Skip to main content
Category: Regulatory & Legal Obligations

CCPA/CPRA

Also known as: CCPA/CPRA, California Consumer Privacy Act, California Privacy Rights Act
Simply put

The CCPA is a California privacy law that protects the privacy rights of California consumers, and the CPRA is a later law that amends and expands it. In practice, the two are closely related and often referred to together, since the CPRA builds directly on the CCPA's framework rather than replacing it entirely.

Formal definition

The California Consumer Privacy Act (CCPA) is a state privacy law regulating the privacy practices of covered businesses handling personal information of California consumers. The California Privacy Rights Act (CPRA) is most accurately characterized as an amendment to the CCPA, specifically amending existing provisions of Title 1.81.5, expanding and modifying key privacy rights and obligations rather than constituting a wholly separate statute. Implementation and enforcement fall to the California Privacy Protection Agency (CalPrivacy), which is also responsible for the Delete Act and its additional requirements unique to data brokers. For a virtual CISO engagement, supporting a client's CCPA/CPRA posture typically means advising on governance, consumer-rights processes, and readiness; legal and regulatory accountability for compliance remains with the client organization and its officers unless a contract specifies otherwise, and readiness support should not be conflated with any assertion of guaranteed compliance.

Why it matters

For businesses handling the personal information of California consumers, the CCPA and its CPRA amendments establish enforceable privacy rights and obligations that carry real regulatory consequences. Because the CPRA amends and expands the CCPA rather than replacing it, organizations often need to treat the two as a single, evolving framework rather than as separate compliance targets. Misunderstanding this relationship can lead to gaps in a privacy program, particularly where a business assumes older CCPA practices remain sufficient without accounting for the expanded and modified requirements introduced by the CPRA.

The stakes are heightened by dedicated enforcement. The California Privacy Protection Agency (CalPrivacy) is responsible for implementing and enforcing the CCPA, and it also administers the Delete Act, which imposes additional requirements unique to data brokers. This means a business's exposure depends not only on how it collects and uses personal information but also on whether it falls into specialized categories such as data brokers. For security and privacy leaders, understanding which obligations apply is a governance and business risk question, not merely a technical one.

A common and consequential mistake is conflating readiness support with guaranteed compliance. Even where a virtual CISO helps a client build consumer-rights processes and governance, legal and regulatory accountability for CCPA/CPRA compliance remains with the client organization and its officers unless a contract specifies otherwise. Treating a security leadership engagement as a substitute for legal counsel or as an assurance of compliance can leave an organization exposed to enforcement it believed it had addressed.

Who it's relevant to

Businesses handling California consumer data
Covered businesses that collect or process the personal information of California consumers fall within the scope of the CCPA as amended by the CPRA. These organizations need a privacy program that reflects the combined framework, and their leadership retains legal and regulatory accountability for compliance regardless of external advisory support.
Data brokers
Data brokers face additional requirements unique to their category under the Delete Act, which CalPrivacy also administers. Organizations that may qualify as data brokers should treat this as a distinct set of obligations layered on top of the broader CCPA/CPRA framework.
Virtual CISOs and security leaders
In many engagements, a virtual CISO supports a client's CCPA/CPRA posture by advising on governance, consumer-rights processes, and readiness. This role directs and advises but does not assume the client's legal or regulatory accountability, and readiness support should not be presented as a guarantee of compliance. Coordination with legal counsel is typically essential.
Executives and officers of covered organizations
Because accountability for privacy compliance generally rests with the client organization and its officers, leadership teams need to understand that engaging advisory support does not transfer this responsibility. They remain the parties answerable to CalPrivacy enforcement unless a contract specifies otherwise.

Inside CCPA/CPRA

California Consumer Privacy Act (CCPA)
A California state privacy law that establishes rights for consumers regarding the collection, use, and sharing of their personal information by covered businesses, and imposes corresponding disclosure and handling obligations on those businesses.
California Privacy Rights Act (CPRA)
An amendment to and expansion of the CCPA that broadened consumer rights, introduced additional obligations, and created a dedicated enforcement authority. In practice the two are often referenced together as the current California privacy framework rather than as separate regimes.
Consumer rights
The law grants defined rights to California consumers, which typically include the ability to access, delete, and correct personal information, and to opt out of certain sales or sharing of that information. The precise scope and mechanics may vary and should be confirmed against the current statutory text.
Business obligations
Covered businesses generally must provide privacy disclosures, honor consumer requests, and implement processes and safeguards around personal information. Determining whether an organization is a covered business depends on statutory thresholds and specifics of its data practices.
Sensitive personal information
The CPRA introduced a category of sensitive personal information with additional handling considerations and consumer controls beyond those applying to other personal information.
Enforcement authority
Enforcement and rulemaking responsibilities sit with designated California authorities. Legal accountability for compliance rests with the covered organization and its officers, not with any advisory security leader engaged to support the program.

Common questions

Answers to the questions practitioners most commonly ask about CCPA/CPRA.

Does hiring a virtual CISO make my organization compliant with CCPA/CPRA?
No. A virtual CISO can support your organization's readiness for CCPA/CPRA by advising on privacy governance, data mapping, risk assessments, and the reasonable security practices these laws reference. However, compliance is an organizational outcome that depends on client cooperation, implementation of controls, legal counsel, and operational follow-through. The engagement typically supports readiness rather than guaranteeing compliance, and legal accountability for privacy obligations generally remains with the client organization and its officers.
Isn't CCPA/CPRA a legal matter that a security leader has no role in?
Not entirely. While CCPA/CPRA are consumer privacy laws that require legal interpretation, they also reference reasonable security procedures and practices, which connects them to security governance and risk management. A virtual CISO often works alongside, rather than in place of, legal counsel and privacy professionals, advising on the security controls and data protection posture that underpin privacy obligations. This is a governance and business risk function, not solely a legal or technical one.
How does a virtual CISO typically support CCPA/CPRA readiness work?
In many engagements, a virtual CISO provides strategy and governance-level guidance, such as advising on data inventory and mapping efforts, evaluating whether security controls align with the reasonable security expectations referenced in the law, helping prioritize risk remediation, and coordinating with legal, privacy, and operational stakeholders. Hands-on tasks such as building data subject request workflows or administering privacy tooling are generally out of scope unless explicitly contracted.
What does the client organization need to provide for CCPA/CPRA-related work to be effective?
The value of the engagement often depends on organizational maturity, client cooperation, a clearly defined scope, and access to relevant stakeholders. For privacy-related work this typically includes access to legal counsel or privacy expertise, visibility into data flows and systems handling consumer information, and engagement from business units that collect or process that data. Without these, a virtual CISO's ability to support readiness is limited.
Where does legal counsel fit relative to a virtual CISO on CCPA/CPRA matters?
A virtual CISO advises and directs on the security and risk dimensions that intersect with these privacy laws but generally does not provide legal interpretation or assume legal accountability. Legal counsel typically owns the interpretation of statutory obligations, consumer rights requirements, and regulatory exposure. The two roles often work in coordination, with the virtual CISO focused on governance and security posture and counsel focused on legal compliance.
Should CCPA/CPRA readiness be scoped into a virtual CISO engagement from the start?
It is advisable to define whether privacy-related advisory work is in or out of scope at the outset, since scope boundaries directly affect deliverables, time commitment, and expectations. Because engagement models vary by provider, privacy support may be included as part of broader governance work or handled as a distinct workstream. Clarifying this early helps avoid conflating security leadership with full privacy program management, which typically requires additional legal and operational resources.

Common misconceptions

A virtual CISO engagement makes an organization CCPA/CPRA compliant or assumes accountability for compliance.
A virtual CISO typically supports privacy program readiness, governance, and risk alignment, but legal and regulatory accountability for CCPA/CPRA compliance remains with the client organization and its officers. Compliance is a legal determination that generally requires qualified legal counsel, not something a vCISO guarantees or assumes liability for unless a contract explicitly states otherwise.
CCPA/CPRA is purely a technical or security control problem that a security team can solve on its own.
The framework centers on governance, consumer rights processes, disclosures, and data handling practices that span legal, privacy, and business functions. Security leadership can help align controls and risk management, but treating it as a purely technical exercise overlooks the legal and business-process dimensions.
CCPA and CPRA are two entirely separate laws requiring separate compliance approaches.
CPRA amends and expands the CCPA, and in practice the two are usually treated together as the current California privacy framework. The distinction matters for understanding how obligations evolved, but organizations generally address them as a single, updated regime.

Best practices

Engage qualified legal or privacy counsel to determine whether the organization is a covered business and to interpret current statutory obligations, rather than relying on a security advisor for legal conclusions.
Clearly define in the engagement scope whether the virtual CISO is supporting privacy program governance and readiness versus performing hands-on operational or legal compliance tasks, which are typically out of scope unless explicitly contracted.
Map where personal information and sensitive personal information are collected, stored, and shared, as processes for consumer access, deletion, correction, and opt-out rights depend on accurate data inventories.
Align privacy program elements with existing governance and risk management structures so that security leadership supports rather than duplicates legal and privacy functions.
Document that legal and organizational accountability for CCPA/CPRA decisions remains with the client and its officers, and reflect this allocation clearly in engagement contracts.
Recognize that the value of any advisory support depends on organizational maturity, stakeholder cooperation, and access to accurate information about the organization's data practices.