05 CCPA & CPRA
The California Consumer Privacy Act (CCPA) is one of the most important comprehensive privacy laws in the United States.
The California Privacy Rights Act (CPRA) amended and expanded the CCPA. CPRA should therefore not normally be treated as a completely separate privacy law.
A better way to describe the current framework is:
CCPA ↓Amended by CPRA ↓CCPA Regulations ↓California PrivacyCompliance FrameworkThe CPRA amendments introduced additional protections including the right to correct inaccurate personal information and the right to limit certain uses and disclosures of sensitive personal information. (California Department of Justice)
The framework is administered and enforced in significant part by the California Privacy Protection Agency (CPPA/CalPrivacy), alongside enforcement authority held by the California Attorney General. The current regulations effective January 1, 2026 also introduce or operationalize important requirements involving risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT), with some compliance deadlines phased in. (California Privacy Protection Agency)
A practical enterprise model looks like:
Applicability ↓Personal Information Inventory ↓Sensitive Personal Information ↓Purpose & Data Minimization ↓Notice at Collection ↓Consumer Rights ↓Sale / Sharing Assessment ↓Opt-Out Management ↓Service Provider Governance ↓Retention ↓Security ↓Risk Assessment ↓Continuous ComplianceLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the relationship between CCPA and CPRA.
-
Determine whether an organization may fall within CCPA scope.
-
Define Consumer.
-
Define Personal Information.
-
Identify Sensitive Personal Information.
-
Understand Business, Service Provider, Contractor, and Third Party roles.
-
Understand Notice at Collection requirements.
-
Explain consumer privacy rights.
-
Understand requests to know, delete, and correct.
-
Explain sale and sharing.
-
Understand opt-out requirements.
-
Understand Global Privacy Control.
-
Explain Sensitive Personal Information limitations.
-
Understand data minimization and purpose limitation.
-
Understand retention governance.
-
Evaluate service provider and contractor relationships.
-
Understand reasonable security expectations.
-
Understand current risk-assessment requirements.
-
Understand cybersecurity-audit requirements.
-
Understand emerging ADMT obligations.
-
Build an enterprise CCPA compliance program.
1. What Is the CCPA?
Section titled “1. What Is the CCPA?”CCPA stands for:
California Consumer Privacy ActThe law gives California consumers significant rights over how businesses collect, use, disclose, sell, and share their personal information.
Core concepts include:
Transparency
Consumer Control
Access
Deletion
Correction
Opt-Out
Sensitive PI Protection
Non-Discrimination2. What Is CPRA?
Section titled “2. What Is CPRA?”CPRA stands for:
California Privacy Rights ActCalifornia voters approved CPRA through Proposition 24 in 2020.
CPRA:
Amended+Expandedthe CCPA.
Important additions included:
Sensitive Personal Information
Right to Correction
Right to Limit Certain Uses of SPI
Expanded Opt-Out Rights
California Privacy Protection Agency
Additional Governance RequirementsThe California Attorney General specifically notes that CPRA amends the CCPA rather than creating an entirely separate law. (California Department of Justice)
3. Current Regulatory Framework
Section titled “3. Current Regulatory Framework”For enterprise compliance, think:
CCPA Statute +CPRA Amendments +CCPA Regulations +CPPA Guidance +EnforcementThe CPPA’s current law and regulations page identifies versions of the CCPA statute and regulations effective January 1, 2026. (California Privacy Protection Agency)
4. Who Is a Consumer?
Section titled “4. Who Is a Consumer?”A:
Consumergenerally means a natural person who is a California resident.
The framework can therefore affect organizations outside California when they do business in California and satisfy applicable thresholds.
5. CCPA Applicability
Section titled “5. CCPA Applicability”CCPA generally applies to qualifying:
For-Profit Businessesdoing business in California that satisfy at least one statutory threshold.
6. Current Business Thresholds
Section titled “6. Current Business Thresholds”As of 2026, one threshold is annual gross revenue above:
$26.625 Millionfor the preceding calendar year.
Other principal thresholds include buying, selling, or sharing personal information of:
100,000+California Consumersor Householdsor deriving:
50%+Annual Revenuefrom selling or sharing California consumers’ personal information. (California Privacy Protection Agency)
7. Applicability Decision
Section titled “7. Applicability Decision”For-Profit Entity ↓Doing Business in California? ↓Threshold Met? ↓Exemption / Exception? ↓CCPA Applicability8. Build Applicability Assessment
Section titled “8. Build Applicability Assessment”Create:
01 CCPA Applicability AssessmentUse:
| Question | Response | Evidence |
|---|---|---|
| For-profit organization? | ||
| Doing business in California? | ||
| Revenue threshold met? | ||
| 100,000 consumer/household threshold met? | ||
| 50% sale/share revenue threshold met? | ||
| Exemptions applicable? | ||
| CCPA applicable? |
9. Nonprofits and Government Agencies
Section titled “9. Nonprofits and Government Agencies”CCPA generally does not apply directly to:
Nonprofit Organizations
Government Agenciesalthough organizations should evaluate their specific relationships and circumstances. (California Privacy Protection Agency)
10. Personal Information
Section titled “10. Personal Information”CCPA defines Personal Information broadly.
Think:
Information That Identifies
Relates To
Describes
Is Reasonably Capableof Being Associated With
or Could Reasonably Be LinkedWith a Consumer or Household11. Examples of Personal Information
Section titled “11. Examples of Personal Information”Examples can include:
Name
Postal Address
Email
IP Address
Account Identifier
Purchase History
Browsing History
Geolocation
Biometric Information
Employment Information
InferencesThe definition can therefore extend considerably beyond traditional identifiers. (California Department of Justice)
12. Household Concept
Section titled “12. Household Concept”An important CCPA characteristic is that Personal Information can potentially relate to:
Consumer ORHouseholdThis differs from some privacy frameworks that focus almost entirely on identifiable individuals.
13. Personal Information Inventory
Section titled “13. Personal Information Inventory”Create:
02 California Personal Information InventoryUse:
| Business Process | PI | Category | System | Purpose | Owner |
|---|
14. Sensitive Personal Information
Section titled “14. Sensitive Personal Information”CPRA introduced the concept of:
Sensitive Personal Informationor:
SPI15. Examples of SPI
Section titled “15. Examples of SPI”Sensitive Personal Information can include specified categories such as:
Social Security Number
Driver's License Information
Financial Account Credentials
Precise Geolocation
Certain Communications Content
Genetic Data
Certain Biometric Information
Health Information
Racial or Ethnic Origin
Religious Beliefs
Sex Life / Sexual Orientationdepending on statutory definitions and processing context. (California Department of Justice)
16. Build SPI Register
Section titled “16. Build SPI Register”Create:
03 Sensitive Personal Information RegisterUse:
| SPI | System | Purpose | Use | Disclosure | Owner |
|---|
17. CCPA Roles
Section titled “17. CCPA Roles”Organizations should identify their role.
Important roles include:
Business
Service Provider
Contractor
Third Party18. Business
Section titled “18. Business”A:
Businessis generally the regulated entity that determines purposes and means of processing and meets applicable statutory requirements.
Conceptually:
Business≈Decision MakerBut do not automatically treat it as legally identical to a GDPR Controller.
19. Service Provider
Section titled “19. Service Provider”A:
Service Providerprocesses Personal Information on behalf of a Business under applicable contractual restrictions.
20. Contractor
Section titled “20. Contractor”The framework also recognizes:
Contractorrelationships with specific statutory and contractual requirements.
21. Third Party
Section titled “21. Third Party”A recipient that does not qualify for applicable Business, Service Provider, Contractor, or other specified treatment may be considered a:
Third Partydepending on the relationship.
22. Role Mapping
Section titled “22. Role Mapping”Create:
04 CCPA Party Role RegisterUse:
| Organization | Relationship | Role | PI | Contract |
|---|
23. Notice at Collection
Section titled “23. Notice at Collection”Businesses must provide required information:
At or Beforethe Point of Collectionthrough an appropriate:
Notice at Collection24. Notice Model
Section titled “24. Notice Model”A practical notice should help explain:
What PI Is Collected?
Why Is It Collected?
How Will It Be Used?
Is Sensitive PI Involved?
How Long Is It Retained?
What Rights Apply?The 2026 regulations specifically contain requirements governing the Notice at Collection. (California Privacy Protection Agency)
25. Example
Section titled “25. Example”Weak:
We May CollectInformation About You.Stronger:
Email Address ↓Account Registration
Payment Information ↓Transaction Processing
Location ↓Delivery26. Build Notice Register
Section titled “26. Build Notice Register”Create:
05 CCPA Notice-at-Collection RegisterUse:
| Collection Point | PI | Purpose | Notice | Owner | Review |
|---|
27. Privacy Policy
Section titled “27. Privacy Policy”Organizations should also maintain an appropriate:
Privacy Policydescribing their CCPA practices and applicable consumer rights.
28. Notice vs Privacy Policy
Section titled “28. Notice vs Privacy Policy”Do not treat these as identical.
Notice at Collection ↓Collection-Specific Transparencywhile:
Privacy Policy ↓Broader Privacy Practices29. Consumer Rights
Section titled “29. Consumer Rights”California consumers have significant rights under CCPA.
Core rights include:
Right to Know
Right to Delete
Right to Correct
Right to Opt-Outof Sale or Sharing
Right to Limit Certain Usesof Sensitive PI
Right to Non-Discrimination(California Department of Justice)
30. Right to Know
Section titled “30. Right to Know”Consumers can request information about Personal Information collected and relevant processing activities.
A request may involve information about:
Categories of PI
Specific Pieces
Sources
Business Purposes
Third Parties
Sale / Sharing31. Know Request Workflow
Section titled “31. Know Request Workflow”Request ↓Identity Verification ↓Data Discovery ↓Review ↓Response ↓Evidence32. Right to Delete
Section titled “32. Right to Delete”Consumers can request deletion of certain Personal Information collected from them, subject to statutory exceptions.
33. Deletion Workflow
Section titled “33. Deletion Workflow”Request ↓Verify ↓Locate PI ↓Assess Exception ↓Delete ↓Service Provider Actions ↓Confirm34. Deletion Exceptions
Section titled “34. Deletion Exceptions”Deletion is not always:
Delete EverythingImmediatelyApplicable exceptions and legal requirements may permit or require continued retention.
35. Right to Correct
Section titled “35. Right to Correct”Consumers may request correction of inaccurate Personal Information.
This right was added through CPRA. (California Department of Justice)
36. Correction Workflow
Section titled “36. Correction Workflow”Correction Request ↓Verify ↓Locate Information ↓Evaluate Accuracy ↓Correct ↓Propagate Where Required ↓Document37. Consumer Rights Register
Section titled “37. Consumer Rights Register”Create:
06 CCPA Consumer Rights RegisterUse:
| Request | Right | Received | Verified | Completed | Evidence |
|---|
38. Request Verification
Section titled “38. Request Verification”Verification should balance:
Privacy+Security+Consumer AccessibilityWeak:
Consumer Requests Data ↓Send EverythingWithout Verificationcreates another privacy risk.
39. Non-Discrimination
Section titled “39. Non-Discrimination”Consumers generally cannot be unlawfully discriminated against because they exercised CCPA rights.
Examples requiring careful review include:
Different Pricing
Different Service Level
Denial of Service
Different Qualitywhere linked to privacy-right exercise.
40. Sale of Personal Information
Section titled “40. Sale of Personal Information”CCPA gives:
Salea broader privacy-law meaning than simply:
Selling a Databasefor CashOrganizations must evaluate the statutory definition and actual data flows.
41. Sharing
Section titled “41. Sharing”CPRA added an important concept:
Sharingparticularly concerning cross-context behavioral advertising.
42. Why This Matters
Section titled “42. Why This Matters”A company may say:
We Never Sell Data.But still use:
Advertising Technology
Tracking Pixels
Advertising SDKs
Cross-Site Trackingthat can create:
Sharingquestions.
43. Sale / Sharing Assessment
Section titled “43. Sale / Sharing Assessment”Create:
07 Sale & Sharing InventoryUse:
| Data Flow | Recipient | PI | Purpose | Sale? | Sharing? |
|---|
44. Website Tracking
Section titled “44. Website Tracking”Assess:
Cookies
Pixels
Advertising SDKs
Analytics Tools
Social PluginsDo not evaluate only backend databases.
45. Right to Opt-Out
Section titled “45. Right to Opt-Out”Consumers have a right to direct a Business to stop applicable:
SaleorSharingof Personal Information. (California Department of Justice)
46. Do Not Sell or Share
Section titled “46. Do Not Sell or Share”Where applicable, businesses may need mechanisms such as:
Do Not Sell or ShareMy Personal InformationThe regulations specifically govern notices and mechanisms for this right. (California Privacy Protection Agency)
47. Global Privacy Control
Section titled “47. Global Privacy Control”A major operational requirement is recognition of applicable:
Opt-Out Preference Signalssuch as:
Global Privacy Controlor:
GPCCalifornia’s Attorney General identifies GPC as a mechanism consumers may use to opt out of sale or sharing. (California Department of Justice)
48. GPC Workflow
Section titled “48. GPC Workflow”Browser ↓GPC Signal ↓Website ↓Detect Signal ↓Apply Opt-Out ↓Stop Applicable Sale / Sharing49. GPC Testing
Section titled “49. GPC Testing”A GRC assessment should verify:
Signal Received?
Signal Recognized?
Advertising Disabled?
Sharing Stopped?
Preference Persisted?
Evidence Available?50. Cross-Device Opt-Out
Section titled “50. Cross-Device Opt-Out”Privacy programs should evaluate whether opt-outs are properly applied across relevant consumer accounts, services, and devices.
This is a real enforcement issue: California’s Attorney General announced a $2.75 million settlement in February 2026 involving allegations that consumer sale/sharing opt-outs were not fully effectuated across associated devices and streaming services. (California Department of Justice)
51. Sensitive PI Limitation
Section titled “51. Sensitive PI Limitation”Consumers can have the right to limit certain:
Use+Disclosureof Sensitive Personal Information. (California Department of Justice)
52. Limit Use Mechanism
Section titled “52. Limit Use Mechanism”Where applicable:
Limit the Use of MySensitive Personal Informationmay need to be made available.
53. SPI Workflow
Section titled “53. SPI Workflow”Sensitive PI ↓Purpose Identified ↓Permitted Use? │ ├── Yes → Process │ └── No ↓Limit Right Assessment54. Data Minimization
Section titled “54. Data Minimization”A strong CCPA program asks:
What InformationDo We Actually Need?rather than:
What InformationCan We Collect?The current regulations restrict collection, use, retention, and sharing in relation to reasonable consumer expectations and disclosed purposes. (California Privacy Protection Agency)
55. Practical Data Minimization
Section titled “55. Practical Data Minimization”Weak:
Collect Everything
Keep Forever
Use LaterStrong:
Defined Purpose ↓Necessary PI ↓Limited Collection ↓Limited Use ↓Defined Retention56. Purpose Limitation
Section titled “56. Purpose Limitation”If information was collected for:
Deliver Productusing it later for:
Unrelated Behavioral Profilingrequires a separate compliance assessment.
57. Data Minimization Enforcement
Section titled “57. Data Minimization Enforcement”Data minimization is not merely theoretical. In May 2026, California authorities announced a $12.75 million privacy settlement involving General Motors, describing it as California’s first CCPA data-minimization case. (California Department of Justice)
58. Purpose Register
Section titled “58. Purpose Register”Create:
08 CCPA Purpose & Minimization RegisterUse:
| PI | Purpose | Necessary? | Additional Use | Approved |
|---|
59. Retention
Section titled “59. Retention”Personal Information should not simply be retained:
Foreverwithout a defined business or legal reason.
60. Retention Lifecycle
Section titled “60. Retention Lifecycle”Collection ↓Purpose ↓Use ↓Retention ↓Deletion / De-identification61. Retention Matrix
Section titled “61. Retention Matrix”Create:
09 CCPA Retention MatrixUse:
| PI | Purpose | Retention | Trigger | Deletion | Owner |
|---|
62. Example
Section titled “62. Example”Marketing Lead ↓Inactive ↓Retention Period Reached ↓Delete / De-identifysubject to applicable requirements.
63. Service Provider Governance
Section titled “63. Service Provider Governance”Organizations frequently disclose PI to:
Cloud Providers
CRM Providers
Marketing Platforms
Analytics Providers
Support Platforms
Payroll Providers64. Vendor Classification
Section titled “64. Vendor Classification”For every vendor ask:
What PI?
Why?
What Role?
Service Provider?
Contractor?
Third Party?
Sale / Sharing?65. Service Provider Contracting
Section titled “65. Service Provider Contracting”Contracts should address applicable restrictions regarding:
Processing Purpose
Use
Disclosure
Retention
Subcontracting
Compliance66. Service Provider Register
Section titled “66. Service Provider Register”Create:
10 CCPA Service Provider & Contractor RegisterUse:
| Vendor | Role | PI | Purpose | Contract | Review |
|---|
67. Contract Alone Is Not Enough
Section titled “67. Contract Alone Is Not Enough”Weak:
Contract Signed ↓Vendor CompliantStronger:
Due Diligence ↓Correct Classification ↓Contract ↓Monitoring ↓Evidence68. Security
Section titled “68. Security”CCPA includes significant security implications.
Organizations should maintain:
Reasonable Securityappropriate to the nature of the Personal Information.
69. Security Controls
Section titled “69. Security Controls”A practical control environment may include:
IAM
MFA
Encryption
Logging
Vulnerability Management
Secure Configuration
Incident Response
Monitoring70. Security Mapping
Section titled “70. Security Mapping”Create:
11 CCPA Security Control MatrixUse:
| PI Risk | Control | System | Owner | Evidence |
|---|
71. Data Breach Exposure
Section titled “71. Data Breach Exposure”Certain breaches involving specified Personal Information can create a private right of action.
The current CPI-adjusted statutory damages range is:
$107 – $799per consumerper incidentor actual damages, whichever is greater, where the statutory requirements are met. (California Privacy Protection Agency)
72. Important Distinction
Section titled “72. Important Distinction”Do not teach:
Every CCPA Violation=Private LawsuitThe private right of action is narrower and principally associated with qualifying security breaches.
73. Incident Workflow
Section titled “73. Incident Workflow”Incident ↓California PI Involved? ↓Data Type ↓Security Assessment ↓Breach Law Assessment ↓CCPA Exposure ↓Remediation74. Risk Assessments
Section titled “74. Risk Assessments”California’s 2026 regulations introduce operational requirements for certain businesses to conduct:
Risk Assessmentsfor specified processing presenting significant privacy risks. (California Privacy Protection Agency)
75. Risk Assessment Model
Section titled “75. Risk Assessment Model”Processing Activity ↓Purpose ↓Consumer Benefit ↓Privacy Risk ↓Safeguards ↓Residual Risk ↓Decision76. Risk Assessment Register
Section titled “76. Risk Assessment Register”Create:
12 CCPA Privacy Risk Assessment RegisterUse:
| Processing | Purpose | Benefit | Risk | Safeguard | Decision |
|---|
77. Risk Assessment Timeline
Section titled “77. Risk Assessment Timeline”Businesses subject to the new requirements were required to begin compliance with the risk-assessment rules on:
January 1, 2026and the CPPA states that required attestations and summary information are due by:
April 1, 2028for the initial submission framework. (California Privacy Protection Agency)
78. Cybersecurity Audits
Section titled “78. Cybersecurity Audits”Certain businesses are also subject to:
Annual Cybersecurity Auditrequirements under the 2026 regulations. (California Privacy Protection Agency)
79. Cybersecurity Audit Readiness
Section titled “79. Cybersecurity Audit Readiness”Assess:
Security Program
Asset Inventory
IAM
Authentication
Encryption
Logging
Incident Response
Vulnerability Management
Third Parties
Governance80. Cybersecurity Audit Deadlines
Section titled “80. Cybersecurity Audit Deadlines”Initial certification deadlines are phased according to business revenue.
The CPPA identifies deadlines beginning:
April 1, 2028for businesses over $100 million in revenue, followed by later deadlines for smaller covered businesses. (California Privacy Protection Agency)
81. Cybersecurity Audit Register
Section titled “81. Cybersecurity Audit Register”Create:
13 CCPA Cybersecurity Audit Readiness RegisterUse:
| Requirement | Control | Evidence | Owner | Status |
|---|
82. Automated Decisionmaking Technology
Section titled “82. Automated Decisionmaking Technology”The current regulations also establish requirements concerning:
Automated Decisionmaking Technologyor:
ADMTin specified circumstances. (California Privacy Protection Agency)
83. ADMT Examples
Section titled “83. ADMT Examples”Potential enterprise use cases may include:
Employment Decisions
Credit Decisions
Insurance Decisions
Eligibility Decisions
Automated Profilingdepending on the actual technology and statutory/regulatory applicability.
84. Significant Decisions
Section titled “84. Significant Decisions”The most important question is not simply:
Do We Use AI?Instead:
Does the TechnologyMeet the ADMT Definition?
Is It Used for aCovered Significant Decision?85. ADMT Consumer Rights
Section titled “85. ADMT Consumer Rights”The regulations include requirements involving consumer:
Accessand:
Opt-Outin applicable ADMT contexts. (California Privacy Protection Agency)
86. ADMT Compliance Timing
Section titled “86. ADMT Compliance Timing”The CPPA states that businesses subject to applicable ADMT requirements must begin complying on:
January 1, 2027(California Privacy Protection Agency)
87. ADMT Inventory
Section titled “87. ADMT Inventory”Create:
14 CCPA ADMT InventoryUse:
| System | Decision | PI | Purpose | Impact | Owner |
|---|
88. Employee and B2B Data
Section titled “88. Employee and B2B Data”An important historical mistake is assuming:
Employee Data=Always Exemptor:
B2B Contact Data=Always ExemptOrganizations should assess current statutory treatment rather than relying on older temporary exemptions.
89. Employee Privacy
Section titled “89. Employee Privacy”A mature program should inventory:
Employee
Applicant
Contractor
Former EmployeePersonal Information where CCPA applies.
90. HR Data Examples
Section titled “90. HR Data Examples”Contact Information
Payroll
Performance Data
Device Monitoring
Background Information
Biometric Data91. Employee Data Register
Section titled “91. Employee Data Register”Create:
15 California Workforce PI RegisterUse:
| Process | PI | Purpose | System | Retention | Owner |
|---|
92. Minors
Section titled “92. Minors”CCPA provides enhanced protections concerning sale or sharing involving consumers under:
1693. Under 16
Section titled “93. Under 16”Organizations should assess whether applicable:
Opt-Inrequirements apply before selling or sharing Personal Information of minors.
94. Under 13
Section titled “94. Under 13”For children under 13, applicable parental authorization requirements become particularly important.
95. Minor Data Workflow
Section titled “95. Minor Data Workflow”Consumer ↓Age Assessment ↓Under 16? ↓Sale / Sharing? ↓Required Authorization96. Privacy Request Operations
Section titled “96. Privacy Request Operations”A scalable enterprise workflow:
Request ↓Authenticate ↓Classify ↓Search Systems ↓Apply Exceptions ↓Fulfill ↓Communicate ↓Evidence97. Request Channels
Section titled “97. Request Channels”Requests may arrive through:
Website
Email
Phone
Privacy Portal
Authorized Agentdepending on applicable requirements and business practices.
98. Authorized Agents
Section titled “98. Authorized Agents”Consumers may use:
Authorized Agentsto exercise certain CCPA rights.
Organizations need procedures to validate appropriate authority.
99. Rights Request Tracker
Section titled “99. Rights Request Tracker”Create:
16 CCPA Privacy Request TrackerUse:
| Request | Consumer | Right | Received | Deadline | Status |
|---|
100. Identity Verification
Section titled “100. Identity Verification”Do not collect excessive additional PI merely to verify a privacy request.
The verification process itself should follow:
Data Minimization101. Privacy Operations Architecture
Section titled “101. Privacy Operations Architecture”Consumer ↓Privacy Portal ↓Identity Verification ↓Request Orchestration ↓CRM ↓Data Lake ↓SaaS ↓Advertising Platforms ↓Response102. Automated Discovery
Section titled “102. Automated Discovery”Large organizations increasingly need:
Data Discovery
Data Classification
Identity Matching
Request Orchestration
Deletion Automationto manage privacy operations at scale.
103. Evidence Repository
Section titled “103. Evidence Repository”Create:
17 CCPA Compliance Evidence RepositoryStructure:
01 Applicability
02 PI Inventory
03 Sensitive PI
04 Notices
05 Consumer Requests
06 Sale & Sharing
07 Opt-Out
08 GPC
09 Vendors
10 Retention
11 Security
12 Risk Assessments
13 Cybersecurity Audits
14 ADMT
15 Training
16 Testing104. Control Testing — Notice
Section titled “104. Control Testing — Notice”Sample:
20 Websites / ApplicationsVerify:
Collection Points
PI Categories
Purpose
Retention
Notice Availability105. Control Testing — Opt-Out
Section titled “105. Control Testing — Opt-Out”Enable:
Global Privacy ControlThen verify:
Website Detects Signal
Advertising Changes
Applicable Sharing Stops
Preference Persists106. Control Testing — Sale / Sharing
Section titled “106. Control Testing — Sale / Sharing”Compare:
Declared Data Flowsagainst:
Actual Network Traffic
Cookies
Pixels
SDKs
Vendor Integrations107. Example Finding
Section titled “107. Example Finding”Privacy team says:
No Personal InformationIs Shared.Website actually loads:
Advertising Pixel ↓Consumer Identifier ↓Third-Party Ad PlatformPotential:
Sale / SharingClassification Gap108. Control Testing — Deletion
Section titled “108. Control Testing — Deletion”Sample:
25 CompletedDeletion RequestsVerify deletion from:
CRM
Marketing Platform
Data Lake
Support Platform
Applicable Vendors109. Control Testing — Correction
Section titled “109. Control Testing — Correction”Sample:
20 Correction RequestsVerify:
Verification
Correction
Propagation
Response
Evidence110. Control Testing — Sensitive PI
Section titled “110. Control Testing — Sensitive PI”Identify systems containing:
Precise Location
Financial Credentials
Health Information
Biometric InformationVerify:
Purpose
Access
Use
Disclosure
Limit Mechanismwhere applicable.
111. Control Testing — Retention
Section titled “111. Control Testing — Retention”Policy:
Inactive Accounts:3 YearsActual:
Oldest Inactive Account:11 YearsPotential:
Retention Control Gap112. Control Testing — Vendors
Section titled “112. Control Testing — Vendors”Population:
80 VendorsProcessing California PIResults:
65 Correctly Classified
10 Missing Required Terms
5 Unknown Data FlowsPotential:
Third-Party Governance Gap113. Control Testing — GPC
Section titled “113. Control Testing — GPC”Test:
Chrome + GPC
Firefox + GPC
Anonymous User
Authenticated UserVerify appropriate handling.
114. Control Testing — Data Minimization
Section titled “114. Control Testing — Data Minimization”Application collects:
Precise GeolocationPurpose:
Email NewsletterAsk:
Why Is Location Necessary?Potential:
Data Minimization Gap115. CCPA Gap Register
Section titled “115. CCPA Gap Register”Create:
18 CCPA Compliance Gap RegisterUse:
| Finding | Requirement | Risk | Severity | Owner | Due |
|---|
116. Example Finding — GPC
Section titled “116. Example Finding — GPC”Finding:
Website Receives GPCBut Advertising CookiesContinue OperatingRisk:
Consumer Opt-OutMay Not Be Honored117. Root Cause
Section titled “117. Root Cause”Why?
CMP Detects GPCbut:
Advertising SDKDoes Not ConsumeCMP PreferenceRoot cause:
Privacy preference management was not integrated with all advertising technologies.
118. Correction
Section titled “118. Correction”Disable ApplicableAdvertising Processingfor GPC Users119. Corrective Action
Section titled “119. Corrective Action”Central Consent /Preference Architecture
Vendor Integration Standard
Automated GPC Testing120. Example Finding — Deletion
Section titled “120. Example Finding — Deletion”Finding:
Consumer Data Deletedfrom CRMbut remains in:
Marketing PlatformRoot cause:
Deletion WorkflowOnly Integratedwith Core Systems121. Corrective Action
Section titled “121. Corrective Action”Enterprise Data Inventory
System Integration
Vendor Deletion Workflow
Completion Validation122. CCPA Dashboard
Section titled “122. CCPA Dashboard”Track:
| Metric | Target |
|---|---|
| PI Processing Activities Inventoried | 100% |
| Collection Points With Current Notice | 100% |
| Rights Requests Within Required Timeline | 100% |
| Applicable GPC Signals Honored | 100% |
| Vendors Correctly Classified | 100% |
| Sensitive PI Uses Assessed | 100% |
| Overdue High-Risk Findings | 0 |
| Unapproved Sale/Sharing Flows | 0 |
123. KPI — Rights
Section titled “123. KPI — Rights”Percentage of ConsumerRequests CompletedWithin Required Timeline124. KPI — GPC
Section titled “124. KPI — GPC”Percentage of ApplicableOpt-Out Preference SignalsSuccessfully Enforced125. KRI — Sale / Sharing
Section titled “125. KRI — Sale / Sharing”Unclassified Third-PartyPersonal Information Flows126. KRI — Sensitive PI
Section titled “126. KRI — Sensitive PI”Sensitive PI ProcessingWithout Documented Purpose127. KRI — Retention
Section titled “127. KRI — Retention”PI RepositoriesBeyond ApprovedRetention Period128. KRI — Vendors
Section titled “128. KRI — Vendors”Vendors Processing PIWithout RequiredContractual Controls129. Practical Activity — Applicability
Section titled “129. Practical Activity — Applicability”Use fictional:
CloudShopFacts:
$40M Revenue
California Customers
150,000 CaliforniaConsumer RecordsDetermine:
Does CCPA Apply?
Which Thresholds?
What Evidence?130. Practical Activity — Data Inventory
Section titled “130. Practical Activity — Data Inventory”CloudShop operates:
Website
Mobile App
CRM
Marketing Platform
Analytics
Customer SupportIdentify:
PI
Sensitive PI
Purpose
Recipient
Retention131. Practical Activity — Tracking Technologies
Section titled “131. Practical Activity — Tracking Technologies”Website uses:
Analytics Cookie
Advertising Pixel
Social Media Pixel
Session Replay
Personalization EngineFor each determine:
What PI?
Which Recipient?
Purpose?
Sale?
Sharing?
Opt-Out Required?132. Practical Activity — Consumer Request
Section titled “132. Practical Activity — Consumer Request”Consumer requests:
Tell Me What You Know
Correct My Address
Delete My Account
Stop Sharing My DataBuild one coordinated workflow.
133. Practical Activity — GPC
Section titled “133. Practical Activity — GPC”Consumer visits with:
GPC = EnabledDetermine expected behavior across:
Website
Advertising
Analytics
Logged-In Account
Mobile Experience134. Practical Activity — Sensitive PI
Section titled “134. Practical Activity — Sensitive PI”Mobile application collects:
Precise Geolocationfor:
Nearby Store RecommendationsAssess:
Purpose
Necessity
Notice
Sensitive PI
Limit Right
Retention135. Practical Activity — Vendor
Section titled “135. Practical Activity — Vendor”Marketing vendor receives:
Email
Device ID
Browsing Activity
Purchase HistoryDetermine:
Role
Purpose
Sale / Sharing
Contract
Opt-Out Impact136. Practical Activity — ADMT
Section titled “136. Practical Activity — ADMT”Organization uses automated technology to:
Score Job Applicants ↓Reject Some ApplicantsAutomaticallyAssess:
ADMT Applicability
Significant Decision
PI
Risk Assessment
Consumer Rights
2027 ReadinessCCPA / CPRA Operational Checklist
Section titled “CCPA / CPRA Operational Checklist”Applicability
Section titled “Applicability”-
California business activity assessed.
-
revenue threshold assessed.
-
consumer/household volume assessed.
-
sale/share revenue assessed.
-
applicable exemptions reviewed.
Data Inventory
Section titled “Data Inventory”-
California PI identified.
-
Sensitive PI identified.
-
systems mapped.
-
collection points documented.
-
recipients identified.
Purpose & Minimization
Section titled “Purpose & Minimization”-
purposes documented.
-
PI necessity assessed.
-
secondary uses reviewed.
-
excessive collection challenged.
Notices
Section titled “Notices”-
Notice at Collection implemented.
-
Privacy Policy maintained.
-
PI categories accurate.
-
purposes accurate.
-
retention disclosures reviewed.
Consumer Rights
Section titled “Consumer Rights”-
know workflow established.
-
deletion workflow established.
-
correction workflow established.
-
opt-out workflow established.
-
Sensitive PI limitation supported where applicable.
-
authorized agents supported.
-
non-discrimination controls established.
Sale & Sharing
Section titled “Sale & Sharing”-
sale assessed.
-
sharing assessed.
-
advertising technologies inventoried.
-
website trackers reviewed.
-
mobile SDKs reviewed.
Opt-Out
Section titled “Opt-Out”-
applicable opt-out mechanism implemented.
-
GPC recognized.
-
preferences propagated.
-
cross-device behavior assessed.
-
opt-out tested.
Sensitive PI
Section titled “Sensitive PI”-
SPI inventory maintained.
-
purposes documented.
-
access restricted.
-
limitation requirements assessed.
Vendors
Section titled “Vendors”-
vendors inventoried.
-
roles classified.
-
contracts reviewed.
-
data flows documented.
-
monitoring established.
Retention
Section titled “Retention”-
retention periods defined.
-
deletion triggers established.
-
exceptions documented.
-
actual retention tested.
Security
Section titled “Security”-
PI security risks assessed.
-
IAM controls established.
-
encryption assessed.
-
logging implemented.
-
vulnerabilities managed.
-
incidents investigated.
Risk Assessments
Section titled “Risk Assessments”-
applicable processing identified.
-
privacy risks assessed.
-
safeguards documented.
-
assessments maintained.
-
submission readiness established.
Cybersecurity Audits
Section titled “Cybersecurity Audits”-
applicability assessed.
-
audit deadline identified.
-
security evidence centralized.
-
audit readiness tracked.
-
ADMT inventory established.
-
significant decisions identified.
-
applicable risks assessed.
-
consumer rights mapped.
-
2027 requirements tracked.
137. Common CCPA / CPRA Mistakes
Section titled “137. Common CCPA / CPRA Mistakes”Mistake 1 — Treating CCPA and CPRA as Separate Laws
Section titled “Mistake 1 — Treating CCPA and CPRA as Separate Laws”CPRA amended the CCPA.
Mistake 2 — Using the Old $25 Million Threshold
Section titled “Mistake 2 — Using the Old $25 Million Threshold”The CPI-adjusted threshold currently applicable is $26.625 million. (California Privacy Protection Agency)
Mistake 3 — Assuming Personal Information Means Only Name and Email
Section titled “Mistake 3 — Assuming Personal Information Means Only Name and Email”CCPA’s definition is considerably broader.
Mistake 4 — Saying “We Don’t Sell Data”
Section titled “Mistake 4 — Saying “We Don’t Sell Data””Organizations must also assess:
Sharingand actual advertising technology.
Mistake 5 — Ignoring GPC
Section titled “Mistake 5 — Ignoring GPC”Opt-out preference signals must be incorporated into applicable privacy operations.
Mistake 6 — Cookie Banner Equals CCPA Compliance
Section titled “Mistake 6 — Cookie Banner Equals CCPA Compliance”A banner alone does not provide:
Rights Management
Data Inventory
Vendor Governance
Retention
Security
Risk AssessmentMistake 7 — Ignoring Employee Data
Section titled “Mistake 7 — Ignoring Employee Data”Older exemption assumptions can produce major gaps.
Mistake 8 — Keeping PI Forever
Section titled “Mistake 8 — Keeping PI Forever”Retention must be governed.
Mistake 9 — Treating Service Provider Contracts as a Checkbox
Section titled “Mistake 9 — Treating Service Provider Contracts as a Checkbox”Actual processing and data flows matter.
Mistake 10 — Ignoring 2026 Regulations
Section titled “Mistake 10 — Ignoring 2026 Regulations”Risk assessments, cybersecurity audits, and ADMT now need to be incorporated into the compliance roadmap, subject to their applicable phased deadlines. (California Privacy Protection Agency)
138. Weak CCPA Program
Section titled “138. Weak CCPA Program”Privacy Policy ↓Cookie Banner ↓Privacy Email Address139. Strong CCPA Program
Section titled “139. Strong CCPA Program”Applicability ↓PI Discovery ↓Purpose Mapping ↓Notice ↓Consumer Rights ↓Sale / Sharing Governance ↓GPC Enforcement ↓Sensitive PI Controls ↓Vendor Governance ↓Retention ↓Security ↓Risk Assessment ↓Continuous Assurance140. GRC Analyst Responsibilities
Section titled “140. GRC Analyst Responsibilities”A GRC professional supporting CCPA may:
-
perform applicability assessments.
-
maintain PI inventories.
-
identify Sensitive PI.
-
map processing purposes.
-
maintain notices.
-
coordinate consumer requests.
-
test deletion workflows.
-
test correction workflows.
-
evaluate sale and sharing.
-
test GPC implementation.
-
maintain vendor classifications.
-
review contractual controls.
-
maintain retention requirements.
-
coordinate security assessments.
-
support privacy risk assessments.
-
support cybersecurity-audit readiness.
-
maintain ADMT inventories.
-
track compliance findings.
-
maintain evidence.
-
prepare privacy dashboards.
-
support regulatory investigations.
GRC connects:
Privacy
Legal
Security
Marketing
Engineering
HR
Procurement
Data
AI Governance
Internal Audit141. CCPA Maturity Model
Section titled “141. CCPA Maturity Model”Level 1 — Reactive
Section titled “Level 1 — Reactive”Privacy Policy
Basic Request Handling
Cookie BannerLevel 2 — Documented
Section titled “Level 2 — Documented”PI Inventory
Notices
Rights Procedures
Vendor RegisterLevel 3 — Governed
Section titled “Level 3 — Governed”Sale / Sharing Mapping
GPC
Sensitive PI
Retention
Control TestingLevel 4 — Integrated
Section titled “Level 4 — Integrated”Automated Rights
Preference Management
Data Discovery
Vendor Integration
Risk AssessmentsLevel 5 — Continuous Assurance
Section titled “Level 5 — Continuous Assurance”Continuous Data Discovery
Automated GPC Validation
Continuous Privacy Testing
Automated Evidence
Real-Time Privacy Risk142. CCPA vs GDPR vs DPDP — Quick Comparison
Section titled “142. CCPA vs GDPR vs DPDP — Quick Comparison”| Area | CCPA / CPRA | GDPR | DPDP |
|---|---|---|---|
| Primary individual | Consumer | Data Subject | Data Principal |
| Primary regulated organization | Business | Controller | Data Fiduciary |
| Processor-type role | Service Provider / Contractor | Processor | Data Processor |
| Core model | Consumer rights + business obligations | Lawful processing | Consent + certain legitimate uses |
| Sensitive data | Sensitive PI | Special categories | Different statutory structure |
| Opt-out of sale | Yes | Different model | Different model |
| Opt-out of sharing | Yes | Different model | Different model |
| GPC | Important operational mechanism | Not equivalent | Not equivalent |
| Correction | Yes | Yes | Yes |
| Deletion | Yes, subject to exceptions | Erasure | Erasure under applicable conditions |
| Regulator | CPPA + AG enforcement | Supervisory Authorities | DPBI |
143. CCPA Mindset
Section titled “143. CCPA Mindset”For every processing activity ask:
Does CCPA Apply?
What California PIDo We Collect?
Is Sensitive PI Involved?
Why Do We Need It?
Is Collection Necessary?
What Did We Tellthe Consumer?
Who Receives It?
Is It Sold?
Is It Shared?
Can the Consumer Opt Out?
Are GPC Signals Honored?
How Long Is It Retained?
Can Consumers Access It?
Can They Correct It?
Can They Delete It?
Which Vendors Process It?
Is Security Reasonable?
Does Processing Requirea Risk Assessment?
Does ADMT Apply?
Can We Demonstrate Compliance?For every advertising technology ask:
What Personal InformationLeaves Our Environment?For every vendor ask:
What Is TheirCCPA Role?For every privacy claim ask:
Can We Prove ItTechnically?That is the practical CCPA/CPRA governance mindset.
Key Takeaways
Section titled “Key Takeaways”-
CPRA amended and expanded CCPA rather than creating a completely separate privacy regime. (California Department of Justice)
-
CCPA provides California consumers with substantial control over Personal Information.
-
The current CPI-adjusted revenue threshold is $26.625 million, alongside other applicability tests. (California Privacy Protection Agency)
-
Personal Information is defined broadly.
-
Sensitive Personal Information receives additional protections.
-
Consumers have rights to know, delete, correct, opt out of sale/sharing, limit certain uses of Sensitive PI, and avoid unlawful discrimination.
-
Sale and sharing must both be assessed.
-
GPC is an important operational opt-out mechanism.
-
Data minimization, purpose limitation, and retention should be built into privacy governance.
-
Service Providers, Contractors, and Third Parties must be correctly classified.
-
Security remains an important CCPA compliance component.
-
Current regulations effective January 1, 2026 add significant requirements involving privacy risk assessments, cybersecurity audits, and ADMT, with phased compliance deadlines. (California Privacy Protection Agency)
-
CCPA enforcement increasingly tests whether privacy controls work technically, not merely whether policies exist.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is CCPA?
-
How does CPRA relate to CCPA?
-
What businesses can fall within CCPA?
-
What is the current revenue threshold?
-
What is Personal Information?
-
What is Sensitive Personal Information?
-
What is a Business?
-
What is a Service Provider?
-
What is a Contractor?
-
What is Notice at Collection?
-
What is the Right to Know?
-
What is the Right to Delete?
-
What is the Right to Correct?
-
What does sale mean under CCPA?
-
What does sharing mean?
-
What is Global Privacy Control?
-
What is the right to limit use of Sensitive PI?
-
Why does data minimization matter?
-
How should vendors be governed?
-
What new areas are addressed by the regulations effective in 2026?
What’s Next?
Section titled “What’s Next?”➡️ Next: 06 — Data Classification
In the next lesson, you will move from individual privacy regulations into the enterprise discipline of classifying information according to its sensitivity, value, legal requirements, and business impact.
You will examine:
Data Discovery ↓Data Inventory ↓Classification Levels ↓Public ↓Internal ↓Confidential ↓Restricted ↓Personal Data ↓Sensitive Data ↓Data Ownership ↓Labeling ↓Handling Requirements ↓Technical Enforcement ↓Continuous ClassificationYou will also build practical artifacts including a Data Classification Standard, Data Classification Matrix, Data Owner Register, Sensitive Data Inventory, Data Handling Matrix, Labeling Standard, Cloud Data Classification Register, and Classification Compliance Dashboard.