---
title: "California CPRA FAQ"
canonical_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq"
source_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq/items/page/3"
author: "Sorena AI"
description: "Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations."
published_at: "2026-05-09"
updated_at: "2026-07-24"
keywords:
  - "California CPRA"
  - "California Privacy Rights Act"
  - "CCPA FAQ"
  - "California privacy compliance"
  - "CCPA"
  - "Privacy compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# California CPRA FAQ

Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.

*Artifact Guide* *California* *FAQ*

## California CPRA FAQ

Use this hub to decide whether the CCPA applies, which consumer right or processing rule is triggered, what deadline controls, and which detailed FAQ to open next.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

The CPRA amended California's CCPA; it is not a separate parallel privacy statute. This FAQ hub orients businesses to coverage, consumer rights, sale and sharing choices, sensitive personal information, vendor roles, retention, and the newer cybersecurity, risk-assessment, and ADMT regulations.

## Definitions

### Business covered by the CCPA

**Term:** CCPA business

A CCPA business is generally a for-profit legal entity that does business in California, determines the purposes and means of processing consumers' personal information, and meets at least one statutory threshold. The definition also contains rules for entities under common control, joint ventures, partnerships, and businesses that voluntarily certify compliance.

**Why it matters here:** Consumer rights and business duties on this page apply only after the correct legal entity meets the business definition and no applicable exemption removes the entity, data, or processing from the rule at issue.

Sources:

- [California Civil Code section 1798.140](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140.&ref=sorena.io)

### Global Privacy Control

Global Privacy Control is a user-enabled browser or device signal that communicates a request to opt out of the sale or sharing of personal information. Under the CCPA regulations, a business that sells or shares personal information must process a signal that meets the regulatory requirements as a valid opt-out request.

**Why it matters here:** The signal applies to the browser or device that sends it. If the business can associate the signal with a known consumer profile, it must also treat the signal as an opt-out for that consumer profile.

Sources:

- [California Consumer Privacy Act Regulations, section 7025](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io)

### Automated decisionmaking technology

**Term:** ADMT

ADMT is technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. It includes profiling that meets that test, but excludes routine tools such as storage, cybersecurity, calculators, databases, and spreadsheets when they do not replace human decisionmaking.

**Why it matters here:** The Article 11 notice, access, opt-out, exception, and appeal rules apply when a covered business uses ADMT to make a significant decision concerning a consumer. A separate risk-assessment trigger may also apply.

Sources:

- [California Consumer Privacy Act Regulations, sections 7001 and 7200](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io)

## Browse sub-FAQ modules

### [California Delete Act data broker registry and DROP guide](/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop.md)

California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.

- 3 items

### [CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation](/artifacts/us/california-privacy-rights-act/faq/enforcement-advisories.md)

US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.

- 3 items

### [CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ](/artifacts/us/california-privacy-rights-act/faq/gpc.md)

US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.

- 3 items

### [What counts as sharing under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/sharing-and-cross-context-behavioral-advertising.md)

How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.

- 3 items

### [What should teams do about ADMT under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/admt.md)

Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.

- 3 items

### [What should teams do about Contract Terms under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/contract-terms.md)

Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.

- 3 items

### [What should teams do about Correction Rights under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/correction-rights.md)

Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.

- 3 items

### [What should teams do about Cybersecurity Audits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/cybersecurity-audits.md)

US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.

- 3 items

### [What should teams do about retention under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/retention.md)

California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.

- 3 items

### [What should teams do about Sensitive Personal Information Limits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/sensitive-personal-information-limits.md)

US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.

- 3 items

### [When is a CPRA risk assessment required?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md)

When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.

- 3 items

Browse all indexed questions: [/artifacts/us/california-privacy-rights-act/faq/items](/artifacts/us/california-privacy-rights-act/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 3 of 33 items.*

### [Which processing activities require a risk assessment?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md#which-processing-activities-require-a-risk-assessment)

*Module: [When is a CPRA risk assessment required?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md)*

The regulations treat six groups of processing as presenting significant risk: selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; using automated processing for specified profiling of an educational-program applicant, job applicant, student, employee, or independent contractor; using automated processing to infer specified traits from a consumer's presence in a sensitive location; and processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, identification, or profiling technology.

- Confirm that the organization is a business subject to the CCPA before applying these triggers.
- Assess each processing activity or a genuinely comparable set of activities with similar processing and similar privacy risks.
- Record why an exception applies; a narrow exception for one purpose does not exempt the rest of a data flow.

Sources for this answer:

- [CPPA approved regulations, sections 7150-7151](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Binding regulatory text for the six covered-processing groups, the limited employee and contractor administration exception, the sensitive-location delivery and transportation exclusion, examples, and required employee participation.

### [What must the report contain, and who approves it?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md#what-must-the-report-contain-and-who-approves-it)

*Module: [When is a CPRA risk assessment required?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md)*

The report must state a specific processing purpose rather than a generic phrase such as "improve our services." It must identify the personal-information categories, including sensitive categories and the minimum information necessary; sources; collection, use, disclosure, retention, and other processing methods; consumer interactions; approximate number of consumers; notices; recipients and their purposes; and, for covered ADMT used for a significant decision, the logic, assumptions or limitations, output, and use of that output.

- Evidence: the scoped data-flow map, notices, recipient list, retention rules, risk analysis, safeguards, and launch decision.
- Approval: the dated report and an authorized decision-maker's name and position.
- Reuse: another law's assessment may be used only when it contains, or is paired with, every item required by section 7152.

Sources for this answer:

- [CPPA approved regulations, sections 7152-7154 and 7156](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Binding requirements for report content, benefits and negative impacts, safeguards, the processing decision, contributors, approval, the balancing goal, comparable activities, and reuse of assessments prepared under other laws.

### [When must the assessment be completed, updated, retained, and submitted?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md#when-must-the-assessment-be-completed-updated-retained-and-submitted)

*Module: [When is a CPRA risk assessment required?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md)*

For covered processing first initiated on or after January 1, 2026, complete and document the assessment before the processing begins. For covered processing initiated before that date and continuing afterward, complete it by December 31, 2027. Review each assessment at least once every three years and update it as necessary.

- Do not use the December 31, 2027 transition date for new covered processing.
- Track the three-year review date and create a material-change trigger tied to product and data-flow change controls.
- Keep the full report and versions separate from the annual submission record and executive attestation.

Sources for this answer:

- [CPPA approved regulations, sections 7155 and 7157](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Binding deadlines for pre-initiation and legacy assessments, three-year reviews, 45-day material-change updates, retention, annual submission information, executive attestation, and 30-day responses to report requests.
- [CPPA completed rulemaking page](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - Official status page confirming OAL approval, completion of the rulemaking, and the January 1, 2026 effective date.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/us/california-privacy-rights-act/faq/items](/artifacts/us/california-privacy-rights-act/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/us/california-privacy-rights-act/faq/items.md) | [2](/artifacts/us/california-privacy-rights-act/faq/items/page/2.md) | [3](/artifacts/us/california-privacy-rights-act/faq/items/page/3.md)

[Previous page](/artifacts/us/california-privacy-rights-act/faq/items/page/2.md)

*Recommended next step*

*Placement: after the practical guidance*

## Turn California CPRA FAQ into assigned work

This California CPRA guide turns FAQ answers into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.

- [Open Assessment Autopilot for California CPRA](/solutions/assessment.md): Turn FAQ into scoped questions, evidence fields, and review tasks.
- [Review California CPRA source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through California CPRA implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq/items/page/3.md
