CCPA / CPRA
Framework Overview
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights over their personal information and imposes obligations on businesses that process it. The CPRA established the California Privacy Protection Agency (CPPA) and added provisions that reach automated decision-making and AI.
Consumers have the right to know what personal information is collected, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of their data, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights.
The CPRA added automated decision-making technology (ADMT) transparency: consumers have the right to know about and opt out of ADMT that produces significant decisions, and the right to access information about its logic and outcomes. The CPPA is finalizing detailed ADMT, risk assessment, and cybersecurity audit regulations.
Businesses must provide privacy notices disclosing categories collected, purposes, retention, and ADMT use; perform risk assessments for high-risk processing; conduct annual cybersecurity audits for large processors; and ensure service providers and contractors are contractually bound.
For-profit businesses that process California residents’ personal information and meet any threshold — over $25 million in annual revenue, or personal information of 100,000+ consumers/households, or 50%+ of annual revenue from selling or sharing personal information.
Up to $7,500 per intentional violation and $2,500 per unintentional violation (adjusted for inflation), enforced by the CPPA and the Attorney General. A private right of action allows consumers to recover $100–$750 per consumer per incident for data breaches.
Key Requirements Checklist
Use this checklist to scope your CCPA / CPRA compliance program.
Publish a compliant privacy notice
Disclose categories of personal information collected, purposes, retention periods, third-party sharing, and the use of automated decision-making technology.
Honor the right to know and access
Respond to consumer requests for the categories and specific pieces of personal information collected, including AI-derived inferences.
Provide deletion and correction rights
Delete consumers’ personal information (and direct service providers to do so) and correct inaccurate information, including in AI training datasets.
Implement opt-out of sale and sharing
Provide a clear “Do Not Sell or Share My Personal Information” link and honor opt-out preference signals for the sale or sharing of data.
Limit sensitive personal information use
Allow consumers to limit the use and disclosure of sensitive personal information to what is necessary to perform the service.
Disclose and allow opt-out of ADMT
Where automated decision-making technology produces significant decisions, provide notice, opt-out, and access to the logic and outcomes.
Conduct risk assessments for high-risk processing
Document and assess risks for high-risk processing activities, including profiling and ADMT, and submit them as required.
Perform annual cybersecurity audits
Large processors must complete an annual cybersecurity audit covering the prior 12 months, as specified by CPPA regulations.
Bind service providers and contractors
Use contracts that restrict service providers and contractors to the specified purposes and require the same safeguards.
Manage children’s data with opt-in consent
Obtain opt-in consent before selling or sharing the personal information of consumers under 16, with verified parental consent for under-13s.
How Aegis Oversight Automates CCPA / CPRA Compliance
Pre-built controls, continuous checks, and audit-ready evidence — so you implement the checklist once and stay compliant automatically.
Map what personal information each AI system collects, the inferences it produces, and where it is shared, so your privacy notice stays accurate.
Track and fulfill know, delete, correct, and opt-out requests against the personal information your AI systems hold, with verifiable identities.
Document the automated decision-making systems you operate, their logic, and outcomes so you can respond to access and disclosure requests.
Generate structured risk assessments for high-risk processing and ADMT from your processing inventory and model context.
Track service providers, contractors, and their contractual obligations so you can confirm safeguards flow down before data is shared.
Centralized access and activity logs give you the evidence base for annual cybersecurity audits and regulator inquiries.
Frequently Asked Questions
Yes. The CPRA added automated decision-making technology (ADMT) transparency, giving consumers the right to know about, opt out of, and access information about ADMT that produces significant decisions — directly covering AI profiling.
Automated Decision-Making Technology is technology that processes personal information and uses computation to replace or substitute human decision-making. The CPPA is finalizing detailed rules on notice, opt-out, and access for ADMT.
Businesses that engage in high-risk processing — which includes certain profiling and ADMT — must conduct and document risk assessments, and submit them to the CPPA as required by regulation.
Up to $7,500 per intentional and $2,500 per unintentional violation, adjusted for inflation and enforced by the CPPA and Attorney General. Consumers also have a private right of action to recover $100–$750 per incident for data breaches.
For-profit businesses processing California residents’ personal information that meet any threshold: over $25 million annual revenue, 100,000+ consumers or households, or deriving 50%+ of annual revenue from selling or sharing personal information.
Yes. You must obtain opt-in consent before selling or sharing the personal information of consumers aged 13–15, and verified parental consent for consumers under 13.
Translate