← Framework library

California Consumer Privacy Act, as amended by the CPRA

The duties of the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the CPPA's regulations, expressed as controls. Each cites the Civil Code section or regulation it derives from. Employee and business-contact data are in scope.

California Privacy Protection Agency (CPPA) and the California Attorney General · Cal. Civ. Code §1798.100 et seq. (CPRA amendments in force since 1 January 2023); CCPA Regulations, Cal. Code Regs. tit. 11, §7000 et seq., including the risk-assessment, cybersecurity-audit and ADMT rules effective 1 January 2026 · United States — California residents' personal information; applies to for-profit businesses meeting any threshold: annual gross revenue over $26,625,000 (2025–2026 CPI adjustment), buying/selling/sharing personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing · Official source

Many other US states now have comprehensive privacy laws modelled on similar ideas (opt-outs of sale and targeted advertising, sensitive-data consent, universal opt-out signals); a CCPA-ready programme covers much, but not all, of them. Dates and thresholds are as published by the CPPA; the monetary threshold is CPI-adjusted every odd-numbered year. Requirement text is paraphrased; the statute and regulations are authoritative and this tool is not legal advice.
21 of 21 controls
1798.100(a)-(b) Notice at collection high

At or before the point of collection, the business informs consumers of the categories of personal information (and sensitive personal information) collected, the purposes for which each is collected or used, whether it is sold or shared, and how long each category will be retained — and does not collect additional categories or use them for incompatible purposes without notice.

Transparency privacy-noticedata-retention
1798.100(c) Purpose limitation and data minimisation high

Collection, use, retention and sharing of personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection, and not further processed incompatibly.

Business obligations data-minimisation
1798.100(d) Contracts with service providers, contractors and third parties critical

Any sale, sharing or disclosure of personal information to a third party, service provider or contractor for a business purpose is made under an agreement that specifies the limited purposes, obliges the recipient to comply with the CCPA and provide the same level of protection, grants the business rights to take reasonable steps to ensure compliance and to stop unauthorised use, and requires notice if the recipient can no longer comply.

Business obligations vendor-managementthird-party
1798.100(e) & 1798.150 Reasonable security procedures critical

The business implements reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorised or illegal access, destruction, use, modification or disclosure. Consumers whose non-encrypted and non-redacted personal information is breached as a result of a failure to do so may sue for statutory damages.

Business obligations encryption-at-restaccess-control
1798.105 Right to delete high

Consumers may request deletion of personal information the business collected from them. The business deletes it from its records, notifies its service providers and contractors to delete, and notifies third parties to which it sold or shared the information — unless an exception in 1798.105(d) applies.

Consumer rights data-subject-rightsdata-deletion
1798.106 Right to correct medium

Consumers may request correction of inaccurate personal information, and the business uses commercially reasonable efforts to correct it, taking into account the nature and purposes of the information.

Consumer rights data-subject-rightsintegrity
1798.110 & 1798.115 Right to know and access high

Consumers may request the categories and specific pieces of personal information collected, the categories of sources, the business or commercial purposes, and the categories of third parties to whom it is disclosed, sold or shared — covering the preceding 12 months, and further back for information collected since 1 January 2022 unless impossible or disproportionate.

Consumer rights data-subject-rights
1798.120 Right to opt out of sale and sharing critical

Consumers may direct a business that sells personal information or shares it for cross-context behavioural advertising to stop, and the business must honour the opt-out and not ask again for at least 12 months. A business that does not sell or share must say so.

Opt-outs and sensitive data opt-out-of-saleconsent
1798.120(c)-(d) Opt-in consent to sell or share minors' information high

A business with actual knowledge that a consumer is under 16 may not sell or share their personal information unless the consumer (aged 13–15) or a parent or guardian (under 13) has affirmatively authorised it; wilfully disregarding age counts as actual knowledge.

Opt-outs and sensitive data childrenconsent
1798.121 Right to limit use of sensitive personal information high

Where a business uses or discloses sensitive personal information (such as SSN, account log-in with credentials, precise geolocation, racial or ethnic origin, health, sex life, biometric data, or contents of communications) for purposes beyond those permitted by regulation, consumers may direct it to limit that use.

Opt-outs and sensitive data data-classificationconsent
1798.125 Non-discrimination and financial incentives medium

Consumers may not be discriminated against — through denial of goods, different prices or quality — for exercising their rights. Any financial incentive or price difference tied to personal information requires a notice of financial incentive, opt-in consent that can be revoked, and a good-faith estimate of the value of the data.

Consumer rights data-subject-rights
1798.130(a)(1)-(2) Methods for requests and 45-day response high

The business offers two or more designated methods for submitting requests to know, delete and correct — including at minimum a toll-free number (online-only businesses with a direct relationship may offer only an email address) — verifies requests, and responds within 45 calendar days, extendable once by 45 days with notice.

Consumer rights data-subject-rights
1798.130(a)(5) Privacy policy content and annual update high

The online privacy policy describes consumers' rights and how to exercise them, the categories of personal information collected, sources, purposes, categories disclosed, sold or shared and to whom, and retention — and is updated at least once every 12 months.

Transparency privacy-notice
1798.130(a)(6) & Regs 7100 Training for staff who handle privacy inquiries medium

All individuals responsible for handling consumer inquiries about the business's privacy practices or CCPA compliance are informed of the requirements and of how to direct consumers to exercise their rights.

Business obligations training
1798.135 "Do Not Sell or Share" and "Limit the Use" links high

A business that sells or shares personal information provides a clear and conspicuous "Do Not Sell or Share My Personal Information" link, and one that uses sensitive personal information beyond permitted purposes provides a "Limit the Use of My Sensitive Personal Information" link — or a single Alternative Opt-out Link — on its homepage and in its privacy policy.

Opt-outs and sensitive data opt-out-of-saleprivacy-notice
Regs 7025 Honour opt-out preference signals (Global Privacy Control) high

A business that sells or shares personal information treats a browser opt-out preference signal such as Global Privacy Control as a valid request to opt out of sale and sharing for that browser or device and any known consumer, and may display whether the signal was honoured.

Opt-outs and sensitive data opt-out-of-saleconsent
Regs 7004 Symmetric choices and no dark patterns medium

Methods for submitting requests and obtaining consent use easy-to-understand language, offer symmetry in choice (declining is no harder than accepting), avoid confusing language, interactive elements or manipulative design, and require minimal steps; agreement obtained through dark patterns is not consent.

Business obligations consent
Regs 7101 Records of consumer requests kept for 24 months medium

The business keeps records of consumer requests made under the CCPA and how it responded for at least 24 months, with reasonable security, and does not use them for other purposes.

Business obligations records
Regs (risk assessments) Risk assessments for significant-risk processing high

From 1 January 2026, a business must conduct a risk assessment before processing that presents significant risk to consumers' privacy — including selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for significant decisions, and certain profiling or AI training — and must submit an attestation and summary to the CPPA by 1 April 2028 for assessments conducted in 2026–2027.

Regulations (2026+) dpiarisk-assessment
Regs (cybersecurity audits) Annual independent cybersecurity audit medium

A business whose processing presents significant risk to security — for example one that derives 50% or more of revenue from selling or sharing personal information, or meets the revenue threshold and processes large volumes of personal or sensitive information — must complete an annual independent cybersecurity audit and certify completion to the CPPA, with first certifications due 1 April 2028, 2029 or 2030 depending on revenue.

Regulations (2026+) auditsecurity-testing
Regs (ADMT) Automated decision-making technology for significant decisions high

From 1 January 2027, a business that uses automated decision-making technology to make significant decisions about consumers (financial or lending, housing, education, employment or healthcare) must give a pre-use notice, offer a right to opt out (or a qualifying human appeal) and respond to requests for access to information about the ADMT's use.

Regulations (2026+) data-subject-rights