Achieve CCPA/CPRA Compliance More Efficiently and with Greater Assurance
CCPA/CPRA compliance on one platform, including the ADMT, risk assessment, and cybersecurity audit rules.
Enforcement exposure. Civil Code section 1798.155 sets penalties of up to $2,500 per violation and $7,500 per intentional violation or one involving a consumer under 16. The CPPA adjusts both figures for inflation every two years, so check its current published amounts.
What Changes, and When
The CPPA's rules on automated decision-making technology, risk assessments, and cybersecurity audits are final. Confirm the deadline that applies to your revenue tier against the CPPA's published regulation text.
Jul 24, 2025
The CPPA Board adopts the final regulations.
Sep 22, 2025
The Office of Administrative Law approves them and files them with the Secretary of State.
Jan 1, 2026
The regulations take effect.
Jan 2027 to Apr 2030
The remaining obligations phase in, with earlier deadlines for higher-revenue businesses.
Who Is Covered, and by Which Rule
Not every obligation lands on every business. Scope is set separately for each one.
| Rule | Who it applies to |
|---|---|
| CCPA/CPRA overall | For-profit businesses doing business in California with gross revenue over $25 million, a figure the CPPA adjusts for inflation every two years; or handling the personal information of 100,000 or more California consumers or households a year; or earning 50% or more of revenue from selling or sharing personal information. |
| Risk assessments | Businesses whose processing presents significant risk to privacy, which includes selling or sharing personal information, processing sensitive personal information, and using ADMT for significant decisions. |
| ADMT rules | Businesses using automated decision-making for outcomes in financial services, housing, education, employment, or healthcare. |
| Cybersecurity audit | Businesses earning 50% or more of revenue from selling or sharing personal information, plus larger-scale processors that meet the revenue threshold and the regulations' volume thresholds for personal and sensitive personal information. A written certification of completion is filed with the CPPA. |
| Consumer rights | All covered businesses. Rights to know, access, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. |
CCPA/CPRA Implementation Architecture
How Sigmify GRC's modules are put to work against the rules above.
Every CCPA/CPRA obligation routes through a mapped control, and every control leaves evidence behind it.
The 2026 rules, not just cookie consent
Assessments and Risk Management cover ADMT, risk assessment, and cybersecurity audit obligations in the same system as everything else.
Controls mapped to obligations
The Unified Compliance Framework links each control to the obligation it satisfies, and reuses shared controls across every framework they serve.
Requests tracked to their deadlines
Consumer rights requests run as workflows with named owners, due-date alerts, and a retained record of how each was handled.
What This Looks Like in Practice
The details teams ask about most. Tap any line to expand it.
CCPA/CPRA applies to any for-profit business doing business in California that meets one of three thresholds:
- Annual gross revenue over $25 million, a figure the CPPA adjusts for inflation every two years
- Buying, selling, or sharing the personal information of 100,000 or more California consumers or households a year
- Deriving 50% or more of annual revenue from selling or sharing personal information
Meeting a threshold while using ADMT for significant decisions or processing sensitive personal information also pulls in the risk assessment rules. Sigmify GRC records which thresholds you meet and maps the resulting obligations onto your processing activities.
A risk assessment is required before processing that presents significant risk to consumers’ privacy. That includes selling or sharing personal information, processing sensitive personal information, and using ADMT for a significant decision. The timing:
- The obligation takes effect January 1, 2026
- Documentation is submitted to the CPPA on the schedule the regulations set
- Assessments are reviewed and updated as processing changes
Sigmify GRC’s Assessments module holds each one with an owner, review date, due-date alerts, and retained evidence, so the record is ready when the attestation falls due.
The finalized ADMT rules cover automated decisions with legal or similarly significant effects, specifically outcomes in financial services, housing, education, employment, or healthcare. Businesses using ADMT for these decisions must:
- Give a plain-language notice before the decision, setting out the purpose and the choices available
- Honor opt-out rights
- Comply by the date the regulations set for ADMT obligations
Sigmify GRC’s Assessments and Risk Management modules hold the ADMT use-case inventory, the assessment behind each one, and the evidence that notice and opt-out controls are in place.
Sigmify GRC’s Unified Compliance Framework centralizes requirements such as transparency, purpose limitation, data minimization, and accountability, and aligns them with your existing controls, policies, and governance structures.
- Each control links back to the obligation it satisfies, so evidence is produced on demand rather than reconstructed at audit time
- A control serving more than one framework is mapped once and reused
- A change to a shared control carries across every framework it touches
Accurate disclosure depends on knowing what personal information you hold, including sensitive personal information, and where it flows. Sigmify GRC’s Data Discovery, Classification and Mapping module:
- Scans structured and unstructured sources across on-premise and cloud environments, from databases and file shares to collaboration tools, SaaS applications, and legacy systems
- Classifies what it finds by sensitivity, purpose, and risk
- Builds the inventory and data map from those same scans rather than periodic manual surveys
- Uses SIEM and HRM integration to keep the picture current as systems and people change
CCPA requires accurate disclosures, including a “Notice at Collection” and a privacy policy, covering the categories of personal information collected, the purposes of collection, and retention and sharing practices. Sigmify GRC’s IT Governance and Compliance module holds these notices and policies alongside the controls they support, so the published language stays on record and available for regulatory review.
CCPA/CPRA gives California consumers the right to know, access, delete, correct, and opt out of the sale or sharing of their personal information, plus the right to limit use of sensitive personal information. Sigmify GRC runs these as data subject request workflows:
- An owner and a due date drawn from the statutory timeline
- Alerts as that date approaches
- A retained record of what was done
- The same platform holds the data map, so the team fulfilling a request can see which systems hold that person’s data
The California Attorney General and the CPPA treat Global Privacy Control (GPC) signals as a valid way to exercise the right to opt out of the sale or sharing of personal information. A covered business must detect and honor them wherever it processes personal information for sale or sharing.
Detection sits in your web and consent infrastructure. Sigmify GRC’s Consent Management module holds the record side: preferences, the purposes each is linked to, withdrawals, and the audit trail showing that “Do Not Sell or Share My Personal Information” and “Limit Use of Sensitive Personal Information” choices were captured and carried through.
The audit does not fall on every covered business. It applies to businesses deriving 50% or more of revenue from selling or sharing personal information, and to larger-scale processors that meet the revenue threshold and the regulations’ volume thresholds for personal and sensitive personal information. For those in scope:
- Deadlines are phased by annual revenue, with higher-revenue businesses certifying first
- The audit must be carried out by a qualified, independent auditor, who may be internal or external
- A written certification of completion is filed with the CPPA each year
Sigmify GRC’s Assessments and Risk Management modules organize the control evidence, gaps, and remediation plans behind each audit period.
Sigmify GRC’s compliance monitoring dashboard shows control status, open tasks, and outstanding risks in real time, and highlights defaults before the situation gets out of hand. SIEM and HRM integration feeds it continuously rather than at reporting time, so an overdue request, a lapsed control, or an unmitigated risk surfaces while there is still time to act.
CCPA requires businesses to assess and monitor the service providers, contractors, and third parties processing California consumer data on their behalf, under agreements carrying the safeguards the law requires. Sigmify GRC’s Vendor Risk Management module keeps each third party’s assessment, agreed obligations, and supporting documents in one place, with review dates and alerts when something falls due, so those safeguards can be evidenced rather than searched for.
CCPA/CPRA accountability means answering an internal audit or regulatory inquiry with documentation, not recollection. Sigmify GRC collects evidence against each control as work is done, keeps it traceable to the obligation it supports, and exports it as audit-ready reporting, so it sits in one place instead of across mailboxes and shared drives.
California law requires notification when personal information is breached, and CCPA gives consumers a private right of action for certain breaches, with statutory damages available per consumer per incident. Meeting that duty depends on knowing quickly what was affected and who. Sigmify GRC’s Breach and Exceptions Management module runs the incident as a structured workflow, tracking investigation steps, decisions, owners, and timing, and holds the evidence behind the notification you send.
- CCPA, effective in 2020, established the foundational rights: to know, to delete, and to opt out of the sale of personal information.
- CPRA, effective January 1, 2023, added the right to correct and the right to limit use of sensitive personal information, raised the consumer-count threshold to 100,000, and created the California Privacy Protection Agency.
- GPC (Global Privacy Control) is a browser-level opt-out-of-sale signal the California Attorney General and the CPPA recognize as a valid way to exercise that right.
In practice, “CCPA” and “CPRA” now describe a single, continuously amended California privacy regime.
Comply with CCPA/CPRA with Confidence
Manage California privacy obligations on one platform: mapped controls, retained evidence, and a single view of where your compliance posture stands.
