CCPA/CPRA
California Consumer Privacy Act, as amended by the California Privacy Rights Act
California's privacy law: consumer rights over personal information, with rulemaking that reaches automated decision-making technology.
30 individual requirements seeded and assessable in AIXYRA.
The CCPA, strengthened by the CPRA, grants California consumers rights over their personal information — access, deletion, correction, and opt-outs from sale and sharing — and created a dedicated regulator, the California Privacy Protection Agency. Its reach extends to profiling and automated decision-making technology, an area of active rulemaking that pulls AI systems squarely into scope.
For AI programs, CCPA/CPRA raises the same operational question as GDPR: which systems process Californians' personal information, from which sources, for what purposes — and can you honor rights requests that reach into those pipelines. The answer starts with an accurate AI and data inventory.
Who it applies to
For-profit businesses meeting the law's thresholds that collect personal information of California residents — wherever the business is located.
Key requirement themes
Consumer rights
Access, deletion, correction, and opt-out rights that must be honored across systems processing personal information — including AI pipelines.
Automated decision-making technology
CPPA rulemaking addresses profiling and ADMT, bringing transparency and opt-out expectations to AI-driven decisions.
Sensitive personal information
A defined category with limitation rights — AI systems touching it need to know they do.
Risk assessments
Rulemaking contemplates risk assessments for high-risk processing, converging with GDPR-style impact assessment practice.
Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.
How AIXYRA helps
- CCPA/CPRA ships as a seeded framework so California obligations are assessed alongside GDPR and UK GDPR in one pass
- The data source registry ties AI systems to the personal information they consume — the map rights-handling depends on
- Data sensitivity is a scored risk dimension, surfacing systems that process sensitive personal information
- Evidence, coverage, and audit reports per framework support regulator and customer inquiries
CCPA/CPRA FAQ
Does CCPA/CPRA apply to AI systems?
Yes, wherever they process California residents' personal information — and the CPPA's rulemaking on automated decision-making technology extends transparency and opt-out expectations directly to AI-driven profiling and decisions.
How do I manage CCPA alongside GDPR without two programs?
In AIXYRA both are built-in frameworks: one compliance assessment maps an AI system's evidence to CCPA/CPRA, GDPR, and UK GDPR articles simultaneously, with per-framework coverage tracking and reporting.
Assess your AI systems against CCPA/CPRA
CCPA/CPRA ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.