California Consumer Privacy Act (CCPA)
Abbreviation: CCPA
Pronunciation: ka-luh-FAWRN-yuh kun-SOO-mur PREYE-vuh-see AKT (C-C-P-A)
Also known as: California Consumer Privacy Act, CCPA
Definition
The CCPA is a California privacy law granting consumers rights and imposing notice, data-handling, and request obligations on covered businesses. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California consumers rights concerning certain personal information. These include rights to know, delete, correct, limit some uses, and opt out of sale or sharing where applicable. The law applies to businesses meeting defined conditions and contains exceptions, detailed definitions, regulations, and requirements for notices and consumer requests.
Overview
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California consumers rights concerning certain personal information. These include rights to know, delete, correct, limit some uses, and opt out of sale or sharing where applicable.
The law applies to businesses meeting defined conditions and contains exceptions, detailed definitions, regulations, and requirements for notices and consumer requests. Service-provider, contractor, data-broker, employee, and sensitive-information rules can materially affect implementation.
Organizations should determine scope using current law and regulations, map data practices, verify requests appropriately, honor applicable preference signals, and maintain contractual controls. A glossary summary cannot determine whether a particular organization, data set, or processing activity is covered.
The CCPA is a California privacy law granting consumers rights and imposing notice, data-handling, and request obligations on covered businesses. CCPA compliance depends on current scope, data practices, consumer rights, notices, contracts, and regulations, not a generic privacy-policy statement.
Implementation of California Consumer Privacy Act (CCPA) should map CCPA is a California privacy law granting consumers rights and imposing notice, data-handling, and request obligations on covered businesses to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for data relationships and observable activity should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the California Consumer Privacy context and data relationships and observable activity should trigger reassessment instead of silent reuse of an outdated conclusion.
Assurance work for California Consumer Privacy Act (CCPA) should sample records involving data relationships and observable activity, test whether stated procedures operated in practice, and keep corrective actions open until a qualified reviewer verifies closure.
Key Takeaway
CCPA compliance depends on current scope, data practices, consumer rights, notices, contracts, and regulations, not a generic privacy-policy statement.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)