CCPA / CPRA (California): cited answers and gap reviews
The California Consumer Privacy Act, as amended by the CPRA, gives Californians rights over their personal information. Compliance Colleague covers thresholds, consumer rights, service-provider contracts and the newer rules on cybersecurity audits, risk assessments and automated decision-making technology.
What it covers
- Business thresholds and consumer rights, including opt-out of sale or sharing
- Service provider, contractor and third-party classification
- Sensitive personal information and opt-out mechanisms, including GPC
- Cybersecurity audits and risk assessments (regulations effective 1 January 2026)
- Automated decision-making technology rules, with a 1 January 2027 compliance date
Questions you can ask
- “Are we a service provider or a third party for this analytics vendor?”
- “When is our first cybersecurity audit certification due?”
- “Which of our hiring tools count as ADMT for significant decisions?”
Every answer cites the CCPA / CPRA requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- Your privacy notice checked against the required disclosures
- A vendor contract checked against service-provider terms
- A data inventory (Excel) checked for sensitive personal information
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk CCPA / CPRA to other standards
With CCPA / CPRA in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
Upcoming CCPA / CPRA dates
Source: CCPA Regulations, 11 CCR § 7200(b)
Source: CCPA Regulations, 11 CCR § 7155(b)
Source: CCPA Regulations, 11 CCR §§ 7121 and 7157(a)
Add every compliance deadline to your calendar, free →
What it’s built from
Compliance Colleague carries the official text and checks its answers against it: California Consumer Privacy Act of 2018 (Cal. Civil Code §§ 1798.100–1798.199.100), as amended (California Privacy Protection Agency (CalPrivacy)); CCPA Regulations (Cal. Code Regs., tit. 11, § 7000 et seq.), incl. cybersecurity audit, risk assessment and ADMT rules (California Privacy Protection Agency (CalPrivacy)).
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More United States standards
NIST CSF · NIST SP 800-53 · NIST AI RMF · FedRAMP · CMMC 2.0 · HIPAA · ITAR · EAR · TSA Security Directives · Section 508
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.