Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomePrivacy laws › USA
Privacy law · Americas

🇺🇸 CCPA/CPRA + states in USA

The United States has no single federal privacy law; instead a growing patchwork of state laws led by California's CCPA/CPRA grants consumers rights to know, delete, correct and opt out of the sale or sharing of their personal information, alongside sector-specific federal rules.

Verified - legal review completed
CCPA/CPRA + states
Governing framework
California Privacy Protection Agency and state AGs
Supervisory authority
6
Controls this market requires
16
Required or strongly expected
Good to know: California shown as the representative (strictest) state profile; the paid tier checks each state you are exposed to.

What CCPA/CPRA + states expects of you

19 of our 22 tracked controls apply in USA, graded by how firmly the law requires each one.

Required mandated by law Expected near-mandatory Prudent advisable Optional emerging
TransparencyRequired

Privacy notice / transparency

A published, current privacy notice giving the prescribed information.

Closes with: Public privacy notice (per-market)
RightsRequired

Individual rights handling

Ability to find, correct and delete one person's data on request within the legal deadline.

Closes with: Rights-request procedure
SecurityRequired

Security controls (TOMs)

Encryption in transit and at rest, least-privilege access, and access logging.

Closes with: Security controls statement (TOMs)
BreachRequired

Breach detection & notification

A written breach plan and knowledge of each market's notification clock.

Closes with: Breach response plan + per-market templates
VendorsRequired

Vendor / processor agreements

DPAs with vendors handling your data, with controller/processor roles defined.

Closes with: Processor agreement template + role allocation
SensitiveRequired

Sensitive / special-category data

Explicit consent, tighter access, and often a DPIA for special-category data.

Closes with: Sensitive-data policy + DPIA where required
RecordsExpected

Records of processing (RoPA)

A living inventory of what personal data you hold, why, where it sits and where it flows.

Closes with: Records of Processing register
Lawful basisExpected

Lawful basis mapping

A valid legal reason for each use of personal data, mapped per activity.

Closes with: Lawful-basis mapping
ConsentExpected

Consent - specific, logged, withdrawable

Where you rely on consent it is freely given, specific, informed, unbundled and withdrawable, with a record.

Closes with: Consent notice + consent-record schema
RetentionExpected

Retention & deletion schedule

Defined, enforced retention periods and deletion, balancing storage-limitation and legal keep-periods.

Closes with: Retention schedule + deletion runbook
ChildrenExpected

Children's-data safeguards

Age assurance and verifiable parental consent; no behavioural tracking of children.

Closes with: Children's-data procedure + age-gating
ePrivacyExpected

Cookies / e-privacy consent

Cookie/tracker consent and an accurate cookie policy where required (esp. EU/UK).

Closes with: Cookie policy + consent banner
MarketingExpected

Direct-marketing consent

Lawful basis/consent for e-marketing and an unsubscribe route.

Closes with: Marketing consent + suppression list
DPIAExpected

Impact assessment / dossier

A DPIA/impact assessment for high-risk processing; some markets require a filed dossier.

Closes with: DPIA / transfer-impact assessment
ADM/AIExpected

Automated decisions / profiling

Safeguards and transparency for automated decision-making and profiling.

Closes with: ADM transparency + safeguards note
PaymentsExpected

PCI / payment-card handling

Card data offloaded to a compliant processor; PCI-DSS scope controlled.

Closes with: PCI-DSS scope note + card-handling policy
GovernancePrudent

Accountable privacy owner / DPO

A named person or role accountable for data protection, with published contact where required.

Closes with: DPO / privacy-owner appointment letter
GrievancePrudent

Grievance / complaints channel

A published route to raise a privacy complaint; India requires a grievance officer.

Closes with: Grievance / complaint notice
Cross-borderOptional

Cross-border transfer mechanism

Every export of personal data is covered by a lawful transfer mechanism.

Closes with: Data-flow map + transfer pack (SCCs/TRA/adequacy)

Get USA-ready without the guesswork

Answer a few questions and PrivMatrix shows you exactly where you stand against CCPA/CPRA + states, then generates the policies, notices and registers that close each gap - written for USA.

Other markets

See all 28 →
🇦🇪 UAE🇸🇦 Saudi Arabia🇶🇦 Qatar🇧🇭 Bahrain🇴🇲 Oman🇰🇼 Kuwait🇹🇷 Turkey🇪🇺 EU / UK