CA · CIV. CODE 1798 · source-led dossier

California
CCPA

California Consumer Privacy Act, as amended by the CPRA and later legislation

What this record can establish

  • The current consolidated statutory rights and covered-business architecture.
  • Where the CPPA separates current regulations from preliminary regulatory activity.

What it cannot establish

  • That every organisation doing business in California is covered.
  • That the statute creates a broad private right of action for every alleged violation.

Instrument and status timeline

Publication, operation and evidence are different moments.

02

Current regulations and separate preliminary activity

The official index identifies regulations effective 1 January 2026 and separately labels preliminary topics that are not formal rulemaking or operative requirements.

CA-02 · California Privacy Protection Agency
In force

17-factor research index

Questions defined. Evidence stays qualitative.

Every factor remains inspectable without implying that evidence across frameworks is numerically equivalent.

01

Readable rules

How the legal architecture can be found, understood and translated into a research plan.

Moderate

The consolidated statute is available, but thresholds, defined roles and current regulations require issue-specific mapping.

  1. clarity
    Accessibility and drafting clarity

    How much interpretation is needed before a team can identify the rule that governs its activity?

    Open framework evidence record
    Current dossier record
    The consolidated statute is available, but thresholds, defined roles and current regulations require issue-specific mapping.
    Seek
    Controlling text, amendment history, commencement records and an issue-specific reading path.
    Avoid
    Shorter text is not automatically clearer, safer or cheaper to implement.
    No jurisdiction value
  2. scope
    Scope and extra-territorial reach

    Which entities, people, data and overseas activities fall inside the framework?

    Open framework evidence record
    Current dossier record
    The consolidated statute is available, but thresholds, defined roles and current regulations require issue-specific mapping.
    Seek
    Definitions, territorial provisions, exclusions, coverage thresholds and relevant official guidance.
    Avoid
    A national market presence does not by itself prove that a specific activity is covered.
    No jurisdiction value
  3. grounds
    Permitted grounds and processing architecture

    Which processing grounds exist, and how does an organisation document the one it relies on?

    Open framework evidence record
    Current dossier record
    The consolidated statute is available, but thresholds, defined roles and current regulations require issue-specific mapping.
    Seek
    Operative ground or exception, purpose record, applicable conditions and supporting documentation.
    Avoid
    Matching labels across laws do not make processing grounds interchangeable.
    No jurisdiction value
  4. notice
    Notice and consent usability

    What must a person be told, when, and in what form before data is used?

    Open framework evidence record
    Current dossier record
    The consolidated statute is available, but thresholds, defined roles and current regulations require issue-specific mapping.
    Seek
    Operative notice duties, delivery context, language or accessibility rules and tested user comprehension.
    Avoid
    Publishing a notice does not prove that people saw or understood it.
    No jurisdiction value
02

Individual agency

What people can understand, choose, contest and ask organisations to do.

Moderate

The statute publishes defined consumer rights, including access, correction, deletion and sale/share controls, subject to scope and exceptions.

  1. withdrawal
    Withdrawal and preference control

    Can a person reverse a choice through a practical, understandable route?

    Open framework evidence record
    Current dossier record
    The statute publishes defined consumer rights, including access, correction, deletion and sale/share controls, subject to scope and exceptions.
    Seek
    Operative withdrawal rule, interface steps, downstream propagation and documented exceptions.
    Avoid
    A stated right to withdraw does not prove that the practical route is equivalent to giving consent.
    No jurisdiction value
  2. rights
    Individual rights and grievance pathways

    Which rights exist, and what must happen before a person can obtain a remedy?

    Open framework evidence record
    Current dossier record
    The statute publishes defined consumer rights, including access, correction, deletion and sale/share controls, subject to scope and exceptions.
    Seek
    Operative right, identity and timing rules, refusal grounds, escalation path and outcome evidence.
    Avoid
    A longer catalogue of rights does not by itself show that remedies are more accessible.
    No jurisdiction value
  3. children
    Children and guardian treatment

    How does the framework recognise age, guardianship and risks to younger people?

    Open framework evidence record
    Current dossier record
    The statute publishes defined consumer rights, including access, correction, deletion and sale/share controls, subject to scope and exceptions.
    Seek
    Age definition, guardian mechanism, applicable safeguards, exceptions and child-facing design evidence.
    Avoid
    A single age threshold does not capture the whole child-safety or guardian model.
    No jurisdiction value
  4. automated
    Automated decision and algorithmic accountability

    What transparency or recourse applies when automated processing affects a person?

    Open framework evidence record
    Current dossier record
    The statute publishes defined consumer rights, including access, correction, deletion and sale/share controls, subject to scope and exceptions.
    Seek
    Scope of covered decisions, explanation or notice duties, contest route and evidence of human review.
    Avoid
    Generic transparency language does not establish a right against every automated outcome.
    No jurisdiction value
03

Organisational architecture

How duties, safeguards, risk processes and transfer mechanisms are organised.

Developing

Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.

  1. processor
    Processor and accountability architecture

    Who remains accountable when processing is delegated or shared?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Role definitions, contracts, instruction boundaries, onward delegation and responsibility for failures.
    Avoid
    Vendor terminology in one framework cannot be copied directly into another role system.
    No jurisdiction value
  2. security
    Security and breach response

    Which safeguards and breach steps are specified, and when are they triggered?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Operative safeguard standard, trigger tests, notification recipients, timing and incident records.
    Avoid
    A detailed checklist does not prove effective security or consistent breach response.
    No jurisdiction value
  3. risk
    Data protection impact and risk duties

    When must an organisation investigate and document risk before processing?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Trigger criteria, required assessment content, reviewer or consultation route and retained decision record.
    Avoid
    Using an impact-assessment template does not prove that the relevant risks were identified.
    No jurisdiction value
  4. transfer
    Cross-border transfer model

    Which transfer routes exist, and what continuing safeguards travel with the data?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Destination, transfer route, restrictions, contract or assessment record and onward-transfer controls.
    Avoid
    A permitted destination does not remove continuing security or accountability duties.
    No jurisdiction value
  5. burden
    MSME implementation burden

    Which obligations create fixed costs, and what tailoring exists for smaller organisations?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Role-specific task inventory, exemptions or tailoring, recurring workload and organisation-level cost evidence.
    Avoid
    Concise legislation does not prove low implementation cost for a smaller organisation.
    No jurisdiction value
  6. interop
    Interoperability and ecosystem potential

    Could teams implement the rule through portable patterns without weakening legal context?

    Open framework evidence record
    Current dossier record
    Business, service-provider, contractor and third-party relationships must be mapped against current rules rather than a generic controller template.
    Seek
    Compatible definitions, documented interfaces, governance ownership and tests across real operating contexts.
    Avoid
    Technical reuse does not make the underlying legal requirements equivalent.
    No jurisdiction value
04

Institutions and remedy

How rules are supervised, enforced, explained and tested through practice.

Developing

The CPPA publishes regulations and enforcement materials; this record does not convert that history into a cross-jurisdiction score.

  1. regulator
    Regulator design and procedural digitisation

    How can people and organisations reach the institution, and what can it do?

    Open framework evidence record
    Current dossier record
    The CPPA publishes regulations and enforcement materials; this record does not convert that history into a cross-jurisdiction score.
    Seek
    Operative mandate, procedure, access route, published powers and evidence of actual use.
    Avoid
    A digital portal or broad statutory power does not prove timely or accessible resolution.
    No jurisdiction value
  2. penalties
    Penalty design

    How are sanctions linked to conduct, context and due process?

    Open framework evidence record
    Current dossier record
    The CPPA publishes regulations and enforcement materials; this record does not convert that history into a cross-jurisdiction score.
    Seek
    Operative penalty provisions, decision factors, appeal route and dated enforcement records.
    Avoid
    A higher maximum penalty does not automatically mean stronger protection or enforcement.
    No jurisdiction value
  3. maturity
    Enforcement maturity and published guidance

    What has the framework's operation, guidance and enforcement record actually demonstrated?

    Open framework evidence record
    Current dossier record
    The CPPA publishes regulations and enforcement materials; this record does not convert that history into a cross-jurisdiction score.
    Seek
    Dated guidance, decisions, enforcement records, appeal outcomes and evidence about access in practice.
    Avoid
    Age or publication volume alone is not a measure of institutional quality.
    No jurisdiction value
Q

TAKE TO COUNSEL / TEAMS

Operational questions, not prescriptions

Start the next conversation here.

  1. 01

    Does the entity meet a statutory coverage threshold for the activity at issue?

  2. 02

    Is the relationship a business, service-provider, contractor or third-party relationship?

  3. 03

    Which current regulation and commencement date governs the requested consumer control?

Official source rail

Open the record behind the summary.

Article revision record

What changed on this page.

This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.

ROUTE/frameworks/ccpa-cpra
ENTRIES01
Inspect the full revision register
Legal or editorial substance changedAdded a pair-aware evidence path and separated current California law and regulations from preliminary regulatory activity.
Why this changed
A current dossier must distinguish operative materials from preliminary activity and apply only a relevant DPDP/California research lens.
Claim impact
No preliminary activity is treated as an operative requirement and no comparison winner is produced.
Review state
Human legal or editorial review still required
Change ID
DOSSIER-CCPA-20260826-01
Source impactCA-01 · California Privacy Protection AgencyCA-02 · California Privacy Protection Agency

Source record

Source record

Authority
Pinpoint
Legal status
Checked
Basis

Official guidance can explain a rule, but it does not replace the controlling legal text.