (2023 Amendment)

The California Privacy Rights Act significantly expanded CCPA. It created a new category, sensitive personal information, which explicitly covers biometric data, facial images, and identity documents. It added the right to limit use of sensitive personal information, strengthened enforcement by establishing the California Privacy Protection Agency, and tightened service provider obligations.

Why It Matters

If your verification provider lacks a CCPA-compliant service provider agreement, or cannot technically support a consumer deletion or access request, you cannot meet your CPRA obligations when a California resident submits a request. The California Privacy Protection Agency is actively enforcing CPRA against businesses whose vendors fail to deliver the required protections.

You have 45 days to respond to a verified consumer rights request

Shufti's API and admin console let you locate, export, or delete an individual's verification records and generate a deletion confirmation. That confirmation is your regulatory evidence that the request was fulfilled.

45 days Statutory response window

For CCPA consumer rights requests. If your verification vendor cannot support individual record deletion or export within that window, the compliance gap is yours to carry.

Certification Assurance

Independently Verified Compliance Standards

Standard

CCPA/CPRA coverage for biometric and identity document data classified as sensitive personal information.

Assessed By

Service-provider role defined contractually, not as a third party or data broker.

Scope

Deletion, access, and portability supported via API and admin console within the 45-day response window, with coverage.

Documentation

CCPA/CPRA service-provider provisions included in the standard enterprise contract, with no separate addendum required.

How Shufti Maintains It

Shufti CCPA/CPRA service provider provisions are in the standard enterprise agreement, you do not need to negotiate a separate addendum. The contract restricts our data use, prohibits data selling and sharing, commits us to specific security standards, and requires us to cooperate on consumer rights requests.

The same compliance approach extends to Virginia CDPA, Colorado CPA, Connecticut CTDPA, and Texas TDPSA, so one Shufti integration covers you across those frameworks without separate addenda.