Governance, risk & compliance
CCPA / CPRA 2023
California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Applies to for-profit businesses that collect California consumers personal information and meet revenue/data thresholds. Requires privacy notices, consumer rights (access, deletion, opt-out of sale/sharing), reasonable security measures, data minimization, and privacy impact assessments for high-risk processing.
Enforced by the California Privacy Protection Agency.
How Lavawall® helps you get to CCPA / CPRA compliance
Most of CCPA / CPRA comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CCPA / CPRA, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against CCPA / CPRA in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports CCPA / CPRA as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- CCPA / CPRA 2023
- Category
- Privacy
- Region
- USA - California
Map this framework freeTalk to our team