CCPA
What is CCPA?
The California Consumer Privacy Act gives California residents rights over their personal information including the right to know, delete, and opt out of sale.
Terms that appear alongside ccpa
Each of these is named in at least one of the same controls as ccpa. The number is how many controls name both.
- gdpr 27 shared controls
- compliance 24 shared controls
- state privacy laws 21 shared controls
- consent 19 shared controls
- audit 16 shared controls
- data subject 15 shared controls
- hipaa 14 shared controls
- nist 13 shared controls
Frameworks that govern ccpa
What the standards actually require on ccpa
Requirements naming ccpa across 6 standards, quoted from the control text.
Florida FDBR coordination with the rapidly-growing US state privacy law ecosystem. COMPARABLE STATE LAWS (as of 2026 - approximately 20 comprehensive state privacy laws): California (CCPA + CPRA + 2018/2020) + Virginia VCDPA (2021) + Colorado CPA (2021) + Conn...
FDBR-Coord-CCPA-CPRA-State-Privacy · Coordination with US State Privacy Laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, ICDPA, TIPA, RIDTPPA, WDPA, MMCL, OCPA, NHDPA, MDPA, TDPSA, KCDPA, NJDPA, DPDPA, INCDPA) →GLBA coordination with related US privacy + financial frameworks. (a) FCRA (FAIR CREDIT REPORTING ACT, 15 USC 1681) - regulates consumer-reporting agencies + furnishers of information + users of consumer reports;
GLBA-Coordination-FCRA-HIPAA-CCPA-Sectoral · GLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks →Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy provides protection of information that might be derived from the observation of network activities.
X805-Dim8-Privacy-Identification-Network-Activity-Personal-Information-Confidentiality · ITU-T X.805 Security Dimension 8 - Privacy + Identification of Network Activity + Personal Information Confidentiality + Subscriber Anonymity + Pseudonymity + Anti-Tracking + Location Privacy + Data Minimization + GDPR/CCPA Alignment →Section 4(3) of Kentucky CDPA establishes the Universal Opt-Out Mechanism (UOOM) requirement + reflects converging US state privacy law standards for browser-level opt-out signals.
KY-CDPA-Universal-Opt-Out-Mechanism-Recognized-Browser-Level-GPC-Global-Privacy-Control · Kentucky CDPA Universal Opt-Out Mechanism + Section 3 + Section 4 + Recognized + Browser-Level + GPC Global Privacy Control + UOOM + Honored for Targeted Advertising + Sale + Profiling + Annual List of Recognized Mechanisms →Indiana CDPA grants Indiana consumers six core rights subject to verifiable consumer request procedures per IC 24-15-3 and IC 24-15-4.
INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day · Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process →Per Iowa Code 715D.7 ICDPA imposes contractual requirements on the relationship between controller and processor. (1) Processor Obligations: a processor shall adhere to the instructions of a controller and shall assist the controller in meeting the controller...
ICDPA-Processor-Contracts-DPA-Subprocessor-Confidentiality-Audit-EndOfContract-Iowa-Code-715D-7 · Iowa CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance →Questions people ask about ccpa
What is CCPA?
Why is CCPA important for compliance?
Which compliance frameworks address CCPA?
Where can I learn more about CCPA?
See how CCPA applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.