What is CCPA / CPRA?
California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Also known as
CCPA / CPRA — explained.
CCPA (California Consumer Privacy Act, in force since 1 January 2020) and its amendment the CPRA (California Privacy Rights Act, in force since 1 January 2023) together comprise California's data-protection regime. They are the most influential US state-level privacy laws and have inspired similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and several others. The core concepts are familiar to anyone who knows GDPR: lawful basis, consumer rights to access / delete / correct / port their data, the right to opt out of the sale or sharing of personal information, and breach notification. CCPA / CPRA enforcement is by the California Privacy Protection Agency (CPPA) and the state Attorney General, with penalties of up to $7,500 per intentional violation. For software vendors selling into California, compliance posture is essentially: implement GDPR primitives (consent, purpose, retention, subject-rights workflows) and add the California-specific 'Do Not Sell or Share My Personal Information' opt-out link.
Zeour solutions that operate on this layer.
Verticals where ccpa / cpra is operationally critical.
Blog posts that go deeper on ccpa / cpra.
Adjacent definitions to read next.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
PDPL
Compliance & DataPersonal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).
Data Residency
Sovereign DeploymentA requirement that personal or regulated data is stored, processed, and backed up within a defined jurisdiction — usually a country or a treaty bloc.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
HIPAA
Compliance & DataThe US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.
IEC 62443
Compliance & DataThe international cybersecurity standard for industrial automation + control systems (IACS) — the OT-world analogue of ISO 27001.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where ccpa / cpra actually sits in your stack, then a fixed-fee Discovery price by the end of the call.