Author: Rimsha Zafar
September 2, 2026

California Privacy Rights Act (CPRA): Everything You Need to Know in 2026

Does your business collect personal data from California residents? If the answer is yes, the California Privacy Rights Act (CPRA) directly affects how you handle, store, and share that data. Ignoring this regulation is not an option when fines can reach up to $7,500 per violation.

 

The California Privacy Rights Act (CPRA) is an expansion of the original CCPA that went into effect on 1 January 2023. It introduced stronger consumer rights, tighter business obligations, and a dedicated enforcement agency. Whether you operate from California or simply serve its residents, this law applies to you.

 

This blog covers everything you need to understand about the California Privacy Rights Act (CPRA). From its core provisions and consumer rights to enforcement penalties and compliance steps, this guide breaks it all down in clear, practical terms. Continue reading!

What Is the California Privacy Rights Act (CPRA)

The California Privacy Rights Act (CPRA) builds upon the CCPA to strengthen data privacy protections for California consumers.

Background and Origin

California voters approved the CPRA through Proposition 24 in November 2020. The act was championed by Alastair Mactaggart, the same privacy advocate behind the original CCPA. Its purpose was to close loopholes in the CCPA and bring California closer to global standards like the GDPR.

 

The CPRA officially took effect on 1 January 2023. However, its enforcement provisions applied to data collected from 1 January 2022 onwards. This retroactive scope caught many businesses off guard, making early compliance essential.

How CPRA Differs from the CCPA

While the CCPA was groundbreaking, it had significant gaps. The CPRA addressed those by introducing new consumer rights, a dedicated enforcement body, and stricter rules around data handling. One major shift was the creation of a separate category for Sensitive Personal Information, which gave consumers more control over data like biometrics, precise location, and financial credentials.

 

The CPRA also removed the automatic 30-day cure period. Under the CCPA, businesses had 30 days to fix a violation before facing penalties. That safety net is now at the discretion of enforcement agencies.

The California Privacy Protection Agency (CPPA)

Perhaps the most significant structural change was the creation of the California Privacy Protection Agency (CPPA). This is the first dedicated state privacy enforcement body in the United States. The CPPA has full authority to investigate complaints, conduct audits, and impose fines without relying on the Attorney General.

 

The CPPA has been actively enforcing since 2024, with several high-profile settlements already on record. Businesses should treat this agency as a proactive regulator, not a passive watchdog.

Who Does the California Privacy Rights Act (CPRA) Apply To

The CPRA applies to any for-profit business that collects personal information from California residents and meets specific thresholds.

Business Threshold Criteria

Your business falls under the CPRA if it meets any one of these conditions:

 

  • Annual gross revenue exceeding $25 million
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year
  • Deriving 50% or more of annual revenue from selling or sharing consumer personal information

 

The CPRA raised the consumer data threshold from 50,000 (under CCPA) to 100,000. This change exempted some smaller businesses, but those meeting revenue or data sale criteria remain covered.

Does It Apply Outside California

Yes. The CPRA is not limited to businesses physically based in California. If your business collects or processes personal data from California residents, regardless of where you operate, compliance is required. This extraterritorial reach is similar to how the GDPR applies to businesses outside the EU.

 

For a detailed comparison between these two frameworks, you can review the differences in our guide on GDPR vs CCPA.

Exemptions and Exceptions

Non-profit organisations and government agencies are not covered. The CPRA also excludes certain data categories like publicly available information and specific types of medical, financial, and employment data already regulated by other federal laws such as HIPAA and GLBA.

Key Consumer Rights Under the California Privacy Rights Act (CPRA)

The CPRA expanded consumer rights significantly, giving individuals more control over how businesses use their personal data.

Right to Know and Right to Access

Consumers can request details about what personal information a business has collected, the sources of that data, and the purpose behind its collection. Under the CPRA, this access now extends beyond the previous 12-month lookback window, covering data as far back as January 2022 where maintained.

 

Businesses must respond to these requests within 45 days. An extension of up to 90 days is allowed if the business provides written notice explaining the delay.

Right to Delete and Right to Correct

The right to delete allows consumers to request removal of their personal data, with limited exceptions for legal obligations and fraud prevention. The CPRA also introduced the right to correct inaccurate personal information, a provision that did not exist under the original CCPA.

 

When a deletion request is received, businesses must also instruct their service providers and contractors to delete that data. This downstream obligation adds a layer of accountability throughout the data processing chain.

Right to Opt Out of Sale and Sharing

Consumers have the right to opt out of both the sale and sharing of their personal information. The CPRA expanded this beyond just data sales to include cross-context behavioural advertising. Understanding the difference between opt-in vs opt-out models is critical for compliance.

 

Businesses must provide a clear and visible link on their website titled ‘Do Not Sell or Share My Personal Information.’ They must also honour browser-based opt-out signals, including the Global Privacy Control (GPC).

Sensitive Personal Information Under the CPRA

One of the most impactful additions in the CPRA is the formal recognition of sensitive personal information as a distinct data category.

What Qualifies as Sensitive Personal Information

The CPRA defines sensitive personal information as data that carries higher privacy risks. This includes Social Security numbers, financial account credentials, precise geolocation data, racial or ethnic origin, religious beliefs, biometric data, health information, sexual orientation, and the contents of personal communications.

 

In 2026, the definition was further expanded to include neural data, covering information from brain-computer interfaces, EEG readings, and similar neurological measurements. This reflects the rapid growth of neurotechnology.

Consumer Rights Over Sensitive Data

Consumers can direct businesses to limit the use of their sensitive personal information to purposes strictly necessary for providing the requested goods or services. This is a powerful restriction that goes well beyond the CCPA. Obtaining valid user consent before processing such data is essential under this framework.

 

Businesses must display a separate link on their website titled ‘Limit the Use of My Sensitive Personal Information.’ This must be distinct from the general opt-out link.

Business Obligations for Sensitive Data

Organisations collecting sensitive personal information must clearly disclose this in their privacy policies. They must specify the categories of sensitive data collected, the purposes for which it is used, and whether it is shared with third parties.

 

Failure to handle sensitive data properly is treated as a higher severity violation. Fines for violations involving children’s data, which is classified as sensitive, are automatically set at the maximum of $7,500 per violation.

Data Minimisation and Purpose Limitation

The CPRA introduces GDPR style principles around data minimisation and purpose limitation, a significant shift from the CCPA.

What Data Minimisation Means Under the CPRA

Businesses may only collect personal information that is reasonably necessary and proportionate to the disclosed purpose. Over-collection, such as gathering data ‘just in case’ or for undefined future use, is a direct violation.

 

This principle also extends to data retention. Businesses must not keep personal data longer than reasonably necessary to fulfil the stated purpose. Privacy policies must include retention schedules or criteria for determining retention periods.

Purpose Limitation Requirements

Personal information collected for one purpose cannot be used for a materially different purpose without providing new notice to the consumer. If a business collects email addresses for order confirmations, it cannot later use those addresses for marketing without separate disclosure and, where applicable, consent.

 

This requirement forces businesses to think carefully about data collection at the point of intake. Vague or overly broad privacy notices no longer provide adequate legal cover.

Impact on Data Strategy

These principles require organisations to conduct thorough data mapping exercises. Businesses must understand what data they collect, why they collect it, where it is stored, and how long they keep it. Companies without a structured data inventory will struggle to demonstrate compliance during audits or investigations.

Enforcement and Penalties Under the CPRA

Enforcement of the California Privacy Rights Act (CPRA) has intensified since 2024, with several major actions signalling a more aggressive regulatory posture. To stay informed, review the Key Updates in CCPA enforcement for 2026.

Penalty Structure

The CPRA authorises fines ranging from $2,500 per unintentional violation to $7,500 per intentional violation. Violations involving children’s data are automatically set at the higher $7,500 threshold, regardless of intent.

 

Unlike the GDPR, there is no statutory cap on total penalties. Each affected consumer record counts as a separate violation. A data breach affecting 10,000 consumers could result in penalties reaching $75 million.

Notable Enforcement Actions

  • Walt Disney Company (2026): Settled for $2.75 million for failing to apply opt-out preferences across devices and not recognising Global Privacy Control signals.
  • Sephora: Fined $1.2 million for selling consumer data without providing opt-out mechanisms or recognising universal opt-out signals.
  • Tilting Point Media: Penalised $500,000 for selling children’s data without parental consent.
  • DoorDash: Fined $375,000 for sharing consumer data with third parties without proper opt-out options.

The End of the Cure Period

The automatic 30-day cure period that existed under the CCPA has been removed. Enforcement agencies now have full discretion on whether to allow time for remediation before pursuing penalties. Post-breach improvements are not considered adequate remediation.

 

This shift means businesses must be compliant before an issue arises, not after. Reactive compliance strategies carry significant financial risk.

How to Achieve California Privacy Rights Act (CPRA) Compliance

Meeting the requirements of the CPRA demands a structured approach across legal, technical, and operational areas of your business.

Conduct a Data Mapping Exercise

Start by identifying every category of personal information your business collects, processes, stores, and shares. Document the source, purpose, retention period, and any third parties involved. A comprehensive data inventory is the foundation of every other compliance step.

Update Your Privacy Policy

Your privacy policy must reflect all CPRA requirements. This includes disclosing data retention periods, listing categories of sensitive personal information collected, explaining consumer rights, and providing clear instructions on how to submit data requests. The policy must be reviewed and updated at least annually.

Implement Consumer Rights Mechanisms

Set up verified processes for handling consumer requests, including access, deletion, correction, and opt-out. Response timelines must be met: 45 days standard, with a possible extension to 90 days. For automated decision-making technology, the response window is 15 business days.

 

Your website must also honour Global Privacy Control (GPC) signals and display confirmation that opt-out requests have been processed.

Service Provider and Contractor Obligations

The CPRA places clear obligations on third parties that process data on behalf of businesses.

Contractual Requirements

Every contract with a service provider or contractor must specify the purpose of data processing, prohibit use of data beyond that purpose, and require compliance with all CPRA provisions. Contracts must also give the business the right to audit the vendor’s practices.

 

If a service provider determines it can no longer meet its CPRA obligations, it must notify the business immediately. This requirement creates a chain of accountability that extends well beyond the primary data collector.

Subcontractor Flow Down

Obligations must flow down to subcontractors. If a service provider engages another company to process data, that subcontractor must be bound by the same restrictions and requirements. Businesses are ultimately responsible for ensuring this chain remains intact.

Vendor Risk Management

Businesses should conduct regular due diligence on their vendors. This includes reviewing privacy practices, verifying contractual compliance, and ensuring that data sharing arrangements are properly documented. A failure at the vendor level can result in penalties for the primary business.

Risk Assessments and Cybersecurity Audits

The CPRA introduced formal requirements for risk assessments and cybersecurity audits, adding a new layer of compliance responsibility.

When Risk Assessments Are Required

Businesses must conduct risk assessments for six categories of significant risk processing activities. These include selling or sharing personal information, processing sensitive data beyond disclosed purposes, using automated decision-making technology, training automated decision-making systems, systematic observation through technology, and automated profiling.

 

These assessments must weigh the benefits of the processing activity against potential risks to consumer privacy. Documentation must be maintained and made available to the CPPA upon request.

Cybersecurity Audit Timelines

Cybersecurity audits are being phased in based on business revenue:

 

  • Businesses with revenue above $100 million: attestation due by April 2028
  • Businesses with revenue between $50 million and $100 million: due by April 2029
  • Businesses with revenue under $50 million: due by April 2030

Automated Decision Making Technology (ADMT)

From January 2027, businesses using ADMT must provide pre-use notices, offer consumers the right to opt out, and establish appeal processes. This applies to automated systems that make decisions about employment, finance, health, housing, or education. The 15-business-day response window for consumer requests related to ADMT is shorter than the standard timeline.

Final Thoughts

The California Privacy Rights Act (CPRA) is not just an update to the CCPA. It represents a fundamental shift in how businesses must approach consumer data. With stronger rights, a dedicated enforcement agency, and penalties that scale with each violation, compliance is no longer optional. The time to act is now, and building a privacy-first approach will serve your business well beyond just meeting legal requirements.

Stay CPRA Compliant with Seers AI

Managing compliance with the California Privacy Rights Act (CPRA) does not have to be complicated. Seers.ai provides the tools you need to handle consent, manage data requests, and stay ahead of regulatory changes, all from one platform. Start building trust with your users and reduce compliance risk today.

START FREE TODAY

Frequently Asked Questions (FAQs)

Does the California Privacy Rights Act (CPRA) apply to small businesses?

The CPRA applies to for-profit businesses meeting specific thresholds: $25 million in annual revenue, processing data of 100,000 or more consumers, or earning 50% of revenue from data sales. Small businesses below all three thresholds are generally exempt. However, those selling personal data should still evaluate their obligations carefully.

What is the difference between personal information and sensitive personal information under the CPRA?

Personal information includes any data that identifies or can be linked to a consumer, such as names, emails, and browsing history. Sensitive personal information is a narrower category covering higher-risk data like social security numbers, biometrics, precise geolocation, and health information. Consumers have additional rights to limit how sensitive data is used.

How does the CPRA handle cross-context behavioural advertising?

The CPRA treats sharing personal data for cross-context behavioural advertising the same as a data sale. Consumers must be given the option to opt out of this type of sharing. Businesses must display a ‘Do Not Sell or Share My Personal Information’ link and honour browser signals like Global Privacy Control.

What happens if a business fails to respond to a consumer data request on time?

Businesses must respond within 45 days, with a possible 90-day extension if notice is provided. Failing to meet these deadlines is a violation that the CPPA can investigate. Repeated failures to respond could result in enforcement action and fines of up to $7,500 per intentional violation.

Are employee data and B2B contact data covered by the CPRA?

The temporary exemptions for employee data and B2B contact data that existed under the CCPA have expired. The CPRA now covers both categories. Businesses must extend the same privacy protections, including access, deletion, and opt-out rights, to employees and B2B contacts whose data they collect.

What is the role of the California Privacy Protection Agency?

The CPPA is the first dedicated state-level privacy enforcement agency in the United States. It has authority to investigate complaints, conduct audits, issue subpoenas, and impose fines. It operates independently from the Attorney General and has been actively pursuing enforcement actions since 2024.

Does the CPRA require businesses to honour Global Privacy Control signals?

Businesses must detect and honour GPC browser signals as valid opt-out of sale and sharing requests. From 2026, businesses must also display visible confirmation that opt-out requests have been processed. Silent processing of these signals is no longer acceptable under the updated regulations.

How does the CPRA affect data stored before the law took effect?

The CPRA enforcement provisions apply to personal information collected from 1 January 2022 onwards. Consumers can request access to historical data going back to that date. Businesses that did not prepare for this retroactive scope may face challenges in responding to older data requests.

What are the CPRA requirements for data brokers?

Data brokers must register with the California Attorney General and participate in the DELETE Act’s DROP platform. From August 2026, brokers must access the DROP system every 45 days to process consumer deletion and opt-out requests. Non-compliance carries additional penalties beyond standard CPRA fines.

Can consumers sue businesses directly under the CPRA?

The private right of action under the CPRA is limited to data breaches resulting from a business’s failure to implement reasonable security measures. Consumers can sue for breaches involving personal information like email addresses and passwords. Other CPRA violations are enforced by the CPPA and the Attorney General, not through private lawsuits.

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn 

Unlock Accurate Insights with Google Consent Mode v2

Is Your Website at Risk of Losing Conversions?


Take our Free Cookie Audit and find out

Ready to Build Trust and Drive Business Growth?

Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.