CCPA ENFORCEMENT GAP REPORT

Everyone reports volume.
No one cryptographically verifies it.

We reviewed public CCPA transparency disclosures from the first reporting cycle in 2020 through the 2025 reports published this year. Companies report how many deletion requests they received and how fast they responded. None of the companies we reviewed can cryptographically verify the data was actually removed.

10M+
CA consumers — the threshold that makes metrics reporting mandatory
4.3M
Deletion requests in the first reporting cycle alone (IAPP review)
22 days
Avg. response time, first-cycle Fortune 500 review (IAPP)
0
Reviewed companies providing cryptographic deletion proof — any reporting year
🔓

The Enforcement Gap

CCPA Requirement: Report deletion request volumes and response times.
CCPA Does NOT Require: Cryptographically prove deletions actually happened.
The Result: Self-reported metrics. None of the companies reviewed provides independent verification — and users have no cryptographic proof their data is gone. That's the gap Adworth's State-Persistence Monitor and Invisibility Ledger are designed to close.

Company
Know Requests
Delete Requests
Denied
Avg. Days
Verified?
Google
Big Tech
~9M (self-svc)
~60.9M (self-svc)
—
14–42 (CCPA)
None
Meta
Big Tech
—
—
—
—
None
Apple
Big Tech
—
—
—
—
None
Amazon
Big Tech
—
—
—
—
None
Microsoft
Big Tech
—
—
—
—
None
Airbnb
Travel
31,971
138,864
—
18.2
None
Slack
SaaS
—
—
—
—
None
Capital One
Finance
390 (CA)
248 (CA)
100% (deletes*)
7.9–13.5
None
TransUnion
Data Broker
—
—
—
—
None
Walmart
Retail
—
—
—
—
None
Square
FinTech
—
—
—
—
None
LinkedIn
Big Tech
—
—
—
—
None
TikTok
Social Media
—
—
—
—
None
Adworth℠
Consent Infrastructure
—
—
—
Instant
✓ Crypto

* GLBA-exempt institutions typically deny more requests. — = data not broken out in published report. Self-svc = includes self-service tool usage, not CCPA-specific requests only. All data from publicly available CCPA transparency disclosures; reporting years vary by row, from the first cycle (calendar 2020) through calendar-2025 reports published by July 1, 2026 — per-row sourcing maintained in our verification log. Adworth row reflects consent grants and revocations recorded cryptographically in real time on the Adworth rail — live today. Broker-side deletion enforcement (Removal Payload Engine) generates signed, legally cited notices; automated delivery is on the roadmap.

Data Source & Methodology

All figures are sourced from publicly available CCPA transparency reports published by each company, spanning multiple reporting cycles — from the first (calendar year 2020) through the most recent (calendar year 2025, published by July 1, 2026); reporting years vary by company. The CCPA metrics reporting obligation applies to businesses that process personal information of 10 million or more California residents annually, as required by California Civil Code § 1798.185(a)(7). Companies are required to publish these metrics by July 1 each year. Some companies report California-specific data; others report all U.S. requests. Where companies include self-service tool usage alongside CCPA-specific requests, this is noted. “Verified?” indicates whether the company provides any cryptographic or independently auditable proof that deletion was executed — not merely that a request was acknowledged.

Aggregate statistics methodology. The top-of-page figures are drawn from published sources: the 10-million-consumer reporting threshold comes from the CCPA regulations (Cal. Civ. Code § 1798.185(a)(7)); the 4.3M deletion-request and 22-day response-time figures come from the IAPP’s review of Fortune 500 companies’ first-cycle (calendar 2020) CCPA metrics disclosures; and the zero-verification finding reflects our row-level review of company disclosures across reporting years. Methodology questions are welcome — contact with subject line “CCPA Gap Methodology.”

Disclaimer: Adworth℠ LLC is not affiliated with any company listed on this page. All data is sourced from publicly available CCPA transparency reports that companies are required to publish under California Civil Code § 1798.185(a)(7). “Verified?” reflects whether the company provides cryptographic or independently auditable proof of deletion execution — not whether the company complied with CCPA response requirements. This page is for informational and research purposes only and does not constitute legal advice.

Key Findings

What the reports don’t tell you

Every company below passed the compliance checkbox. None of them can prove your data is actually gone.

🗑️
0%

Verification Rate

Not a single company provides cryptographic proof that data was actually removed. “Complied with” means they acknowledged the request — not that they can prove it was executed.

⚠️
Thousands

Denials on Vague Grounds

Across all reporting companies, denials citing "other grounds" or unclear justifications are common. No independent audit exists to verify these claims industry-wide.

🔑
5 Systems

Adworth’s Answer

The State-Persistence Monitor, Invisibility Ledger, Consent API, Governance Engine, and Removal Payload Engine — five patent-pending systems that make verification automatic and cryptographic.

The Solution

Deletion claims are self-reported.
We make them cryptographically verifiable.

Regulators don't accept "we trust them." They want proof. We provide it — mathematically.

Join the Waitlist →