---------------------------
Title: California Privacy Rights Act (CPRA)
URL: https://www.cookiebot.com/en/cpra/
---------------------------

# California Privacy Rights Act (CPRA)

The California Privacy Rights Act (CPRA) is a 2020 amendment to the CCPA that expanded consumer rights and created the California Privacy Protection Agency (CPPA) as enforcer. It has been in full effect since January 1, 2023, with further CPPA regulations added as recently as January 1, 2026.

## At a Glance

- The CPRA amends and expands the CCPA. It's been fully in effect since January 1, 2023, with rules on automated decision-making, risk assessments, and cybersecurity audits phasing in through 2030.
- Grants four new consumer rights and expands five existing ones, including a stricter sensitive personal information (SPI) category expanded in 2025 to include neural data.
- Applies to businesses meeting any one of three thresholds: over $26,625,000 in annual revenue, buying/selling/sharing 100,000 or more consumers' data per year, or deriving 50 percent or more of revenue from selling or sharing personal information.
- Enforced by the California Privacy Protection Agency (CalPrivacy), with civil penalties up to $7,988 per violation and a narrow private right of action limited to certain data breaches.
- Starting 2027, the California Opt Me Out Act adds a browser-level opt-out signal requirement on top of the Global Privacy Control (GPC) signals businesses must already honor today.
- The California Invasion of Privacy Act (CIPA), a separate 1967 wiretapping law, remains a live source of litigation risk for California-facing websites regardless of CPRA/CCPA compliance.

### CPRA: The What, When, and Obligations for Your Website

The California Privacy Rights Act (CPRA) is a statewide privacy law passed by California voters on November 3, 2020.

It builds directly on the [California Consumer Privacy Act (CCPA)](/en/what-is-ccpa/), the first comprehensive privacy law of its kind among U.S. states. The CCPA took effect on January 1, 2020, and [CCPA compliance](https://www.cookiebot.com/en/what-is-ccpa/) is still watched closely by regulators and businesses across the country.

The CPRA doesn't replace the CCPA. It amends and expands it, strengthening the rights California residents have over their personal information (PI) and tightening the rules businesses must follow when handling it. It also created the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/) to enforce the law statewide.

## Timeline of the CPRA

- **November 3, 2020** — Proposition 24 approved: California voters approve Proposition 24, enacting the CPRA.
- **December 16, 2020** — CPRA takes effect and the CPPA is established: The CPRA becomes effective, and the California Privacy Protection Agency (CPPA) is established.
- **January 1, 2022** — Lookback period begins: Personal information (PI) collected from this date onward becomes subject to the CPRA's one-year lookback period for right-to-know requests.
- **April 21, 2022** — Rulemaking authority transfers to the CPPA: Rulemaking authority formally transfers from the California Attorney General to the CPPA, later than the July 1, 2021 target originally set in the statute.
- **January 1, 2023** — CPRA becomes fully operative: The CPRA's substantive provisions enter full force.
- **March 29, 2023** — Final CPRA regulations take effect: The CPPA's final regulations take effect, missing the statute's original July 1, 2022 adoption deadline.
- **July 1, 2023** — Enforcement begins: The CPPA begins enforcing CPRA obligations.
- **January 1, 2025** — Sensitive personal information expanded: SB 1223 and AB 1008 add neural data to the SPI category and clarify that personal information can exist in physical, digital, and abstract digital form.
- **January 1, 2026** — ADMT, risk assessment, and cybersecurity audit regulations take effect: Finalized CPPA regulations on automated decision-making technology, risk assessments, and cybersecurity audits take effect, alongside the launch of the Delete, Request, and Opt-Out Platform (DROP).
- **August 1, 2026** — DROP compliance deadline: Deadline for data brokers to comply with DROP requirements.
- **JANUARY 1, 2027** — ADMT significant-decision requirements begin: Businesses must give consumers pre-use notice before using automated decision-making technology for significant decisions, and provide opt-out and appeal rights.
- **APRIL 1, 2028** — Risk assessments and first cybersecurity audits due: Risk assessments become required before high-risk processing, such as selling or sharing personal information, or handling sensitive personal information. Businesses with more than $100 million in annual revenue must complete their first cybersecurity audit.
- **APRIL 1, 2029** — Cybersecurity audit deadline, mid-tier businesses: First cybersecurity audit due for businesses with $50–100 million in annual revenue.
- **APRIL 1, 2030** — Cybersecurity audit deadline, smaller businesses: First cybersecurity audit due for businesses under $50 million in annual revenue.

### **CCPA vs. CPRA: What's the Difference for Your Website?**

If your website has visitors from California, you've likely come across both the CCPA and the CPRA. Here's the short version: they're not two separate laws. They're one privacy law, in two stages.

The CCPA came first. It took effect on January 1, 2020, and gave California residents new rights over their personal data, including the right to know what's collected and the right to opt out of its sale.

The CPRA didn't replace the CCPA. It amended it. Since January 1, 2023, the CPRA's changes have applied on top of the existing CCPA framework, adding new rights (like the right to correct inaccurate data and the right to limit use of sensitive personal information) and creating a dedicated enforcement body, the California Privacy Protection Agency.

So when people ask "is my site CCPA compliant or CPRA compliant?" the honest answer is: it's the same question. The CPRA just raised the bar on what compliance with California's privacy law now requires.

For your business, that means one thing to get right, not two. If your privacy notices, opt-out mechanisms, and data handling practices meet current CPRA requirements, you're meeting the CCPA's as well.

## Quick Breakdown of the CPRA

- **Enforcement Authority** — The California Privacy Protection Agency (CPPA) serves as lead enforcer and supervisor of the CCPA/CPRA data privacy regime, now backed by regulations on automated decision-making, risk assessments, and cybersecurity audits phasing in from 2026 through 2030.
- **Business Scope** — The definition of "business" under the CCPA is revised to exempt smaller businesses while capturing larger ones that derive significant revenue from the collection, sharing, and/or selling of Californians' personal information (PI).
- **Consumer Rights** — California residents gain four new rights and see five existing rights modified.
- **Sensitive Personal Information** — A new category, sensitive personal information (SPI), is regulated more strictly than personal information (PI) and was expanded in 2025 to include neural data.
- **Behavioral Advertising** — The opt-out right is narrowed to specifically govern cross-context behavioral advertising and its use of personal information.
- **Third-Party Accountability** — Businesses are held responsible for how third parties use, share, or sell personal information that the business originally collected.
- **GDPR-Style Provisions** — Data minimization, purpose limitation, and storage limitation are introduced to the CCPA, drawing directly on GDPR concepts.
- **Consent Requirements** — Consent obligations are expanded to cover additional scenarios beyond the CCPA's original scope.

## **Consumer Rights Under the CPRA**

The CPRA amends the CCPA to grant Californians four new rights and expand five existing ones. Consumers can exercise these rights by submitting a verified request to a business:

- **Right to correct (new):** Request that inaccurate personal information or sensitive personal information be corrected
- **Right to opt out of automated decision-making (new):** Object to personal information or sensitive personal information being used to make automated inferences, including profiling for targeted advertising
- **Right to know about automated decision-making (new):** Request access to information about how automated decision-making technology works and its likely outcomes
- **Right to limit use of sensitive personal information (new):** Restrict how a business uses sensitive personal information, particularly around third-party sharing
- **Right to delete (expanded):** Request deletion of personal information; businesses must now notify third parties to delete it as well
- **Right to know (expanded):** Request access to personal information collected beyond the CCPA's original 12-month window
- **Right to opt out (expanded):** Opt out of the sale and sharing of personal information for behavioral advertising, not only its sale
- **Right to opt out for minors (expanded):** Businesses need opt-in consent to share, not just sell, a minor's personal information for behavioral advertising
- **Right to data portability (expanded):** Request that personal information be transferred to another business or organization

Businesses must provide a "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link, and a separate "[Limit the Use of My Sensitive Personal Information](https://usercentrics.com/guides/website-disclaimers/limit-the-use-of-my-sensitive-personal-information/)" link, so consumers can exercise these rights directly from a business's website.

There is no general private right of action under the CPRA for most violations. Enforcement is reserved to the California Privacy Protection Agency (CalPrivacy), with a narrow private right of action limited to certain data breaches involving unencrypted personal information.

## **Who the CPRA Applies To**

A business is covered if it meets any one of three thresholds:

- Annual gross revenue over USD 25 million (adjusted to $26,625,000 for inflation as of 2025)
- Buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year, or
- Deriving 50 percent or more of annual revenue from selling or sharing personal information

The CPPA (CalPrivacy) adjusts the revenue threshold for inflation every two years.

Selling or sharing a minor's personal information also has its own consent rule, separate from the business thresholds above: businesses need opt-in consent from the minor for ages 13 to 15, and from a parent or guardian for anyone under 13.

### **Sensitive Personal Information (SPI)**

SPI is a stricter category covering things like health data, precise geolocation, biometric and genetic data, race, religion, and sexual orientation. In 2025, SB 1223 added neural data to that list.

Websites must give consumers a way to limit how their SPI is used, typically through a "Limit the Use of My Sensitive Personal Information" link, alongside the existing "Do Not Sell or Share My Personal Information" link.

### **Opt-Out Rights and Behavioral Advertising**

California consumers can opt out of cross-context behavioral advertising specifically, not just the sale of their data. Non-personalized advertising is treated differently and doesn't require an opt-out.

### **Enforcement and Penalties**

The California Privacy Protection Agency, now publicly known as CalPrivacy, enforces the CCPA and CPRA with authority to investigate, fine, and regulate. Starting January 1, 2026, that authority began phasing in rules on automated decision-making, risk assessments, and mandatory cybersecurity audits, with specific compliance deadlines staggered through 2030 depending on the requirement and business size.

The CalPrivacy and the California Attorney General share enforcement authority for the CCPA/CPRA. CalPrivacy can't limit the Attorney General's authority and must pause its own proceedings if the AG asks.

- **Civil penalties:** Up to USD 2,663 per unintentional violation and USD 7,988 per intentional violation or one involving a minor's data (current since the CPPA's January 1, 2025 CPI adjustment; next review due 2027)
- **Private right of action:** Limited to data breaches involving unencrypted or unredacted personal information, where the breach resulted from a business's failure to maintain reasonable security measures
- **Cure period:** Consumers must give businesses 30 days to fix the issue and confirm no future violations before suing
- **Consumer damages:** USD 107 to USD 799 per incident, or actual damages, whichever is greater (also periodically adjusted to the CPI)
- **Other violations:** Consumers without a breach-related claim can file a complaint with the Attorney General or CalPrivacy directly

### **Browser-Level Opt-Out: The California Opt Me Out Act**

Starting January 2027, browsers used in California must include a built-in setting that sends an opt-out preference signal (OOPS) to websites, and businesses must honor it. The [California Opt Me Out Act](https://cookiebot.com/us/california-opt-me-out-act/) also requires browser makers to clearly explain what the signal does before a consumer turns it on.

Businesses must already honor [Global Privacy Control (GPC)](https://www.cookiebot.com/en/global-privacy-control/) signals today, and the Opt Me Out Act adds a browser-level mandate on top of that in 2027. This adds to what's already required, rather than replacing it.

### **GDPR-Style Requirements**

The CPRA borrows three principles from the GDPR: data minimization, purpose limitation, and storage limitation. In practice, that means collecting only what's needed, using it only for stated purposes, and telling consumers how long you'll keep it. A comprehensive and up-to-date [privacy policy](https://www.cookiebot.com/en/how-to-write-a-privacy-policy/) is important to meet CPRA obligations and provide required information to visitors about data handling and their rights.

## **CIPA and Related Website Litigation**

The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is a separate, older law from the CCPA/CPRA. It's a 1967 wiretapping statute that plaintiffs have increasingly applied to ordinary website tools like pixels, session replay, and chat widgets. It's worth mentioning because the requirements are different and a CCPA/CPRA-compliant privacy setup does not protect against CIPA claims and [demand letters](https://www.cookiebot.com/us/understand-and-respond-to-cipa-demand-letter/).

## CIPA Overview

- **Private right of action** — CIPA lets consumers sue directly, with statutory damages of $5,000 per violation or three times actual damages, whichever is greater.
- **Pen register / trap-and-trace theory (§638.51)** — By legislative estimates, this theory alone drives roughly two-thirds of active California privacy litigation.
- **Wiretapping and eavesdropping (§631, §632)** — These remain fully live regardless of any pending legislative reform.
- **Mixed case outcomes** — Some courts have dismissed pen-register claims against websites on the grounds the statute doesn't reach internet communications; a federal court approved a $3.85 million class settlement on the same theory in June 2026.

SB 690 would eliminate private lawsuits under the pen-register theory specifically, leaving enforcement to the California Attorney General. It passed a key Assembly committee on July 1, 2026, but still needs to clear the full Assembly, return to the Senate, and be signed by the Governor before the August 31, 2026 legislative deadline.

The current amended text would apply retroactively to claims filed within two years of the law's operative date, however, it would not touch §631 or §632 either way.

CIPA sits outside the CPRA's own compliance requirements, but for any business managing consent on a California-facing website, it's a live, separate source of exposure worth addressing now.

## **Compliance Built for California and Everywhere Else**

Cookiebot CMP helps you manage cookie consent and support CCPA compliance today. As California's rules evolve, so does our platform, so your setup keeps pace without a rebuild. Protect your ad revenue as well with [Google Consent Mode](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/), [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/) and [Clarity Consent Mode](https://www.cookiebot.com/en/microsoft-clarity-consent-mode-resources/), and [Amazon Consent Signal](https://www.cookiebot.com/en/cookiebot-cmp-and-amazon-consent-signal/).

### **One CMP, Every Major Framework**

In addition to the U.S. state laws, manage compliance requirements for the GDPR, PIPEDA, LGPD, POPIA, and more from a single setup instead of stitching together separate tools. [Check which regulations apply to your business.](https://www.cookiebot.com/en/regulations-and-frameworks/)

### **The Scanner Does the Legwork**

Cookiebot automatically finds all the active cookies and trackers running on your site, so you always know what's collecting data and why. [Scan your website for free now.](https://www.cookiebot.com/en/cookie-checker/) Get your customized report in minutes.

### **The Right Consent Experience for Every Visitor**

Geotargeting detects visitor location and shows the correct consent experience automatically, whether your visitors are in California, across the country, or anywhere in the world.

Manage CCPA and CPRA compliance without the guesswork
Cookiebot CMP scans your site, detects trackers, and shows the right consent experience to every visitor. Set it up in minutes and support your California privacy compliance from day one.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Preamble

The California Privacy Rights Act (CPRA) took effect on January 1, 2023, and will become fully enforceable on July 1, 2023 – with a lookback period from January 1, 2022.
In this blogpost, we break down the California Privacy Rights Act (CPRA) and what consequences it might have for your website and business.
Cookiebot consent management platform (CMP) already includes full compliance with California’s CCPA and we welcome a stronger, more GDPR-like addendum in the Golden State.

## Summary

The California Privacy Rights Act (CPRA) is a state-wide data privacy bill passed into law in the General Election 2020 – breaking new waves in the Pacific frontier of US data protection.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.4 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)