Compliance Colleague · Standards · United States

CCPA / CPRA (California): cited answers and gap reviews

An AI compliance assistant for businesses handling Californians' personal information · updated 2026-10-03

The California Consumer Privacy Act, as amended by the CPRA, gives Californians rights over their personal information. Compliance Colleague covers thresholds, consumer rights, service-provider contracts and the newer rules on cybersecurity audits, risk assessments and automated decision-making technology.

Try it on your own CCPA / CPRA work: one document review or two questions, free for 30 days, no card required. Start free →

What it covers

Questions you can ask

Every answer cites the CCPA / CPRA requirement, article or control it rests on, so you can check it in seconds.

What you can upload for review

Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.

Crosswalk CCPA / CPRA to other standards

With CCPA / CPRA in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:

Upcoming CCPA / CPRA dates

January 1, 2027
California CCPA: ADMT compliance date

Source: CCPA Regulations, 11 CCR § 7200(b)

December 31, 2027
California CCPA: risk assessments due for processing begun before 2026

Source: CCPA Regulations, 11 CCR § 7155(b)

April 1, 2028
California CCPA: first cybersecurity audit certifications and risk-assessment submissions

Source: CCPA Regulations, 11 CCR §§ 7121 and 7157(a)

Add every compliance deadline to your calendar, free →

What it’s built from

Compliance Colleague carries the official text and checks its answers against it: California Consumer Privacy Act of 2018 (Cal. Civil Code §§ 1798.100–1798.199.100), as amended (California Privacy Protection Agency (CalPrivacy)); CCPA Regulations (Cal. Code Regs., tit. 11, § 7000 et seq.), incl. cybersecurity audit, risk assessment and ADMT rules (California Privacy Protection Agency (CalPrivacy)).

Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.

More United States standards

NIST CSF · NIST SP 800-53 · NIST AI RMF · FedRAMP · CMMC 2.0 · HIPAA · ITAR · EAR · TSA Security Directives · Section 508

Compliance Colleague covers 30+ security, privacy and AI governance standards. It reviews policies, spreadsheets and diagrams and answers questions with the clause cited; your judgment and sign-off stay with you. Try it free, no card required →

Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.