CCPA/CPRA
CCPA (California Consumer Privacy Act) and its amendment CPRA grant California residents rights over their personal data and impose obligations on businesses.
CCPA/CPRA are California's comprehensive privacy laws that give consumers control over their personal information.
Consumer rights: - Right to Know: What data is collected - Right to Delete: Request data deletion - Right to Opt-Out: Stop data sale/sharing - Right to Correct: Fix inaccurate data - Right to Limit: Restrict sensitive data use
Applies to businesses that: - Gross revenue over $25 million - Buy/sell 100,000+ consumers' data - 50%+ revenue from selling data
CPRA additions: - Created California Privacy Protection Agency - "Sensitive personal information" category - Data minimization requirements - Sharing (not just selling) restrictions
Why It Matters
CCPA/CPRA affects any business serving California's 40 million residents, regardless of where the business is located. With fines up to $7,500 per intentional violation and a private right of action for data breaches, non-compliance creates significant financial exposure. As other US states adopt similar laws, CCPA compliance positions organizations well for the broader US privacy landscape.
Key Points
Applicable Compliance Frameworks
Related Terms
GDPR (General Data Protection Regulation) is the EU's comprehensive data privacy law that governs how organizations collect, process, and protect personal data of EU residents.
Data privacy refers to the proper handling of personal information including how it is collected, used, shared, and protected in compliance with regulations.
Privacy by Design is an approach that embeds privacy into the design and architecture of systems from the start, rather than adding it later.
Frequently Asked Questions
Does CCPA apply to B2B data?
CPRA removed the B2B exemption. Employee and B2B contact data are now covered by consumer rights.
How is CCPA different from GDPR?
CCPA is opt-out based; GDPR is opt-in. CCPA has revenue thresholds; GDPR applies more broadly. Penalties differ significantly.
Related Services & Resources
Vanta Implementation
Expert Vanta deployment with 80+ integrations configured in 4-6 weeks
Learn moreDrata Implementation
Full Drata setup with automated evidence collection and control mapping
Learn moreSOC 2 Compliance
Trust services criteria for security, availability, and confidentiality
Learn moreISO 27001 Certification
International standard for information security management
Learn moreSOC 2 Complete Guide
Everything you need to know about achieving SOC 2 compliance
Learn moreHIPAA Checklist
Comprehensive checklist for HIPAA compliance requirements
Learn moreNeed Help with CCPA/CPRA?
Our experts can help you understand and implement the right controls for your organization.