Framework Information Security & Privacy
CCPA/CPRA
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, is California's general privacy law for for-profit businesses that handle personal information about California residents.
It creates consumer rights (to know, delete, correct, opt out of sale or sharing, and limit use of sensitive data) and obligations for businesses, service providers and contractors.
Regulations approved on September 22, 2025 and effective January 1, 2026 added three major obligations: documented privacy risk assessments for high-risk processing, annual independent cybersecurity audits for larger businesses, and rules for automated decision-making technology (ADMT), whose consumer-facing requirements apply from January 1, 2027.
What must exist in writing: a privacy policy and notice at collection, a documented process for handling consumer requests within the statutory deadlines, service provider and contractor contracts with the required terms, records of requests and responses, risk assessments for covered processing (with the first attestation and summaries due to the CPPA by April 1, 2028), and, for businesses over the audit threshold, an annual cybersecurity audit report by an independent auditor with a certification of completion filed with the CPPA on a phased schedule starting April 1, 2028.
Who has to comply
For-profit businesses doing business in California that meet one of three thresholds: annual gross revenue above $25 million (inflation-adjusted; $26.625 million from January 1, 2025), buying, selling or sharing personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.
Service providers and contractors are bound by contract. The cybersecurity audit applies to businesses over the revenue threshold that process personal information of 250,000 or more consumers or households or sensitive information of 50,000 or more, and to businesses earning half their revenue from selling or sharing.
What the assessor asks to see
Privacy policy and notices at collection; data inventory and processing purposes; consumer request logs with response times and metrics; opt-out and Global Privacy Control handling records; service provider and contractor agreements; risk assessment documents for each covered activity; ADMT pre-use notices and opt-out records; cybersecurity audit scope, auditor independence statement, audit report and the certification filed with the CPPA; breach response records.
Where the requirement sits: Cal. Civ. Code 1798.130(a)(5)-(6); regs 11 CCR 7102 record-keeping; CPPA 2025 regs (risk assessments, cyber audits, phased 2027-2030 - verify)
2026 regulations
The CPPA's regulations on risk assessments, cybersecurity audits and ADMT were approved by the Office of Administrative Law on September 22, 2025 and took effect January 1, 2026. Risk assessments for processing that began before 2026 must be documented by December 31, 2027.
The first risk assessment attestation and the first cybersecurity audit certification for the largest businesses are both due April 1, 2028. ADMT consumer rights apply from January 1, 2027.
What AllyMatter does here
Policy and training-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses CCPA/CPRA
No certification. Enforcement is by the CPPA and the Attorney General through investigations and administrative or civil actions. The cybersecurity audit must be performed by a qualified, objective, independent professional (internal or external) using accepted auditing standards, and the business certifies completion to the CPPA; the audit is not a government-issued approval.
The CPPA sets the audit and risk assessment rules; auditors are not registered or accredited by the state.
No firm has claimed a CCPA/CPRA assessor listing yet. Claim yours →
Consultants
Who helps with CCPA/CPRA
A large ecosystem: privacy law firms, privacy consultancies and consent and data-mapping platforms. They build data inventories, write notices and policies, draft risk assessments and contract terms, and, for the audit rule, engage audit firms. Cybersecurity audit work is emerging among CPA and security assessment firms.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CCPA/CPRA consultant listing yet. Claim yours →
Software
Tools for CCPA/CPRA
Tools that name this framework in their own material.
Related reading
- California's CCPA cybersecurity audit rule takes effect: what businesses need to knowExplains which businesses hit the audit threshold, who may perform the audit, and the staggered first-report deadlines.Ropes & Gray
- Plan ahead: updated CCPA regulations go into effect January 1Covers the risk assessment, automated decision-making and audit rules together, with the documentation each one expects.Paul Hastings
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CCPA/CPRA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of CCPA/CPRA in AllyMatter
Approve the policies CCPA/CPRA asks for, keep every version, and record a named acknowledgment from each person who has to read them.