CCPA/CPRAData PrivacyCalifornia, USAAll Industries

California Consumer Privacy Act / California Privacy Rights Act

California privacy law granting consumers rights over their personal information. Applies to businesses with >$25M revenue, data on 100k+ consumers, or 50%+ revenue from selling data.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

CCPA/CPRASection 1798.100Answering for an individual

Right to Know

Consumers can request disclosure of specific personal information collected. REQUIRES ability to locate and report all consumer data.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

CCPA/CPRASection 1798.105Answering for an individual

Right to Delete

MUST delete consumer data upon request and verify deletion across all systems.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

CCPA/CPRASection 1798.150Patching, hardening, and exposureA record of access

Security Requirements

Businesses MUST implement reasonable security procedures. Failure creates private right of action.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

CCPA/CPRACPRA AdditionKnowing where the data isPatching, hardening, and exposure

Sensitive Personal Information

Enhanced protections REQUIRED for sensitive data including precise geolocation and financial information.

You cannot evidence a control over data you have not located. Discovery scans every connected store continuously and classifies what it finds against 200+ built-in patterns and 20+ categories, so the inventory reflects the estate as it is today rather than as it was at the last manual survey. Because the classification is what ranks the scanning and shapes the reports, it cannot quietly go stale without something visibly breaking.

What CCPA/CPRA covers

Cal. Civ. Code Sec. 1798.140(v); sensitive personal information at Sec. 1798.140(ae)

Information that identifies, relates to, or could reasonably be linked with a consumer or household — the household limb is broader than most privacy laws.

In scope

  • Identifiers and account names
  • Commercial and purchasing history
  • Internet activity, including browsing and search history
  • Geolocation data
  • Inferences drawn to create a profile

Sensitive personal information (Sec. 1798.140(ae))

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • Social security, driver licence and passport numbers
  • Account log-in and financial account credentials
  • Precise geolocation
  • Racial or ethnic origin, religion, union membership
  • Contents of mail, email and text messages
  • Genetic, biometric and health data
  • Sex life or sexual orientation

What falls outside

Deidentified and aggregate consumer information, and publicly available information lawfully obtained from government records.

Cal. Civ. Code Sec. 1798.140 · as at 2026-08

How CCPA/CPRA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The California Privacy Protection Agency and the Attorney General — and, for breaches, consumers themselves.

Published maximumChargedAs at
USD 2,663per violation, counted per affected consumer2026-08
USD 7,988per intentional violation, or one involving a minor2026-08
USD 100 to USD 750No ceilingper consumer per incident under the Sec. 1798.150 private right of action, with no proof of harm required and no aggregate cap2026-08

Administrative penalties are assessed per violation, and a violation is usually counted per affected consumer, so a single practice can compound quickly. Separately, Section 1798.150 gives consumers a private right of action after a breach of unencrypted personal information caused by a failure to maintain reasonable security, with statutory damages of USD 100 to USD 750 per consumer per incident and no need to prove harm.

Both the administrative penalties and the Section 1798.150 damages range are adjusted for inflation in odd-numbered years, so published figures drift.

Uncapped exposure that sits outside this instrument

These come from company law rather than from CCPA/CPRA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

The Act does not name an accountable officer. What it does instead is create the private right of action at Section 1798.150, which means the decision not to remediate is one that counsel for a class may later read.

The insurance position

Statutory damages under Section 1798.150 are typically covered as a privacy liability loss where the policy is written broadly, while civil penalties from the Agency are commonly excluded as fines.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for CCPA/CPRA,
not configured for it afterwards

Policy Template

Consumer Data Access Tracking

Track all queries accessing California consumer records

Report

Data Subject Request Report

Generate complete access history for any consumer within minutes

Classification

CA Consumer PII

Identify California-specific data: CA driver license, state IDs

Alert

Bulk Data Export Detection

Alert when large volumes of consumer data are accessed or exported

Other Data Privacy frameworks

Walk into the CCPA/CPRA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment