HomeFrameworksInformation Security & PrivacyCCPA/CPRA

Framework  Information Security & Privacy

CCPA/CPRA

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, is California's general privacy law for for-profit businesses that handle personal information about California residents.

It creates consumer rights (to know, delete, correct, opt out of sale or sharing, and limit use of sensitive data) and obligations for businesses, service providers and contractors.

Regulations approved on September 22, 2025 and effective January 1, 2026 added three major obligations: documented privacy risk assessments for high-risk processing, annual independent cybersecurity audits for larger businesses, and rules for automated decision-making technology (ADMT), whose consumer-facing requirements apply from January 1, 2027.

What must exist in writing: a privacy policy and notice at collection, a documented process for handling consumer requests within the statutory deadlines, service provider and contractor contracts with the required terms, records of requests and responses, risk assessments for covered processing (with the first attestation and summaries due to the CPPA by April 1, 2028), and, for businesses over the audit threshold, an annual cybersecurity audit report by an independent auditor with a certification of completion filed with the CPPA on a phased schedule starting April 1, 2028.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPrivacy procedure v3by name, on record
Do Not Sell Do Provewith AllyMatter
Opt In the Modern WayEvery privacy procedure, acknowledged by the staff who handle requests
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every request handler on record
Who read which version, and when
03
Show the agency the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

For-profit businesses doing business in California that meet one of three thresholds: annual gross revenue above $25 million (inflation-adjusted; $26.625 million from January 1, 2025), buying, selling or sharing personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.

Service providers and contractors are bound by contract. The cybersecurity audit applies to businesses over the revenue threshold that process personal information of 250,000 or more consumers or households or sensitive information of 50,000 or more, and to businesses earning half their revenue from selling or sharing.

What the assessor asks to see

Privacy policy and notices at collection; data inventory and processing purposes; consumer request logs with response times and metrics; opt-out and Global Privacy Control handling records; service provider and contractor agreements; risk assessment documents for each covered activity; ADMT pre-use notices and opt-out records; cybersecurity audit scope, auditor independence statement, audit report and the certification filed with the CPPA; breach response records.

Where the requirement sits: Cal. Civ. Code 1798.130(a)(5)-(6); regs 11 CCR 7102 record-keeping; CPPA 2025 regs (risk assessments, cyber audits, phased 2027-2030 - verify)

2026 regulations

The CPPA's regulations on risk assessments, cybersecurity audits and ADMT were approved by the Office of Administrative Law on September 22, 2025 and took effect January 1, 2026. Risk assessments for processing that began before 2026 must be documented by December 31, 2027.

The first risk assessment attestation and the first cybersecurity audit certification for the largest businesses are both due April 1, 2028. ADMT consumer rights apply from January 1, 2027.

What AllyMatter does here

Policy and training-acknowledgment layer.

AllyMatter publishes this site.

Assessors

Who assesses CCPA/CPRA

No certification. Enforcement is by the CPPA and the Attorney General through investigations and administrative or civil actions. The cybersecurity audit must be performed by a qualified, objective, independent professional (internal or external) using accepted auditing standards, and the business certifies completion to the CPPA; the audit is not a government-issued approval.

The CPPA sets the audit and risk assessment rules; auditors are not registered or accredited by the state.

No firm has claimed a CCPA/CPRA assessor listing yet. Claim yours →

Consultants

Who helps with CCPA/CPRA

A large ecosystem: privacy law firms, privacy consultancies and consent and data-mapping platforms. They build data inventories, write notices and policies, draft risk assessments and contract terms, and, for the audit rule, engage audit firms. Cybersecurity audit work is emerging among CPA and security assessment firms.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CCPA/CPRA consultant listing yet. Claim yours →

Software

Tools for CCPA/CPRA

Tools that name this framework in their own material.

Related reading

  1. California's CCPA cybersecurity audit rule takes effect: what businesses need to knowExplains which businesses hit the audit threshold, who may perform the audit, and the staggered first-report deadlines.Ropes & Gray
  2. Plan ahead: updated CCPA regulations go into effect January 1Covers the risk assessment, automated decision-making and audit rules together, with the documentation each one expects.Paul Hastings

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CCPA/CPRA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of CCPA/CPRA in AllyMatter

Approve the policies CCPA/CPRA asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.