Skip to content
Live12+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is CCPA / CPRA?

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Also known as

california consumer privacy actcalifornia privacy rights actcpra
Definition

CCPA / CPRA — explained.

CCPA (California Consumer Privacy Act, in force since 1 January 2020) and its amendment the CPRA (California Privacy Rights Act, in force since 1 January 2023) together comprise California's data-protection regime. They are the most influential US state-level privacy laws and have inspired similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and several others. The core concepts are familiar to anyone who knows GDPR: lawful basis, consumer rights to access / delete / correct / port their data, the right to opt out of the sale or sharing of personal information, and breach notification. CCPA / CPRA enforcement is by the California Privacy Protection Agency (CPPA) and the state Attorney General, with penalties of up to $7,500 per intentional violation. For software vendors selling into California, compliance posture is essentially: implement GDPR primitives (consent, purpose, retention, subject-rights workflows) and add the California-specific 'Do Not Sell or Share My Personal Information' opt-out link.

Solutions where ccpa / cpra applies

Zeour solutions that operate on this layer.

MediCare Clinic

medicare · clinic · management · system

Zeour MediCare — the multilingual on-premise clinic and EMR management system for small-to-mid healthcare practices. Covers patients (records, allergies, conditions, medications, body diagrams), appointments + visits with SOAP notes, prescriptions with drug-interaction checks, lab orders + samples + results, billing + payments + invoicing, inventory, expenses, referrals, medical certificates, refill requests, patient communications, telemedicine (WebRTC), an AI clinical assistant (OpenAI-powered with 7 modes), a patient self-service portal, and a full role-based access model across Admin, Doctor, Reception, and Lab Tech roles. Engineered multilingual — (with full RTL) as the production baseline, extensible to any locale — and runs locally on a single server.

See the solution
Related terms

Adjacent definitions to read next.

GDPR

Compliance & Data

The EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.

PDPL

Compliance & Data

Personal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).

Data Residency

Sovereign Deployment

A requirement that personal or regulated data is stored, processed, and backed up within a defined jurisdiction — usually a country or a treaty bloc.

Cyber Essentials

Compliance & Data

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Explicit Consent

Compliance & Data

Consent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.

HIPAA

Compliance & Data

The US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.

IEC 62443

Compliance & Data

The international cybersecurity standard for industrial automation + control systems (IACS) — the OT-world analogue of ISO 27001.

Want to discuss ccpa / cpra for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where ccpa / cpra actually sits in your stack, then a fixed-fee Discovery price by the end of the call.