Control frameworkCompliance & Audit

CCPA / CPRA policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Help a business map California privacy controls for personal data. The template covers notices, access, deletion, correction, sensitive data, sale or sharing opt-outs and automated decision-making requirements. Build applicable consumer-request operations separately.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

US

Source references

3 source references

Control areas

6 mapped control areas

Deployment options

Regulated SaaS

Source frameworks, standards and obligations

California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.)CPRA (effective Jan 2023)California Consumer Privacy Act Regulations (11 CCR, Division 6, Chapter 1; effective Jan. 1, 2026)

Control areas mapped by this template

Data privacy
Consumer rights
Opt-out
Data sale restrictions
Automated decision opt-out
Transparency

Deployment options

Regulated SaaS

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.