Regulation

CCPA/CPRA

CCPA/CPRA — California Consumer Privacy

10 requirements · 8 connected unified controls

Open CCPA/CPRA in the map
Version
CCPA (2018) as amended by CPRA (2020)
Published
2018-06-28
Effective
2023-01-01 (CPRA operative)
Amendments
CPRA amendments; CPPA regulations

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

CCPA/CPRA (California Consumer Privacy)

RequirementUnified control and mapping
CCPA-1798.100Notice at collection and consumer right to know
UC-DATA-05 — Provide privacy notices and transparency to data subjectsPartial

Remaining requirement: beyond notice-at-collection: 1798.100 general duties (purpose limitation, reasonable security, contractor requirements) and verified right-to-know fulfillment satisfied by companion privacy-rights and security controls

CCPA-1798.105Right to delete personal information
UC-DATA-08 — Execute deletion and other rights requests within deadlinesPartial

Remaining requirement: notifying third parties (beyond service providers) to delete sold/shared data omitted

CCPA-1798.106Right to correct inaccurate personal information
CCPA-1798.110-115Rights to access and disclosure of personal information collected, sold, or shared
UC-DATA-06 — Provide data subjects access to their personal dataPartial

Remaining requirement: response must also disclose categories of sources and business/commercial purposes

CCPA-1798.120-121Right to opt out of sale/sharing and to limit use of sensitive personal information
UC-DATA-02 — Obtain and honor consent for collection, use, and disclosurePartial

Remaining requirement: under-16 opt-in consent before selling/sharing minors' data not addressed

CCPA-1798.125Non-discrimination and financial-incentive requirements
CCPA-1798.130-135Request-handling mechanics, verification, and opt-out link requirements
UC-DATA-08 — Execute deletion and other rights requests within deadlinesPartial

Remaining requirement: homepage 'Do Not Sell/Share' links and opt-out preference-signal (GPC) handling omitted

CCPA-1798.140Service-provider and contractor contract requirements
CCPA-1798.150Reasonable security procedures; private right of action for breaches
CCPA-1798.185CPPA regulations: cybersecurity audits and risk assessments
UC-AUDIT-23 — Coordinate independent assurance reviews across providersPartial

Remaining requirement: risk-assessment submission obligations handled under risk management controls