AI Compliance Vendors

What is CCPA/CPRA?

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), applies to for-profit businesses that do business in California and meet at least one t

Last updated September 21, 2026 · Every fact traceable to a public source

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), applies to for-profit businesses that do business in California and meet at least one threshold: gross annual revenue over $25 million; buy, sell, or share personal information of 100,000+ California residents/households; or derive 50%+ of annual revenue from selling California residents' personal information. The California Privacy Protection Agency (CPPA) has issued draft regulations governing Automated Decision-Making Technology (ADMT), risk assessments, and cybersecurity audits under CCPA authority. Enforcement is shared between the CPPA and the California Attorney General.

What does CCPA/CPRA actually require?

Key obligations include: Provide notice at or before the point of collection describing personal-information categories and purposes; Respond to consumer requests to know, delete, correct, and opt out of sale/sharing; Honor Global Privacy Control (GPC) opt-out signals for sale and sharing; Limit use and disclosure of sensitive personal information upon consumer request; Provide a Do Not Sell or Share My Personal Information link on the homepage; Enter into contracts with service providers, contractors, and third parties restricting use of personal information.

Who is in scope of CCPA/CPRA?

CCPA/CPRA is in_force in United States - California. Scope attaches based on jurisdiction and the role a company plays in the AI supply chain. See /frameworks/ccpa-cpra for the full scope note and source links.

When does CCPA/CPRA take effect?

The primary enforcement date is 2023-01-01. Some provisions may phase in earlier or later — see the framework brief for the full timeline.

What are the penalties?

Maximum penalties: Civil penalties of up to $2,500 per violation and up to $7,500 per intentional violation or violation involving a minor. Consumers may recover statutory damages of $100 to $750 per incident, or actual damages, whichever is greater, for certain data breaches (Cal. Civ. Code §1798.150; §1798.155).. Enforcement is carried out by the designated authorities in the jurisdiction.

Related

Editorial independence

This FAQ is editorial. No vendor can pay to be highlighted or ranked in answers, and the written commentary on this page is payment-free. Featured slots in directory listings are always labeled where they appear. Read our methodology for details.