Skip to content

05 CCPA & CPRA

The California Consumer Privacy Act (CCPA) is one of the most important comprehensive privacy laws in the United States.

The California Privacy Rights Act (CPRA) amended and expanded the CCPA. CPRA should therefore not normally be treated as a completely separate privacy law.

A better way to describe the current framework is:

CCPA
Amended by CPRA
CCPA Regulations
California Privacy
Compliance Framework

The CPRA amendments introduced additional protections including the right to correct inaccurate personal information and the right to limit certain uses and disclosures of sensitive personal information. (California Department of Justice)

The framework is administered and enforced in significant part by the California Privacy Protection Agency (CPPA/CalPrivacy), alongside enforcement authority held by the California Attorney General. The current regulations effective January 1, 2026 also introduce or operationalize important requirements involving risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT), with some compliance deadlines phased in. (California Privacy Protection Agency)

A practical enterprise model looks like:

Applicability
Personal Information Inventory
Sensitive Personal Information
Purpose & Data Minimization
Notice at Collection
Consumer Rights
Sale / Sharing Assessment
Opt-Out Management
Service Provider Governance
Retention
Security
Risk Assessment
Continuous Compliance

By the end of this lesson, you will be able to:

  • Explain the relationship between CCPA and CPRA.

  • Determine whether an organization may fall within CCPA scope.

  • Define Consumer.

  • Define Personal Information.

  • Identify Sensitive Personal Information.

  • Understand Business, Service Provider, Contractor, and Third Party roles.

  • Understand Notice at Collection requirements.

  • Explain consumer privacy rights.

  • Understand requests to know, delete, and correct.

  • Explain sale and sharing.

  • Understand opt-out requirements.

  • Understand Global Privacy Control.

  • Explain Sensitive Personal Information limitations.

  • Understand data minimization and purpose limitation.

  • Understand retention governance.

  • Evaluate service provider and contractor relationships.

  • Understand reasonable security expectations.

  • Understand current risk-assessment requirements.

  • Understand cybersecurity-audit requirements.

  • Understand emerging ADMT obligations.

  • Build an enterprise CCPA compliance program.

CCPA stands for:

California Consumer Privacy Act

The law gives California consumers significant rights over how businesses collect, use, disclose, sell, and share their personal information.

Core concepts include:

Transparency
Consumer Control
Access
Deletion
Correction
Opt-Out
Sensitive PI Protection
Non-Discrimination

CPRA stands for:

California Privacy Rights Act

California voters approved CPRA through Proposition 24 in 2020.

CPRA:

Amended
+
Expanded

the CCPA.

Important additions included:

Sensitive Personal Information
Right to Correction
Right to Limit Certain Uses of SPI
Expanded Opt-Out Rights
California Privacy Protection Agency
Additional Governance Requirements

The California Attorney General specifically notes that CPRA amends the CCPA rather than creating an entirely separate law. (California Department of Justice)

For enterprise compliance, think:

CCPA Statute
+
CPRA Amendments
+
CCPA Regulations
+
CPPA Guidance
+
Enforcement

The CPPA’s current law and regulations page identifies versions of the CCPA statute and regulations effective January 1, 2026. (California Privacy Protection Agency)

A:

Consumer

generally means a natural person who is a California resident.

The framework can therefore affect organizations outside California when they do business in California and satisfy applicable thresholds.

CCPA generally applies to qualifying:

For-Profit Businesses

doing business in California that satisfy at least one statutory threshold.

As of 2026, one threshold is annual gross revenue above:

$26.625 Million

for the preceding calendar year.

Other principal thresholds include buying, selling, or sharing personal information of:

100,000+
California Consumers
or Households

or deriving:

50%+
Annual Revenue

from selling or sharing California consumers’ personal information. (California Privacy Protection Agency)

For-Profit Entity
Doing Business in California?
Threshold Met?
Exemption / Exception?
CCPA Applicability

Create:

01 CCPA Applicability Assessment

Use:

Question Response Evidence
For-profit organization?
Doing business in California?
Revenue threshold met?
100,000 consumer/household threshold met?
50% sale/share revenue threshold met?
Exemptions applicable?
CCPA applicable?

CCPA generally does not apply directly to:

Nonprofit Organizations
Government Agencies

although organizations should evaluate their specific relationships and circumstances. (California Privacy Protection Agency)

CCPA defines Personal Information broadly.

Think:

Information That Identifies
Relates To
Describes
Is Reasonably Capable
of Being Associated With
or Could Reasonably Be Linked
With a Consumer or Household

Examples can include:

Name
Postal Address
Email
IP Address
Account Identifier
Purchase History
Browsing History
Geolocation
Biometric Information
Employment Information
Inferences

The definition can therefore extend considerably beyond traditional identifiers. (California Department of Justice)

An important CCPA characteristic is that Personal Information can potentially relate to:

Consumer
OR
Household

This differs from some privacy frameworks that focus almost entirely on identifiable individuals.

Create:

02 California Personal Information Inventory

Use:

Business Process PI Category System Purpose Owner

CPRA introduced the concept of:

Sensitive Personal Information

or:

SPI

Sensitive Personal Information can include specified categories such as:

Social Security Number
Driver's License Information
Financial Account Credentials
Precise Geolocation
Certain Communications Content
Genetic Data
Certain Biometric Information
Health Information
Racial or Ethnic Origin
Religious Beliefs
Sex Life / Sexual Orientation

depending on statutory definitions and processing context. (California Department of Justice)

Create:

03 Sensitive Personal Information Register

Use:

SPI System Purpose Use Disclosure Owner

Organizations should identify their role.

Important roles include:

Business
Service Provider
Contractor
Third Party

A:

Business

is generally the regulated entity that determines purposes and means of processing and meets applicable statutory requirements.

Conceptually:

Business
Decision Maker

But do not automatically treat it as legally identical to a GDPR Controller.

A:

Service Provider

processes Personal Information on behalf of a Business under applicable contractual restrictions.

The framework also recognizes:

Contractor

relationships with specific statutory and contractual requirements.

A recipient that does not qualify for applicable Business, Service Provider, Contractor, or other specified treatment may be considered a:

Third Party

depending on the relationship.

Create:

04 CCPA Party Role Register

Use:

Organization Relationship Role PI Contract

Businesses must provide required information:

At or Before
the Point of Collection

through an appropriate:

Notice at Collection

A practical notice should help explain:

What PI Is Collected?
Why Is It Collected?
How Will It Be Used?
Is Sensitive PI Involved?
How Long Is It Retained?
What Rights Apply?

The 2026 regulations specifically contain requirements governing the Notice at Collection. (California Privacy Protection Agency)

Weak:

We May Collect
Information About You.

Stronger:

Email Address
Account Registration
Payment Information
Transaction Processing
Location
Delivery

Create:

05 CCPA Notice-at-Collection Register

Use:

Collection Point PI Purpose Notice Owner Review

Organizations should also maintain an appropriate:

Privacy Policy

describing their CCPA practices and applicable consumer rights.

Do not treat these as identical.

Notice at Collection
Collection-Specific Transparency

while:

Privacy Policy
Broader Privacy Practices

California consumers have significant rights under CCPA.

Core rights include:

Right to Know
Right to Delete
Right to Correct
Right to Opt-Out
of Sale or Sharing
Right to Limit Certain Uses
of Sensitive PI
Right to Non-Discrimination

(California Department of Justice)

Consumers can request information about Personal Information collected and relevant processing activities.

A request may involve information about:

Categories of PI
Specific Pieces
Sources
Business Purposes
Third Parties
Sale / Sharing
Request
Identity Verification
Data Discovery
Review
Response
Evidence

Consumers can request deletion of certain Personal Information collected from them, subject to statutory exceptions.

Request
Verify
Locate PI
Assess Exception
Delete
Service Provider Actions
Confirm

Deletion is not always:

Delete Everything
Immediately

Applicable exceptions and legal requirements may permit or require continued retention.

Consumers may request correction of inaccurate Personal Information.

This right was added through CPRA. (California Department of Justice)

Correction Request
Verify
Locate Information
Evaluate Accuracy
Correct
Propagate Where Required
Document

Create:

06 CCPA Consumer Rights Register

Use:

Request Right Received Verified Completed Evidence

Verification should balance:

Privacy
+
Security
+
Consumer Accessibility

Weak:

Consumer Requests Data
Send Everything
Without Verification

creates another privacy risk.

Consumers generally cannot be unlawfully discriminated against because they exercised CCPA rights.

Examples requiring careful review include:

Different Pricing
Different Service Level
Denial of Service
Different Quality

where linked to privacy-right exercise.

CCPA gives:

Sale

a broader privacy-law meaning than simply:

Selling a Database
for Cash

Organizations must evaluate the statutory definition and actual data flows.

CPRA added an important concept:

Sharing

particularly concerning cross-context behavioral advertising.

A company may say:

We Never Sell Data.

But still use:

Advertising Technology
Tracking Pixels
Advertising SDKs
Cross-Site Tracking

that can create:

Sharing

questions.

Create:

07 Sale & Sharing Inventory

Use:

Data Flow Recipient PI Purpose Sale? Sharing?

Assess:

Cookies
Pixels
Advertising SDKs
Analytics Tools
Social Plugins

Do not evaluate only backend databases.

Consumers have a right to direct a Business to stop applicable:

Sale
or
Sharing

of Personal Information. (California Department of Justice)

Where applicable, businesses may need mechanisms such as:

Do Not Sell or Share
My Personal Information

The regulations specifically govern notices and mechanisms for this right. (California Privacy Protection Agency)

A major operational requirement is recognition of applicable:

Opt-Out Preference Signals

such as:

Global Privacy Control

or:

GPC

California’s Attorney General identifies GPC as a mechanism consumers may use to opt out of sale or sharing. (California Department of Justice)

Browser
GPC Signal
Website
Detect Signal
Apply Opt-Out
Stop Applicable Sale / Sharing

A GRC assessment should verify:

Signal Received?
Signal Recognized?
Advertising Disabled?
Sharing Stopped?
Preference Persisted?
Evidence Available?

Privacy programs should evaluate whether opt-outs are properly applied across relevant consumer accounts, services, and devices.

This is a real enforcement issue: California’s Attorney General announced a $2.75 million settlement in February 2026 involving allegations that consumer sale/sharing opt-outs were not fully effectuated across associated devices and streaming services. (California Department of Justice)

Consumers can have the right to limit certain:

Use
+
Disclosure

of Sensitive Personal Information. (California Department of Justice)

Where applicable:

Limit the Use of My
Sensitive Personal Information

may need to be made available.

Sensitive PI
Purpose Identified
Permitted Use?
├── Yes → Process
└── No
Limit Right Assessment

A strong CCPA program asks:

What Information
Do We Actually Need?

rather than:

What Information
Can We Collect?

The current regulations restrict collection, use, retention, and sharing in relation to reasonable consumer expectations and disclosed purposes. (California Privacy Protection Agency)

Weak:

Collect Everything
Keep Forever
Use Later

Strong:

Defined Purpose
Necessary PI
Limited Collection
Limited Use
Defined Retention

If information was collected for:

Deliver Product

using it later for:

Unrelated Behavioral Profiling

requires a separate compliance assessment.

Data minimization is not merely theoretical. In May 2026, California authorities announced a $12.75 million privacy settlement involving General Motors, describing it as California’s first CCPA data-minimization case. (California Department of Justice)

Create:

08 CCPA Purpose & Minimization Register

Use:

PI Purpose Necessary? Additional Use Approved

Personal Information should not simply be retained:

Forever

without a defined business or legal reason.

Collection
Purpose
Use
Retention
Deletion / De-identification

Create:

09 CCPA Retention Matrix

Use:

PI Purpose Retention Trigger Deletion Owner
Marketing Lead
Inactive
Retention Period Reached
Delete / De-identify

subject to applicable requirements.

Organizations frequently disclose PI to:

Cloud Providers
CRM Providers
Marketing Platforms
Analytics Providers
Support Platforms
Payroll Providers

For every vendor ask:

What PI?
Why?
What Role?
Service Provider?
Contractor?
Third Party?
Sale / Sharing?

Contracts should address applicable restrictions regarding:

Processing Purpose
Use
Disclosure
Retention
Subcontracting
Compliance

Create:

10 CCPA Service Provider & Contractor Register

Use:

Vendor Role PI Purpose Contract Review

Weak:

Contract Signed
Vendor Compliant

Stronger:

Due Diligence
Correct Classification
Contract
Monitoring
Evidence

CCPA includes significant security implications.

Organizations should maintain:

Reasonable Security

appropriate to the nature of the Personal Information.

A practical control environment may include:

IAM
MFA
Encryption
Logging
Vulnerability Management
Secure Configuration
Incident Response
Monitoring

Create:

11 CCPA Security Control Matrix

Use:

PI Risk Control System Owner Evidence

Certain breaches involving specified Personal Information can create a private right of action.

The current CPI-adjusted statutory damages range is:

$107 – $799
per consumer
per incident

or actual damages, whichever is greater, where the statutory requirements are met. (California Privacy Protection Agency)

Do not teach:

Every CCPA Violation
=
Private Lawsuit

The private right of action is narrower and principally associated with qualifying security breaches.

Incident
California PI Involved?
Data Type
Security Assessment
Breach Law Assessment
CCPA Exposure
Remediation

California’s 2026 regulations introduce operational requirements for certain businesses to conduct:

Risk Assessments

for specified processing presenting significant privacy risks. (California Privacy Protection Agency)

Processing Activity
Purpose
Consumer Benefit
Privacy Risk
Safeguards
Residual Risk
Decision

Create:

12 CCPA Privacy Risk Assessment Register

Use:

Processing Purpose Benefit Risk Safeguard Decision

Businesses subject to the new requirements were required to begin compliance with the risk-assessment rules on:

January 1, 2026

and the CPPA states that required attestations and summary information are due by:

April 1, 2028

for the initial submission framework. (California Privacy Protection Agency)

Certain businesses are also subject to:

Annual Cybersecurity Audit

requirements under the 2026 regulations. (California Privacy Protection Agency)

Assess:

Security Program
Asset Inventory
IAM
Authentication
Encryption
Logging
Incident Response
Vulnerability Management
Third Parties
Governance

Initial certification deadlines are phased according to business revenue.

The CPPA identifies deadlines beginning:

April 1, 2028

for businesses over $100 million in revenue, followed by later deadlines for smaller covered businesses. (California Privacy Protection Agency)

Create:

13 CCPA Cybersecurity Audit Readiness Register

Use:

Requirement Control Evidence Owner Status

The current regulations also establish requirements concerning:

Automated Decisionmaking Technology

or:

ADMT

in specified circumstances. (California Privacy Protection Agency)

Potential enterprise use cases may include:

Employment Decisions
Credit Decisions
Insurance Decisions
Eligibility Decisions
Automated Profiling

depending on the actual technology and statutory/regulatory applicability.

The most important question is not simply:

Do We Use AI?

Instead:

Does the Technology
Meet the ADMT Definition?
Is It Used for a
Covered Significant Decision?

The regulations include requirements involving consumer:

Access

and:

Opt-Out

in applicable ADMT contexts. (California Privacy Protection Agency)

The CPPA states that businesses subject to applicable ADMT requirements must begin complying on:

January 1, 2027

(California Privacy Protection Agency)

Create:

14 CCPA ADMT Inventory

Use:

System Decision PI Purpose Impact Owner

An important historical mistake is assuming:

Employee Data
=
Always Exempt

or:

B2B Contact Data
=
Always Exempt

Organizations should assess current statutory treatment rather than relying on older temporary exemptions.

A mature program should inventory:

Employee
Applicant
Contractor
Former Employee

Personal Information where CCPA applies.

Contact Information
Payroll
Performance Data
Device Monitoring
Background Information
Biometric Data

Create:

15 California Workforce PI Register

Use:

Process PI Purpose System Retention Owner

CCPA provides enhanced protections concerning sale or sharing involving consumers under:

16

Organizations should assess whether applicable:

Opt-In

requirements apply before selling or sharing Personal Information of minors.

For children under 13, applicable parental authorization requirements become particularly important.

Consumer
Age Assessment
Under 16?
Sale / Sharing?
Required Authorization

A scalable enterprise workflow:

Request
Authenticate
Classify
Search Systems
Apply Exceptions
Fulfill
Communicate
Evidence

Requests may arrive through:

Website
Email
Phone
Privacy Portal
Authorized Agent

depending on applicable requirements and business practices.

Consumers may use:

Authorized Agents

to exercise certain CCPA rights.

Organizations need procedures to validate appropriate authority.

Create:

16 CCPA Privacy Request Tracker

Use:

Request Consumer Right Received Deadline Status

Do not collect excessive additional PI merely to verify a privacy request.

The verification process itself should follow:

Data Minimization
Consumer
Privacy Portal
Identity Verification
Request Orchestration
CRM
Data Lake
SaaS
Advertising Platforms
Response

Large organizations increasingly need:

Data Discovery
Data Classification
Identity Matching
Request Orchestration
Deletion Automation

to manage privacy operations at scale.

Create:

17 CCPA Compliance Evidence Repository

Structure:

01 Applicability
02 PI Inventory
03 Sensitive PI
04 Notices
05 Consumer Requests
06 Sale & Sharing
07 Opt-Out
08 GPC
09 Vendors
10 Retention
11 Security
12 Risk Assessments
13 Cybersecurity Audits
14 ADMT
15 Training
16 Testing

Sample:

20 Websites / Applications

Verify:

Collection Points
PI Categories
Purpose
Retention
Notice Availability

Enable:

Global Privacy Control

Then verify:

Website Detects Signal
Advertising Changes
Applicable Sharing Stops
Preference Persists

Compare:

Declared Data Flows

against:

Actual Network Traffic
Cookies
Pixels
SDKs
Vendor Integrations

Privacy team says:

No Personal Information
Is Shared.

Website actually loads:

Advertising Pixel
Consumer Identifier
Third-Party Ad Platform

Potential:

Sale / Sharing
Classification Gap

Sample:

25 Completed
Deletion Requests

Verify deletion from:

CRM
Marketing Platform
Data Lake
Support Platform
Applicable Vendors

Sample:

20 Correction Requests

Verify:

Verification
Correction
Propagation
Response
Evidence

Identify systems containing:

Precise Location
Financial Credentials
Health Information
Biometric Information

Verify:

Purpose
Access
Use
Disclosure
Limit Mechanism

where applicable.

Policy:

Inactive Accounts:
3 Years

Actual:

Oldest Inactive Account:
11 Years

Potential:

Retention Control Gap

Population:

80 Vendors
Processing California PI

Results:

65 Correctly Classified
10 Missing Required Terms
5 Unknown Data Flows

Potential:

Third-Party Governance Gap

Test:

Chrome + GPC
Firefox + GPC
Anonymous User
Authenticated User

Verify appropriate handling.

114. Control Testing — Data Minimization

Section titled “114. Control Testing — Data Minimization”

Application collects:

Precise Geolocation

Purpose:

Email Newsletter

Ask:

Why Is Location Necessary?

Potential:

Data Minimization Gap

Create:

18 CCPA Compliance Gap Register

Use:

Finding Requirement Risk Severity Owner Due

Finding:

Website Receives GPC
But Advertising Cookies
Continue Operating

Risk:

Consumer Opt-Out
May Not Be Honored

Why?

CMP Detects GPC

but:

Advertising SDK
Does Not Consume
CMP Preference

Root cause:

Privacy preference management was not integrated with all advertising technologies.

Disable Applicable
Advertising Processing
for GPC Users
Central Consent /
Preference Architecture
Vendor Integration Standard
Automated GPC Testing

Finding:

Consumer Data Deleted
from CRM

but remains in:

Marketing Platform

Root cause:

Deletion Workflow
Only Integrated
with Core Systems
Enterprise Data Inventory
System Integration
Vendor Deletion Workflow
Completion Validation

Track:

Metric Target
PI Processing Activities Inventoried 100%
Collection Points With Current Notice 100%
Rights Requests Within Required Timeline 100%
Applicable GPC Signals Honored 100%
Vendors Correctly Classified 100%
Sensitive PI Uses Assessed 100%
Overdue High-Risk Findings 0
Unapproved Sale/Sharing Flows 0
Percentage of Consumer
Requests Completed
Within Required Timeline
Percentage of Applicable
Opt-Out Preference Signals
Successfully Enforced
Unclassified Third-Party
Personal Information Flows
Sensitive PI Processing
Without Documented Purpose
PI Repositories
Beyond Approved
Retention Period
Vendors Processing PI
Without Required
Contractual Controls

Use fictional:

CloudShop

Facts:

$40M Revenue
California Customers
150,000 California
Consumer Records

Determine:

Does CCPA Apply?
Which Thresholds?
What Evidence?

130. Practical Activity — Data Inventory

Section titled “130. Practical Activity — Data Inventory”

CloudShop operates:

Website
Mobile App
CRM
Marketing Platform
Analytics
Customer Support

Identify:

PI
Sensitive PI
Purpose
Recipient
Retention

131. Practical Activity — Tracking Technologies

Section titled “131. Practical Activity — Tracking Technologies”

Website uses:

Analytics Cookie
Advertising Pixel
Social Media Pixel
Session Replay
Personalization Engine

For each determine:

What PI?
Which Recipient?
Purpose?
Sale?
Sharing?
Opt-Out Required?

132. Practical Activity — Consumer Request

Section titled “132. Practical Activity — Consumer Request”

Consumer requests:

Tell Me What You Know
Correct My Address
Delete My Account
Stop Sharing My Data

Build one coordinated workflow.

Consumer visits with:

GPC = Enabled

Determine expected behavior across:

Website
Advertising
Analytics
Logged-In Account
Mobile Experience

Mobile application collects:

Precise Geolocation

for:

Nearby Store Recommendations

Assess:

Purpose
Necessity
Notice
Sensitive PI
Limit Right
Retention

Marketing vendor receives:

Email
Device ID
Browsing Activity
Purchase History

Determine:

Role
Purpose
Sale / Sharing
Contract
Opt-Out Impact

Organization uses automated technology to:

Score Job Applicants
Reject Some Applicants
Automatically

Assess:

ADMT Applicability
Significant Decision
PI
Risk Assessment
Consumer Rights
2027 Readiness
  • California business activity assessed.

  • revenue threshold assessed.

  • consumer/household volume assessed.

  • sale/share revenue assessed.

  • applicable exemptions reviewed.

  • California PI identified.

  • Sensitive PI identified.

  • systems mapped.

  • collection points documented.

  • recipients identified.

  • purposes documented.

  • PI necessity assessed.

  • secondary uses reviewed.

  • excessive collection challenged.

  • Notice at Collection implemented.

  • Privacy Policy maintained.

  • PI categories accurate.

  • purposes accurate.

  • retention disclosures reviewed.

  • know workflow established.

  • deletion workflow established.

  • correction workflow established.

  • opt-out workflow established.

  • Sensitive PI limitation supported where applicable.

  • authorized agents supported.

  • non-discrimination controls established.

  • sale assessed.

  • sharing assessed.

  • advertising technologies inventoried.

  • website trackers reviewed.

  • mobile SDKs reviewed.

  • applicable opt-out mechanism implemented.

  • GPC recognized.

  • preferences propagated.

  • cross-device behavior assessed.

  • opt-out tested.

  • SPI inventory maintained.

  • purposes documented.

  • access restricted.

  • limitation requirements assessed.

  • vendors inventoried.

  • roles classified.

  • contracts reviewed.

  • data flows documented.

  • monitoring established.

  • retention periods defined.

  • deletion triggers established.

  • exceptions documented.

  • actual retention tested.

  • PI security risks assessed.

  • IAM controls established.

  • encryption assessed.

  • logging implemented.

  • vulnerabilities managed.

  • incidents investigated.

  • applicable processing identified.

  • privacy risks assessed.

  • safeguards documented.

  • assessments maintained.

  • submission readiness established.

  • applicability assessed.

  • audit deadline identified.

  • security evidence centralized.

  • audit readiness tracked.

  • ADMT inventory established.

  • significant decisions identified.

  • applicable risks assessed.

  • consumer rights mapped.

  • 2027 requirements tracked.

Mistake 1 — Treating CCPA and CPRA as Separate Laws

Section titled “Mistake 1 — Treating CCPA and CPRA as Separate Laws”

CPRA amended the CCPA.

Mistake 2 — Using the Old $25 Million Threshold

Section titled “Mistake 2 — Using the Old $25 Million Threshold”

The CPI-adjusted threshold currently applicable is $26.625 million. (California Privacy Protection Agency)

Mistake 3 — Assuming Personal Information Means Only Name and Email

Section titled “Mistake 3 — Assuming Personal Information Means Only Name and Email”

CCPA’s definition is considerably broader.

Mistake 4 — Saying “We Don’t Sell Data”

Section titled “Mistake 4 — Saying “We Don’t Sell Data””

Organizations must also assess:

Sharing

and actual advertising technology.

Opt-out preference signals must be incorporated into applicable privacy operations.

Section titled “Mistake 6 — Cookie Banner Equals CCPA Compliance”

A banner alone does not provide:

Rights Management
Data Inventory
Vendor Governance
Retention
Security
Risk Assessment

Older exemption assumptions can produce major gaps.

Retention must be governed.

Mistake 9 — Treating Service Provider Contracts as a Checkbox

Section titled “Mistake 9 — Treating Service Provider Contracts as a Checkbox”

Actual processing and data flows matter.

Risk assessments, cybersecurity audits, and ADMT now need to be incorporated into the compliance roadmap, subject to their applicable phased deadlines. (California Privacy Protection Agency)

Privacy Policy
Cookie Banner
Privacy Email Address
Applicability
PI Discovery
Purpose Mapping
Notice
Consumer Rights
Sale / Sharing Governance
GPC Enforcement
Sensitive PI Controls
Vendor Governance
Retention
Security
Risk Assessment
Continuous Assurance

A GRC professional supporting CCPA may:

  • perform applicability assessments.

  • maintain PI inventories.

  • identify Sensitive PI.

  • map processing purposes.

  • maintain notices.

  • coordinate consumer requests.

  • test deletion workflows.

  • test correction workflows.

  • evaluate sale and sharing.

  • test GPC implementation.

  • maintain vendor classifications.

  • review contractual controls.

  • maintain retention requirements.

  • coordinate security assessments.

  • support privacy risk assessments.

  • support cybersecurity-audit readiness.

  • maintain ADMT inventories.

  • track compliance findings.

  • maintain evidence.

  • prepare privacy dashboards.

  • support regulatory investigations.

GRC connects:

Privacy
Legal
Security
Marketing
Engineering
HR
Procurement
Data
AI Governance
Internal Audit
Privacy Policy
Basic Request Handling
Cookie Banner
PI Inventory
Notices
Rights Procedures
Vendor Register
Sale / Sharing Mapping
GPC
Sensitive PI
Retention
Control Testing
Automated Rights
Preference Management
Data Discovery
Vendor Integration
Risk Assessments
Continuous Data Discovery
Automated GPC Validation
Continuous Privacy Testing
Automated Evidence
Real-Time Privacy Risk

142. CCPA vs GDPR vs DPDP — Quick Comparison

Section titled “142. CCPA vs GDPR vs DPDP — Quick Comparison”
Area CCPA / CPRA GDPR DPDP
Primary individual Consumer Data Subject Data Principal
Primary regulated organization Business Controller Data Fiduciary
Processor-type role Service Provider / Contractor Processor Data Processor
Core model Consumer rights + business obligations Lawful processing Consent + certain legitimate uses
Sensitive data Sensitive PI Special categories Different statutory structure
Opt-out of sale Yes Different model Different model
Opt-out of sharing Yes Different model Different model
GPC Important operational mechanism Not equivalent Not equivalent
Correction Yes Yes Yes
Deletion Yes, subject to exceptions Erasure Erasure under applicable conditions
Regulator CPPA + AG enforcement Supervisory Authorities DPBI

For every processing activity ask:

Does CCPA Apply?
What California PI
Do We Collect?
Is Sensitive PI Involved?
Why Do We Need It?
Is Collection Necessary?
What Did We Tell
the Consumer?
Who Receives It?
Is It Sold?
Is It Shared?
Can the Consumer Opt Out?
Are GPC Signals Honored?
How Long Is It Retained?
Can Consumers Access It?
Can They Correct It?
Can They Delete It?
Which Vendors Process It?
Is Security Reasonable?
Does Processing Require
a Risk Assessment?
Does ADMT Apply?
Can We Demonstrate Compliance?

For every advertising technology ask:

What Personal Information
Leaves Our Environment?

For every vendor ask:

What Is Their
CCPA Role?

For every privacy claim ask:

Can We Prove It
Technically?

That is the practical CCPA/CPRA governance mindset.

  • CPRA amended and expanded CCPA rather than creating a completely separate privacy regime. (California Department of Justice)

  • CCPA provides California consumers with substantial control over Personal Information.

  • The current CPI-adjusted revenue threshold is $26.625 million, alongside other applicability tests. (California Privacy Protection Agency)

  • Personal Information is defined broadly.

  • Sensitive Personal Information receives additional protections.

  • Consumers have rights to know, delete, correct, opt out of sale/sharing, limit certain uses of Sensitive PI, and avoid unlawful discrimination.

  • Sale and sharing must both be assessed.

  • GPC is an important operational opt-out mechanism.

  • Data minimization, purpose limitation, and retention should be built into privacy governance.

  • Service Providers, Contractors, and Third Parties must be correctly classified.

  • Security remains an important CCPA compliance component.

  • Current regulations effective January 1, 2026 add significant requirements involving privacy risk assessments, cybersecurity audits, and ADMT, with phased compliance deadlines. (California Privacy Protection Agency)

  • CCPA enforcement increasingly tests whether privacy controls work technically, not merely whether policies exist.

Before continuing, make sure you can answer:

  1. What is CCPA?

  2. How does CPRA relate to CCPA?

  3. What businesses can fall within CCPA?

  4. What is the current revenue threshold?

  5. What is Personal Information?

  6. What is Sensitive Personal Information?

  7. What is a Business?

  8. What is a Service Provider?

  9. What is a Contractor?

  10. What is Notice at Collection?

  11. What is the Right to Know?

  12. What is the Right to Delete?

  13. What is the Right to Correct?

  14. What does sale mean under CCPA?

  15. What does sharing mean?

  16. What is Global Privacy Control?

  17. What is the right to limit use of Sensitive PI?

  18. Why does data minimization matter?

  19. How should vendors be governed?

  20. What new areas are addressed by the regulations effective in 2026?

➡️ Next: 06 — Data Classification

In the next lesson, you will move from individual privacy regulations into the enterprise discipline of classifying information according to its sensitivity, value, legal requirements, and business impact.

You will examine:

Data Discovery
Data Inventory
Classification Levels
Public
Internal
Confidential
Restricted
Personal Data
Sensitive Data
Data Ownership
Labeling
Handling Requirements
Technical Enforcement
Continuous Classification

You will also build practical artifacts including a Data Classification Standard, Data Classification Matrix, Data Owner Register, Sensitive Data Inventory, Data Handling Matrix, Labeling Standard, Cloud Data Classification Register, and Classification Compliance Dashboard.