Sécurité et conformité
Lynx Compliance - US State Privacy (CCPA / CPRA)
The California Consumer Privacy Act as amended by the CPRA, with the CPPA regulations - consumer rights, the two required links, service-provider contract terms and the risk assessment and cybersecurity audit duties.
lynx_compliance_us_privacy
· v19.0.1.0.0
· Complément
Bêta
Ce que cela résout
Lynx Compliance - US State Privacy (CCPA / CPRA)
The California statute is not shaped like the European regimes, and assuming it is produces a programme that looks compliant and is not. There is no lawful basis to establish. Instead there is a set of consumer rights, and a distinction between disclosing personal information and selling or sharing it that turns entirely on what the contract with the recipient says.
A GDPR programme covers a good deal of this pack. It does not cover the parts that produce enforcement actions: the two required links, the Global Privacy Control, the service-provider contract terms, and the CPPA regulations on risk assessment, cybersecurity audit and automated decision-making.
Cross-references are populated against real GDPR and Law 25 control codes rather than article numbers, so they resolve through the crosswalk and an existing privacy assessment actually propagates. Where no equivalent obligation exists in either regime the reference is left empty rather than stretched to the nearest article, because a wrong mapping is worse than no mapping.
Key Features
46 controls across five functions - coded by statutory section, so a reader can find the source text without a mapping table.
Organised by obligation type, not section order - so Virginia, Colorado and Connecticut drop in under the same functions and the same add-on without restructuring. California is what ships today.
The CPPA regulations included as controls - risk assessment, annual cybersecurity audit and automated decision-making rights, which are separate duties from "reasonable security" and are where the next wave of enforcement sits.
Contract terms treated as a technical control - because under this statute the terms are what decide whether a disclosure is a sale, and the classification is about actual use rather than about the vendor.
Global Privacy Control called out specifically - it is the single easiest thing for a regulator to test from outside, and the most common failure.
Downstream propagation assessed separately from the right itself - deletion and opt-out that work in the primary application and not in the marketing platform are the recurring finding, so they are separate controls.
Integrates With
lynx_compliance_gdpr and lynx_compliance_law25 - cross-referenced per control against real control codes, so one privacy programme answers all three.
lynx_compliance_privacy - the DSAR register is the primary evidence for the consumer rights function.
lynx_compliance_subprocessor_map - recipient classification and downstream propagation.
Essayer Lynx Compliance - US State Privacy (CCPA / CPRA) de votre équipe.
Essai gratuit, sans carte de crédit. Parlez à l'équipe des ventes quand vous êtes prêt.