California — data protection and AI governance
California Consumer Privacy Act + California Privacy Rights Act (CCPA/CPRA), in force since 2020-01-01. Supervisory authority: CPPA.
Data protection
- Instrument
- California Consumer Privacy Act + California Privacy Rights Act (CCPA/CPRA)
- In force since
- 2020-01-01
- Authority
- CPPA
- Penalties
- 7 500$/violation
- Key obligations
- Droit de savoir
- Suppression
- Opt-out vente
- Minimisation
What the engine decides here
These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.
- Transfer regime
- Open
No general transfer regime applies: moving data out is not conditioned by this framework.
- Localisation mandate
- Not modelled
- Automated decision rights
- Not modelled
- Verified on
- 2026-08-14
Three decisions, computed just now
Same actions, this jurisdiction's context. These answers come out of the engine as the page renders — the same function the API calls.
- ALLOW
Read an internal contract
Low-risk operation
- ALLOW
Send a customer record to US_FED
Low-risk operation
- DENY
Decide on a job application
Decision reserved for a human
Advisory decisions. StructureClerk decides; your infrastructure enforces.
AI governance
- Framework
- SB 942 + SB 53
- Status
- enacted
- Date
- 2026-01-01
- Key points
- SB 942 : transparence du contenu généré par IA (AI Transparency Act)
- SB 53 : sécurité des modèles frontière
- Règlements CPPA sur les décisions automatisées (ADMT)
Do your agents operate in California?
The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.