- Binding scope and role definitions.
References and citations
- Binding consumer rights, business duties, exceptions, enforcement, and private-action provisions.
- Rights and request context.
- Current requirements that the evidence must demonstrate.
Start with the right or business activity involved, then use the focused pages for the controlling rule, exceptions, implementation steps, and evidence.
The current CPPA regulations took effect January 1, 2026. Some cybersecurity-audit, risk-assessment, and automated-decisionmaking compliance dates are phased later.
Structured answer sets in this page tree.
Cited legal and guidance references.
The (CCPA), as amended by the California Privacy Rights Act, gives California residents rights over personal information and regulates covered for-profit businesses. This hub explains the main scope test, consumer rights, notices, opt-outs, request handling, and specialized rules. A specific outcome still depends on the entity, data, purpose, recipient, contract, consumer relationship, and statutory exceptions.
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.
The core business definition covers a for-profit legal entity that does business in California, determines the purposes and means of processing, and meets at least one statutory threshold. Effective January 1, 2025, the adjusted gross-revenue threshold is more than $26,625,000 in the preceding calendar year. The alternatives are buying, selling, or sharing personal information of at least 100,000 consumers or households in a year, or deriving at least 50 percent of annual revenue from selling or sharing consumers' personal information. Related entities, joint ventures, partnerships, and voluntary certification can be covered under additional conditions.
Covered businesses must give required notices, respond to applicable rights requests, avoid discrimination for exercising rights, honor sale and sharing opt-outs and qualifying preference signals, limit collection, use, and retention to disclosed and compatible purposes, secure personal information reasonably, and use compliant contracts and downstream controls. Exemptions can be data-specific or activity-specific rather than an exemption for the whole entity.
Assign each CCPA decision to an owner and keep the scope, source, implementation, evidence, and review date together.
Turn FAQ into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
Choose the page that matches the immediate decision. Several pages may apply to one flow: an advertising sign-up can involve notice at collection, personal-information categories, sale or sharing, GPC, minors, a financial incentive, and dark-pattern review.
Keep evidence that connects the legal trigger to actual product and operational behavior. A policy is one record, not proof that notices appeared on time, requests reached every system, vendor roles were classified correctly, or retention rules ran.
Update the record when the entity, threshold, data category, purpose, interface, recipient, contract, consumer relationship, or system behavior changes.