DEFINITION
CCPA
The California Consumer Privacy Act and its 2023 successor, the CPRA — the United States' most influential state-level privacy law.
In depth
The California Consumer Privacy Act (CCPA, 2018), as amended by the California Privacy Rights Act (CPRA, 2023), grants California residents rights over their personal information: to know, delete, correct, and limit use of sensitive categories. It applies to most for-profit businesses doing business in California above a size threshold. CCPA defines personal information broadly — anything that identifies, relates to, or could reasonably be linked to a consumer or household — and treats categories like SSNs, geolocation, and biometric data as 'sensitive personal information' with stronger limits. Pasting California residents' personal information into an unsanctioned AI tool is a sale or sharing event under CCPA's broad definitions in many fact patterns.
Examples
- A consumer-facing company routing customer support transcripts containing California residents' details through ChatGPT.
- A marketing analyst using AI to enrich a California email list without a CCPA-compliant disclosure.
- A retailer's analytics team pasting purchase histories into a coding assistant to debug a recommendation model.
How Locke handles ccpa
Locke flags identifiers that fall under CCPA's personal information and sensitive personal information definitions — names, emails, phone numbers, SSNs, account credentials — and can mask or block before any AI tool sees them. Detection is local, so Sonomos itself is not a third party receiving CCPA personal information.
See the productRelated terms
- GDPR
The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).
- Data Loss Prevention (DLP)
A category of security tooling that inspects outbound data flows to prevent sensitive content from leaving an organisation's control.