CCPA / CPRA — California Consumer Privacy Act / California Privacy Rights Act

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is a state privacy regulation that helps organizations protect Californians’ personal data and ensure transparency in data processing activities. Its primary aim is to give individuals greater control over how their personal information is collected, used, and shared by businesses.
Enforced by the California Privacy Protection Agency, this regulation applies to for-profit entities doing business in California that meet specific thresholds, such as revenue size or volume of data processed. The CCPA/CPRA covers key areas including data protection, privacy governance, consumer rights, risk management, and incident response requirements, aligning with other privacy frameworks like the EUGDPR.
Organizations support compliance by updating privacy notices, enabling consumer rights requests, maintaining records of processing activities, assessing third-party data sharing, and implementing technical and administrative safeguards. Integration with broader data protection and cybersecurity programs strengthens risk management and audit readiness.
Why it Matters
CCPA/CPRA establishes privacy standards that strengthen consumer rights and improve the accountability of organizations handling personal information.
Key benefits include:
- Strengthen privacy governance
Promote structured oversight and management of personal data, reducing risks associated with unauthorized access or mishandling.
- Enhance regulatory alignment
Support consistent adherence to state and international privacy requirements, simplifying compliance efforts and legal reporting obligations.
- Increase audit readiness
Enable organizations to systematically document data practices and consumer requests, improving preparedness for regulatory audits and investigations.
- Support consumer trust
Boost public confidence by transparently communicating data practices and honoring individuals’ rights over their personal information.
- Reduce data breach risk
Encourage implementation of safeguards and incident response processes, minimizing exposure to enforcement action and reputational damage.
How it Works
The CCPA / CPRA establishes a set of regulatory requirements focused on consumer privacy and data protection for organizations processing the personal information of California residents. The framework is structured around core principles, including consumer rights (access, deletion, correction, opt-out), transparency, and accountability in business practices. Compliance obligations are mapped to defined processes such as notice, data inventory, risk assessment, third-party management, and breach notification, providing a model for privacy governance.
Organizations implement the CCPA / CPRA by developing privacy programs that address statutory requirements through security controls, governance policies, and operational procedures. This involves data mapping to document information flows, conducting privacy risk assessments, updating consent and opt-out mechanisms, and allocating roles for compliance oversight. Continuous monitoring and internal audits support the identification and remediation of gaps in privacy and security practices, ensuring ongoing regulatory compliance.
Using SmartSuite, organizations can operationalize CCPA / CPRA requirements by using control libraries specific to data privacy, managing risk registers related to personal information handling, documenting policies and evidence for compliance, and tracking remediation activities. Automated workflows and dashboards facilitate compliance monitoring, audit readiness, and reporting, enabling effective governance over consumer privacy and data protection requirements.
Key Elements
- Data Processing Principles
Specifies foundational requirements for collecting, using, and retaining personal information within regulated entities.
- Consumer Rights Categories
Defines structured rights for individuals regarding access, deletion, correction, and opt-out of data sharing.
- Privacy Governance Structure
Establishes mechanisms for oversight, policy development, and internal accountability relating to data protection.
- Risk and Impact Assessments
Describes mandated processes for evaluating risks to individuals’ privacy and the effectiveness of data safeguards.
- Third-Party Management Controls
Outlines management and documentation requirements for data sharing, including vendor and service provider relationships.
- Incident and Breach Response Framework
Organizes obligations for responding to, documenting, and notifying consumers and authorities about data security incidents.
Framework Scope
The California Consumer Privacy Act (CCPA), amended by the CPRA, is adopted by companies that collect, process, or share Californians’ personal data in commercial operations. It governs personal data processing environments, information systems, and third-party data sharing, and is typically implemented when addressing privacy obligations, supporting compliance programs, or improving risk management and data protection.
Framework Objectives
The California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) establishes requirements for enhancing data protection and privacy governance for California residents.
Strengthen data protection and privacy controls to reduce cybersecurity risk
Enable transparency and accountability in the processing of personal information
Enhance compliance with regulatory obligations governing consumer data rights
Support effective risk management and incident response capabilities
Promote operational resilience through governance and oversight
Maintain audit readiness by documenting and monitoring privacy practices CCPA/CPRA complements global laws like GDPR and LGPD and can be aligned with privacy management frameworks such as ISO/IEC27701 and the NIST Privacy Framework. Organizations implement CCPA/CPRA for regulatory compliance, to build privacy programs, manage vendor/data flows, and demonstrate consumer-rights handling to regulators and customers.
Common Framework Mappings
Organizations map CCPA/CPRA to international and sector-specific privacy frameworks to harmonize controls, simplify compliance efforts, and support cross‑jurisdictional data protection alignment.
Mapped frameworks include:
EU General Data Protection Regulation (GDPR)
ISO/IEC 27701
NIST Privacy Framework
Personal Data Protection Act (PDPA) — Singapore
Personal Information Protection and Electronic Documents Act (PIPEDA)— Canada
UK Data Protection Act 2018 / UK GDPR
- ClassificationCategoryData Protection & PrivacyDomainPrivacyFramework FamilyGlobal Privacy Regulations
- Regulatory ContextTypeRegulationLegal InstrumentActSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailCaliforniaPublisherCalifornia Privacy Protection Agency (CPPA)
- VersioningVersionCCPA (2018) as amended by CPRA (2020)Effective DateJanuary 1, 2023Issue DateNovember 2, 2022
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The CCPA and CPRA are California state laws and are publicly available through official California government resources.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports US-CA CCPA / CPRA (Nov 2022)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
Data Inventory and Classification
Document personal data categories, sources, uses, and sharing with traceability.
DSAR and Opt-Out Workflows
Manage access, deletion, correction, and opt-out requests with deadlines and evidence.
Vendor, Service Provider, and Contractor Oversight
Track contracts, restrictions, and monitoring for third parties handling personal data.
Notice, Consent, and Policy Governance
Manage notice content, policy reviews, and evidence that practices match statements.
Retention and Deletion Controls
Operationalize retention rules and deletion processes with proof of execution.
Compliance Reporting and Audit Trail
Report request performance, open issues, and accountability evidence.
Related frameworks

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

HIPAA Omnibus Rule strengthens privacy, security, and breach notification requirements and extends protections to business associates handling health information.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Singapore's Personal Data Protection Act sets rules for how organizations collect, use, and disclose individuals' personal data.
Frequently Asked Questions For CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)
The CCPA / CPRA is designed to enhance the privacy rights and data protection of California residents by regulating how organizations collect, use, and share personal information. It requires businesses to enable consumer rights, improve transparency in data processing, and implement robust privacy governance practices.
CCPA / CPRA compliance is mandatory for for-profit organizations that do business in California and meet certain thresholds, such as annual gross revenues above $25 million, processing personal information of 100,000 or more consumers or households, or deriving 50% or more of their revenue from selling or sharing personal information. Companies outside California may still be subject if they target California residents.
The CCPA / CPRA applies to personal information collected from California residents by qualifying businesses, regardless of the organization’s geographic location. The regulation excludes certain data sets, such as those covered by specific U.S. federal privacy laws, and generally applies only to for-profit entities meeting regulatory thresholds.
Key requirements include providing updated privacy notices, honoring consumer rights (access, deletion, correction, opt-out), maintaining records of data processing activities, conducting risk assessments related to sensitive personal information, and managing third-party data sharing agreements. Required artifacts include records of requests, processing inventories, and impact assessments.
Implementation involves data mapping to understand information flows, updating consumer consent mechanisms, deploying technical and administrative safeguards, establishing incident response processes, and creating governance policies. Continuous staff training and assigning roles for privacy oversight are also critical for effective compliance.
The CCPA / CPRA aligns with global privacy standards like the EU GDPR by emphasizing transparency, data minimization, and consumer rights. However, it has unique requirements tailored for California and features specific enforcement mechanisms and consumer rights distinct from other frameworks.
Ongoing obligations include continually updating privacy notices, regularly assessing privacy risks, maintaining records of processing and consumer requests, monitoring third-party data sharing, and conducting periodic internal audits. Organizations must also respond to consumer rights requests within regulatory timelines.
SmartSuite supports CCPA / CPRA compliance by enabling organizations to track privacy risks, manage data protection controls, and document compliance evidence such as policies and request logs. Its features facilitate audit readiness through centralized dashboards, streamline reporting, and automate workflows for managing consumer rights, remediation tasks, and regulatory deadlines.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

