Skip to main content
—
Framework library
Framework module · ccpa-cpra-state-privacy

CCPA/CPRA + US state privacy

California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

CCPA/CPRA with 2026 CPPA regulations · California Privacy Protection Agency · published 2025-09-23

Standing today
Directory entry

00Answer

from the registry record
What is CCPA/CPRA + US state privacy?
California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.
Who does CCPA/CPRA + US state privacy apply to?
CCPA/CPRA + US state privacy applies to all sectors, US-CA, US-TX, US-VA, US-CO, US-CT, US-UT, per California Privacy Protection Agency.
What is the current version of CCPA/CPRA + US state privacy?
The current edition is CCPA/CPRA with 2026 CPPA regulations, issued by California Privacy Protection Agency and published 2025-09-23. Source: https://cppa.ca.gov/regulations/.
What does an assessment under CCPA/CPRA + US state privacy require?
No control catalog has been ingested for CCPA/CPRA + US state privacy yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

CCPA/CPRA + US state privacy is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Notice at collection · Consumer rights · Service provider contracts · Sensitive personal information · Risk assessments · Automated decision-making technology · Cybersecurity audits
Applies to
all sectors · US-CA · US-TX · US-VA · US-CO · US-CT · US-UT
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
The regulations took effect 2026-01-01, confirmed directly against cppa.ca.gov, but most substantive obligations phase in later — ADMT obligations begin 2027-01-01, risk assessments for processing already underway must be documented by 2027-12-31, and cybersecurity-audit certifications follow a staged schedule by revenue tier through 2030.Expected: Phased through 2030

03Version ledger

2 editions
CCPA/CPRA (2020 regulations)Supersededdate not published
CCPA/CPRA with 2026 CPPA regulationsCurrent edition · supersedes CCPA/CPRA (2020 regulations)2025-09-23

05Change history

06Related frameworks

scored from registry facts
  1. Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)

    Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.

  2. Also applies to all sectors · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  3. Shared Assessments SIG2026 annual release

    Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  4. FTC Health Breach Notification Rule16 CFR Part 318 (2024 amended rule)

    Same framework family · The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services.

CCPA/CPRA + US state privacy | ControlFrame