AIXYRA
All Frameworks
PrivacyIn force. CPRA amendments effective January 2023, enforced by the California Privacy Protection Agency.

CCPA/CPRA

California Consumer Privacy Act, as amended by the California Privacy Rights Act

California's privacy law: consumer rights over personal information, with rulemaking that reaches automated decision-making technology.

30 individual requirements seeded and assessable in AIXYRA.

The CCPA, strengthened by the CPRA, grants California consumers rights over their personal information — access, deletion, correction, and opt-outs from sale and sharing — and created a dedicated regulator, the California Privacy Protection Agency. Its reach extends to profiling and automated decision-making technology, an area of active rulemaking that pulls AI systems squarely into scope.

For AI programs, CCPA/CPRA raises the same operational question as GDPR: which systems process Californians' personal information, from which sources, for what purposes — and can you honor rights requests that reach into those pipelines. The answer starts with an accurate AI and data inventory.

Who it applies to

For-profit businesses meeting the law's thresholds that collect personal information of California residents — wherever the business is located.

Key requirement themes

Consumer rights

Access, deletion, correction, and opt-out rights that must be honored across systems processing personal information — including AI pipelines.

Automated decision-making technology

CPPA rulemaking addresses profiling and ADMT, bringing transparency and opt-out expectations to AI-driven decisions.

Sensitive personal information

A defined category with limitation rights — AI systems touching it need to know they do.

Risk assessments

Rulemaking contemplates risk assessments for high-risk processing, converging with GDPR-style impact assessment practice.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • CCPA/CPRA ships as a seeded framework so California obligations are assessed alongside GDPR and UK GDPR in one pass
  • The data source registry ties AI systems to the personal information they consume — the map rights-handling depends on
  • Data sensitivity is a scored risk dimension, surfacing systems that process sensitive personal information
  • Evidence, coverage, and audit reports per framework support regulator and customer inquiries

CCPA/CPRA FAQ

Does CCPA/CPRA apply to AI systems?

Yes, wherever they process California residents' personal information — and the CPPA's rulemaking on automated decision-making technology extends transparency and opt-out expectations directly to AI-driven profiling and decisions.

How do I manage CCPA alongside GDPR without two programs?

In AIXYRA both are built-in frameworks: one compliance assessment maps an AI system's evidence to CCPA/CPRA, GDPR, and UK GDPR articles simultaneously, with per-framework coverage tracking and reporting.

Assess your AI systems against CCPA/CPRA

CCPA/CPRA ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.