All Blog Posts

CCPA vs. CPRA: What Is the Difference?

Close
Read time
11 mins
Updated
Aug 14, 2026
Share
  • The CPRA didn't replace the CCPA; it's an amendment layered onto it. Most current guidance refers to the combined framework as "the CCPA/CPRA."
  • The CPRA raised the consumer-volume threshold from 50,000 to 100,000 California consumers or households, added "sharing" alongside "selling," and created the California Privacy Protection Agency (CPPA) as a dedicated enforcement agency alongside the Attorney General.
  • The CPRA introduced entirely new rights, including correction, data portability, and the right to opt out of automated decision-making, as well as a new protected category for sensitive personal information.
  • The CPRA removed the automatic 30-day cure period for most violations and increased the maximum penalty for intentional violations, or any violation involving a consumer under 16, to $7,988.
  • Annual cybersecurity audits, risk assessments, and ADMT consumer rights, introduced by the CPRA, took effect January 1, 2026, though most compliance deadlines land in 2027 and beyond.
  • A consent management platform such as Cookiebot CMP can help meet both laws' cookie-related obligations, including scanning for trackers, gating them behind consent, and surfacing the required opt-out links.

The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) get talked about as if they're two competing laws. They aren't. The CPRA is an amendment to the CCPA — but it changed enough that knowing the difference matters for compliance. Here's what each law actually does, what changed between them, and what's still the same.

What Is the CCPA?

The California Consumer Privacy Act (CCPA) is the first comprehensive consumer privacy law in the U.S. It was passed in 2018 and took effect January 1, 2020, giving California residents, defined by the law as "consumers," rights over the personal information businesses collect about them.

Being physically present in California isn't enough to qualify as a "consumer" under the CCPA. The law's residency definition covers people in the state for other than a temporary or transitory purpose, and people domiciled in California but temporarily elsewhere — someone visiting California on vacation isn't covered, but a Californian on vacation elsewhere still is.

What Is the CPRA?

The California Privacy Rights Act (CPRA) was a ballot measure that passed on November 3, 2020, and took effect January 1, 2023. A legal challenge delayed enforcement past the law's original July 2023 date, but the California Third District Court of Appeal ruled on February 9, 2024 that the CPPA could enforce the CPRA's regulations immediately, retroactive to July 1, 2023.

Does the CPRA Replace the CCPA?

No, they work together. The CPRA amends and builds on the CCPA rather than replacing it outright, by:

  • Introducing new consumer rights
  • Expanding existing consumer rights
  • Imposing additional compliance obligations on businesses
  • Establishing the California Privacy Protection Agency (CPPA), which goes by CalPrivacy publicly, for enforcement

The two are sometimes referred to together, as the CCPA/CPRA, or the shorthand reference to the CCPA now includes both laws.

Compliance Thresholds: CCPA vs. CPRA

The original CCPA (2020) applied to for-profit businesses operating in California that met at least one of these thresholds:

  • Annual gross revenue exceeding $25,000,000
  • Receive, buy, or sell the personal information of 50,000 or more consumers, households, or devices
  • Earn more than 50 percent of annual revenue from selling consumers' personal information

The CPRA changed two of these. The consumer-volume threshold rose from 50,000 to 100,000, and "sharing" personal information — not just selling it — now counts toward that threshold and requires the same compliance obligations. The revenue threshold stayed conceptually the same but is now adjusted for inflation every odd-numbered year. As of the 2025 adjustment, it stands at $26,625,000, with the next adjustment due January 1, 2027.

This applies regardless of where a business is physically located, so a business outside California, or outside the U.S. entirely, is covered if it meets a threshold and processes California residents' data.

Consumer Rights: What the CPRA Added

The CCPA gave consumers the right to know what personal information is collected about them, delete it, opt out of its sale, and not be discriminated against for exercising these rights.

The CPRA both expanded these and added entirely new ones. Expansions include letting consumers request records going back further than the CCPA's original 12-month window (for data collected on or after January 1, 2022), and extending the opt-out right to cover sharing and targeted advertising, not just sale.

Entirely new rights include:

  • Right to correct inaccurate personal information
  • Right to limit the use and disclosure of sensitive personal information
  • Right to data portability
  • Right to access information about automated decision-making or profiling used against them
  • Right to opt out of that automated decision-making

That last two regarded automated decision-making connect to the CPRA's automated decision-making technology (ADMT) regulations, finalized in 2025 and taking effect January 1, 2027.

Risk Assessments, Cybersecurity Audits, and ADMT

The CPRA created the legal basis for these three obligations, but they sat unimplemented for years. The CPPA didn't finalize the actual regulations until July 24, 2025, with the Office of Administrative Law approving them on September 22, 2025. They took effect January 1, 2026, with compliance deadlines staggered out through 2030.

Risk Assessments

These are required before a business engages in processing that presents a significant risk to consumers, like selling or sharing personal information, processing sensitive personal information, or using ADMT for a significant decision, among other triggers.

Compliance began January 1, 2026 for new processing; any covered processing that was already underway before that date has until December 31, 2027 to be assessed. Businesses then submit an attestation and summary to the CPPA. The first one is due April 1, 2028, covering assessments from 2026 and 2027, with annual submissions after that.

Cybersecurity Audits

These apply to a narrower set of businesses:

  • Those deriving 50 percent or more of revenue from selling or sharing personal information
  • Those meeting the CCPA's revenue threshold while processing the personal information of 250,000 or more consumers, or the sensitive personal information of 50,000 or more

Audit certifications are due to the CPPA on a schedule based on 2026 revenue:

  • April 1, 2028 for businesses with more than USD 100 million
  • April 1, 2029 for USD 50–100 million
  • April 1, 2030 for businesses under USD 50 million

Automated Decision-Making Technology (ADMT)

These rights take effect January 1, 2027. Businesses using ADMT to make "significant decisions" about consumers — in areas like employment, lending, or housing — must provide pre-use notice, let consumers access an explanation of how the decision was made, and generally offer an opt-out, with a human-review option built in. ADMT already in use before that date needs to be brought into compliance by January 1, 2027; anything deployed after that date needs to comply before it's used at all.

Do you know what your website is collecting?

Try our free scanner to detect all cookies and trackers in use on your website. Get your report and compliance risk level in minutes to address consent gaps.

Personal Information vs. Sensitive Personal Information

Both laws define personal information broadly: anything that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." That covers names and emails, but also cookies, IP addresses, and browsing history.

The CPRA introduced a narrower, more protected category on top of this: sensitive personal information, which includes:

  • Social Security and government ID numbers
  • Precise geolocation
  • Racial or ethnic origin
  • Religious beliefs
  • Union membership
  • Genetic data
  • Contents of private mail or messages

Businesses must disclose when they collect it, and consumers have the right to limit its use to what's necessary to provide the requested service. This is enforced through a "Limit the Use of My Sensitive Personal Information" link, which can be combined with the "Do Not Sell or Share My Personal Information" sale/share opt-out link where applicable.

Data Sharing, Contractors, and Consent

The CPRA formally regulates "sharing" personal information for cross-context behavioral advertising, whether or not money changes hands, closing a gap where businesses argued that giving data away for free (rather than selling it) fell outside the CCPA's scope.

It also introduced the term contractor, which is defined as a third party that receives personal information under a written contract for a specified business purpose, distinct from a "service provider." A contractor can't sell, share, or use that data for anything outside the contracted purpose, and businesses need data processing agreements in place with them.

The CPRA's consent standard is stricter than the CCPA's, and closer to the GDPR's. Consent must be a freely given, specific, informed, unambiguous indication of the consumer's wishes. Accepting a broad terms-of-use document, hovering over or dismissing a banner, or agreeing through a dark pattern doesn't count. This higher bar applies specifically when selling or sharing a minor's personal information, when reversing a consumer's prior opt-out, or when using sensitive personal information beyond its original purpose.

For businesses running cookies specifically, this consent standard connects directly to Global Privacy Control (GPC), which is a browser-level opt-out signal set by individuals in browser settings or via a plugin. The CPRA requires businesses' websites to honor it automatically, without waiting for a visitor to find a link.

Enforcement, Cure Periods, and Penalties

Under the original CCPA, enforcement was the Attorney General's job alone, and businesses got a 30-day window to fix a flagged violation before facing penalties. The CPRA changed both by adding the CPPA as a second enforcement body. However, the CPPA can't override the Attorney General and must stand down if the AG is already investigating the same matter, and a business can't be fined twice for the same violation. The CPRA also eliminated the automatic 30-day cure period for most violations, leaving it up to regulators' discretion.

Penalty amounts didn't change between the two laws. Both cap violations at the same statutory tiers, now adjusted for inflation to USD 2,663 per unintentional violation and USD 7,988 per intentional violation or any violation involving a consumer the business knew was under 16. What changed procedurally is that the CPPA can now impose these administratively, alongside the AG's civil enforcement track.

Private Right of Action

The CCPA gave consumers a narrow private right to sue: only in the case of a data breach involving unencrypted or unredacted personal information, caused by a business's failure to maintain reasonable security. The CPRA extended this to cover breaches of an email address combined with a password or security question that could grant account access. California remains the only state with this kind of private right of action in a comprehensive privacy law.

This is a different and narrower private right than the one increasingly used in litigation under the California Invasion of Privacy Act (CIPA), which has no revenue or volume threshold and doesn't require a data breach at all.

Differences Between the CCPA and CPRA

ElementCCPACPRA
Threshold- Annual gross revenues of USD 25 million or more
- Process personal information from 50,000 or more consumers, households, or devices
- Earn more than 50 percent annual revenue from sale of personal information
- Annual gross revenues of USD 26,625,000 or more (2025 adjustment to the CPI, next adjustment in 2027)
- Process personal information from 100,000 or more consumers, households (devices removed)
- Earn more than 50 percent annual revenue from sale or sharing of personal information (sharing added)
Personal Information- Protects personal information of California residents
- No specific category for sensitive personal information
Sensitive Personal Information category with stricter requirements introduced
New Rights- Right to know
- Right to access
- Right to delete
- Right to opt out (of sale)
- Right to non-discrimination
- Right to be informed (at or before collection)
- Right to know (expanded)
- Right to access (expanded)
- Right to delete (expanded)
- Right to opt out of sale or sharing (expanded)
- Right to non-discrimination (expanded)
- Right to correct inaccurate personal information
- Right to limit use and disclosure of sensitive personal information
- Right to opt out of automated decision-making technology (per the CPPA's ADMT rulemaking)
- Right to data portability
Right to DeleteConsumers can request deletion of personal information collected directly from them; businesses must also notify their service providers to delete it.Businesses must also notify any third parties they've sold or shared the information with and instruct them to delete it.
Right to Opt OutConsumers can opt out only of the sale of their personal information.Consumers can opt out of both the sale and sharing of personal information, including for cross-context behavioral advertising.
Rights of MinorsRequires opt-in consent to sell personal information for consumers under 16 (parent or guardian consent required under 13).Extends opt-in consent to cover sharing as well as selling; if a minor under 16 declines, businesses must wait 12 months before requesting consent again.
ConsentLimited opt-in consent requirements, mainly concerning minors' data.Expands opt-in consent requirements and defines consent explicitly, including for sensitive personal information and minors under 16.
Data MinimizationNo requirementBusinesses may only collect personal information that is reasonably necessary and proportionate to the disclosed purpose.
Notice at CollectionRequires basic disclosures at the point of collection.Adds disclosure requirements covering data sharing, sensitive personal information, and data retention periods.
Risk AssessmentsNo requirementBusinesses conducting higher-risk processing must perform regular risk assessments and submit them to the CPPA.
EnforcementThe Attorney General has sole enforcement authority.Establishes the California Privacy Protection Agency (CPPA), which shares enforcement authority with the Attorney General.
Cure PeriodBusinesses had 30 days to cure alleged violations before Attorney General enforcement.- Removes the automatic 30-day cure period for regulatory enforcement. The CPPA may grant one at its discretion.
- The separate 30-day notice-and-cure provision for private data breach actions is unchanged.
Private Right of ActionAllows private action for breaches involving nonencrypted or nonredacted personal information.Extends this right to breaches involving an email address combined with a password or security question and answer.

Complying With the CCPA/CPRA

Practical CCPA/CPRA Compliance Actions

Compliance

Feature "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" links, combined if applicable

Provide a notice at or before the point of collection disclosing what's collected, why, and whether it's sold or shared

Publish and maintain a privacy policy that covers all required disclosures, including cookie use

Offer at least two ways for consumers to exercise their rights

Honor Global Privacy Control and other valid opt-out signals automatically

Respond to opt-out requests within 15 days and to verifiable access/deletion requests within 45 days

Obtain opt-in consent before selling or sharing the personal information of consumers under 16

Apply non-discrimination consistently for consumers who exercise any of these rights

How Cookiebot CMP Supports CCPA/CPRA Compliance

Cookiebot™ CMP doesn't require picking which version of California law to build for. Just set it up and configure it once. It scans your site to find every cookie and tracker in use, holds anything non-essential until a visitor has made a consent choice, and reads and acknowledges Global Privacy Control signals automatically rather than waiting for a click. For visitors it identifies as being in California, it also surfaces the "Do Not Sell or Share My Personal Information" link without extra setup on your part. Automated updates help you maintain compliance as your cookies and trackers, marketing operations, and regulatory obligations evolve.

Frequently asked questions

The CCPA is the original 2020 law; the CPRA is the 2023 amendment that expanded it. The CPRA added new consumer rights, including the right to correct inaccurate data and opt out of automated decision-making, tightened data-minimization rules, and created the California Privacy Protection Agency (CPPA) to enforce the law alongside the Attorney General. In practice, "CCPA" and "CPRA" now describe a single combined law, referred to here as the CCPA/CPRA.

No, the CPRA does not replace the CCPA, though the CPRA does replace some conditions of the CCPA. The CRPA strengthens and expands the CCPA, introducing new rights for consumers and additional obligations for businesses. It also establishes the CPPA for enforcement. The two laws are often referred to collectively as “the CCPA, as amended by the CPRA.”

Businesses that meet at least one of three thresholds: annual gross revenue over USD 25 million (currently $26,625,000 adjusted for the CPI), buying/selling/sharing the personal information of 100,000 or more California consumers or households annually, or deriving 50 percent or more of revenue from selling or sharing personal information.

The right to correct inaccurate personal information, the right to limit the use of sensitive personal information, the right to data portability, and rights around automated decision-making and profiling.

No. The CPPA operates alongside the Attorney General, not in place of it. It can't limit the AG's authority, must halt an action if the AG requests it, and a business can't be penalized twice by both for the same violation.