One-line definition
The California Privacy Rights Act (CPRA) is a 2020 ballot initiative that amended and expanded the California Consumer Privacy Act (CCPA), creating California's primary consumer data privacy framework — introducing sensitive personal information protections, a right to correction, data minimization and purpose limitation principles, and a new enforcement agency (the CPPA), with most obligations fully enforceable since July 1, 2023.
Real-life analogy
Think of the CCPA as a house with a solid foundation but only a few rooms finished. The CPRA is the renovation that adds the rooms the original design promised but never built: a locked safe for your most sensitive documents (sensitive personal information), a "fix this" desk where you can correct errors in your file (right to correct), and a permanent building inspector who lives on-site (the California Privacy Protection Agency).
Under the old CCPA, a business could collect your precise geolocation, your health data, or your login credentials and use them almost like any other data point. Under the CPRA, that data now sits behind a higher wall: it needs a documented purpose, it can't be kept longer than necessary, and you can tell a business to limit its use. The renovation also tightened the rules on how long the house can keep your belongings (retention limits) and required the landlord to actually enforce the rules rather than just posting them.
The key shift: CCPA was largely about *transparency and opt-out*. CPRA is about *accountability and control* — not just telling you what happens to your data, but restricting what's allowed to happen in the first place.
Core formula
CPRA compliance = (CCPA baseline + SPI protections + correction right + data minimization) × (service provider & contractor contracts) × (CPPA enforcement + 12-month lookback liability)
Broken into its working parts:
1. CCPA baseline — notice at collection, right to know, delete, opt out of sale/sharing, non-discrimination. CPRA keeps all of this.
2. SPI protections — sensitive personal information (government IDs, precise geolocation, racial/ethnic origin, religious beliefs, health, sexual orientation, biometric data, and more) requires a right to limit use and disclosure.
3. Correction right — consumers can demand inaccurate personal information be fixed, not just deleted.
4. Data minimization & purpose limitation — collection must be reasonably necessary and proportionate to the disclosed purpose.
5. Contractor/service provider obligations — written contracts must bind downstream recipients to the same restrictions.
6. Enforcement multiplier — the CPPA can now write regulations and bring its own enforcement actions, alongside the Attorney General.
Comparison with related terms
| Term | Jurisdiction | Scope | Key feature | Enforcement |
|---|---|---|---|---|
| **CCPA** (2018) | California | For-profit businesses meeting thresholds | Opt-out of sale; notice and delete rights | AG only, 30-day cure period |
| **CPRA** (2020, effective 2023) | California | Same thresholds, expanded obligations | SPI limits, correction, data minimization, retention | CPPA + AG; cure period removed |
| **GDPR** (2018) | EU/EEA | Any entity processing EU resident data | Lawful basis, DPO, 72-hour breach notice | Supervisory authorities; up to 4% global revenue |
| **CPA** (2023) | Colorado | Controllers meeting thresholds | Universal opt-out, data protection assessments | Colorado AG; 60-day cure |
| **VCDPA** (2023) | Virginia | Controllers meeting thresholds | Opt-out of targeted ads and profiling | Virginia AG; 30-day cure |
The practical distinction: CPRA is the strictest U.S. state privacy law and the closest American analogue to GDPR — but it applies only to California residents and only to businesses crossing specific thresholds.
Use cases
1. E-commerce brand with a California customer base. A DTC skincare company collects email addresses, purchase history, and — through a quiz funnel — skin health concerns. Under CPRA, that health data is SPI. The brand must offer a "Limit the Use of My Sensitive Personal Information" link and cannot use that data for advertising without consent.
2. Ad tech and pixel-heavy sites. A Shopify store running Meta Pixel and TikTok Pixel is likely "sharing" personal information for cross-context behavioral advertising. CPRA requires honoring Global Privacy Control (GPC) signals as a valid opt-out — roughly 40%+ of California users on privacy-hardened browsers send them.
3. SaaS with B2B California contacts. Even if your customers are businesses, California employees and contacts have rights. You need a compliant privacy policy, a request intake process, and contracts with subprocessors.
4. Data broker or list rental. Selling personal information triggers opt-out obligations, and selling SPI of minors under 16 requires opt-in consent.
5. Retention and deletion workflows. Because CPRA requires disclosed retention periods and prohibits indefinite storage, brands need actual data maps and deletion schedules — not just a policy page.
Misconceptions
"CPRA replaced the CCPA." It didn't. CPRA amended the CCPA. The law is formally the CCPA as amended by the CPRA, and many practitioners still say "CCPA" to mean the current text.
"Only large companies are covered." The thresholds are lower than people assume: $25 million in annual gross revenue, or buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50%+ of revenue from selling/sharing personal information.
"A privacy policy is enough." CPRA requires operational compliance: request handling, SPI limitation links, GPC honoring, vendor contracts, and retention enforcement. A policy without process is a liability.
"The 30-day cure period still exists." The CPRA removed the mandatory cure period for most violations. The CPPA can act immediately, and statutory damages in the private right of action for data breaches run $100–$750 per consumer per incident.
"It only applies to California companies." It applies to any business meeting the thresholds that processes California residents' data — including non-U.S. companies.
"SPI is the same as GDPR special categories." They overlap heavily but not perfectly. CPRA's SPI list includes account login credentials and precise geolocation, which GDPR treats separately.
Related terms
- CCPA — the underlying statute CPRA amended
- CPPA — California Privacy Protection Agency, the enforcement body created by CPRA
- Sensitive Personal Information (SPI) — the elevated data category
- Global Privacy Control (GPC) — browser signal CPRA requires businesses to honor
- Service provider / contractor — CPRA-defined roles with contractual obligations
- Data minimization — collection limited to what's reasonably necessary
- Purpose limitation — use restricted to disclosed purposes
- Right to correct — new consumer right introduced by CPRA
- Right to limit — SPI-specific restriction right
- GDPR — EU counterpart and frequent comparison point
- CPA / VCDPA / CTDPA — subsequent U.S. state laws modeled partly on CPRA