California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…

MITAuto-check passedLegal & Compliance

Install Ccpa

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .claude/skills/ccpa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ccpa
GitHub stars
946
Used in
1 other repo
Token cost
~7.1k tokens
SKILL.md length
3,682 words
Files
3 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…

  • Works in 2 steps: Confirm entity type. Must be a… → Test the three thresholds — the business…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Applicability Workflow, Key Definitions, Consumer Rights and Key Obligations, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ccpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI, ADMT opt-out), privacy notice drafting, service provider vs. contractor vs. third-party classification, sensitive personal information (SPI) handling, data minimization, opt-out mechanisms (including GPC), cybersecurity audits and risk assessments (live since Jan 1, 2026), ADMT obligations…

Its SKILL.md is about 7.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/ccpa-gdpr-comparison.md` and `references/consumer-rights-workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/ccpa”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Confirm entity type. Must be a for-profit business doing business in California. Non-profits and government entities are generally not…
  2. Test the three thresholds — the business is covered if it meets at least one

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ccpa loads about 7.1k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 3,682 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~183
When it runs · the whole SKILL.md, loaded when a task matches
~7.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 3,682 words, ~7,077 tokens.

Download SKILL.mdSave it as .claude/skills/ccpa/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
ccpa
description
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI, ADMT opt-out), privacy notice drafting, service provider vs. contractor vs. third-party classification, sensitive personal information (SPI) handling, data minimization, opt-out mechanisms (including GPC), cybersecurity audits and risk assessments (live since Jan 1, 2026), ADMT obligations (effective 2026, deadline Jan 1, 2027), CPPA enforcement (Disney $2.75M, PlayOn $1.1M, Ford $375K), penalty exposure, GDPR comparison, and gap assessments for businesses operating in or targeting California residents.

CCPA/CPRA Compliance Advisor

Last verified: 2026-10-03

You are an expert on California's comprehensive privacy laws:

  • CCPA: California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.), effective January 1, 2020
  • CPRA: California Privacy Rights Act (Proposition 24), effective January 1, 2023 — significantly amends and expands CCPA, creates the California Privacy Protection Agency (CPPA)

Applicability Workflow

Work through these steps in order for any organization asking "does CCPA/CPRA apply to us?"

  1. Confirm entity type. Must be a for-profit business doing business in California. Non-profits and government entities are generally not covered, though some CPRA provisions may apply indirectly through service provider/contractor obligations flowing down from a covered business.
  2. Test the three thresholds — the business is covered if it meets at least one:
#ThresholdExact Figure
1Annual gross revenueExceeds $25 million in the preceding calendar year
2Data volumeAnnually buys, sells, receives, or shares the personal information of 100,000 or more consumers or households
3Revenue from data monetizationDerives 50% or more of annual revenue from selling or sharing consumers' personal information
  1. Classify each downstream data recipient. Applicability findings are incomplete without classifying who the business shares PI with:
ClassificationDefinitionSale?
Service ProviderProcesses PI on behalf of the business under a written contract that prohibits further use beyond the specified business purposeNot a sale
Contractor (CPRA addition)Receives PI under a contract that prohibits use for any purpose other than specified; must certify complianceNot a sale
Third PartyReceives PI but is not a service provider or contractorMay constitute a sale or sharing
  1. Document the determination — revenue and data-volume thresholds must be reassessed annually; vendor classifications should be reassessed whenever a contract is renewed or a new data recipient is onboarded.

Key Definitions

  • Personal Information (PI): Information that identifies, relates to, describes, or could reasonably be linked to a consumer or household. Includes name, email, IP address, browsing history, purchase history, biometric data, geolocation.
  • Sensitive Personal Information (SPI) (CPRA addition): PI that reveals SSN/government ID, account credentials, precise geolocation, racial/ethnic origin, religious beliefs, union membership, genetic/biometric data, health/medical data, sexual orientation, or contents of consumer communications. See the full SPI category table and right-to-limit workflow below.
  • Sale: Disclosing PI to a third party for monetary or other valuable consideration (broad definition — includes data brokering).
  • Sharing (CPRA addition): Disclosing PI to a third party for cross-context behavioral advertising, even without monetary consideration.
  • Service Provider: Processes PI on behalf of a business under a written contract that prohibits further use; not considered a sale.
  • Contractor (CPRA addition): Entity receiving PI under a contract that prohibits use for any other purpose; must certify compliance.
  • Third Party: Entity that receives PI from a business but is not a service provider or contractor.

Consumer Rights

RightDescriptionResponse Deadline
Right to Know (§1798.110 / §1798.115)Access specific PI collected, categories, sources, purposes, third parties45 days (+ 45-day extension)
Right to Delete (§1798.105)Delete PI collected from the consumer; exceptions apply45 days (+ 45-day extension)
Right to Correct (§1798.106)Correct inaccurate PI (CPRA addition)45 days (+ 45-day extension)
Right to Opt-Out of Sale/Sharing (§1798.120)Stop sale or sharing of PI to third partiesImmediate upon request; propagate within 15 business days
Right to Limit SPI Use (§1798.121)Limit use/disclosure of SPI to what's necessary (CPRA addition)15 business days
Right to Non-Discrimination (§1798.125)Cannot deny goods/services or charge different prices for exercising rightsN/A
Right to Data PortabilityReceive PI in portable, usable formatIncluded in right to know
Right to Opt-In (minors)Opt-in required for sale/sharing of minors' PI (under 16); parental consent under 13N/A
Automated Decision-Making (ADMT) (§1798.185(a)(16))Right to opt-out of ADMT; right to access logic; right to human review. Regulations finalized and effective January 1, 2026. Compliance deadline for ADMT opt-out mechanism: January 1, 2027.Per CPPA regulations
General Request-Handling Principles
  • Response timeline (state it in every request-handling answer): confirm receipt within 10 business days with a description of the verification process (Regs §7021(a)); substantive response within 45 calendar days, extendable once by a further 45 days with notice to the consumer (§1798.130(a)(2)); opt-out and limit requests must be effectuated within 15 business days.
  • Intake channels (§1798.130): Provide at least two methods for submitting requests, including (where applicable) a toll-free phone number and a web form or email. Online-only businesses may provide an email address as one method.
  • Identity verification — tiered standards (Regs §§7060–7062):
    • Reasonable degree of certainty (e.g., categories-of-PI requests, deletion of non-sensitive data): match at least 2 data points the business already holds
    • Reasonably high degree of certainty (specific pieces of PI; deletion of sensitive data): match at least 3 data points PLUS a signed declaration under penalty of perjury that the requestor is the consumer
    • Verification failure handling: a request to know specific pieces that cannot be verified is answered with categories instead; a deletion request that cannot be verified is denied as deletion but must be treated as an opt-out of sale/sharing where applicable (Regs §7022(f)); opt-out requests themselves require no identity verification (only fraud screening)
    • Authorized-agent requests: require written permission from the consumer plus verification of the agent's identity; may also require direct verification with the consumer (except opt-out requests where the agent has power of attorney)
  • Free of charge: Fulfill requests free of charge, twice per 12-month period. A reasonable fee may be charged for additional requests within 12 months if manifestly unfounded or excessive.
  • Record-keeping: Businesses handling PI of 10 million or more consumers/households must maintain records of consumer requests and responses, disclosures, and CCPA/CPRA training for 24 months.
Right to Know — Workflow (§1798.110 / §1798.115)

Must disclose: specific pieces of PI collected; categories of PI; categories of sources; business/commercial purpose for collecting, selling, or sharing; categories of third parties PI was disclosed to; categories of PI sold or shared and to whom.

Scope: default lookback is the 12 months prior to the request; for PI collected on or after January 1, 2022, the consumer may request information beyond 12 months and the business must provide it unless doing so proves impossible or would involve disproportionate effort (§1798.130(a)(2)(B)).

Exceptions: disclosure would reveal third-party trade secrets; would conflict with federal/state law; PI was collected for a single one-time transaction and not retained; PI is used solely for internal operations consistent with context of collection; PI is used solely to complete the transaction for which it was collected.

StepAction
1Receive and log request with timestamp
2Verify consumer identity (2-point match for standard requests)
3Search PI systems using identifying data
4Compile responsive PI across all systems (CRM, analytics, ad tech, etc.)
5Apply exceptions — remove third-party trade secrets, conflicting legal holds
6Deliver response in portable, readily usable format within 45 days
7Provide extension notice if needed (within the original 45-day window)
Right to Delete — Workflow (§1798.105)

Business must delete the consumer's PI from its records and direct service providers and contractors to delete it.

Exceptions (business may retain PI if necessary to): (1) complete a transaction or perform a contract; (2) detect security incidents or protect against malicious, deceptive, fraudulent, or illegal activity; (3) fix errors that impair intended functionality; (4) exercise free speech or ensure another consumer's right to free speech; (5) comply with a legal obligation (§1798.145(a)); (6) use PI solely for internal purposes compatible with the context of collection (limited CPRA exception); (7) research, journalism, or statistical purposes in the public interest.

Two-step deletion confirmation workflow:

StepAction
1Receive and log deletion request
2Verify consumer identity
3Check whether any exception applies; document reasoning if invoking one
4Step one — execute: if proceeding, identify all PI records and propagate deletion instructions to service providers and contractors
5Step two — confirm: confirm deletion to the consumer (or explain the exception invoked) within 45 days
6Retain deletion-request records as proof of compliance (retaining the request record itself is not a contradiction of the deletion)
Right to Correct — Workflow (§1798.106, CPRA addition)

Business must take commercially reasonable steps to correct inaccurate PI and instruct service providers and contractors to correct it. Consumer must provide documentation if the business contests the claimed inaccuracy. Business may decline if correction would require revealing another individual's PI, or if it disagrees the PI is inaccurate and documents its decision.

StepAction
1Receive correction request with claimed correction details
2Verify consumer identity
3Evaluate accuracy of the claimed correction (may request supporting documentation)
4If agreeing to correct: update all relevant systems; instruct service providers and contractors
5Notify consumer of outcome within 45 days
Right to Opt-Out of Sale/Sharing — Workflow (§1798.120)

Scope: "Sale" = disclosure of PI to a third party for monetary or other valuable consideration. "Sharing" (CPRA) = disclosure of PI to a third party for cross-context behavioral advertising.

Sale vs. sharing analysis for ad tech: any pipeline that passes PI (cookie IDs, device fingerprints, hashed emails, IP addresses) to ad exchanges, DMPs, or ad tech partners for cross-context behavioral advertising is "sharing" even absent monetary payment, and must be covered by the opt-out mechanism. First-party analytics tools that do not disclose PI to third parties are typically unaffected. Once a consumer opts out, the business must wait 12 months before asking them to re-consent.

The service-provider workaround does not exist for CCBA (Regs §7050(c)): a person who contracts with a business to provide cross-context behavioral advertising is a third party, not a service provider or contractor, with respect to those services — restricted-use contract terms cannot convert CCBA disclosures into service-provider activity. Service providers may still provide contextual advertising and non-CCBA marketing services, but must not combine opted-out consumers' PI with PI from other sources. State this rule explicitly in any ad-tech classification answer.

GPC / opt-out preference signal handling: the business must honor the Global Privacy Control (GPC) signal as a valid opt-out — the CPPA has confirmed GPC compliance is required. GPC signals must be treated equivalently to a manual click on the "Do Not Sell or Share" link; no separate identity verification is required to act on an opt-out (only reasonable verification that the requester is the consumer).

StepAction
1Consumer submits opt-out via link, form, or GPC signal
2No identity verification required for opt-out beyond reasonable confirmation the requester is the consumer
3Update consent/preference management platform within 15 business days
4Propagate opt-out to service providers and contractors engaged in sale/sharing
5Do not contact the consumer for 12 months to ask them to reconsider
Right to Limit Use of Sensitive Personal Information — Workflow (§1798.121, CPRA addition)

SPI categories (applicability trigger for the right to limit):

  • Social Security number, driver's license, passport, or other government ID
  • Financial account credentials (login + security code)
  • Precise geolocation (locating a consumer within a radius of 1,850 feet — §1798.140(w))
  • Racial/ethnic origin, religious/philosophical beliefs, union membership
  • Contents of consumer mail, email, or text messages (unless the business is the intended recipient)
  • Genetic data
  • Biometric data used to uniquely identify a person
  • Health/medical information
  • Sexual orientation or sex life

The right to limit does NOT apply when SPI is used only for these permitted purposes:

  • Performing services or providing goods reasonably expected by the consumer
  • Safety, security, and integrity of services
  • Short-term, transient use (e.g., a contextual ad based on the current session)
  • Services performed on behalf of the business (service provider context)
  • Verifying or maintaining quality of services
  • Activities for which the SPI was specifically provided
StepAction
1Provide "Limit the Use of My Sensitive Personal Information" link on the homepage (alongside or combined with the "Do Not Sell or Share" link)
2Consumer exercises the right — no identity verification required beyond confirming consumer identity
3Process within 15 business days
4Restrict SPI use to only the permitted purposes listed above
5Propagate the limitation instruction to service providers and contractors
Right to Non-Discrimination (§1798.125)

Businesses cannot, because a consumer exercised a CCPA/CPRA right: deny goods or services; charge a different price (except where directly related to the value of the data); provide a different level or quality of goods/services; or suggest that any of the above will occur.

Financial incentive exception: businesses may offer financial incentives (loyalty programs, discounts) in exchange for PI, provided the incentive is reasonably related to the value of the consumer's PI, the consumer gives opt-in consent with a clear description of material terms, and the consumer can withdraw at any time.

Authorized Agent Requests

Consumers may designate an authorized agent to submit requests on their behalf. The business must require written permission from the consumer (signed authorization), verify the agent's identity, and may require direct verification with the consumer as well — except for opt-out requests where the agent holds power of attorney.

Key Obligations

Privacy Notice at Collection

Inform consumers at or before PI collection: categories collected, purposes, whether PI is sold or shared, retention periods (CPRA requirement), and link to privacy policy.

Privacy Policy

Must include: categories of PI collected in last 12 months, purposes of use, categories of third parties PI disclosed to, consumer rights and how to exercise them, contact info for requests, and "Do Not Sell or Share My Personal Information" link (or opt-out of SPI limitation where applicable). Update the privacy policy annually.

Show full SKILL.md (1,487 more words)Show less
Opt-Out Mechanisms
  • "Do Not Sell or Share My Personal Information" link on homepage
  • Accept opt-out signals including Global Privacy Control (GPC) — must be honored as a valid opt-out
  • "Limit the Use of My Sensitive Personal Information" link (if SPI used beyond necessary purposes)
  • ADMT opt-out — Must be implemented by January 1, 2027; applies to automated decisions producing legal or similarly significant effects
Data Minimization & Purpose Limitation (CPRA additions)

PI collected must be adequate, relevant, and limited to what is necessary for the disclosed purpose. Cannot use PI for undisclosed purposes.

Retention Limits (CPRA addition)

Disclose retention periods or criteria for each category. Cannot retain PI longer than reasonably necessary.

Service Provider, Contractor, and Third-Party Contracts

Contracts with service providers and contractors must include: purpose limitations, prohibition on further sale/sharing, obligation to comply with consumer requests, rights to audit, and data deletion obligations. Confirm vendors are properly classified as service providers/contractors (not a sale) versus third parties (may constitute a sale or sharing) — a mismatch between contractual classification and actual data flow is a common gap-assessment finding.

Cybersecurity Audits (CPRA — Effective January 1, 2026)

Businesses that process PI that presents significant risk to consumers' security must conduct annual cybersecurity audits. Regulations (finalized 2025, effective January 1, 2026) define scope and audit requirements. Non-compliance is an enforcement risk — the Disney $2.75M enforcement (2026) involved, in part, failure to implement adequate security practices.

Risk Assessments (CPRA — Effective January 1, 2026)

Businesses must conduct and document risk assessments before processing PI that presents significant risk to consumers. Assessments must be submitted to the CPPA upon request. Regulations are live (effective January 1, 2026).

Automated Decision-Making Technology (ADMT) (Effective January 1, 2026 / Deadline January 1, 2027)
  • CPPA finalized ADMT regulations in 2025; effective January 1, 2026
  • Consumers have the right to: opt out of ADMT producing significant decisions; know about automated processing; request human review
  • Businesses must implement opt-out mechanisms by January 1, 2027
  • ADMT covers decisions with legal or significant effects (employment, credit, housing, insurance, education)

Penalties & Enforcement

CPPA: Independent enforcement agency (created by CPRA). Issues regulations, investigates complaints, brings administrative actions. The California Attorney General (AG) retains concurrent enforcement authority.

Civil penalties (§1798.155):

  • Unintentional violations: up to $2,500 per violation
  • Intentional violations: up to $7,500 per violation
  • Violations involving minors' PI: up to $7,500 per violation (always treated as intentional)

Cure provisions: a 30-day cure period applies to AG actions (CPPA administrative actions may differ and are not subject to the same formal cure notice process).

Private right of action (§1798.150) — data breach only:

  • Applies when PI is subject to unauthorized access due to failure to implement reasonable security measures
  • Statutory damages: $100–$750 per consumer per incident (or actual damages, whichever is greater)
  • Class action eligible; 30-day cure period (for non-CPRA actions)
2026 Enforcement Precedents

These cases define the current enforcement posture and penalty expectations:

CompanyFineKey Violations
The Walt Disney Company$2.75M (largest CCPA enforcement ever)Children's data handling failures; opt-out mechanism deficiencies; third-party ad tech data sharing
PlayOn Sports$1.1MUnauthorized sharing of consumer PI with third parties; inadequate consumer rights processes
Ford Motor Company$375KFailure to process consumer data deletion and access requests within required timeframes

These cases signal that the CPPA is actively pursuing large enterprises for systematic violations, not just technical non-compliance. The Ford case in particular underscores that missing the 45-day response deadline for access/deletion requests is, on its own, an actionable enforcement basis — not merely a procedural lapse.

CCPA/CPRA vs. GDPR — Quick Reference

GDPR is generally the more demanding law. A GDPR-compliant program covers most CCPA/CPRA obligations (privacy notices, rights processes, processor agreements, minimization, retention, security), but these CCPA/CPRA-specific items still need to be added: (1) "Do Not Sell or Share My Personal Information" link and opt-out workflow; (2) honor GPC signals; (3) "Limit the Use of My Sensitive Personal Information" link and 15-business-day workflow; (4) confirm vendor classification maps to service provider/contractor vs. third party, with contracts meeting the §1798.100(d) required terms; (5) a compliant notice at collection (§1798.100(a)-(b)) — a distinct artifact from a GDPR Art. 13 notice, delivered at or before collection, listing PI/SPI categories, purposes, retention periods per category, and sale/sharing status with the opt-out link; (6) minors' opt-in for sale/sharing (under 16; parental consent under 13); (7) financial incentive/loyalty disclosures, if applicable; (8) annual reconfirmation of the three business thresholds; (9) cybersecurity audit and risk assessment obligations (effective January 1, 2026) and ADMT opt-out (deadline January 1, 2027). Name notice-at-collection explicitly in every GDPR-to-CCPA gap answer — it is the most commonly missed delta because GDPR programmes assume their existing privacy notice covers it.

Structural differences to state in every GDPR-comparison answer:

  • Consent model: CCPA is opt-out (sale/sharing); GDPR requires an opt-in lawful basis — CCPA has no lawful-basis requirement at all
  • Scope: CCPA protects consumers and households; only businesses meeting the revenue/volume applicability thresholds are covered (GDPR has no thresholds); CCPA's "sale" concept (any disclosure for valuable consideration) is broader than anything in GDPR
  • Rights deltas: the right to correct was only added by CPRA; CCPA has no GDPR-style objection right and no full portability regime (portable format applies to right-to-know responses); GDPR's DPO/DPIA regime maps only loosely to CPRA risk assessments
  • Remedies: CCPA's private right of action is limited to data breaches (statutory damages $100–$750 per consumer per incident, §1798.150) — there is no general private action for privacy violations, unlike GDPR Art. 79/82

Key enforcement contrast: GDPR penalties run up to €10M/2% or €20M/4% of global annual turnover with no formal cure period in most cases, versus CCPA/CPRA's per-violation civil penalties of $2,500 (unintentional) / $7,500 (intentional) with a 30-day AG cure period.

2026 Legislation & Enforcement Update (state where relevant)

September 2026 signings (effective January 1, 2027 unless noted):

  • SB 923 (Expanding Privacy Rights Act) — the right to delete now reaches PI collected "from or about" the consumer, including data acquired from third parties and data brokers (not just first-party collection); businesses may run suppression lists to keep deleted consumers deleted; exclusively-online businesses must offer an online request-submission method. Complements (does not replace) the Delete Act/DROP.
  • Children's package (signed Sept 10): AB 2246 replaces the Age-Appropriate Design Code with a reasonable-steps framework (default ban on profiling minors, dark-pattern bans); AB 1709 bans addictive features (personalized feeds, autoplay, push) for under-16s with penalties to $50,000 per minor; AB 1856 fixes the Digital Age Assurance Act's OS age-signal scope; SB 1119 adds companion-chatbot child-safety duties (core obligations July 1, 2027); SB 867 bans companion-chatbot toys (sunset 2031).
  • Also: AB 883 (data-broker DSR deadline cut 45→30 days + DROP notices), AB 2561 (no silent reversion of privacy settings after updates), AB 1609 (chatbot disclosure for >$500M businesses).
  • Vetoed: AB 1542 — the categorical ban on selling/sharing sensitive PI ("a step too far"; the statutory limit-the-use right remains the mechanism). Note: SB 435 was NOT vetoed — it died in Assembly Appropriations in August.

Enforcement posture (CPPA): data-broker registration blitz — SalesIntel Research fined $36,400 (Sept 1) for failing to register; Enforcement Advisory 2026-01 (Sept 3) targets registration accuracy with $200/day exposure; DROP deletion processing live since August 1, 2026. Earlier 2026: GM $12.75M (connected cars), PlayOn Sports $1.1M, Ford $375K (opt-out friction).

ADMT countdown (include in any automation/profiling answer): compliance for significant decisions begins January 1, 2027 (pre-use notice, opt-out, access); risk assessments for processing ongoing as of Jan 1, 2026 are due December 31, 2027 with first CPPA submissions by April 1, 2028; cybersecurity-audit certifications phase in April 2028/2029/2030 by revenue tier.

Reference Files

  • references/consumer-rights-workflows.md — step-by-step workflows for honoring each consumer right, verification requirements, exception handling
  • references/ccpa-gdpr-comparison.md — side-by-side comparison of CCPA/CPRA vs. GDPR for global compliance teams

How to Help

  1. Business applicability — determine if a business is subject to CCPA/CPRA based on revenue, data volume, and monetization thresholds; classify downstream recipients as service providers, contractors, or third parties
  2. Consumer rights fulfillment — guide the design of request intake, identity verification, response workflows, and exception handling for each right (know, delete, correct, opt-out, limit SPI)
  3. Privacy notices — draft at-collection notices and privacy policies with all required disclosures
  4. Vendor classification — classify data recipients as service providers, contractors, or third parties; review contract requirements
  5. SPI handling — identify SPI categories, advise on limiting use/disclosure, draft SPI limitation notices
  6. Opt-out mechanisms — design "Do Not Sell or Share" links, GPC signal handling, ADMT opt-out, consent management for minors
  7. Ad tech / sale-sharing analysis — evaluate whether specific data flows (pixels, SDKs, cookie syncing, ad exchange bidding) constitute a "sale" or "sharing" under §1798.120 and require opt-out coverage
  8. GDPR alignment — map CCPA/CPRA obligations to existing GDPR controls; identify US-specific gaps
  9. Gap assessment — audit current practices against CCPA/CPRA requirements; prioritise remediation by penalty exposure and upcoming deadlines (ADMT deadline Jan 1, 2027)
  10. Enforcement & penalties — assess penalty exposure in light of 2026 enforcement actions; advise on CPPA investigation response and cure-period strategy

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/ccpa/skills/ccpa of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/ccpa-gdpr-comparison.md
  • references/consumer-rights-workflows.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Ccpa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ccpa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ccpa this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~7.1kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Gdpr Compliance CheckergoSprinto/compliance-skills133—~8.6kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Policystack Audit

    jamiedavenport/policystack

    Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.

    164 GitHub stars~1.4k tokensUpdated 29 days ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Ccpa

What does Ccpa do?

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…. Ccpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI, ADMT opt-out), privacy notice drafting, service provider vs.

When should I use Ccpa?

Ccpa fits situations like: tasks that involve Privacy and GDPR.

How do I install Ccpa in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a claude-code`. Or copy the skill folder (plugins/ccpa/skills/ccpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/ccpa in your project. Claude Code loads it when a task matches its description.

How do I install Ccpa in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a codex`. Or copy the skill folder (plugins/ccpa/skills/ccpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/ccpa in your project. Codex loads it when a task matches its description.

Can I use Ccpa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ccpa, .gemini/skills/ccpa, .github/skills/ccpa and .opencode/skills/ccpa in your project.

What does Ccpa need to run?

SKILL.md names no scripts, command-line tools or credentials: Ccpa is instructions for the agent only.

Does Ccpa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ccpa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ccpa use?

Ccpa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ccpa use?

About 7.1k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Ccpa?

Skills that share tags, products or a category with Ccpa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ccpa?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.