Loading Vaultize
Skip to main content

Compliance/Global/CCPA

Forty-six sections: fifteen leave evidence in the file.

The Act gives California consumers rights over their personal information and makes the business responsible for handling it, including keeping it reasonably secure. Vaultize adds records that stay with the file.

  • Cal. Civ. Code 1798.100 et seq.
  • Amended by the CPRA, effective 1 January 2023
  • Enforced by the CPPA and the Attorney General
  • Capability mapping, not legal advice

100(c)General duties

A business’ collection, use, retention, and sharing of a consumer’s personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.

Discover & Classify

  1. A

    General duties

    1 of 1

    • 100
  2. B

    Consumer rights

    4 of 7

    • 105
    • 106
    • 110
    • 115
    • 120
    • 121
    • 125
  3. C

    Notice and definitions

    2 of 4

    • 130
    • 135
    • 136
    • 140
  4. D

    Exemptions and enforcement

    1 of 5

    • 145
    • 146
    • 148
    • 150
    • 155
  5. E

    Agency and final provisions

    0 of 29

    • 160
    • 175
    • 180
    • 185
    • 190
    • 192
    • 194
    • 196
    • 198
    • 199
    • 199.10
    • 199.15
    • 199.20
    • 199.25
    • 199.30
    • 199.35
    • 199.40
    • 199.45
    • 199.50
    • 199.55
    • 199.60
    • 199.65
    • 199.70
    • 199.75
    • 199.80
    • 199.85
    • 199.90
    • 199.95
    • 199.100
15of 46 sections, in 4 of 5 groups

The answer in 30 seconds

Vaultize adds file-level records to fifteen provisions across eight sections in four of the Act's five groups: general duties, consumer rights, notice and disclosure, and the private right of action after a breach. Business thresholds, consumer opt-out and correction requests, identity verification, exemptions, and the California Privacy Protection Agency's own rulemaking, investigation and penalty powers sit outside a governed file, with the business and its counsel.

The Act in one view

Five groups. Forty-six sections. Where file evidence lands.

The Act runs from Section 1798.100 to Section 1798.199.100 with no chapters of its own. We have grouped its forty-six sections by topic, in our words, keeping the Act's own section order. Section numbers on this page drop the “1798.” prefix, so Section 1798.100 appears as 100. Select a group to see which of its sections a governed file can evidence.

AGENERALDUTIESBCONSUMERRIGHTSCNOTICE ANDDEFINITIONSDEXEMPTIONS ANDENFORCEMENTEAGENCY ANDFINAL PROVISIONS

A

General duties

Section 1798.100. The general duties a business has when it collects personal information: telling consumers what is collected, keeping collection and retention proportionate, contracting with the third parties, service providers and contractors it shares data with, and keeping the data reasonably secure.

Outcomes the file can evidence

How Vaultize contributes
Vaultize Seal encrypts personal information in the document at source and Vaultize Secure keeps tamper-evident, immutable records of every version, so the security procedures and the contractual rights this section asks for both leave their own record. Discover & Classify shows what personal information a document holds.
Evidence to retain
Encryption on the file. Sealed-file state. Tamper-evident records. Immutable version history. Classification history.

Section by section

What each provision asks. What the file can answer.

Wording is quoted from the California Consumer Privacy Act of 2018, as amended by the CPRA, read from the California Legislative Information website. Section numbers on this page drop the “1798.” prefix, so Section 1798.100 appears as 100. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Act and take advice on business status, applicability and consumer rights.

Using this page

Where these rows fit in a CCPA programme.

The Act has applied since 1 January 2020 and was amended by the CPRA from 1 January 2023. The rows above are evidence for the provisions that touch documents.

  1. 1

    Confirm scope

    Section 1798.140. Whether the organisation meets the Act's definition of a business, including the revenue, data-volume or revenue-share thresholds, and whether the personal information involved is a California consumer's.

  2. 2

    Answer the consumer's request

    Sections 1798.105, 1798.110, 1798.115 and 1798.130. Verify the request, then disclose, correct or delete the personal information within the 45 days Section 1798.130 sets.

  3. 3

    Apply reasonable security procedures

    Section 1798.100(e). Implement security procedures and practices appropriate to the personal information held. These rows belong here.

    Bring the fifteen rows above as evidence of the security procedures and deletion records Sections 1798.100 and 1798.105 ask for.

  4. 4

    Direct deletion across service providers

    Section 1798.105. Delete the business's own copy and notify every service provider, contractor and third party holding it to delete theirs.

  5. 5

    Know the breach exposure

    Section 1798.150. A private right of action follows a breach of nonencrypted, nonredacted personal information caused by a failure to maintain reasonable security procedures and practices.

Responsibility boundary

Controls support compliance. They are not legal advice.

Vaultize contributes technical measures and evidence for personal information held in documents. It does not decide whether the organisation is a business within the Act's thresholds, manage a consumer's opt-out or correction request, verify a consumer's identity, or decide whether its security procedures are reasonable under Section 1798.100(e). This page is a capability mapping, not legal advice. Read the Act and take qualified advice before relying on it.

“A business that collects a consumer’s personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.”

Section 1798.100(e), California Consumer Privacy Act of 2018 (as amended by the CPRA)

A practical next step

Bring one document that carries personal information.

We will show which sections the governed document can evidence today. We will name the owner responsible for the rest.

Request a compliance mapping session