The California Consumer Privacy Act (CCPA) took effect in 2020 and was substantially amended by the California Privacy Rights Act (CPRA), a ballot measure approved by voters in November 2020. Most CPRA amendments became operative on January 1, 2023. Unlike a certifiable standard, this is law: there is no certificate to earn, only obligations to meet and records that show you meet them when a regulator or plaintiff asks.
Does the law apply to you?
The CCPA applies to a for-profit "business" that does business in California, collects consumers' personal information (or has it collected on its behalf), determines the purposes and means of processing, and meets at least one of three thresholds. "Consumer" means any California resident, which since 2023 includes employees, job applicants, and business contacts.
Applicability thresholds (meet any one)
Who enforces it
The CPRA created the California Privacy Protection Agency (CPPA), a dedicated regulator with rulemaking, audit, and administrative enforcement powers. The California Attorney General retains civil enforcement authority. The CPRA also removed the automatic 30-day cure period businesses previously relied on. Consumers have a limited private right of action for data breaches caused by a failure to maintain reasonable security, which makes your security program part of your privacy exposure.
The rights you must operationalize
- Right to know and access the categories and specific pieces of personal information collected, including in a portable format.
- Right to delete personal information, subject to exceptions, and to pass deletion on to service providers and contractors.
- Right to correct inaccurate personal information (added by the CPRA).
- Right to opt out of sale or sharing, where "sharing" means disclosure for cross-context behavioral advertising (added by the CPRA). Opt-out preference signals such as Global Privacy Control must be honored.
- Right to limit use and disclosure of sensitive personal information to purposes the regulations permit (added by the CPRA).
- Right to non-discrimination and no retaliation for exercising these rights, including against employees and applicants.
Sensitive personal information is a defined category that includes government identifiers, account log-in credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of certain communications, genetic and biometric data, and health, sex life, or sexual orientation data. Tag these fields in your data inventory early, because they drive notice language, the limit-use right, and retention decisions.
Building the program in five workstreams
- Data inventory. Record categories of personal information, sources, purposes, recipients, retention periods, and whether each disclosure is a sale, a share, or a service provider transfer.
- Notices. Publish a notice at collection and a privacy policy reviewed at least every 12 months, including retention periods by category. Add the required opt-out links where you sell, share, or use sensitive data beyond permitted purposes.
- Request handling. Stand up intake methods, identity verification proportionate to the request, and tracking against regulatory response deadlines, which are set in the statute and CPPA regulations.
- Contracts. Update agreements with service providers, contractors, and third parties to include the terms the law requires, such as purpose limitations and restrictions on combining data. Your vendor risk program is the natural home for this.
- Security and assessments. Maintain reasonable security procedures and track the CPPA's regulations on cybersecurity audits, risk assessments, and automated decisionmaking technology, which phase in over several years.
Records that demonstrate compliance
Common gaps
- Employee and applicant data left out of scope, even though the former exemptions expired on January 1, 2023
- Advertising pixels and SDKs that constitute "sharing" but are not covered by the opt-out
- Global Privacy Control signals detected in the browser but not applied to server-side data flows
- Retention periods written in the policy that no deletion job actually enforces
- Service provider agreements signed before 2023 that lack the CPRA-required contract terms
Overlap with GDPR and ISO 27701, and where Asurvo fits
If you already run a GDPR program, your records of processing, DSR workflow, and processor contracts carry over, although CCPA's sale and sharing concepts and opt-out model differ from GDPR's lawful bases. An ISO 27701 PIMS gives both laws a management system to live in. Asurvo cross-maps CCPA/CPRA with GDPR and ISO 27701 so shared controls are evidenced once, while Third Party tracks vendor contracts and questionnaires and the policy center versions your notices and records approvals.