/us-ccpa-expert
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider /
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-ccpa-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/us-ccpa-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider /
SKILL.md
us-ccpa-expert.SKILL.mdname: us-ccpa-expert
description: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider / Contractor / Third Party distinctions, the Universal Opt-Out Mechanism (Global Privacy Control), CPPA risk assessments and cybersecurity audits, and dual enforcement by the California Privacy Protection Agency and the California Attorney General.
allowed-tools: Read, Glob, Grep, Write
California Consumer Privacy Act / California Privacy Rights Act Expert
Reference-depth expertise for the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This skill paraphrases the statute and cites California Civil Code section by section — never reproduce verbatim statute text.
Framework identity
- **SCF framework ID**: `usa-state-ca-ccpa-cpra-2026`
- **Region**: Americas
- **Country**: United States
- **Statute**: California Civil Code §1798.100 et seq.
- **Implementing regulations**: 11 California Code of Regulations §7000 et seq.
- **Regulators**: California Privacy Protection Agency (CPPA) and the California Attorney General — both have civil-enforcement authority.
Framework in plain language
CCPA gives California residents ("consumers" in the statute, which includes households for some rights) the right to know what personal information a business collects about them, the right to delete and correct it, the right to opt out of its sale or sharing, and the right to limit a business's use of certain sensitive categories. CPRA — passed by California voters as Proposition 24 in November 2020 and operative January 1, 2023 with enforcement beginning July 1, 2023 — amended the original 2018 CCPA (effective 2020) by adding the right to correct, the right to limit use of Sensitive Personal Information, the new "share" concept covering cross-context behavioral advertising, the standalone CPPA agency, and a mandatory recognition of Universal Opt-Out Mechanisms such as the Global Privacy Control. CPRA also raised one of the applicability thresholds, removed the AG's prior 30-day mandatory cure period, and authorized CPPA rulemaking on risk assessments and cybersecurity audits for processing that presents significant risk.
Key dates and history
- **June 2018**: California Legislature enacts AB 375 (CCPA), Civil Code §§1798.100–1798.199.
- **January 1, 2020**: CCPA operative.
- **July 1, 2020**: Attorney General begins enforcement under original CCPA.
- **November 3, 2020**: Voters pass Proposition 24 (CPRA).
- **January 1, 2023**: CPRA amendments operative; B2B and HR partial exemptions sunset; CPPA rulemaking authority active.
- **July 1, 2023**: CPPA enforcement begins (the CPPA, distinct from the AG, takes over its share of administrative enforcement).
- **2024–2026**: CPPA finalizes regulations on automated decision-making technology (ADMT), risk assessments, cybersecurity audits, and Universal Opt-Out Mechanisms — practitioners should track CPPA Board meeting agendas for current rulemaking status.
Territorial scope and applicability
CCPA/CPRA applies to a **for-profit business** that:
1. **Does business in California**, AND 2. **Collects (or has collected on its behalf) personal information about California residents**, AND **alone or jointly determines the purposes and means** of processing that information, AND 3. Meets **at least one** of the following three thresholds — see California Civil Code §1798.140(d) for the current text:
- **Revenue threshold**: had annual gross revenues in excess of **US $25 million** in the preceding calendar year (the dollar figure was $25M from inception and is subject to periodic CPPA inflation adjustment — confirm current value at assessment time).
- **Volume threshold**: alone or in combination, annually **buys, sells, or shares** the personal information of **100,000 or more** California consumers or households. *(CCPA's original threshold was 50,000 consumers/households/devices and used "buys, receives, sells, or shares for commercial purposes." CPRA raised the count to 100,000, removed "receives," removed "devices," and added "shares" — narrowing what triggers the threshold but extending coverage to behavioral-advertising recipients.)*
- **Revenue-derivation threshold**: derives **50 percent or more** of annual revenue from **selling or sharing** consumers' personal information. *(CPRA added "sharing" — relevant for adtech businesses that exchange data without monetary consideration.)*
Two additional categories of entity are also covered:
- Any **entity that controls or is controlled by** a covered business and shares common branding (the parent/affiliate hook).
- A **joint venture or partnership** in which each business has at least a 40 percent interest, with the joint venture itself treated as a separate business for compliance.
Coverage carve-outs
Several categories of data — not entire entities — are carved out so that the Civil Code does not apply to them:
- **Protected Health Information** governed by HIPAA / California Confidentiality of Medical Information Act, and other patient information collected by a covered entity or business associate to the extent it is treated under those laws.
- **Personal information collected, processed, sold, or disclosed pursuant to the GLBA** (financial institutions) or California Financial Information Privacy Act.
- **Personal information collected, processed, sold, or disclosed under the Driver's Privacy Protection Act**.
- **Personal information processed pursuant to the Fair Credit Reporting Act** when used for FCRA-permissible purposes.
- **Clinical-trial information** governed by federal common-rule requirements.
Important: these are **data-level carve-outs**, not entity-level exemptions. A bank that holds GLBA-covered custo
Read more
name: us-ccpa-expert description: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider / Contractor / Third Party distinctions, the Universal Opt-Out Mechanism (Global Privacy Control), CPPA risk assessments and cybersecurity audits, and dual enforcement by the California Privacy Protection Agency and the California Attorney General. allowed-tools: Read, Glob, Grep, Write
California Consumer Privacy Act / California Privacy Rights Act Expert
Reference-depth expertise for the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This skill paraphrases the statute and cites California Civil Code section by section — never reproduce verbatim statute text.
Framework identity
- **SCF framework ID**: `usa-state-ca-ccpa-cpra-2026`
- **Region**: Americas
- **Country**: United States
- **Statute**: California Civil Code §1798.100 et seq.
- **Implementing regulations**: 11 California Code of Regulations §7000 et seq.
- **Regulators**: California Privacy Protection Agency (CPPA) and the California Attorney General — both have civil-enforcement authority.
Framework in plain language
CCPA gives California residents ("consumers" in the statute, which includes households for some rights) the right to know what personal information a business collects about them, the right to delete and correct it, the right to opt out of its sale or sharing, and the right to limit a business's use of certain sensitive categories. CPRA — passed by California voters as Proposition 24 in November 2020 and operative January 1, 2023 with enforcement beginning July 1, 2023 — amended the original 2018 CCPA (effective 2020) by adding the right to correct, the right to limit use of Sensitive Personal Information, the new "share" concept covering cross-context behavioral advertising, the standalone CPPA agency, and a mandatory recognition of Universal Opt-Out Mechanisms such as the Global Privacy Control. CPRA also raised one of the applicability thresholds, removed the AG's prior 30-day mandatory cure period, and authorized CPPA rulemaking on risk assessments and cybersecurity audits for processing that presents significant risk.
Key dates and history
- **June 2018**: California Legislature enacts AB 375 (CCPA), Civil Code §§1798.100–1798.199.
- **January 1, 2020**: CCPA operative.
- **July 1, 2020**: Attorney General begins enforcement under original CCPA.
- **November 3, 2020**: Voters pass Proposition 24 (CPRA).
- **January 1, 2023**: CPRA amendments operative; B2B and HR partial exemptions sunset; CPPA rulemaking authority active.
- **July 1, 2023**: CPPA enforcement begins (the CPPA, distinct from the AG, takes over its share of administrative enforcement).
- **2024–2026**: CPPA finalizes regulations on automated decision-making technology (ADMT), risk assessments, cybersecurity audits, and Universal Opt-Out Mechanisms — practitioners should track CPPA Board meeting agendas for current rulemaking status.
Territorial scope and applicability
CCPA/CPRA applies to a **for-profit business** that:
1. **Does business in California**, AND 2. **Collects (or has collected on its behalf) personal information about California residents**, AND **alone or jointly determines the purposes and means** of processing that information, AND 3. Meets **at least one** of the following three thresholds — see California Civil Code §1798.140(d) for the current text:
- **Revenue threshold**: had annual gross revenues in excess of **US $25 million** in the preceding calendar year (the dollar figure was $25M from inception and is subject to periodic CPPA inflation adjustment — confirm current value at assessment time).
- **Volume threshold**: alone or in combination, annually **buys, sells, or shares** the personal information of **100,000 or more** California consumers or households. *(CCPA's original threshold was 50,000 consumers/households/devices and used "buys, receives, sells, or shares for commercial purposes." CPRA raised the count to 100,000, removed "receives," removed "devices," and added "shares" — narrowing what triggers the threshold but extending coverage to behavioral-advertising recipients.)*
- **Revenue-derivation threshold**: derives **50 percent or more** of annual revenue from **selling or sharing** consumers' personal information. *(CPRA added "sharing" — relevant for adtech businesses that exchange data without monetary consideration.)*
Two additional categories of entity are also covered:
- Any **entity that controls or is controlled by** a covered business and shares common branding (the parent/affiliate hook).
- A **joint venture or partnership** in which each business has at least a 40 percent interest, with the joint venture itself treated as a separate business for compliance.
Coverage carve-outs
Several categories of data — not entire entities — are carved out so that the Civil Code does not apply to them:
- **Protected Health Information** governed by HIPAA / California Confidentiality of Medical Information Act, and other patient information collected by a covered entity or business associate to the extent it is treated under those laws.
- **Personal information collected, processed, sold, or disclosed pursuant to the GLBA** (financial institutions) or California Financial Information Privacy Act.
- **Personal information collected, processed, sold, or disclosed under the Driver's Privacy Protection Act**.
- **Personal information processed pursuant to the Fair Credit Reporting Act** when used for FCRA-permissible purposes.
- **Clinical-trial information** governed by federal common-rule requirements.
Important: these are **data-level carve-outs**, not entity-level exemptions. A bank that holds GLBA-covered custo
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

