Skip to content

/us-ccpa-expert

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider /

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-ccpa-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/us-ccpa-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider /

SKILL.md

us-ccpa-expert.SKILL.md
name: us-ccpa-expert
description: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider / Contractor / Third Party distinctions, the Universal Opt-Out Mechanism (Global Privacy Control), CPPA risk assessments and cybersecurity audits, and dual enforcement by the California Privacy Protection Agency and the California Attorney General.
allowed-tools: Read, Glob, Grep, Write

California Consumer Privacy Act / California Privacy Rights Act Expert

Reference-depth expertise for the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This skill paraphrases the statute and cites California Civil Code section by section — never reproduce verbatim statute text.

Framework identity

  • **SCF framework ID**: `usa-state-ca-ccpa-cpra-2026`
  • **Region**: Americas
  • **Country**: United States
  • **Statute**: California Civil Code §1798.100 et seq.
  • **Implementing regulations**: 11 California Code of Regulations §7000 et seq.
  • **Regulators**: California Privacy Protection Agency (CPPA) and the California Attorney General — both have civil-enforcement authority.

Framework in plain language

CCPA gives California residents ("consumers" in the statute, which includes households for some rights) the right to know what personal information a business collects about them, the right to delete and correct it, the right to opt out of its sale or sharing, and the right to limit a business's use of certain sensitive categories. CPRA — passed by California voters as Proposition 24 in November 2020 and operative January 1, 2023 with enforcement beginning July 1, 2023 — amended the original 2018 CCPA (effective 2020) by adding the right to correct, the right to limit use of Sensitive Personal Information, the new "share" concept covering cross-context behavioral advertising, the standalone CPPA agency, and a mandatory recognition of Universal Opt-Out Mechanisms such as the Global Privacy Control. CPRA also raised one of the applicability thresholds, removed the AG's prior 30-day mandatory cure period, and authorized CPPA rulemaking on risk assessments and cybersecurity audits for processing that presents significant risk.

Key dates and history

  • **June 2018**: California Legislature enacts AB 375 (CCPA), Civil Code §§1798.100–1798.199.
  • **January 1, 2020**: CCPA operative.
  • **July 1, 2020**: Attorney General begins enforcement under original CCPA.
  • **November 3, 2020**: Voters pass Proposition 24 (CPRA).
  • **January 1, 2023**: CPRA amendments operative; B2B and HR partial exemptions sunset; CPPA rulemaking authority active.
  • **July 1, 2023**: CPPA enforcement begins (the CPPA, distinct from the AG, takes over its share of administrative enforcement).
  • **2024–2026**: CPPA finalizes regulations on automated decision-making technology (ADMT), risk assessments, cybersecurity audits, and Universal Opt-Out Mechanisms — practitioners should track CPPA Board meeting agendas for current rulemaking status.

Territorial scope and applicability

CCPA/CPRA applies to a **for-profit business** that:

1. **Does business in California**, AND 2. **Collects (or has collected on its behalf) personal information about California residents**, AND **alone or jointly determines the purposes and means** of processing that information, AND 3. Meets **at least one** of the following three thresholds — see California Civil Code §1798.140(d) for the current text:

  • **Revenue threshold**: had annual gross revenues in excess of **US $25 million** in the preceding calendar year (the dollar figure was $25M from inception and is subject to periodic CPPA inflation adjustment — confirm current value at assessment time).
  • **Volume threshold**: alone or in combination, annually **buys, sells, or shares** the personal information of **100,000 or more** California consumers or households. *(CCPA's original threshold was 50,000 consumers/households/devices and used "buys, receives, sells, or shares for commercial purposes." CPRA raised the count to 100,000, removed "receives," removed "devices," and added "shares" — narrowing what triggers the threshold but extending coverage to behavioral-advertising recipients.)*
  • **Revenue-derivation threshold**: derives **50 percent or more** of annual revenue from **selling or sharing** consumers' personal information. *(CPRA added "sharing" — relevant for adtech businesses that exchange data without monetary consideration.)*

Two additional categories of entity are also covered:

  • Any **entity that controls or is controlled by** a covered business and shares common branding (the parent/affiliate hook).
  • A **joint venture or partnership** in which each business has at least a 40 percent interest, with the joint venture itself treated as a separate business for compliance.

Coverage carve-outs

Several categories of data — not entire entities — are carved out so that the Civil Code does not apply to them:

  • **Protected Health Information** governed by HIPAA / California Confidentiality of Medical Information Act, and other patient information collected by a covered entity or business associate to the extent it is treated under those laws.
  • **Personal information collected, processed, sold, or disclosed pursuant to the GLBA** (financial institutions) or California Financial Information Privacy Act.
  • **Personal information collected, processed, sold, or disclosed under the Driver's Privacy Protection Act**.
  • **Personal information processed pursuant to the Fair Credit Reporting Act** when used for FCRA-permissible purposes.
  • **Clinical-trial information** governed by federal common-rule requirements.

Important: these are **data-level carve-outs**, not entity-level exemptions. A bank that holds GLBA-covered custo

Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked