United States - California

CCPA/CPRA

32 controls. 12 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

32 controls 12 frameworks share controls with it United States - California verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CCR §7012Notice at Collection Drafting Requirements8
CCR §7025Opt-Out Preference Signal Configuration2
CCR §7026Requests to Opt-Out of Sale/Sharing Handling5
CCR §7027Requests to Limit Use of Sensitive PI Handling3
CCR §7050Service Provider and Contractor Obligations6
CCR §7060Consumer Identity Verification5
CCR §7100-7102Recordkeeping Requirements3
CCR §7301-7304CPPA Audit and Investigation Cooperation2
Sec.1798.100(c)Data Minimisation, Necessity and Proportionality0
§1798.100General Duties of Businesses that Collect Personal Information8
§1798.100(d)Contractual Requirements for Third Parties, Service Providers, and Contractors6
§1798.105Right to Delete Personal Information10
§1798.106Right to Correct Inaccurate Personal Information7
§1798.110Right to Know Categories and Specific Pieces of Personal Information Collected9
§1798.115Right to Know Personal Information Sold or Shared and Recipients6
§1798.120Right to Opt Out of Sale or Sharing of Personal Information11
§1798.121Right to Limit Use and Disclosure of Sensitive Personal Information6
§1798.125Non-Discrimination for Exercise of Rights5
§1798.130(a)(1)Designated Methods for Submitting Consumer Requests5
§1798.130(a)(2)45-Day Response Window and Identity Verification6
§1798.130(a)(3)Privacy Policy Content Requirements6
§1798.130(a)(5)(C)Notice at Collection8
§1798.130(c)Annual Metrics Disclosure (Large Businesses)1
§1798.135(a)Do Not Sell or Share My Personal Information Link6
§1798.135(b)Opt-Out Preference Signals (Global Privacy Control)4
§1798.135(c)Authorized Agent Requests3
§1798.140Threshold for Applicability and Key Definitions3
§1798.145Exemptions and Permitted Activities0
§1798.150Private Right of Action for Data Breaches7
§1798.155Administrative Enforcement and Civil Penalties0
§1798.185(a)(15)Risk Assessments for High-Risk Processing3
§1798.185(a)(16)Automated Decisionmaking Technology Access and Opt-Out2

Tell me when CCPA/CPRA files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Request workflow with SLA timers
  • Extension notification templates and logs
  • Identity verification policy (matching to existing records, signed declaration)
  • Look-back data retention configuration
  • SLA management for cloud services
  • SLA monitoring records

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for CCPA/CPRA, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition