Compliance & Regulations/North America/CCPA / CPRA
Privacy · California, United States

CCPA / CPRA

The California consumer privacy law that introduced the right to delete, opt-out of sale/share, and limit use of sensitive personal information.

Regulator
California Privacy Protection Agency (CPPA) and California Attorney General
Jurisdiction
California, United States
Status
Active.
In force since
January 2020 (CCPA); CPRA amendments effective January 2023.
Regulator's source
Who it applies to

Businesses doing business in California meeting one of three thresholds (revenue, volume, or revenue share from data sales).

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What CCPA / CPRA actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Right to know, delete, correct, opt-out of sale/share, and limit use of sensitive personal information.

02

Conspicuous "Do Not Sell or Share My Personal Information" link.

03

Annual cybersecurity audit and risk assessment for businesses processing large volumes of personal information (CPPA regulations).

04

Service provider / contractor contractual safeguards including no further use of personal information.

05

Data minimisation and purpose limitation per CCPA §1798.100.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Data Subject Access Request (DSAR) workflow with 45-day clock and verification gates.

Data inventory and PII discovery across configured cloud and SaaS systems.

Cybersecurity audit and risk assessment template aligned to draft CPPA regulations.

Contractor/service-provider registry with contract metadata.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

DSAR ledger with timing, scope, and resolution status.

Annual cybersecurity audit report (CPPA-aligned).

Risk assessment per CPPA draft regulations.

Data inventory and category-of-recipient register.

Ready for CCPA / CPRA?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing