← CCPA/CPRA · Business obligations
Regs 7101 — Records of consumer requests kept for 24 months
medium
records
Requirement
The business keeps records of consumer requests made under the CCPA and how it responded for at least 24 months, with reasonable security, and does not use them for other purposes.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
records of requestsrequest logrequests loglog of requestsrecord of requestsrecords of consumer requestsrequest recordslog of consumer requestsrecord of consumer requestsrequests and our responses
Required element 2 — any one of
24 monthstwo years2 yearsretain…keptmaintain…
Supporting terms — specificity signals
regs 7101regs 7102metrics10 million
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(2) | Accountability | records |
| GDPR | Art.30 | Records of processing activities | records |
| SOC 2 | CC2.1 | Quality information for internal control | records |
| ISO 27001 | A.5.31 | Legal, statutory, regulatory and contractual requirements | records |
| PCI DSS 4.0.1 | 12.5.2 | PCI DSS scope documented and confirmed annually | records |
| NDPA 2023 | s.44 | Registration as a data controller or processor of major importance | records |
| NDPA 2023 | GAID Art.10 | Compliance audit returns and records of processing (GAID 2025) | records |
| ISO 27001 | A.5.28 | Collection of evidence | records |