Compliance · United States · California
California Consumer Privacy Act, 2018 California Privacy Rights Act, effective January 2023

CCPA / CPRA

Plain-English definition

The CCPA is California's consumer privacy law. The CPRA amended and expanded it, effective January 2023, adding new consumer rights and creating a dedicated enforcement agency. Together they grant California residents rights over their personal data and impose obligations on businesses that meet specific revenue or data-volume thresholds, regardless of where the business itself is located.

Treated as one evolving framework here: the CPRA didn't replace the CCPA, it built on it.

Who needs it

Any business collecting personal data of California residents that meets CCPA/CPRA thresholds: over $25M in annual revenue, or buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50%+ of revenue from selling or sharing personal information.

Key requirements

Privacy notice at the point of collection, honoring consumer rights requests (access, deletion, correction, opt-out of sale/sharing), data minimization, and CPRA-required terms in contracts with service providers and third parties.

Cyber/privacy implications

The CCPA creates a private right of action for consumers following a data breach involving specific categories of personal information, not just regulator enforcement, which raises the stakes for demonstrable security controls.

Assessment methodology

Data inventory and mapping, an applicability-threshold assessment, a vendor and service-provider contract review, a rights-request process audit, and a security-control gap assessment against the "reasonable security" standard.

Implementation phases

01
Assess

Confirm applicability thresholds and map personal data flows and vendors.

02
Remediate

Update privacy notices, vendor contracts, and the rights-request handling process.

03
Evidence

Maintain rights-request logs and security control documentation in audit-ready form.

Evidence & documentation requirements

Privacy notices, service-provider and third-party data-processing agreements, rights-request logs, risk assessment records for high-risk processing, and documentation of the security controls protecting covered personal information.

Common mistakes

Assuming GDPR compliance automatically satisfies CCPA/CPRA (different rights, thresholds and enforcement mechanism); overlooking the private right of action tied to breaches of specific data categories; leaving vendor contracts without the CPRA-required service-provider terms.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Does this apply if we're not based in California or the US?
Yes, if you meet the revenue or data-volume thresholds and process personal data of California residents, regardless of where your company is headquartered.
What's the difference between CCPA and CPRA?
The CPRA, effective 2023, amended and expanded the original 2018 CCPA: it added new rights such as correction and limiting use of sensitive personal information, created a dedicated enforcement agency, and adjusted the applicability thresholds.

Request a Gap Assessment

See exactly where your data handling stands against CCPA/CPRA before a consumer request or regulator asks.

Request a Gap Assessment →