All Blog Posts

California Privacy Rights Act (CPRA)

Close
Read time
10 mins
Updated
Apr 3, 2026
Share
  • The CPRA amends and expands the CCPA. It's been fully in effect since January 1, 2023, with rules on automated decision-making, risk assessments, and cybersecurity audits phasing in through 2030.
  • Grants four new consumer rights and expands five existing ones, including a stricter sensitive personal information (SPI) category expanded in 2025 to include neural data.
  • Applies to businesses meeting any one of three thresholds: over $26,625,000 in annual revenue, buying/selling/sharing 100,000 or more consumers' data per year, or deriving 50 percent or more of revenue from selling or sharing personal information.
  • Enforced by the California Privacy Protection Agency (CalPrivacy), with civil penalties up to $7,988 per violation and a narrow private right of action limited to certain data breaches.
  • Starting 2027, the California Opt Me Out Act adds a browser-level opt-out signal requirement on top of the Global Privacy Control (GPC) signals businesses must already honor today.
  • The California Invasion of Privacy Act (CIPA), a separate 1967 wiretapping law, remains a live source of litigation risk for California-facing websites regardless of CPRA/CCPA compliance.

CPRA: The What, When, and Obligations for Your Website

The California Privacy Rights Act (CPRA) is a statewide privacy law passed by California voters on November 3, 2020.

It builds directly on the California Consumer Privacy Act (CCPA), the first comprehensive privacy law of its kind among U.S. states. The CCPA took effect on January 1, 2020, and CCPA compliance is still watched closely by regulators and businesses across the country.

The CPRA doesn't replace the CCPA. It amends and expands it, strengthening the rights California residents have over their personal information (PI) and tightening the rules businesses must follow when handling it. It also created the California Privacy Protection Agency (CPPA) to enforce the law statewide.

Timeline of the CPRA

Timeline of the CPRA
November 3, 2020

Proposition 24 approved: California voters approve Proposition 24, enacting the CPRA.

December 16, 2020

CPRA takes effect and the CPPA is established: The CPRA becomes effective, and the California Privacy Protection Agency (CPPA) is established.

January 1, 2022

Lookback period begins: Personal information (PI) collected from this date onward becomes subject to the CPRA's one-year lookback period for right-to-know requests.

April 21, 2022

Rulemaking authority transfers to the CPPA: Rulemaking authority formally transfers from the California Attorney General to the CPPA, later than the July 1, 2021 target originally set in the statute.

January 1, 2023

CPRA becomes fully operative: The CPRA's substantive provisions enter full force.

March 29, 2023

Final CPRA regulations take effect: The CPPA's final regulations take effect, missing the statute's original July 1, 2022 adoption deadline.

July 1, 2023

Enforcement begins: The CPPA begins enforcing CPRA obligations.

January 1, 2025

Sensitive personal information expanded: SB 1223 and AB 1008 add neural data to the SPI category and clarify that personal information can exist in physical, digital, and abstract digital form.

January 1, 2026

ADMT, risk assessment, and cybersecurity audit regulations take effect: Finalized CPPA regulations on automated decision-making technology, risk assessments, and cybersecurity audits take effect, alongside the launch of the Delete, Request, and Opt-Out Platform (DROP).

August 1, 2026

DROP compliance deadline: Deadline for data brokers to comply with DROP requirements.

JANUARY 1, 2027

ADMT significant-decision requirements begin: Businesses must give consumers pre-use notice before using automated decision-making technology for significant decisions, and provide opt-out and appeal rights.

APRIL 1, 2028

Risk assessments and first cybersecurity audits due: Risk assessments become required before high-risk processing, such as selling or sharing personal information, or handling sensitive personal information. Businesses with more than $100 million in annual revenue must complete their first cybersecurity audit.

APRIL 1, 2029

Cybersecurity audit deadline, mid-tier businesses: First cybersecurity audit due for businesses with $50–100 million in annual revenue.

APRIL 1, 2030

Cybersecurity audit deadline, smaller businesses: First cybersecurity audit due for businesses under $50 million in annual revenue.

CCPA vs. CPRA: What's the Difference for Your Website?

If your website has visitors from California, you've likely come across both the CCPA and the CPRA. Here's the short version: they're not two separate laws. They're one privacy law, in two stages.

The CCPA came first. It took effect on January 1, 2020, and gave California residents new rights over their personal data, including the right to know what's collected and the right to opt out of its sale.

The CPRA didn't replace the CCPA. It amended it. Since January 1, 2023, the CPRA's changes have applied on top of the existing CCPA framework, adding new rights (like the right to correct inaccurate data and the right to limit use of sensitive personal information) and creating a dedicated enforcement body, the California Privacy Protection Agency.

So when people ask "is my site CCPA compliant or CPRA compliant?" the honest answer is: it's the same question. The CPRA just raised the bar on what compliance with California's privacy law now requires.

For your business, that means one thing to get right, not two. If your privacy notices, opt-out mechanisms, and data handling practices meet current CPRA requirements, you're meeting the CCPA's as well.

Quick Breakdown of the CPRA

Quick Breakdown of the CPRA
Enforcement Authority

The California Privacy Protection Agency (CPPA) serves as lead enforcer and supervisor of the CCPA/CPRA data privacy regime, now backed by regulations on automated decision-making, risk assessments, and cybersecurity audits phasing in from 2026 through 2030.

Business Scope

The definition of "business" under the CCPA is revised to exempt smaller businesses while capturing larger ones that derive significant revenue from the collection, sharing, and/or selling of Californians' personal information (PI).

Consumer Rights

California residents gain four new rights and see five existing rights modified.

Sensitive Personal Information

A new category, sensitive personal information (SPI), is regulated more strictly than personal information (PI) and was expanded in 2025 to include neural data.

Behavioral Advertising

The opt-out right is narrowed to specifically govern cross-context behavioral advertising and its use of personal information.

Third-Party Accountability

Businesses are held responsible for how third parties use, share, or sell personal information that the business originally collected.

GDPR-Style Provisions

Data minimization, purpose limitation, and storage limitation are introduced to the CCPA, drawing directly on GDPR concepts.

Consent Requirements

Consent obligations are expanded to cover additional scenarios beyond the CCPA's original scope.

Consumer Rights Under the CPRA

The CPRA amends the CCPA to grant Californians four new rights and expand five existing ones. Consumers can exercise these rights by submitting a verified request to a business:

  • Right to correct (new): Request that inaccurate personal information or sensitive personal information be corrected
  • Right to opt out of automated decision-making (new): Object to personal information or sensitive personal information being used to make automated inferences, including profiling for targeted advertising
  • Right to know about automated decision-making (new): Request access to information about how automated decision-making technology works and its likely outcomes
  • Right to limit use of sensitive personal information (new): Restrict how a business uses sensitive personal information, particularly around third-party sharing
  • Right to delete (expanded): Request deletion of personal information; businesses must now notify third parties to delete it as well
  • Right to know (expanded): Request access to personal information collected beyond the CCPA's original 12-month window
  • Right to opt out (expanded): Opt out of the sale and sharing of personal information for behavioral advertising, not only its sale
  • Right to opt out for minors (expanded): Businesses need opt-in consent to share, not just sell, a minor's personal information for behavioral advertising
  • Right to data portability (expanded): Request that personal information be transferred to another business or organization

Businesses must provide a "Do Not Sell or Share My Personal Information" link, and a separate "Limit the Use of My Sensitive Personal Information" link, so consumers can exercise these rights directly from a business's website.

There is no general private right of action under the CPRA for most violations. Enforcement is reserved to the California Privacy Protection Agency (CalPrivacy), with a narrow private right of action limited to certain data breaches involving unencrypted personal information.

Who the CPRA Applies To

A business is covered if it meets any one of three thresholds:

  • Annual gross revenue over USD 25 million (adjusted to $26,625,000 for inflation as of 2025)
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year, or
  • Deriving 50 percent or more of annual revenue from selling or sharing personal information

The CPPA (CalPrivacy) adjusts the revenue threshold for inflation every two years.

Selling or sharing a minor's personal information also has its own consent rule, separate from the business thresholds above: businesses need opt-in consent from the minor for ages 13 to 15, and from a parent or guardian for anyone under 13.

Sensitive Personal Information (SPI)

SPI is a stricter category covering things like health data, precise geolocation, biometric and genetic data, race, religion, and sexual orientation. In 2025, SB 1223 added neural data to that list.

Websites must give consumers a way to limit how their SPI is used, typically through a "Limit the Use of My Sensitive Personal Information" link, alongside the existing "Do Not Sell or Share My Personal Information" link.

Opt-Out Rights and Behavioral Advertising

California consumers can opt out of cross-context behavioral advertising specifically, not just the sale of their data. Non-personalized advertising is treated differently and doesn't require an opt-out.

Enforcement and Penalties

The California Privacy Protection Agency, now publicly known as CalPrivacy, enforces the CCPA and CPRA with authority to investigate, fine, and regulate. Starting January 1, 2026, that authority began phasing in rules on automated decision-making, risk assessments, and mandatory cybersecurity audits, with specific compliance deadlines staggered through 2030 depending on the requirement and business size.

The CalPrivacy and the California Attorney General share enforcement authority for the CCPA/CPRA. CalPrivacy can't limit the Attorney General's authority and must pause its own proceedings if the AG asks.

  • Civil penalties: Up to USD 2,663 per unintentional violation and USD 7,988 per intentional violation or one involving a minor's data (current since the CPPA's January 1, 2025 CPI adjustment; next review due 2027)
  • Private right of action: Limited to data breaches involving unencrypted or unredacted personal information, where the breach resulted from a business's failure to maintain reasonable security measures
  • Cure period: Consumers must give businesses 30 days to fix the issue and confirm no future violations before suing
  • Consumer damages: USD 107 to USD 799 per incident, or actual damages, whichever is greater (also periodically adjusted to the CPI)
  • Other violations: Consumers without a breach-related claim can file a complaint with the Attorney General or CalPrivacy directly

Browser-Level Opt-Out: The California Opt Me Out Act

Starting January 2027, browsers used in California must include a built-in setting that sends an opt-out preference signal (OOPS) to websites, and businesses must honor it. The California Opt Me Out Act also requires browser makers to clearly explain what the signal does before a consumer turns it on.

Businesses must already honor Global Privacy Control (GPC) signals today, and the Opt Me Out Act adds a browser-level mandate on top of that in 2027. This adds to what's already required, rather than replacing it.

GDPR-Style Requirements

The CPRA borrows three principles from the GDPR: data minimization, purpose limitation, and storage limitation. In practice, that means collecting only what's needed, using it only for stated purposes, and telling consumers how long you'll keep it. A comprehensive and up-to-date privacy policy is important to meet CPRA obligations and provide required information to visitors about data handling and their rights.

The California Invasion of Privacy Act (CIPA) is a separate, older law from the CCPA/CPRA. It's a 1967 wiretapping statute that plaintiffs have increasingly applied to ordinary website tools like pixels, session replay, and chat widgets. It's worth mentioning because the requirements are different and a CCPA/CPRA-compliant privacy setup does not protect against CIPA claims and demand letters.

CIPA Overview

Private right of action

CIPA lets consumers sue directly, with statutory damages of $5,000 per violation or three times actual damages, whichever is greater.

Pen register / trap-and-trace theory (§638.51)

By legislative estimates, this theory alone drives roughly two-thirds of active California privacy litigation.

Wiretapping and eavesdropping (§631, §632)

These remain fully live regardless of any pending legislative reform.

Mixed case outcomes

Some courts have dismissed pen-register claims against websites on the grounds the statute doesn't reach internet communications; a federal court approved a $3.85 million class settlement on the same theory in June 2026.

SB 690 would eliminate private lawsuits under the pen-register theory specifically, leaving enforcement to the California Attorney General. It passed a key Assembly committee on July 1, 2026, but still needs to clear the full Assembly, return to the Senate, and be signed by the Governor before the August 31, 2026 legislative deadline.

The current amended text would apply retroactively to claims filed within two years of the law's operative date, however, it would not touch §631 or §632 either way.

CIPA sits outside the CPRA's own compliance requirements, but for any business managing consent on a California-facing website, it's a live, separate source of exposure worth addressing now.

Compliance Built for California and Everywhere Else

Cookiebot CMP helps you manage cookie consent and support CCPA compliance today. As California's rules evolve, so does our platform, so your setup keeps pace without a rebuild. Protect your ad revenue as well with Google Consent Mode, Microsoft UET Consent Mode and Clarity Consent Mode, and Amazon Consent Signal.

One CMP, Every Major Framework


In addition to the U.S. state laws, manage compliance requirements for the GDPR, PIPEDA, LGPD, POPIA, and more from a single setup instead of stitching together separate tools. Check which regulations apply to your business.

The Scanner Does the Legwork


Cookiebot automatically finds all the active cookies and trackers running on your site, so you always know what's collecting data and why. Scan your website for free now. Get your customized report in minutes.


Geotargeting detects visitor location and shows the correct consent experience automatically, whether your visitors are in California, across the country, or anywhere in the world.

Manage CCPA and CPRA compliance without the guesswork

Cookiebot CMP scans your site, detects trackers, and shows the right consent experience to every visitor. Set it up in minutes and support your California privacy compliance from day one.

Frequently asked questions

The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor.

The California Consumer Privacy Act (CCPA) laid the foundation for data privacy law in the state of California, when it entered into effect on January 1, 2020. The California Privacy Rights Act (CPRA) isn’t a new law in itself, so much as it is a rewrite of the CCPA. Together, the CCPA/CPRA form one data privacy regime in California.

Learn more about CCPA and cookies

The California Privacy Rights Act (CPRA) took effect on January 1, 2023 with a lookback period to January 1, 2022. The California Privacy Protection Agency (CPPA) will begin enforcing the CPRA from July 1, 2023.

If you’re already in compliance with the CCPA, you need to change certain practices and add new data privacy features to your business’ website. Using Cookiebot CMP already offers your website full control of data collection, respecting user opt-out for CCPA compliance.