California Consumer Privacy Act as amended by CPRA
Version: Cal. Civ. Code §1798.100 et seq. and CPPA regulations (11 CCR §7000 et seq., incl. 2025 amendments)
California's consumer privacy statute, as amended by the California Privacy Rights Act, and the implementing regulations of the California Privacy Protection Agency (CPPA). It applies to for-profit businesses that do business in California and meet a revenue or data-volume threshold, and it shapes the contracts those businesses hold with service providers, contractors, and third parties.
Where we stand
Controls
87%
Evidence
12%
Policies
37%
8 of 24 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| §1798.100 | General duties of businesses that collect personal information Controls: BIZ-14, DATA-04 | Passing | Not current | Not approved | Not yet |
| §1798.105 | Consumers' right to delete personal information Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| §1798.106 | Consumers' right to correct inaccurate personal information | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.110 | Consumers' right to know and access personal information collected Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| §1798.115 | Consumers' right to know what personal information is sold or shared and to whom Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| §1798.120 | Consumers' right to opt out of sale or sharing of personal information | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.121 | Consumers' right to limit use and disclosure of sensitive personal information | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.125 | Consumers' right of no retaliation following opt out or exercise of other rights | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.130 | Notice, disclosure, correction, and deletion requirements Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| §1798.135 | Methods of limiting sale, sharing, and use of personal information and use of sensitive personal information | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.140 | Definitions | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.145 | Exemptions | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.150 | Personal information security breaches Controls: BIZ-14, DATA-02 | Passing | Not current | Not approved | Not yet |
| §1798.155 | Administrative enforcement | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.185 | Regulations | Unmapped | Unmapped | Unmapped | Not yet |
| §1798.199.40 | Agency functions, including audits | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7012 | Notice at collection of personal information | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7025 | Opt-out preference signals | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7051 | Contract requirements for service providers and contractors | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7100 | Training | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7101 | Record-keeping Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| 11 CCR §7120 | Requirement to complete a cybersecurity audit Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| 11 CCR §7150 | When a business must conduct a risk assessment | Unmapped | Unmapped | Unmapped | Not yet |
| 11 CCR §7200 | Automated decisionmaking technology | Unmapped | Unmapped | Unmapped | Not yet |
