A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

CCPA / CPRA

Last updated: Nov 26, 2025

Glossary › CCPA / CPRA

What is CCPA / CPRA?

CCPA establishes baseline privacy rights, while CPRA enhances those rights through stricter accountability rules, expanded definitions of sensitive data, and new controls for vendors handling personal information. Organizations must manage data mapping, access rights, and vendor restrictions carefully. In TPRM, CPRA increases scrutiny on service provider contracts and monitoring practices.

FAQs

How does CPRA affect vendor contracts?

It adds specific requirements for data use limitations and audit rights.

What new governance expectations were introduced?

CPRA introduced record-keeping, risk assessments, and accountability measures for sensitive data.

Are CCPA and CPRA separate laws?

CPRA amends and builds on CCPA as part of a unified compliance framework.

robot-human

Responsible-AI TPRM Guide

Discover how risk teams apply AI responsibly to reduce third-party blind spots and stay audit-ready across global regulations.

Easier third-party onboarding. Seamless compliance. Complete risk control.