What It Is

What is the CCPA?

The California Consumer Privacy Act is a state privacy law that gives California consumers rights over their personal information and imposes duties on the businesses that collect, store, use, and share it. It was enacted in 2018 as AB 375 and took effect January 1, 2020, and it is widely regarded as the first comprehensive state privacy law in the United States (California Attorney General).

What is the CPRA?

The California Privacy Rights Act amends and expands the CCPA, closing loopholes and moving California's model closer to the EU's GDPR. California voters approved it as Proposition 24 in November 2020, and its amendments took effect January 1, 2023 (California Attorney General).

The CPRA:

  • Created a dedicated enforcement agency: the California Privacy Protection Agency (CPPA) now writes and enforces the regulations.
  • Defined sensitive personal information (SPI): a new data category carrying stricter processing limits.
  • Tightened data minimization: collection is limited to what disclosed purposes actually require.
  • Expanded consumer rights: including correction and SPI limitation rights.
  • Mandated cybersecurity audits and risk assessments: requirements the CPPA finalized in 2025, with phased deadlines.

Together, these laws form one of the most comprehensive privacy regimes in the United States.

What Information Is Regulated

The CCPA defines personal information (PI) broadly - nearly anything that identifies or can reasonably be linked to a person or household.

Examples of PI:

  • Names, addresses, and phone numbers
  • Email addresses
  • Account credentials
  • Browsing history and online identifiers
  • IP addresses
  • Location data
  • Purchase history
  • Device IDs
  • Inferred behavioral profiles

The CPRA adds sensitive personal information (SPI), including:

  • Social Security numbers
  • Driver's license numbers
  • Precise geolocation
  • Financial account information
  • Biometric data
  • Health data not covered by HIPAA
  • Racial or ethnic origin
  • Union membership
  • Sexual orientation
  • Contents of private messages

SPI triggers higher security obligations and stricter processing limits.

What rights do consumers have under CCPA/CPRA?

The law requires businesses to provide working mechanisms for consumers to:

1. Know: what personal information is collected, for what purposes, and who it is shared with. 2. Access: receive a copy of their personal information on request. 3. Correct: fix inaccurate information. The CPRA added this right. 4. Delete: have their information deleted, with limited exceptions. 5. Opt out: of the sale of their data, of sharing for cross-context behavioral advertising, and of certain uses of automated decisionmaking technology (ADMT). The ADMT regulations were finalized in 2025, with compliance required beginning January 1, 2027. 6. Limit: the use and disclosure of sensitive personal information. 7. Not face discrimination: consumers cannot be penalized for exercising any of these rights.

IT Requirements

Many SMBs think privacy laws just mean updating the privacy policy. In reality, compliance requires real changes to technology, cybersecurity, and data management operations. Here is what the law expects to be in place:

1. Strong access controls. Only authorized individuals may access PI or SPI. That means role-based access controls (RBAC), enforced MFA, least-privilege permissions, and logging with audit trails.

2. Encryption at rest and in transit. The statute does not name encryption as a mandate. But the private right of action reaches breaches of nonencrypted, nonredacted personal information caused by a failure to maintain reasonable security (Civ. Code §1798.150) - which makes encryption one of the strongest mitigating controls available to you.

3. Data minimization. The CPRA limits collection to what disclosed purposes require. Stop collecting unnecessary data, stop retaining data longer than needed, and document your purpose limitations.

4. Data retention schedules. The CPRA requires disclosure of how long data is retained, why it is retained, and when it will be deleted. This is newer than most SMB documentation - many businesses have never written it down.

5. Vendor and contractor management. The law requires contracts holding your service providers to CPRA standards: restricted data use, no selling or sharing, security obligations, and assistance with consumer rights requests. You can remain accountable when a vendor mishandles data - the law expects contracts and due diligence, so vendor oversight is part of your compliance program, not someone else's.

6. Consumer rights workflows. Access, deletion, correction, opt-out, and SPI limitation requests all need to be fulfilled quickly and securely. That takes ticketing or case tracking, identity verification, and system integrations that can actually locate the data.

7. Incident response and breach notification. A documented incident response plan, trained staff, tabletop exercises, and prompt notification of affected consumers after a breach. Mishandled SPI raises breach exposure under the CPRA.

8. Cybersecurity audits and risk assessments. The CPPA finalized its cybersecurity audit, risk assessment, and ADMT regulations in September 2025; they took effect January 1, 2026. Annual audit certifications phase in by revenue: April 1, 2028 for businesses over $100 million, April 1, 2029 for $50 to $100 million, and April 1, 2030 below $50 million. Risk assessment obligations began January 1, 2026, with the first attestations due April 1, 2028 (CPPA regulations).

How It Fits Into Cyber Risk Management

Treat CCPA/CPRA as a program, not a project. The obligations now arrive on a schedule - ADMT compliance beginning January 1, 2027, phased audit certifications from 2028 - and enforcement belongs to a dedicated agency with rulemaking authority.

That is exactly what a Governance, Risk & Compliance program manages: tracking which deadlines apply to you, keeping documentation current, and assigning ownership. Cyber Risk Management keeps the underlying controls real, and Third-Party Assessments validate them independently - the same evidence your privacy compliance rests on.

The CPPA remains active on retention guidance, SPI processing limits, and enforcement. Businesses that build the program now, with strong controls, documented data practices, and privacy built into operations, stay compliant and become safer, more trustworthy, and more resilient in the process.

How We Help With CCPA/CPRA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your data inventory and controls against the CCPA/CPRA thresholds, the CPPA's audit and risk assessment rules, and the reasonable-security bar behind the private right of action.

How to Prepare

  1. Identify what personal data you collect and where it lives

    Build the data inventory: systems, data types, data flows, and every vendor who receives data. You cannot protect or disclose what you have not mapped.

  2. Classify data into PI and SPI

    Sensitive personal information requires stricter controls and minimized processing. Classification decides which obligations attach to which systems.

  3. Implement or upgrade cybersecurity controls

    The essentials: MFA everywhere, endpoint protection, email security, encryption, logging, SIEM or monitoring, regular backups, and a tested incident response plan.

  4. Update your privacy policy

    It needs to disclose the categories of PI collected, purposes of use, retention periods, sales and sharing practices, SPI handling, and how consumers exercise their rights.

  5. Build a consumer rights request workflow

    Web forms for intake, identity verification, internal ticketing, and automated data lookup where possible. Requests need to be answered quickly and securely.

  6. Update vendor agreements

    Service provider and contractor terms are required: restrict data use, require compliance, and prevent selling or sharing. Vendor oversight is part of your program.

  7. Train your staff

    Everyone who handles personal data should understand privacy rights, data handling principles, SPI restrictions, and security basics.

  8. Conduct regular risk assessments

    Annually at minimum - more often when handling SPI at scale. If the CPPA's formal risk assessment regulations apply to you, obligations began January 1, 2026, with first attestations due April 1, 2028.

Official source

Official source: California Privacy Protection Agency

Secondary source: California Legislative Information - Civ. Code §1798.100 et seq.

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25