Framework module · ccpa-cpra-state-privacy
CCPA/CPRA + US state privacy
California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.
CCPA/CPRA with 2026 CPPA regulations · California Privacy Protection Agency · published 2025-09-23
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
CCPA/CPRA + US state privacy is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Notice at collection · Consumer rights · Service provider contracts · Sensitive personal information · Risk assessments · Automated decision-making technology · Cybersecurity audits
- Applies to
- all sectors · US-CA · US-TX · US-VA · US-CO · US-CT · US-UT
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- The regulations took effect 2026-01-01, but most substantive obligations phase in later — risk assessments for processing already underway must be documented by 2027-12-31, and audit certifications follow a staged schedule.Expected: Phased through 2030
03Version ledger
2 editions
| CCPA/CPRA (2020 regulations) | Superseded | date not published |
| CCPA/CPRA with 2026 CPPA regulations | Current edition · supersedes CCPA/CPRA (2020 regulations) | 2025-09-23 |