Artifact GuideCaliforniaFAQ

California CPRA FAQ

Use this hub to decide whether the CCPA applies, which consumer right or processing rule is triggered, what deadline controls, and which detailed FAQ to open next.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
11

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The CPRA amended California's CCPA; it is not a separate parallel privacy statute. This FAQ hub orients businesses to coverage, consumer rights, sale and sharing choices, sensitive personal information, vendor roles, retention, and the newer cybersecurity, risk-assessment, and regulations.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items33
Focused FAQ modules
11
Showing 11 of 11
FAQ module

California Delete Act data broker registry and DROP guide

California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.

3 items
FAQ module

CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation

US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ

US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What counts as sharing under the California CPRA?

How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.

3 items
FAQ module

What should teams do about ADMT under the US CPRA?

Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.

3 items
FAQ module

What should teams do about Contract Terms under the US CPRA?

Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.

3 items
FAQ module

What should teams do about Correction Rights under the US CPRA?

Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.

3 items
FAQ module

What should teams do about Cybersecurity Audits under the US CPRA?

US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about retention under the California CPRA?

California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.

3 items
FAQ module

What should teams do about Sensitive Personal Information Limits under the US CPRA?

US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

When is a CPRA risk assessment required?

When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.

3 items
Question 1

How should teams use the California CPRA FAQ hub for privacy compliance decisions?

Start with entity coverage. A for-profit entity doing business in California is a if it determines the purposes and means of processing and meets at least one statutory test: the current adjusted gross-revenue threshold, buying, selling, or sharing the personal information of at least 100,000 consumers or households in a year, or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Parent, subsidiary, joint-control, nonprofit, sectoral, and data-specific rules can change the result, so document the legal entity and data flow before applying a control.

Next identify the action: notice at collection; a request to know, delete, or correct; an opt-out of sale or sharing; a signal; a request to limit sensitive personal information; a vendor-role contract; retention; or a newer cybersecurity audit, risk assessment, or duty. For ADMT used to make a significant decision, identify the separate pre-use notice, opt-out, access, and any human-appeal path. The CPRA is an amendment to the CCPA, while the Delete Act's data-broker registry and DROP duties come from a separate California title.

Name the exact trigger, consumer or data category, responsible business process, deadline, owner, downstream recipients, evidence, and escalation point. Use the detailed FAQ for the selected issue rather than applying one answer across unrelated rights.

  • Record the applicable legal entity and which coverage test it meets before assessing a right or processing duty.
  • Record which role, product, system, customer group, or data flow is in scope.
  • Attach the cited rule, the owner, and the evidence field before approving the control.
  • Escalate uncertainty when the facts depend on adjusted thresholds, statutory exemptions, household counts, recipient roles, or a case-specific interpretation.
Question 2

Who should maintain the California CPRA FAQ evidence and source-review process?

Assign operational ownership to the team that can change the relevant system: privacy operations for request intake, product and engineering for interfaces and preference signals, procurement and legal for recipient contracts, data owners for retention, and security leadership for audits. Privacy counsel should review coverage, exemptions, denials, and other legal interpretations.

Consumer requests to delete, correct, know, access , or appeal ADMT generally require confirmation within 10 business days and a response within 45 calendar days, with one explained extension of up to 45 additional days when allowed. The response period starts when the business receives the request, regardless of verification time. Sale-or-sharing opt-outs, ADMT opt-outs, and sensitive-information limitation requests follow different rules, including a 15-business-day outer limit for stopping the covered processing and sending required downstream instructions. Keep each clock tied to the correct request type.

Evidence should show the coverage analysis, collection notices, request handling, GPC processing, sensitive-information purpose mapping, recipient contracts, retention controls, and any risk-assessment, cybersecurity-audit, or readiness work that the actual processing triggers.

  • Name one accountable owner and one reviewer for the FAQ workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Question 3

Which edge cases should teams check before relying on California CPRA FAQ guidance?

Do not treat a sectoral or data-specific exemption as an entity-wide exclusion unless the statute says it is one. Publicly available information, deidentified information, employee records, business contacts, regulated financial or health data, and data handled by government bodies each require the exact statutory definition and facts. The temporary employee and business-contact exemptions expired after 2022, so current employment and business-contact processing cannot be excluded on that historical basis.

Reassess before a material change to the data, purpose, interface, vendor, recipient role, system logic, or law. In particular, distinguish selling from sharing for cross-context behavioral advertising, a service provider from a third party, and a sensitive-data use that is limitable from one allowed by section 7027(m). A signal applies at least to the browser or device that sends it and must also reach a known account when the business can associate the signal with that consumer.

  • Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Question 4

How should teams turn California CPRA FAQ guidance into owned controls?

Use one intake that captures entity coverage, data categories and purposes, consumer right, opt-out signal, recipient role, retention logic, cybersecurity-audit, risk-assessment and triggers, owner, deadline, and review date.

The result should be a specific record: a coverage memo, notice update, consumer-request workflow, opt-out and GPC test record, sensitive-information purpose map, vendor clause map, retention schedule, risk assessment, rights package, or cybersecurity-audit evidence pack.

  • Create a short intake question that identifies the FAQ scenario.
  • Map the answer to a required action, evidence field, owner, reviewer, and review date.
  • Review the flow for scope, deadlines, controls, penalties, and templates before moving to the next implementation step.
  • Update the workflow when official source material changes or when non-public evidence shows recurring exceptions.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Official California statutory source for opt-out preference signals, sale or sharing opt-outs, and cross-context behavioral advertising rulemaking authority.
"Global opt out from sale and sharing of personal information"
cppa.ca.gov
Referenced sections
  • Official CPPA registry source for California data-broker registration context referenced by this FAQ hub.
"The previous data broker registries can be accessed at the Office of the Attorney General's Data Broker webpage."
cppa.ca.gov
Referenced sections
  • CPPA FAQ source for the relationship between CCPA and CPRA and for consumer-right examples used by this FAQ hub.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.