CCPA/CPRA
California Consumer Privacy Act / California Privacy Rights Act
CCPA/CPRA is a compliance framework from United States - California with 6 domains and 32 controls that map to 12 other frameworks. The largest domains are Business Obligations (11 controls), Consumer Rights (9 controls), Privacy Operations (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Business Obligations
| Code | Title |
|---|---|
| CCR §7012 | Notice at Collection Drafting Requirements |
| CCR §7025 | Opt-Out Preference Signal Configuration |
| ccpa-cpra::Sec.1798.100(c) | Data Minimisation, Necessity and Proportionality |
| §1798.100 | General Duties of Businesses that Collect Personal Information |
| §1798.130(a)(3) | Privacy Policy Content Requirements |
| §1798.130(a)(5)(C) | Notice at Collection |
| §1798.135(a) | Do Not Sell or Share My Personal Information Link |
| §1798.135(b) | Opt-Out Preference Signals (Global Privacy Control) |
| §1798.185(a)(15) | Risk Assessments for High-Risk Processing |
Consumer Rights
| Code | Title |
|---|---|
| CCR §7026 | Requests to Opt-Out of Sale/Sharing Handling |
| §1798.105 | Right to Delete Personal Information |
| §1798.106 | Right to Correct Inaccurate Personal Information |
| §1798.110 | Right to Know Categories and Specific Pieces of Personal Information Collected |
| §1798.115 | Right to Know Personal Information Sold or Shared and Recipients |
| §1798.120 | Right to Opt Out of Sale or Sharing of Personal Information |
| §1798.125 | Non-Discrimination for Exercise of Rights |
| §1798.135(c) | Authorized Agent Requests |
| §1798.185(a)(16) | Automated Decisionmaking Technology Access and Opt-Out |
Enforcement
| Code | Title |
|---|---|
| CCR §7301-7304 | CPPA Audit and Investigation Cooperation |
| §1798.150 | Private Right of Action for Data Breaches |
| §1798.155 | Administrative Enforcement and Civil Penalties |
Privacy Operations
| Code | Title |
|---|---|
| CCR §7060 | Consumer Identity Verification |
| CCR §7100-7102 | Recordkeeping Requirements |
| §1798.130(a)(1) | Designated Methods for Submitting Consumer Requests |
| §1798.130(a)(2) | 45-Day Response Window and Identity Verification |
| §1798.130(c) | Annual Metrics Disclosure (Large Businesses) |
Sensitive PI
Service Provider
| Code | Title |
|---|---|
| CCR §7050 | Service Provider and Contractor Obligations |
| §1798.100(d) | Contractual Requirements for Third Parties, Service Providers, and Contractors |
Your Compliance Coverage
If you comply with CCPA/CPRA, you already cover:
Maps to 12 other frameworks
What is CCPA/CPRA and who does it apply to?
CCPA/CPRA is a compliance framework from United States - California with 6 domains and 32 controls. California Consumer Privacy Act / California Privacy Rights Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does CCPA/CPRA actually require?
CCPA/CPRA has 32 controls organised across 6 domains. The largest domains are Business Obligations (11 controls), Consumer Rights (9 controls), Privacy Operations (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of CCPA/CPRA do I already cover?
CCPA/CPRA maps to 12 other compliance frameworks. The top mapping partners are GDPR (90% coverage), APEC Cross-Border Privacy Rules (CBPR) System (80% coverage), Australian Privacy Principles (APPs) (70% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement CCPA/CPRA?
Start your CCPA/CPRA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CCPA/CPRA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required