---
title: "US CCPA Privacy Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/us/california-consumer-privacy-act/faq"
source_url: "https://www.sorena.io/artifacts/us/california-consumer-privacy-act/faq/items/page/3"
author: "Sorena AI"
description: "Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers."
published_at: "2026-05-09"
updated_at: "2026-07-24"
keywords:
  - "US CCPA"
  - "FAQ"
  - "US CCPA FAQ"
  - "compliance checklist"
  - "practical guidance"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# US CCPA Privacy Law FAQ

Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.

*Artifact Guide* *US* *FAQ*

## US CCPA FAQ

Start with the right or business activity involved, then use the focused pages for the controlling rule, exceptions, implementation steps, and evidence.

The current CPPA regulations took effect January 1, 2026. Some cybersecurity-audit, risk-assessment, and automated-decisionmaking compliance dates are phased later.

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, gives California residents rights over personal information and regulates covered for-profit businesses. This hub explains the main scope test, consumer rights, notices, opt-outs, request handling, and specialized rules. A specific outcome still depends on the entity, data, purpose, recipient, contract, consumer relationship, and statutory exceptions.

## Definitions

### California Consumer Privacy Act

The California Consumer Privacy Act is California Civil Code Title 1.81.5. The California Privacy Rights Act amended that title rather than creating a separate replacement law. The amended CCPA gives California consumers rights over personal information and imposes duties on covered businesses, service providers, contractors, third parties, and other persons.

**Why it matters here:** Use the consolidated statutory text and current CPPA regulations for present duties. Earlier CCPA or CPRA summaries may omit later amendments, expired temporary exemptions, or regulations that took effect on January 1, 2026.

Sources:

- [California Civil Code, Title 1.81.5](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io)
- [CPPA CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io)

### Automated decisionmaking technology

**Term:** ADMT

ADMT is technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. A process substantially replaces human decisionmaking when the business uses its output to decide without a human who can interpret the output, review the relevant information, and make or change the decision.

**Why it matters here:** The current CCPA regulations create access, appeal, notice, and opt-out duties for specified ADMT uses. Those duties do not apply to every automated tool; the business's use, the role of human review, and whether the technology makes a significant decision control the analysis.

Sources:

- [CPPA CCPA Regulations effective January 1, 2026, section 7001 and Article 11](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io)

## Browse sub-FAQ modules

### [California Data Brokers: CCPA, Registration, and DROP Duties](/artifacts/us/california-consumer-privacy-act/faq/data-broker-crossover.md)

Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.

- 3 items

### [CCPA Dark Patterns: Rules, Examples, and Review Checklist](/artifacts/us/california-consumer-privacy-act/faq/dark-patterns.md)

Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.

- 3 items

### [CCPA Do Not Sell or Share: Scope and Implementation](/artifacts/us/california-consumer-privacy-act/faq/do-not-sell-or-share.md)

Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.

- 3 items

### [CCPA Financial Incentives: Notice, Consent, and Data Value](/artifacts/us/california-consumer-privacy-act/faq/financial-incentives.md)

Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.

- 3 items

### [CCPA Global Privacy Control (GPC): team obligations and technical implementation](/artifacts/us/california-consumer-privacy-act/faq/gpc.md)

Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.

- 3 items

### [CCPA Minors: Opt-In Rules for Consumers Under 16](/artifacts/us/california-consumer-privacy-act/faq/minors.md)

Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.

- 4 items

### [CCPA Notice at Collection: Timing, Content, and Examples](/artifacts/us/california-consumer-privacy-act/faq/notice-at-collection.md)

Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.

- 3 items

### [CCPA Personal and Sensitive Information Categories](/artifacts/us/california-consumer-privacy-act/faq/personal-and-sensitive-pi-categories.md)

Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.

- 3 items

### [Does the CCPA apply to my business? Threshold guide](/artifacts/us/california-consumer-privacy-act/faq/thresholds.md)

Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.

- 3 items

### [What must a CCPA privacy policy include?](/artifacts/us/california-consumer-privacy-act/faq/privacy-policy.md)

A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.

- 3 items

### [What must CCPA service-provider contracts include?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md)

Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.

- 3 items

### [What should teams do about consumer request verification under the CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md)

Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.

- 3 items

### [When does the CCPA require risk assessments or cyber audits?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md)

CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.

- 3 items

Browse all indexed questions: [/artifacts/us/california-consumer-privacy-act/faq/items](/artifacts/us/california-consumer-privacy-act/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 10 of 40 items.*

### [Which mistakes create risk when handling Privacy Policy under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/privacy-policy.md#which-mistakes-create-risk-when-handling-privacy-policy-under-the-us-ccpa)

*Module: [What must a CCPA privacy policy include?](/artifacts/us/california-consumer-privacy-act/faq/privacy-policy.md)*

A privacy policy is an overview, not a substitute for a notice at collection. The business must give the collection notice at or before collection, and it must provide a new notice when it plans to collect an additional category or use personal information for an incompatible additional purpose.

- Do not hide the request mechanism behind broken, circular, or hard-to-find links.
- Do not omit the under-16 statement, sensitive-personal-information statement, or opt-out and limit instructions when the stated conditions apply.
- Do not wait for the annual review if a new data flow makes a material policy statement false or incomplete.

Sources for this answer:

- [California Consumer Privacy Act Regulations effective January 1, 2026, sections 7002, 7004, 7011, and 7012](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - These sections distinguish the privacy policy from notice at collection, require specific and understandable disclosures, and address new notices for additional categories or incompatible purposes.

### [What must the contract say?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md#what-must-the-contract-say)

*Module: [What must CCPA service-provider contracts include?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md)*

Execute the contract before disclosing personal information. It must prohibit sale or sharing; identify each specific business purpose; prohibit retaining, using, or disclosing the data outside those purposes, for an unpermitted commercial purpose, or outside the direct business relationship; and address impermissible combining of data from other sources. A reference to the agreement as a whole is not specific enough.

- Map each service to a specific purpose, personal-information category, consumer population, system, retention rule, and permitted disclosure.
- Separate service-provider or contractor processing from any third-party or independent use and apply the contract and consumer-choice rules for the actual role.
- Confirm consumer-request assistance, security duties, oversight rights, inability-to-comply notice, remediation, deletion or return, and subcontractor flow-downs.

Sources for this answer:

- [California Consumer Privacy Act Regulations effective January 1, 2026, sections 7050-7051](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7050 and 7051 establish role consequences, required contract terms, subcontractor flow-downs, and the relevance of due diligence and enforcement.
- [California Civil Code section 1798.140](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140.&ref=sorena.io) - The statute defines service provider, contractor, business purpose, sale, and sharing and sets the core contractual restrictions that determine the role.

### [What evidence should teams keep for Service Provider and Contractor Contracts under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md#what-evidence-should-teams-keep-for-service-provider-and-contractor-contracts-under-the-us-ccpa)

*Module: [What must CCPA service-provider contracts include?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md)*

Keep a role assessment for each vendor, the signed agreement and amendments, the specific-purpose schedule, data-flow record, security review, subcontractor list, and evidence that the vendor can support consumer requests. Record which systems and personal-information categories are in scope and which vendor uses are prohibited.

- Contract evidence: executed terms, incorporated schedules, purpose descriptions, prohibited uses, request assistance, oversight, notice, and remediation rights.
- Operational evidence: data inventory, transfer diagram, access list, retention and deletion settings, security assessment, and request test.
- Downstream evidence: current subcontractor register, approval or notice records, and compliant flow-down terms.

Sources for this answer:

- [California Consumer Privacy Act Regulations effective January 1, 2026, section 7051](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Section 7051 supports the contract file, reasonable oversight and testing, inability-to-comply notice, remediation evidence, consumer-request assistance, subcontractor contracts, and due diligence.

### [Which mistakes create risk when handling Service Provider and Contractor Contracts under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md#which-mistakes-create-risk-when-handling-service-provider-and-contractor-contracts-under-the-us-ccpa)

*Module: [What must CCPA service-provider contracts include?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md)*

A data-protection addendum does not prove service-provider or contractor status. Reassess the role when the vendor adds a product feature, combines customer data, uses data for its own advertising or model training, changes retention, or adds a subcontractor.

- Do not describe the purpose by pointing to the whole agreement or using a generic label.
- Do not allow independent commercial use, sale, sharing, or unapproved combining through a side document or product setting.
- Do not assume a subcontractor inherits restrictions unless the required downstream contract exists.

Sources for this answer:

- [California Consumer Privacy Act Regulations effective January 1, 2026, sections 7050-7051](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7050 and 7051 address loss of service-provider or contractor status, specific-purpose drafting, actual compliance, subcontractors, due diligence, and enforcement of oversight rights.

### [What should teams do about DSAR Verification under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md#what-should-teams-do-about-dsar-verification-under-the-us-ccpa)

*Module: [What should teams do about consumer request verification under the CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md)*

Start by classifying the right. For a password-protected account, the regulations generally allow verification through the business's existing authentication practices, but the business must reauthenticate the consumer before deleting or correcting data or disclosing the requested data. It must also use reasonable security safeguards.

- Classify the request before asking for identity information.
- Use existing account authentication or existing records when reasonably possible.
- Document the assurance level, matching points, reliability, sensitivity, fraud risk, and consequence of unauthorized action.
- If verification fails, explain the result and any available way to provide additional information without disclosing whether specific data exists.
- Treat an authorized agent's authority and the consumer's identity as separate checks where both apply.

Sources for this answer:

- [CPPA CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7060-7063 set the verification rules for accounts, non-accountholders, deletion, and authorized agents.
- [CPPA Enforcement Advisory No. 2024-01](https://cppa.ca.gov/pdf/enfadvisory202401.pdf?ref=sorena.io) - Agency guidance on applying data minimization when selecting and operating verification methods.

### [What evidence should teams keep for DSAR Verification under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md#what-evidence-should-teams-keep-for-dsar-verification-under-the-us-ccpa)

*Module: [What should teams do about consumer request verification under the CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md)*

Keep enough evidence to reproduce why a request passed, failed, or was handled at a particular assurance level without retaining unnecessary identity documents.

- Request type, account status, requested data or action, sensitivity, and risk of harm.
- Verification method, matching data points, source reliability, result, retries, and authorized-agent checks.
- Additional information requested, why it was necessary, how it was protected, and when it was deleted.
- Consumer notices, completion or denial reason, exception basis, owner, and review date.

Sources for this answer:

- [CPPA CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sets verification, response, security, and consumer-request recordkeeping requirements.

### [Which mistakes create risk when handling DSAR Verification under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md#which-mistakes-create-risk-when-handling-dsar-verification-under-the-us-ccpa)

*Module: [What should teams do about consumer request verification under the CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md)*

Verification should reduce impersonation risk without turning the request process into a new source of sensitive personal information.

- Applying the same identity check to every right and every data set.
- Requiring identity verification for opt-out or limit requests.
- Requesting a government identifier when less sensitive existing data can provide the required assurance.
- Using new verification information for marketing, profiling, or any unrelated purpose.
- Treating proof of an authorized agent's authority as proof of the consumer's identity.

Sources for this answer:

- [CPPA CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Distinguishes request types, prohibits verification for opt-out and limit requests, and limits additional verification data.

### [Which activities trigger a risk assessment or cybersecurity audit?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md#which-activities-trigger-a-risk-assessment-or-cybersecurity-audit)

*Module: [When does the CCPA require risk assessments or cyber audits?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md)*

A business must conduct a risk assessment before selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; carrying out specified systematic-observation or sensitive-location profiling; or processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. A narrow exception covers sensitive personal information processed solely for listed employment-administration purposes.

- Inventory each processing activity and record the exact section 7150 trigger or the reason no trigger applies.
- Calculate the cybersecurity test from the correct preceding-year revenue and consumer or household counts; do not use the general CCPA business threshold as the audit test by itself.
- Assign an executive with the knowledge and authority required for the Agency submission, while keeping the auditor's review independent and objective.

Sources for this answer:

- [CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7120-7121 establish cybersecurity-audit thresholds and phased report dates; sections 7150 and 7155 establish risk-assessment triggers and timing, including the transition for existing processing.
- [CPPA final rulemaking page for cyber, risk, ADMT, and insurance regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - Official status page confirming Office of Administrative Law approval, completion of rulemaking, and the January 1, 2026 effective date.

### [What evidence should teams keep for Risk and Cyber Audits under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md#what-evidence-should-teams-keep-for-risk-and-cyber-audits-under-the-us-ccpa)

*Module: [When does the CCPA require risk assessments or cyber audits?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md)*

For a cybersecurity audit, keep the scope, criteria, evidence examined, testing and sampling, findings, gaps, remediation plan and dates, auditor qualifications, signed auditor statement, and any required breach-notification material. The business and auditor must retain all documents relevant to each audit for at least five years after completion.

- Cybersecurity file: threshold calculation, audit period, auditor independence review, report, remediation tracking, executive certification, and submission receipt.
- Risk file: trigger analysis, report and updates, stakeholder inputs, benefit-risk decision, executive submission, and Agency receipt.
- Calendar: annual audit cycle, three-year risk-assessment review, material-change review, filing dates, and retention end dates.

Sources for this answer:

- [CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7122-7124 specify audit independence, report content, five-year retention, and executive certification; sections 7152 and 7155-7157 specify assessment content, retention, submissions, and regulator requests.

### [Which mistakes create risk when handling Risk and Cyber Audits under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md#which-mistakes-create-risk-when-handling-risk-and-cyber-audits-under-the-us-ccpa)

*Module: [When does the CCPA require risk assessments or cyber audits?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md)*

Do not combine the two threshold tests. High-risk privacy processing can require a risk assessment even when the business does not meet the cybersecurity-audit thresholds. Conversely, a business subject to annual audits must still test each activity separately under section 7150.

- Do not treat a security framework assessment as sufficient unless it covers every requirement in the CCPA audit article or is supplemented.
- Do not submit the audit report as the routine certification or mistake the risk-assessment summary filing for the underlying report.
- Do not reuse one assessment across activities unless the activities and privacy risks are comparable.

Sources for this answer:

- [CCPA Regulations effective January 1, 2026](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) - Sections 7122-7124 and 7155-7157 establish independence, reuse conditions, update triggers, distinct filings, and regulator access to reports.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/us/california-consumer-privacy-act/faq/items](/artifacts/us/california-consumer-privacy-act/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/us/california-consumer-privacy-act/faq/items.md) | [2](/artifacts/us/california-consumer-privacy-act/faq/items/page/2.md) | [3](/artifacts/us/california-consumer-privacy-act/faq/items/page/3.md)

[Previous page](/artifacts/us/california-consumer-privacy-act/faq/items/page/2.md)

*Recommended next step*

*Placement: after the practical guidance*

## Turn US CCPA FAQ into assigned work

Assign each CCPA decision to an owner and keep the scope, source, implementation, evidence, and review date together.

- [Open Assessment Autopilot for US CCPA](/solutions/assessment.md): Turn FAQ into scoped questions, evidence fields, and review tasks.
- [Review US CCPA source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-consumer-privacy-act/faq/items/page/3.md
