- Current statutory text as reflected in CPPA materials.
References and citations
- Rulemaking and effective date updates.
- Official California FAQ.
- Official California regulations hub.
Translate the current California regime into control statements that teams can build and test.
Grounded in the California statute, CPPA regulations, and the 2026 California rule changes.
Structured answer sets in this page tree.
Cited legal and guidance references.
The California requirement model is easier to run when it is grouped into control domains and each domain has a named owner and evidence output.
The baseline domains cover scope, notice architecture, rights workflows, GPC or opt out preference signals, recordkeeping, and recipient contracts. Every in scope business starts here.
The second layer covers SPI, sharing, contractor and third party terms, due diligence, and notice details that became more important under the amended regime.
The latest California rules add or clarify risk assessments, cybersecurity audits, ADMT related duties, and new data broker workflows.
Assessment Autopilot can take California CPRA Requirements from turning the requirements into assigned actions to a reusable workflow inside Sorena. Teams working on California CPRA can keep owners, evidence, and next steps aligned without copying this guide into separate documents.
Start from California CPRA Requirements and turn the guidance into owned tasks, evidence requests, and review checkpoints.
Review your current process, evidence gaps, and next steps for California CPRA Requirements.