Skip to content

Compliance matrix

California Consumer Privacy Act, as amended by the CPRA

California, United States · Updated 2026-07-19

Applies to: For-profit businesses meeting revenue or data-volume thresholds that handle California residents' personal information.

Vendor certification snapshot

CCPA readiness status across the 48 vendors we track, read live from each profile. This field reflects vendor-stated readiness, not an independent audit.

45

Certified

1

Partial

2

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Right to know and access

Consumers can request the categories and specifics of personal information you hold about them.

CIAM controls

  • Verified-identity request flow before disclosure
  • Self-service data access

Evidence

  • Request verification records
  • Disclosure logs

Ask the vendor

  • How is the requester's identity verified before data is disclosed?

Right to delete and correct

Consumers can have their personal information deleted or corrected, subject to exceptions.

CIAM controls

  • Self-service deletion and profile correction
  • Verified deletion with confirmation

Evidence

  • Deletion logs with timestamps
  • Correction audit trail

Ask the vendor

  • Can consumers self-serve deletion and correction with an audit trail?

Right to opt out of sale / sharing

Consumers can opt out of the sale or sharing of personal information, including via the Global Privacy Control signal.

CIAM controls

  • Opt-out preference capture
  • Recognition of Global Privacy Control (GPC)
  • Consent / preference center

Evidence

  • Opt-out records
  • GPC handling configuration

Ask the vendor

  • Do you capture and honor opt-out preferences and GPC signals?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

How is CCPA different from GDPR for CIAM?
Both grant access, deletion, and portability-style rights, so the same self-service identity flows serve both. CCPA/CPRA adds an explicit opt-out of sale/sharing and requires honoring the Global Privacy Control browser signal, which GDPR does not.
Do we need to verify identity before a deletion request?
Yes. The regulations require reasonable verification of the requester before acting, which is why a CIAM platform's identity-verification and authentication controls are central to compliant request handling.

Source

California Privacy Protection Agency (CPRA regulations)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.