Artifact GuideUSCompliance

US CPRA Compliance

This implementation guide translates the US CPRA duties into owned controls, evidence, review checkpoints, and escalation paths.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The CPRA amended the California Consumer Privacy Act; compliance is therefore with the CCPA as amended, not a separate CPRA regime. A needs an operating system for accurate notices, consumer requests, sale and sharing opt-outs, sensitive personal information, recipient contracts, retention, reasonable security, and any triggered 2026 risk-assessment, cybersecurity-audit, or ADMT duties.

Section 1

How should privacy, product, and data teams structure a US CPRA Compliance plan?

Begin with a dated scope decision for each legal entity. Record the California nexus, preceding-year threshold calculation, common-control and common-branding analysis, and every exemption by data set. Revisit that record after acquisitions, reorganizations, new California activity, and each annual close.

Build the program around actual data flows. For each category of personal information, record the source, disclosed purpose, system, retention rule, sale or sharing status, sensitive-information status, and recipient role. Use that inventory to control the notice at collection, privacy policy, request search, opt-out propagation, deletion, correction, and contract instructions.

Keep Delete Act duties in a separate lane. Registration and DROP obligations apply to businesses that meet California's data-broker definition; they are adjacent California law, not a requirement for every CCPA-.

  • Privacy and legal: own scope, interpretations, notices, rights policy, exemptions, and regulator-facing records.
  • Product and engineering: own collection controls, opt-out preference signals, sensitive-information choices, request execution, and regression testing.
  • Data governance and security: own inventories, retention, deletion evidence, access controls, incident readiness, and the 2026 trigger screens.
  • Procurement and business owners: classify recipients, execute required terms, transmit consumer instructions, and document monitoring and remediation.
Section 2

What controls and evidence should the program maintain?

Notices should match actual collection, purposes, retention, sale, and sharing. For requests to know, delete, and correct, consumer-rights evidence should show intake, verification, confirmation within 10 business days, the response within 45 calendar days or the explained extension of up to 45 additional days, system actions, recipient instructions, and the reason for any partial or full denial. Start the 45-day clock on receipt, not after verification or internal assignment.

For sale or sharing, retain the public opt-out method, opt-out preference signal tests, downstream instructions, and proof that the choice persists as required. Stop sale or sharing as soon as feasibly possible and no later than 15 business days after receiving the request, and notify relevant third parties within that period. For sensitive personal information, document whether each use falls within a permitted purpose or triggers the right to limit; that request has its own 15-business-day operational limit.

Keep request records for at least 24 months. The log should show the request date and type, intake method, response date and result, and the basis for any denial, without retaining personal information solely for recordkeeping beyond what is necessary.

  • Notice evidence: published copy, effective date, approval, data-map reconciliation, and annual review.
  • Rights evidence: request log, verification outcome, search scope, response, exception or denial analysis, and downstream completion.
  • Choice evidence: opt-out link and GPC tests, account association, recipient notification, sensitive-information decision, and non-discrimination review.
  • Governance evidence: recipient contracts, retention schedules, deletion records, security controls, risk assessments, audit reports and certifications, ADMT records, training, and exceptions.
Section 3

Which exceptions and boundaries need separate review?

Do not turn an information-specific exemption into an entity-wide exclusion. Health, financial, credit-reporting, and other regulated data require a provision-by-provision analysis. Employment and business-contact information are no longer covered by the temporary exemptions that ended after 2022.

A vendor's title does not decide its role. If the written agreement or actual use falls outside the service-provider or contractor rules, the disclosure may be a sale or sharing and may trigger notice, opt-out, and third-party contract duties.

The regulations adopted in 2025 became effective January 1, 2026, but their operational dates are phased. Risk assessments for existing covered processing, first submissions, cybersecurity-audit reports and certifications, and ADMT compliance do not all share one deadline.

  • Minors: distinguish the opt-in rules for consumers under 16 from ordinary adult opt-out handling.
  • Backups: follow the regulation-specific timing for deletion and correction when archived or backup data returns to an active system.
  • Consumer requests: document verification, authorized-agent authority, exceptions, and disproportionate-effort reasoning rather than using a generic denial.
  • ADMT, risk assessments, and cybersecurity audits: apply each regulatory definition and threshold separately, including the applicable phase-in date.
Section 4

How should the program run over time?

Use a control register with one row per obligation and fields for the legal trigger, affected entity and processing, owner, system action, evidence, exception, deadline, test result, and next review. Link each control to the source provision and the data flow it governs.

Review before launch and after material changes to collection, purpose, retention, advertising, recipient roles, consumer interfaces, security architecture, or ADMT. Run periodic tests on request timing, correction and deletion propagation, opt-out preference signals, contract instructions, and public notices.

  • Before launch: complete the scope, notice, purpose, retention, sale or sharing, recipient-role, and 2026-rule trigger reviews.
  • During operation: monitor each request type against its own deadline, GPC handling by browser, device, account, and offline data where linkable, recipient instructions, deletion jobs, complaints, and control failures.
  • After a material change: update the inventory and public notices before the changed processing begins where the rules require notice at collection.
  • At review: test the control, inspect the evidence, record exceptions and remediation, and set the next event-based or calendar review.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding source for scope, consumer rights, purpose and retention limits, recipient agreements, enforcement, and statutory exemptions.
cppa.ca.gov
Referenced sections
  • Official CPPA rulemaking page for the binding March 2023 CCPA regulations.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
leginfo.legislature.ca.gov
Referenced sections
  • Binding California Delete Act text for DROP workflows; it does not establish CCPA implementation duties for businesses generally.
"(ii) Does not make use of any dark patterns"
cppa.ca.gov
Referenced sections
  • Operational implementation support for the US CPRA compliance.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
nist.gov
Referenced sections
  • Voluntary, non-binding NIST crosswalk material for privacy-control evidence; it does not establish CCPA requirements.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.