- Binding requirements for minimization, notices, rights, security, non-discrimination, contracts, and enforcement.
References and citations
- Articles 9-11 establish cybersecurity-audit, risk-assessment, and ADMT triggers, duties, and phased dates.
Use this reference to map each CCPA duty to its trigger, responsible actor, action, deadline, evidence, and exception.
The CCPA as amended by the CPRA is one regime. The regulations effective January 1, 2026 add phased risk-assessment, cybersecurity-audit, and ADMT duties for businesses that meet their specific triggers.
Structured answer sets in this page tree.
Cited legal and guidance references.
The CCPA, as amended by the CPRA, applies to covered for-profit businesses handling California residents' personal information and also assigns duties to , contractors, and third parties. Test entity coverage and data-specific exemptions first, then map each applicable duty to its trigger, owner, deadline, evidence, exception, and reassessment event.
A must limit collection, use, retention, and sharing to what is reasonably necessary and proportionate for disclosed purposes. It must give notice at or before collection and maintain a privacy policy describing online and offline practices, consumer rights, and request methods. Exemptions under sections 1798.145 and 1798.146 often attach to specified information or activities, so an exempt dataset does not necessarily remove the entity or its other processing from scope.
The business must provide and operate the rights that apply to the data and activity: know, delete, correct, opt out of sale or sharing, limit specified uses or disclosures of sensitive personal information, and receive equal treatment. Current regulations also govern access to and opt-out from covered .
For requests to know, delete, correct, access , or appeal ADMT, confirm receipt within 10 business days and respond within 45 calendar days. A necessary extension can add up to 45 calendar days if the consumer receives timely notice and an explanation.
Verify know, delete, correct, and -access requests with a reasonable, documented method. Do not require identity verification for sale-or-sharing opt-outs, limit requests, or ADMT opt-outs. Sale-or-sharing and limit requests generally must be implemented as soon as feasible and no later than 15 business days.
A disclosure is not automatically outside sale or sharing because a contract calls the recipient a service provider. The contract and actual processing must satisfy the applicable service-provider or contractor definition and restrictions.
Contracts with , contractors, and third parties must identify limited purposes, restrict unauthorized use and disclosure, require the applicable level of CCPA protection, support consumer requests, and permit appropriate monitoring and remediation.
Risk assessments, cybersecurity audits, and duties use separate regulatory triggers. General CCPA coverage does not prove that every one applies.
Risk assessments began for new covered processing on January 1, 2026. Covered processing already underway before that date must be assessed by December 31, 2027. compliance for significant decisions begins January 1, 2027. Initial cybersecurity-audit certifications are phased by revenue from April 1, 2028 through April 1, 2030.
Assign each applicable requirement to an owner and retain the notice, log, contract, test, assessment, audit, or approval that shows the control operated.
Turn Requirements into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.