Artifact GuideUSRequirements

California CPRA Requirements

This page maps California CPRA requirements into scope triggers, accountable owners, controls, evidence records, deadlines, and escalation points.

Start with coverage and the data flow, then identify the notices, request methods, opt-outs, contracts, security controls, assessments, audits, and ADMT duties that apply.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The amended the CCPA, so the operative requirements come from the CCPA as amended and the CPPA regulations. A covered business must control what it collects and why, tell consumers what it does, honor applicable rights and opt-outs, govern recipients, limit retention, maintain reasonable security, and apply the separate triggers and phase-in dates in the regulations effective January 1, 2026.

Section 1

What are the core requirements for a covered business?

Start with coverage. The main business definition applies to a for-profit entity that does business in California, determines the purposes and means of processing, and crosses at least one statutory threshold: preceding-year annual gross revenue above $25 million, as adjusted under the statute; buying, selling, or sharing the personal information of at least 100,000 consumers or households in a year; or deriving at least 50 percent of annual revenue from selling or sharing personal information. The statute also has rules for certain related entities, joint ventures or partnerships, and voluntary certification.

Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked directly or indirectly with a consumer or household. It can include device identifiers, browsing activity, inferences, and pseudonymous profiles, not only names and contact details. Publicly available, deidentified, and aggregate consumer information are excluded only when their statutory conditions are met.

Give notice at or before collection, use and retain personal information only as reasonably necessary and proportionate to the disclosed compatible purposes, and keep the privacy policy current. The policy and request methods must cover the rights that apply, including know or access, deletion, correction, sale or sharing opt-out, and limitation of qualifying uses and disclosures of sensitive personal information.

A business that sells or shares personal information must provide the required choice mechanism and honor qualifying opt-out preference signals. If it sells or shares the personal information of a consumer it has actual knowledge is under 16, the opt-in rules apply, with the consumer consenting at ages 13 through 15 and the parent or guardian consenting below 13.

Use written agreements when personal information is sold, shared, or disclosed to a service provider or contractor. The agreement must state the limited purpose, restrict use, require the same level of protection, allow reasonable compliance checks, require notice of inability to comply, and allow the business to stop and remediate unauthorized use.

For deletion, correction, know, -access, and ADMT-appeal requests, confirm receipt within 10 business days and respond within 45 calendar days. One extension of up to 45 additional calendar days is available when necessary if the business gives notice and explains the delay. Sale-or-sharing opt-outs and sensitive-personal-information limits have a different deadline: comply as soon as feasibly possible and no later than 15 business days.

  • Notices: map each category to source, purpose, sale or sharing status, sensitive-information status, and retention period or criteria.
  • Rights: provide compliant intake methods, verify only where required, meet response times, act across systems and instructed recipients, and explain denials.
  • Choice: implement sale or sharing opt-outs, opt-out preference signals, sensitive-information limits, minor consent, and non-discrimination.
  • Governance: maintain recipient contracts, reasonable security, request records, staff training, retention controls, and evidence for every claimed exception.
Section 2

What changed with the regulations effective January 1, 2026?

The rulemaking completed in September 2025 and became effective January 1, 2026. It updated existing CCPA regulations and added requirements for risk assessments, annual cybersecurity audits, and consumer rights relating to used for significant decisions. Each article has a separate scope test and compliance schedule.

Risk assessments apply before specified processing that presents significant risk to consumers' privacy and must document the purpose, categories and context, benefits, negative impacts, safeguards, and approval. Existing covered processing continuing after the effective date must be assessed by December 31, 2027, and information for assessments conducted in 2026 and 2027 is first submitted by April 1, 2028.

Cybersecurity-audit deadlines phase in by annual gross revenue: April 1, 2028 for businesses over $100 million, April 1, 2029 for businesses from $50 million through $100 million, and April 1, 2030 for businesses below $50 million, provided the business otherwise meets the audit trigger.

Automated decisionmaking technology () is technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. Article 11 applies when a business uses ADMT to provide or deny financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising alone is not a significant decision. A covered use that began before January 1, 2027, must comply by January 1, 2027.

  • Risk assessments: inventory triggering processing, complete the assessment before starting new covered processing, retain approval, and track Agency submission fields and dates.
  • Cybersecurity audits: document trigger status, revenue tier, audit period, qualified independent auditor, audit report, remediation, and annual certification deadline.
  • : inventory uses that replace or substantially replace human decisionmaking for significant decisions, then implement pre-use notice, access, opt-out, and appeal requirements where applicable.
  • Do not treat a January 1, 2026 effective date as the first deadline for every business; record the article, trigger, existing-or-new processing status, and phase-in date.
Section 3

Which boundaries and exemptions change the requirements?

Sale and sharing are distinct statutory concepts. A sale is making personal information available to a third party for money or other valuable consideration. Sharing covers making it available to a third party for cross-context behavioral advertising, whether or not money changes hands. Both definitions have conditional exclusions. A recipient cannot be treated as a service provider or contractor for cross-context behavioral advertising services.

Sensitive personal information is a defined subset that includes specified government identifiers and account credentials, precise geolocation, listed origin and belief data, union membership, certain communication contents, genetic and neural data, qualifying biometric and health data, sex-life or sexual-orientation information, and information about consumers the business actually knows are under 16. The right to limit applies to uses and disclosures outside specified permitted purposes rather than to every processing operation involving that information. Publicly available information, deidentified information, and aggregate consumer information also have defined conditions.

Exemptions often attach to information or activity, not the entire organization. Analyze CMIA, HIPAA, GLBA, FCRA, and other statutory provisions against the specific data and processing. Keep Delete Act data-broker registration and DROP duties separate from the CCPA requirements inventory.

  • Check whether the entity is a , service provider, contractor, third party, or data broker for the processing at issue.
  • Check whether the data is personal information, sensitive personal information, publicly available, deidentified, aggregate, or covered by a statutory exemption.
  • Check whether the disclosure is a sale, sharing, or permitted business-purpose disclosure supported by the required contract.
  • Check whether a consumer request may be denied or limited and record the exact exception, verification problem, impossibility, or disproportionate-effort basis.
Section 4

How should teams document requirements and evidence?

Create a requirements register that identifies the controlling provision, trigger, affected entity and processing, owner, required action, response or compliance date, evidence location, exception, and test result. Link the entry to the data inventory and the public notice that describes the processing.

Evidence should show how each control operates. Keep dated request records, opt-out and GPC test results, system deletion and correction records, recipient instructions, executed contracts, retention jobs, risk-assessment approvals and submissions, cybersecurity-audit reports and certifications, and notices and request outcomes.

  • Assign one accountable owner and one reviewer to each requirement.
  • Test the control against a real data flow or representative request and retain the result.
  • Record partial applicability and exceptions at the data-set or processing level.
  • Reassess after changes to entities, purposes, systems, recipients, advertising, retention, security risk, , or the governing text.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding source for sale, sharing, sensitive personal information, recipient roles, statutory exemptions, and consumer-request limits.
cppa.ca.gov
Referenced sections
  • Official CPPA rulemaking page for the regulations approved and made effective in March 2023.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Official CPPA explanatory material on the CPRA amendments and consumer rights; the FAQ states that it is not legal advice or regulatory guidance.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.