Framework library
Framework module · ccpa-cpra-state-privacy

CCPA/CPRA + US state privacy

California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

CCPA/CPRA with 2026 CPPA regulations · California Privacy Protection Agency · published 2025-09-23

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

CCPA/CPRA + US state privacy is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Notice at collection · Consumer rights · Service provider contracts · Sensitive personal information · Risk assessments · Automated decision-making technology · Cybersecurity audits
Applies to
all sectors · US-CA · US-TX · US-VA · US-CO · US-CT · US-UT
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
The regulations took effect 2026-01-01, but most substantive obligations phase in later — risk assessments for processing already underway must be documented by 2027-12-31, and audit certifications follow a staged schedule.Expected: Phased through 2030

03Version ledger

2 editions
CCPA/CPRA (2020 regulations)Supersededdate not published
CCPA/CPRA with 2026 CPPA regulationsCurrent edition · supersedes CCPA/CPRA (2020 regulations)2025-09-23
CCPA/CPRA + US state privacy — framework module | ControlFrame