FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
33of33items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
What should teams do about Contract Terms under the US CPRA?

What should teams do about Contract Terms under the US CPRA?

Classify the recipient from the actual data flow, not its job title or the agreement's label. A service provider processes personal information for a business under a written contract; a contractor receives information for a business purpose and makes the required certification; a third party is a recipient that does not qualify for an applicable exclusion. If the arrangement does not meet the service-provider or contractor requirements, a disclosure may be a sale or sharing unless another statutory exception applies.

A service-provider or contractor contract must identify specific business purposes, prohibit sale or sharing, restrict retention, use, and disclosure outside those purposes and the direct business relationship, restrict combining data except as allowed, require compliance with the CCPA, allow monitoring, require notice if the recipient can no longer comply, and let the business stop and remediate unauthorized use. It must also require assistance with consumer requests and, where applicable, cybersecurity audits and risk assessments.

A third-party contract for sold or shared information must identify limited and specified purposes, require the third party to comply with the CCPA and provide the same level of privacy protection, allow reasonable steps to verify compliant use, require notice if the third party can no longer comply, and give the business the right to stop and remediate unauthorized use. A third party without a section 7053-compliant contract may not collect, use, process, retain, sell, or share the personal information the business made available.

Execute the correct contract before making personal information available. If a service provider or contractor uses a subcontractor for the business purpose, the subcontract must bind that recipient to the same CCPA requirements. Due diligence and enforcement matter after signature: the regulations say that never enforcing the contract or exercising audit and test rights can affect whether the business may claim it lacked reason to believe the recipient intended a violating use.

  • Map the recipient role, data categories, transfer purpose, sale or sharing analysis, and permitted uses before selecting a template.
  • Write specific purposes; generic descriptions such as "business operations" do not establish the required limits.
  • Name the contract owner, recipient control owner, consumer-request contact, notice route for inability to comply, and stop-and-remediate procedure.
  • Reassess the role and amend the agreement before the data, purpose, subcontracting, or recipient behavior changes.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

What should teams do about Contract Terms under the US CPRA?

What evidence should teams keep for Contract Terms under the US CPRA?

Keep the executed agreement and effective date, role analysis, data-flow record, data categories, specific purposes, sale or sharing analysis, subcontractor notices and terms, consumer-right assistance procedure, compliance notices, monitoring or audit evidence, remediation records, and approval trail. Link each contract obligation to the system and team that can carry it out.

For monitoring, retain the review scope, evidence requested, finding, recipient response, remediation owner, due date, retest, and closure decision. When the recipient says it can no longer comply, record when notice arrived, which data and systems are affected, whether transfers stopped, what data was returned or deleted, and how remediation was verified.

  • Source URL and quote used for the decision.
  • Scope notes, data-flow and system references, role mapping, contract version, effective date, and approved purposes.
  • Subcontractor chain, request-assistance test, monitoring record, exception notes, remediation evidence, and next review date.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

What should teams do about Contract Terms under the US CPRA?

Which mistakes create risk when handling Contract Terms under the US CPRA?

Common failures include relying on the word "processor" without meeting California's role tests, describing purposes generically, omitting the right to stop and remediate unauthorized use, allowing combination of data beyond the regulatory conditions, failing to flow terms to subcontractors, or leaving consumer-request assistance and compliance monitoring undefined.

  • Using a service-provider template for a recipient whose actual use makes it a third party.
  • Listing a broad purpose that does not limit how the recipient may use, retain, or disclose the data.
  • Signing required terms without monitoring compliance or acting when the recipient reports it can no longer comply.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

What should teams do about Correction Rights under the US CPRA?

How should a business handle a correction request under the US CPRA?

A California consumer may ask a covered business to correct inaccurate personal information that the business maintains. The business must use commercially reasonable efforts, taking into account the nature of the information and the purposes for which it is processed. It must confirm receipt within 10 business days and respond within 45 calendar days of receipt. If necessary, it may extend once for up to 45 additional calendar days, but it must notify the consumer and explain the delay.

Verify the consumer with information other than the field being disputed. The business may deny the request if it cannot verify the consumer or if, after considering the totality of the circumstances, the contested information is more likely than not accurate. The assessment should consider whether the information is objective or subjective, how it was obtained, why the business uses it, its effect on the consumer, and documentation from the consumer, the business, or another source. If the business is not the source and has no supporting documentation, the consumer's assertion may be enough to establish inaccuracy.

When granting the request, correct active systems, prevent later data imports from restoring the error, and instruct service providers and contractors that maintain the information to correct it and keep it corrected. A correction in an archived or backup system may wait until that system is restored, accessed, or used. A denial response should explain the basis and tell the consumer that they may submit a complaint to the CPPA or California Attorney General.

Other denial grounds require their own records. A business may deny the same alleged inaccuracy after a denial within the previous six months, or deny a request it reasonably and in good faith believes is fraudulent or abusive, but it must explain the decision. A claim of impossibility or disproportionate effort needs enough facts for the consumer to understand why compliance is not possible; a bare label is insufficient.

The business may delete instead of correct only if deletion will not harm the consumer or the consumer consents. If the business is not the source, it must either name the source to the consumer or tell the source to correct the information. A consumer can ask to confirm the correction; for sensitive identifiers such as account credentials, government identifiers, financial account numbers, health identifiers, and unique biometric data, provide a secure confirmation method rather than disclosing the value.

A denial involving personal information collected and analyzed about the consumer's health has an additional branch. The response must explain that the consumer may submit a written statement, limited to 250 words for each alleged inaccuracy, and ask for it to be added to the record. On request, the business must make that statement available to a person to whom it discloses, shares, or sells the disputed information.

  • Confirm the disputed record and requested correction without collecting more verification data than necessary.
  • Track the 10-business-day confirmation and the 45-calendar-day response period from the date of receipt, not the verification date.
  • Test whether source feeds, service providers, contractors, and restored backups preserve the corrected value.
  • Use correction documentation only for the correction and required recordkeeping, protect it with reasonable security, and retain the request-and-response record for at least 24 months.
Citations
What should teams do about Correction Rights under the US CPRA?

What evidence should teams keep for Correction Rights under the US CPRA?

Keep the request, receipt confirmation, verification steps, disputed field and proposed correction, accuracy evidence considered, decision, systems and recipients updated, response date, extension notice if any, and denial explanation. Minimize retained identity evidence and record how the business prevents an inaccurate source feed from overwriting the correction.

The request log should show the request date and method, request type, response date and type, and any denial basis for at least 24 months. If the business relies on a repeat-request, fraud, abuse, impossibility, disproportionate-effort, deletion, source-notification, or health-statement branch, retain the facts, notice, approval, and completed follow-up for that branch.

  • Source URL and quote used for the decision.
  • Scope notes, disputed field, source system, downstream recipients, backup behavior, and verification method.
  • Implementation ticket, decision and approval, consumer response, exception evidence, overwrite test, and review date.
Citations
What should teams do about Correction Rights under the US CPRA?

Which mistakes create risk when handling Correction Rights under the US CPRA?

Common failures include starting the 45-day clock after verification, correcting only the customer-facing profile, allowing a later import to restore the error, demanding disproportionate verification, treating a disputed opinion as an objectively false fact without considering its nature, or denying a request without a factual explanation.

  • Starting the response clock after verification instead of on the day the request arrives.
  • Rejecting the consumer's evidence without considering the source, nature, and existing documentation for the disputed field.
  • Correcting an active record without preventing an old source or restored backup from reintroducing the error.
Citations
What should teams do about Cybersecurity Audits under the US CPRA?

What should teams do about Cybersecurity Audits under the US CPRA?

The annual cybersecurity-audit duty applies only when section 7120's objective trigger is met. A business qualifies if it derived at least 50% of its preceding-year revenue from selling or sharing consumers' personal information. It also qualifies if it met the CCPA's gross-revenue threshold and, in the preceding year, processed personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers. The gross-revenue threshold is $26.625 million for calendar years beginning January 1, 2025, but the Agency adjusts it over time, so record the threshold that applied to the year being tested.

A qualifying business must use a qualified, objective, independent auditor. The first report is phased by revenue: April 1, 2028 for a business above $100 million using 2026 revenue, April 1, 2029 for a business between $50 million and $100 million using 2027 revenue, and April 1, 2030 for a business below $50 million using 2028 revenue. These are first-report deadlines, not a claim that every covered business already owed a completed audit on January 1, 2026.

The audit must assess how the business's cybersecurity program protects personal information and availability, including the applicable section 7123 components. Those components cover authentication, encryption, access control, inventories, secure configuration, vulnerability testing, logging, network defense, training, secure development, vendor oversight, disposal, incident response, business continuity, and backups. The report must describe the information system, audit criteria, evidence examined, findings, gap status, and remediation timeframes. An audit prepared for another purpose, including one using NIST Cybersecurity Framework 2.0, can be reused only if it meets every California requirement on its own or through supplementation.

The auditor may be internal or external but must be a qualified, objective, independent auditor who exercises impartial judgment and does not rely primarily on management assertions. An internal auditor's highest-ranking auditor must report to an executive who does not directly run the cybersecurity program; the auditor also cannot develop, implement, or maintain activities that the same auditor may assess.

Each year an audit is required, an executive with direct responsibility, sufficient knowledge, and submission authority must certify completion to the CPPA by April 1 following the audit year. The business and auditor must retain all audit-relevant documents for at least five years after completion.

  • Document which section 7120 trigger applies and the preceding-year revenue and processing counts used.
  • Use a qualified, objective, independent auditor and keep the auditor free from management influence.
  • Retain the audit report and all relevant documents for at least five years, and submit only the required completion certification to the Agency by the section 7124 deadline.
Citations
What should teams do about Cybersecurity Audits under the US CPRA?

What evidence should teams keep for Cybersecurity Audits under the US CPRA?

Keep the section 7120 threshold calculation, auditor qualifications and independence record, audit scope and criteria, evidence reviewed, findings and remediation plan, final report, governing-body or executive review, annual certification, and submission receipt. Retain the audit-relevant documents for at least five years after completion and record which phased first-report deadline applies.

  • Threshold file: the tested legal entity, applicable $26.625 million or later adjusted revenue threshold, preceding-year revenue source, consumer and household counts, sensitive-personal-information count, and sale-or-sharing revenue percentage.
  • Audit file: system boundary, policies and controls assessed, accepted audit standard, samples, tests, interviews, findings, remediation owners and dates, prior-report corrections, and breach or regulator-notification material required by section 7123.
  • Governance file: auditor qualifications and conflict review, internal-auditor reporting line if used, executive receipt of the report, five-year retention dates, signed annual certification, and Agency submission receipt.
Citations
What should teams do about Cybersecurity Audits under the US CPRA?

Which mistakes create risk when handling Cybersecurity Audits under the US CPRA?

Common failures include using a stale gross-revenue threshold, mixing the audit trigger with the separate risk-assessment trigger, assuming the regulations required every business to finish an audit on January 1, 2026, relying mainly on management attestations, omitting a remediation plan, or sending the audit report when section 7124 calls for a completion certification.

  • Using the separate risk-assessment trigger as the cybersecurity-audit trigger.
  • Treating an auditor as independent while management controls findings or the auditor relies mainly on management assertions.
  • Submitting a certification without retaining the report and supporting audit documents for five years.
What should teams do about retention under the California CPRA?

What should teams do about retention under the California CPRA?

A covered business must disclose at collection how long it intends to retain each category of personal information or, when a fixed period is not possible, the criteria it uses to determine that period. The business cannot retain a category longer than reasonably necessary for the disclosed purpose for which it was collected.

Build retention by data category and purpose. For each record set, identify the collection notice, primary and compatible purposes, minimum period needed, legal or operational dependency, deletion or deidentification event, system owner, and exception handling. An objective criterion should identify the event and rule used to calculate a deletion date. A bare statement such as "we keep data as long as necessary" does not explain the criteria or show that systems can execute them.

Section 7002 also limits collection, use, retention, and sharing to what is reasonably necessary and proportionate for a disclosed compatible purpose or a purpose covered by valid consent. A new incompatible purpose requires fresh notice and consent before processing. Separate routine retention from records preserved for a legal obligation, dispute, security investigation, or applicable deletion exception, and restrict retained exception data to that purpose.

  • State a period or objective criteria for every disclosed personal-information category.
  • Configure deletion or deidentification in active systems, vendors, analytics stores, and restored backups, with an owner and test date.
  • Record the legal basis and access restriction for each hold or exception; do not convert one exception into indefinite general retention.
Citations
What should teams do about retention under the California CPRA?

What evidence should teams keep for retention under the California CPRA?

Keep the notice-at-collection text, data inventory, category-and-purpose retention schedule, system configuration, deletion or deidentification test, vendor instruction, backup treatment, exception or hold record, consumer-request logs where relevant, owner approval, and review date. Evidence should connect the public statement to actual deletion behavior.

  • Schedule record: personal-information category, collection source, disclosed purpose, compatible or consented purpose, period or objective criteria, start event, deletion or deidentification event, system and vendor owner, and approval date.
  • Execution record: deletion-job configuration, active-system and derived-copy results, vendor instructions, backup restoration control, sample test dates, failures, remediation ticket, and retest.
  • Exception record: legal provision or documented operational need, affected records, restricted purpose and access, hold owner, review and release dates, and proof that the exception did not reset unrelated retention clocks.
Citations
What should teams do about retention under the California CPRA?

Which mistakes create risk when handling retention under the California CPRA?

Common failures include using one indefinite period for all data, stating criteria that systems cannot execute, resetting a retention clock when data moves systems, retaining derived or logged copies after deleting the primary record, allowing a legal hold to cover unrelated data, or changing to an incompatible purpose without the required notice and consent.

  • Publishing a period or criterion that does not match deletion jobs, vendor behavior, or backup restoration.
  • Restarting the retention period when the same information moves to another system.
  • Keeping exception data available for unrelated analytics, marketing, or product use.
Citations
What should teams do about Sensitive Personal Information Limits under the US CPRA?

What should teams do about Sensitive Personal Information Limits under the US CPRA?

Sensitive personal information includes specified government and account credentials; precise geolocation; racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, genetic data, and neural data; private communications when the business is not the intended recipient; biometric information processed to identify a consumer; analyzed health, sex-life, or sexual-orientation information; and personal information of a consumer the business actually knows is under 16. Publicly available information is excluded from the category.

The right to limit applies when a covered business uses or discloses sensitive personal information for purposes beyond those listed in regulation section 7027(m). Those permitted purposes include providing goods or services an average consumer reasonably expects, specified security and safety activities, short-term transient use that does not build a consumer profile, and performing services on the business's behalf. Every permitted use must still be reasonably necessary and proportionate. For example, a directions app may use precise geolocation to route the consumer, while a gaming app cannot rely on that expectation if location is unnecessary. A health-article search box may use a query to return results without inferring a characteristic; using the query to profile the consumer changes the analysis.

A business subject to the right must provide at least two request methods, including an online form reached through the "Limit the Use of My Sensitive Personal Information" link or a permitted Alternative Opt-out Link when it collects sensitive personal information online. It cannot require an account or a verifiable consumer request. It must stop non-permitted uses and disclosures as soon as feasibly possible and no later than 15 business days after receipt, instruct affected service providers and contractors within the same period, and notify relevant third parties for disclosures made during the processing window.

After honoring a request, the business generally must wait at least 12 months before asking the consumer to consent to a use or disclosure outside section 7027(m). If the consumer initiates a transaction or tries to use a product that requires an additional sensitive-data use, the business may explain the requirement and ask for consent through the section 7004 process. Record the data category, whether the business infers characteristics, each purpose and recipient, the request date, the date restrictions took effect, downstream instructions, and any exception or later consent.

  • Map each sensitive-data use to a specific section 7027(m) purpose; do not label an entire product or system exempt.
  • Test the request method without login and confirm that all affected downstream uses and disclosures stop within 15 business days.
  • Escalate disputes about inference, reasonable consumer expectations, proportionality, or consent before relying on an exception.
Citations
What should teams do about Sensitive Personal Information Limits under the US CPRA?

What evidence should teams keep for Sensitive Personal Information Limits under the US CPRA?

Keep the sensitive-data inventory, inference analysis, section 7027(m) purpose mapping, recipients, notice and choice-link screenshots, request and consent logs, downstream instructions, and dated tests. The evidence should show both the request date and when every restricted use or disclosure stopped.

  • Scope record: each sensitive-information category, source, system, inference purpose, section 7027(m) purpose if claimed, necessity and proportionality analysis, recipient, and owner.
  • Choice record: notice and link screenshots, methods offered, request timestamp, confirmation state, restricted-use effective time, third-party notices, service-provider and contractor instructions, and the 15-business-day outside deadline.
  • Consent record: prior request date, 12-month timer, consumer-initiated transaction if applicable, two-step opt-in evidence, purpose authorized, withdrawal path, exception note, implementation ticket, and dated retest.
Citations
What should teams do about Sensitive Personal Information Limits under the US CPRA?

Which mistakes create risk when handling Sensitive Personal Information Limits under the US CPRA?

Common failures include treating every sensitive-data use as limitable, claiming the no-inference boundary while using the data to profile a consumer, treating one permitted purpose as an entity-wide exemption, relying on a cookie banner that does not address the right to limit, or changing a preference display while downstream use and disclosure continue.

  • Claiming a permitted purpose without showing that the use is reasonably necessary and proportionate.
  • Requiring account creation or identity verification for a request that does not require either.
  • Recording the preference in one interface while vendors or other recipients continue a restricted use.
Citations
Page 2 of 3