CCPA/CPRA
California Consumer Privacy Act / California Privacy Rights Act
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Business Obligations
| Code | Title |
|---|---|
| CCR §7012 | Notice at Collection Drafting Requirements |
| CCR §7025 | Opt-Out Preference Signal Configuration |
| §1798.100 | General Duties of Businesses that Collect Personal Information |
| §1798.130(a)(3) | Privacy Policy Content Requirements |
| §1798.130(a)(5)(C) | Notice at Collection |
| §1798.135(a) | Do Not Sell or Share My Personal Information Link |
| §1798.135(b) | Opt-Out Preference Signals (Global Privacy Control) |
| §1798.140 | Threshold for Applicability and Key Definitions |
| §1798.145 | Exemptions and Permitted Activities |
| §1798.185(a)(15) | Risk Assessments for High-Risk Processing |
CCPA/CPRA: Accountability & Compliance
Demonstration of compliance and accountability (CCPA/CPRA)
| Code | Title |
|---|---|
| CCPA-25 | Compliance monitoring and auditing |
| CCPA-26 | Training and awareness programs |
| CCPA-27 | Regulatory reporting and cooperation |
| CCPA-28 | Complaints handling and resolution |
| CCPA-29 | Enforcement and penalties awareness |
CCPA/CPRA: Data Collection & Consent
Requirements for lawful collection and consent management (CCPA/CPRA)
| Code | Title |
|---|---|
| CCPA-01 | Notice and transparency requirements |
| CCPA-02 | Consent management and withdrawal |
| CCPA-03 | Lawful basis for processing |
| CCPA-04 | Purpose limitation and specification |
| CCPA-05 | Data minimization requirements |
CCPA/CPRA: Data Governance
Organizational governance of personal data processing (CCPA/CPRA)
| Code | Title |
|---|---|
| CCPA-19 | Data protection officer designation |
| CCPA-20 | Records of processing activities |
| CCPA-21 | Data protection impact assessments |
| CCPA-22 | Privacy by design and default |
| CCPA-23 | Data processing agreements |
| CCPA-24 | Cross-border transfer safeguards |
CCPA/CPRA: Data Security
Technical and organizational security measures (CCPA/CPRA)
| Code | Title |
|---|---|
| CCPA-13 | Encryption of personal data |
| CCPA-14 | Pseudonymization techniques |
| CCPA-15 | Access control for personal data |
| CCPA-16 | Data breach notification requirements |
| CCPA-17 | Security incident response procedures |
| CCPA-18 | Regular security testing and assessment |
CCPA/CPRA: Data Subject Rights
Individual rights regarding their personal data (CCPA/CPRA)
| Code | Title |
|---|---|
| CCPA-06 | Right of access to personal data |
| CCPA-07 | Right to rectification of inaccurate data |
| CCPA-08 | Right to erasure and deletion |
| CCPA-09 | Right to data portability |
| CCPA-10 | Right to restrict processing |
| CCPA-11 | Right to object to processing |
| CCPA-12 | Automated decision-making protections |
Consumer Rights
| Code | Title |
|---|---|
| CCR §7026 | Requests to Opt-Out of Sale/Sharing Handling |
| §1798.105 | Right to Delete Personal Information |
| §1798.106 | Right to Correct Inaccurate Personal Information |
| §1798.110 | Right to Know Categories and Specific Pieces of Personal Information Collected |
| §1798.115 | Right to Know Personal Information Sold or Shared and Recipients |
| §1798.120 | Right to Opt Out of Sale or Sharing of Personal Information |
| §1798.125 | Non-Discrimination for Exercise of Rights |
| §1798.135(c) | Authorized Agent Requests |
| §1798.185(a)(16) | Automated Decisionmaking Technology Access and Opt-Out |
Enforcement
| Code | Title |
|---|---|
| CCR §7301-7304 | CPPA Audit and Investigation Cooperation |
| §1798.150 | Private Right of Action for Data Breaches |
| §1798.155 | Administrative Enforcement and Civil Penalties |
Privacy Operations
| Code | Title |
|---|---|
| CCR §7060 | Consumer Identity Verification |
| CCR §7100-7102 | Recordkeeping Requirements |
| §1798.130(a)(1) | Designated Methods for Submitting Consumer Requests |
| §1798.130(a)(2) | 45-Day Response Window and Identity Verification |
| §1798.130(c) | Annual Metrics Disclosure (Large Businesses) |
Sensitive PI
| Code | Title |
|---|---|
| CCR §7027 | Requests to Limit Use of Sensitive PI Handling |
| §1798.121 | Right to Limit Use and Disclosure of Sensitive Personal Information |
Service Provider
| Code | Title |
|---|---|
| CCR §7050 | Service Provider and Contractor Obligations |
| §1798.100(d) | Contractual Requirements for Third Parties, Service Providers, and Contractors |
Your Compliance Coverage
If you comply with CCPA/CPRA, you already cover:
APPI
23%
14 controls mapped
Compare →LGPD
23%
14 controls mapped
Compare →Bahrain PDPL
23%
14 controls mapped
Compare →+ 606 more: Argentina PDPA (23%), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (23%)
See all 609 mapped frameworks ↓Maps to 609 other frameworks
Frequently Asked Questions
What is CCPA/CPRA?
CCPA/CPRA is a compliance framework from United States - California with 11 domains and 60 controls. California Consumer Privacy Act / California Privacy Rights Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CCPA/CPRA have?
CCPA/CPRA has 60 controls organised across 11 domains. The largest domains are Business Obligations (10 controls), Consumer Rights (9 controls), CCPA/CPRA: Data Subject Rights (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CCPA/CPRA map to?
CCPA/CPRA maps to 609 other compliance frameworks. The top mapping partners are APPI (23% coverage), LGPD (23% coverage), Bahrain PDPL (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CCPA/CPRA compliance?
Start your CCPA/CPRA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CCPA/CPRA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 60 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required