California Consumer Privacy Act as amended by the CPRA

cmp_us_ca_ccpa_cpra

California Consumer Privacy Act as amended by the CPRA defines payment-sector compliance duties for for-profit businesses meeting statutory thresholds that collect california consumers' personal information, plus covered service providers and contractors.

TL;DR:

  • Covers For-profit businesses meeting statutory thresholds that collect California consumers' personal information, plus covered service providers and contractors.
  • Provide notices; support access, deletion, correction, portability and opt-out rights; limit sensitive-data use; contract with service providers; use reasonable security.
  • Respond to verified requests, document compliance and report or notify breaches under applicable California breach law.

Summary

Covers For-profit businesses meeting statutory thresholds that collect California consumers' personal information, plus covered service providers and contractors.

The main requirements are to provide notices; support access, deletion, correction, portability and opt-out rights; limit sensitive-data use; contract with service providers; use reasonable security.

Personal-data protection follows information through collection, use, storage, sharing and deletion. The organisation deciding the purpose of processing can have different responsibilities from a supplier processing information on its behalf. Identifying those roles makes it possible to connect notices, permissions, contracts and security controls to the actual handling of customer and transaction data.

The practical questions are what information is needed, why it is used, who receives it, how long it is retained and how individuals can exercise the rights available under the relevant framework. Payment execution, financial-crime prevention, legal record keeping and optional marketing are different purposes. A basis for one purpose should not be treated as unlimited permission for every other use.

Security and privacy overlap but are not identical. Preventing unauthorised access does not alone answer whether an authorised use is lawful, while a privacy notice does not replace effective access control or incident response. Cross-border processing and outsourced services add further relationships that need to be understood within the instrument's territorial and substantive scope.

The instrument also addresses reporting and evidence: respond to verified requests, document compliance and report or notify breaches under applicable California breach law.

Keywords

  • California Consumer Privacy Act as amended by the CPRA
  • California CCPA/CPRA
  • California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act
  • California Consumer Privacy Act as amended by the CPRA summary
  • California Consumer Privacy Act as amended by the CPRA requirements
  • California Consumer Privacy Act as amended by the CPRA compliance
  • California payment regulation
  • California financial regulation
  • California Privacy Protection Agency and California Attorney General regulation
  • State of California publication