Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA) made California the first US state to adopt a broad consumer privacy law modeled loosely on the EU’s General Data Protection Regulation (GDPR). Although its language is framed around data privacy, CCPA's operational impact has deep implications for cybersecurity teams, based on its compliance requirements for annual cybersecurity audits (Article 9, §§ 7120–7124) and Data Protection Impact Assessments (Article 10, §§ 7150–7157).

The impact of CCPA has direct legal ramifications for any in-scope Chief Information Security Officer (CISO), where CCPA Articles 9 and 10 require qualifying businesses to conduct annual cybersecurity audits and data protection impact assessments. The California Privacy Protection Agency (CPPA) actively enforces these obligations and failure to comply exposes businesses to civil penalties, regulatory action and even consumer lawsuits.

Key Takeaways

Here is what CCPA and CPRA compliance means for your organization:

  • The CCPA (effective 2020) and its amendment the CPRA (effective 2023) apply to for-profit businesses that meet revenue, data-volume, or data-monetization thresholds, regardless of where the business is located.
  • The CPRA created the California Privacy Protection Agency (CPPA), which enforces the law alongside the California Attorney General.
  • New CPPA regulations, effective January 1, 2026, require significant-risk businesses to perform risk assessments and annual, independent cybersecurity audits, with certifications to the CPPA phased in from 2028 to 2030 by revenue.
  • The law requires reasonable security procedures and practices but does not define them, so businesses must operationalize compliance with a recognized framework such as NIST, ISO 27002, or the Secure Controls Framework.
  • Non-compliance risk is real: civil penalties of $2,500 or $7,500 per violation, plus a consumer private right of action for breaches of $100 to $750 per consumer per incident when reasonable security was not maintained.
Who Needs To Comply?

What Companies Must Comply With the CCPA & CPRA?

The California Consumer Privacy Act (CCPA), effective January 1, 2020, and its amendment, the California Privacy Rights Act (CPRA), effective January 1, 2023, apply to for-profit businesses that do business in California and handle California residents' Personal Information (PI) if they meet at least one of three thresholds:

  • Have annual gross revenue over $26,625,000 (the original $25 million threshold, adjusted for inflation for 2026);
  • Annually buy, sell, or share the PI of 100,000 or more California consumers or households; or
  • Derive 50% or more of annual revenue from selling or sharing consumers' PI.

A business does not have to be located in California, or even in the United States, to be covered. If you meet a threshold and handle the PI of California residents, the CCPA and CPRA apply.

Do Service Providers & Contractors Have To Comply?

Service Provider & Contractor Obligations

Yes. The CCPA and CPRA extend obligations beyond the "business" to the vendors that process PI on its behalf. The law defines specific roles, including service providers, contractors, and third parties, each with different responsibilities.

A business that discloses PI to a service provider or contractor must have a written contract containing the data protection terms the statute requires, and those vendors are contractually restricted in how they may retain, use, or disclose the PI. The CPRA strengthened these flow-down requirements so that privacy obligations follow the data down the supply chain.

How Do You Ensure Your Vendors Are Compliant?

How To Ensure Service Provider Compliance

Compliance flows through contracts and oversight. Covered businesses should execute data processing agreements with the specific clauses the CCPA and CPRA require, perform due diligence before sharing PI, flow privacy and security obligations down to subcontractors, retain audit and assessment rights, and monitor vendors throughout the relationship.

Civil penalties and consumer lawsuits can attach to a business for a vendor's failure, Third-Party Risk Management (TRPM) is a core part of CCPA and CPRA compliance, supported by documented contracts, standards, and procedures.

Do You Have To Perform Annual Cybersecurity Audits & Risk Assessments?

Cybersecurity Audits & Risk Assessments

For many businesses, yes - it depends on your business. On July 24, 2025, the California Privacy Protection Agency (CPPA) adopted regulations, effective January 1, 2026, that require businesses whose processing presents "significant risk" to consumers' privacy to conduct annual cybersecurity audits and complete risk assessments.

A cybersecurity audit must be performed by an objective, independent professional, and businesses must submit a written certification of completion to the CPPA by April 1 each year. "Significant risk" processing includes selling or sharing PI, processing sensitive PI, using automated decision-making technology (ADMT) for significant decisions, using biometrics for identification or profiling, and making automated inferences in sensitive contexts.

First certifications phase in by revenue: April 1, 2028 for businesses over $100 million in annual revenue; April 1, 2029 for those between $50 million and $100 million; and April 1, 2030 for those under $50 million.

Does The CCPA & CPRA Scale To Organization Size?

A Risk-Based, Threshold-Driven Law

The CCPA and CPRA are not a flat "one size fits all" mandate. They are threshold-driven and risk-based. Whether the law applies at all depends on revenue, data-volume, and data-monetization thresholds, and the newest obligations (cybersecurity audits and risk assessments) are triggered by whether your processing presents "significant risk," with certification deadlines phased in by revenue.

Larger businesses, and those that sell or share data or process sensitive PI, carry the heaviest obligations, but any covered business must maintain reasonable security and honor consumer rights.

The CCPA & CPRA Are Not A Cybersecurity Framework

A Law, Not A Controls Framework

Like most privacy laws, the CCPA and CPRA tell you what outcomes to achieve, such as protecting PI with "reasonable security procedures and practices," honoring consumer rights, and assessing risk, but they do not give you a prescriptive set of controls to implement.

The statute never defines "reasonable security," which leaves businesses to select and operationalize a recognized cybersecurity and data privacy framework (such as NIST, ISO 27002, or the Secure Controls Framework) to demonstrate that their security is, in fact, reasonable.

How To Comply With CCPA & CPRA Cybersecurity Requirements

How To Operationalize Compliance

Operationalizing CCPA and CPRA compliance comes down to documented governance. Covered businesses should adopt a controls framework and map it to CCPA and CPRA obligations, implement documented policies, standards, and procedures that establish reasonable security, build a data privacy program grounded in privacy by design, maintain data inventories and mapping with a process to fulfill consumer-rights requests within 45 days, put compliant contracts and third-party risk management in place, and stand up the risk-assessment and cybersecurity-audit processes the CPPA regulations now require.

ComplianceForge's editable documentation, including policies and standards mapped to the Secure Controls Framework (SCF), procedures, and a Data Privacy Program, provides that evidence of due care and due diligence the same business day.

What Are The Requirements Of The CCPA & CPRA?

CCPA & CPRA Requirements

At a high level, the CCPA and CPRA grant California consumers a set of rights and impose corresponding obligations on businesses. Consumer rights include the right to:

  • Know and access the PI a business collects, uses, discloses, and sells or shares;
  • Delete PI a business has collected;
  • Correct inaccurate PI (added by the CPRA);
  • Opt out of the sale or sharing of PI;
  • Limit the use and disclosure of sensitive PI (added by the CPRA);
  • Data portability; and
  • Non-discrimination for exercising these rights.

Businesses must respond to verified consumer requests within 45 days. Business obligations include providing clear privacy notices, implementing and maintaining reasonable security procedures and practices, practicing data minimization and purpose limitation, entering compliant contracts with service providers, contractors, and third parties, honoring opt-out preference signals, and, for significant-risk processing, completing risk assessments and annual cybersecurity audits.

The CPPA and the California Attorney General enforce the law, with civil penalties up to $2,500 per violation and $7,500 per intentional violation or any violation involving a minor. Consumers also have a private right of action for data breaches: if nonencrypted, nonredacted PI is exposed because a business failed to maintain reasonable security, consumers may recover statutory damages of $100 to $750 per consumer per incident, or actual damages if greater.