Glossary

DEFINITION

CCPA

The California Consumer Privacy Act and its 2023 successor, the CPRA — the United States' most influential state-level privacy law.

In depth

The California Consumer Privacy Act (CCPA, 2018), as amended by the California Privacy Rights Act (CPRA, 2023), grants California residents rights over their personal information: to know, delete, correct, and limit use of sensitive categories. It applies to most for-profit businesses doing business in California above a size threshold. CCPA defines personal information broadly — anything that identifies, relates to, or could reasonably be linked to a consumer or household — and treats categories like SSNs, geolocation, and biometric data as 'sensitive personal information' with stronger limits. Pasting California residents' personal information into an unsanctioned AI tool is a sale or sharing event under CCPA's broad definitions in many fact patterns.

Examples

  • A consumer-facing company routing customer support transcripts containing California residents' details through ChatGPT.
  • A marketing analyst using AI to enrich a California email list without a CCPA-compliant disclosure.
  • A retailer's analytics team pasting purchase histories into a coding assistant to debug a recommendation model.

How Locke handles ccpa

Locke flags identifiers that fall under CCPA's personal information and sensitive personal information definitions — names, emails, phone numbers, SSNs, account credentials — and can mask or block before any AI tool sees them. Detection is local, so Sonomos itself is not a third party receiving CCPA personal information.

See the product