CCPA/CPRA + US state privacy
California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.
CCPA/CPRA with 2026 CPPA regulations · California Privacy Protection Agency · published 2025-09-23
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
CCPA/CPRA + US state privacy is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Notice at collection · Consumer rights · Service provider contracts · Sensitive personal information · Risk assessments · Automated decision-making technology · Cybersecurity audits
- Applies to
- all sectors · US-CA · US-TX · US-VA · US-CO · US-CT · US-UT
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- The regulations took effect 2026-01-01, confirmed directly against cppa.ca.gov, but most substantive obligations phase in later — ADMT obligations begin 2027-01-01, risk assessments for processing already underway must be documented by 2027-12-31, and cybersecurity-audit certifications follow a staged schedule by revenue tier through 2030.Expected: Phased through 2030
03Version ledger
| CCPA/CPRA (2020 regulations) | Superseded | date not published |
| CCPA/CPRA with 2026 CPPA regulations | Current edition · supersedes CCPA/CPRA (2020 regulations) | 2025-09-23 |
05Change history
06Related frameworks
- Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)
Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.
Also applies to all sectors · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- FTC Health Breach Notification Rule16 CFR Part 318 (2024 amended rule)
Same framework family · The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services.