California · verified through August 25, 2026

California: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

CA · 5 requirements mapped / control outcomes supported

Law status

Verified comprehensive law

Yes - California Consumer Privacy Act of 2018 as amended (CCPA/CPRA)

Official name / citation
Cal. Civ. Code §§ 1798.100-1798.199.100
Status / effective date
In force; fetched statute copy marked effective 01/01/2025
Principal enforcer
Attorney General and California Privacy Protection Agency (CalPrivacy)

Direct attached-library attribution

14 cases · $33,438,078

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

n.a. (comprehensive law exists)

Public enforcement context

Tier 1

General Motors / OnStar

$12,750,000 · May 8, 2026

The AG's enforcement list states GM allegedly sold California drivers' driving and precise-location data collected through OnStar to data brokers while misleading consumers about the sales.

Legal basis: California Consumer Privacy Act; Unfair Competition Law

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 3 downstream copy tracking; 6 opt-out propagation validation; 7 marketing/vendor provenance; 10 regulator audit evidence

Kestryl can evidence discovery and inventory of the personal-data elements implicated in sale/sharing and opt-out claims across structured data and unstructured attachments/images, and can generate audit rows/evidence packs showing which stores and copies were identified; structured-data remediation is limited to mask/vault/strip. It cannot alter source attachments/documents and cannot by itself demonstrate that opt-out or deletion obligations were legally satisfied.