Does your business collect personal data from California residents? If the answer is yes, the California Privacy Rights Act (CPRA) directly affects how you handle, store, and share that data. Ignoring this regulation is not an option when fines can reach up to $7,500 per violation.
The California Privacy Rights Act (CPRA) is an expansion of the original CCPA that went into effect on 1 January 2023. It introduced stronger consumer rights, tighter business obligations, and a dedicated enforcement agency. Whether you operate from California or simply serve its residents, this law applies to you.
This blog covers everything you need to understand about the California Privacy Rights Act (CPRA). From its core provisions and consumer rights to enforcement penalties and compliance steps, this guide breaks it all down in clear, practical terms. Continue reading!
The California Privacy Rights Act (CPRA) builds upon the CCPA to strengthen data privacy protections for California consumers.
California voters approved the CPRA through Proposition 24 in November 2020. The act was championed by Alastair Mactaggart, the same privacy advocate behind the original CCPA. Its purpose was to close loopholes in the CCPA and bring California closer to global standards like the GDPR.
The CPRA officially took effect on 1 January 2023. However, its enforcement provisions applied to data collected from 1 January 2022 onwards. This retroactive scope caught many businesses off guard, making early compliance essential.
While the CCPA was groundbreaking, it had significant gaps. The CPRA addressed those by introducing new consumer rights, a dedicated enforcement body, and stricter rules around data handling. One major shift was the creation of a separate category for Sensitive Personal Information, which gave consumers more control over data like biometrics, precise location, and financial credentials.
The CPRA also removed the automatic 30-day cure period. Under the CCPA, businesses had 30 days to fix a violation before facing penalties. That safety net is now at the discretion of enforcement agencies.
Perhaps the most significant structural change was the creation of the California Privacy Protection Agency (CPPA). This is the first dedicated state privacy enforcement body in the United States. The CPPA has full authority to investigate complaints, conduct audits, and impose fines without relying on the Attorney General.
The CPPA has been actively enforcing since 2024, with several high-profile settlements already on record. Businesses should treat this agency as a proactive regulator, not a passive watchdog.
The CPRA applies to any for-profit business that collects personal information from California residents and meets specific thresholds.
Your business falls under the CPRA if it meets any one of these conditions:
The CPRA raised the consumer data threshold from 50,000 (under CCPA) to 100,000. This change exempted some smaller businesses, but those meeting revenue or data sale criteria remain covered.
Yes. The CPRA is not limited to businesses physically based in California. If your business collects or processes personal data from California residents, regardless of where you operate, compliance is required. This extraterritorial reach is similar to how the GDPR applies to businesses outside the EU.
For a detailed comparison between these two frameworks, you can review the differences in our guide on GDPR vs CCPA.
Non-profit organisations and government agencies are not covered. The CPRA also excludes certain data categories like publicly available information and specific types of medical, financial, and employment data already regulated by other federal laws such as HIPAA and GLBA.
The CPRA expanded consumer rights significantly, giving individuals more control over how businesses use their personal data.
Consumers can request details about what personal information a business has collected, the sources of that data, and the purpose behind its collection. Under the CPRA, this access now extends beyond the previous 12-month lookback window, covering data as far back as January 2022 where maintained.
Businesses must respond to these requests within 45 days. An extension of up to 90 days is allowed if the business provides written notice explaining the delay.
The right to delete allows consumers to request removal of their personal data, with limited exceptions for legal obligations and fraud prevention. The CPRA also introduced the right to correct inaccurate personal information, a provision that did not exist under the original CCPA.
When a deletion request is received, businesses must also instruct their service providers and contractors to delete that data. This downstream obligation adds a layer of accountability throughout the data processing chain.
Consumers have the right to opt out of both the sale and sharing of their personal information. The CPRA expanded this beyond just data sales to include cross-context behavioural advertising. Understanding the difference between opt-in vs opt-out models is critical for compliance.
Businesses must provide a clear and visible link on their website titled ‘Do Not Sell or Share My Personal Information.’ They must also honour browser-based opt-out signals, including the Global Privacy Control (GPC).
One of the most impactful additions in the CPRA is the formal recognition of sensitive personal information as a distinct data category.
The CPRA defines sensitive personal information as data that carries higher privacy risks. This includes Social Security numbers, financial account credentials, precise geolocation data, racial or ethnic origin, religious beliefs, biometric data, health information, sexual orientation, and the contents of personal communications.
In 2026, the definition was further expanded to include neural data, covering information from brain-computer interfaces, EEG readings, and similar neurological measurements. This reflects the rapid growth of neurotechnology.
Consumers can direct businesses to limit the use of their sensitive personal information to purposes strictly necessary for providing the requested goods or services. This is a powerful restriction that goes well beyond the CCPA. Obtaining valid user consent before processing such data is essential under this framework.
Businesses must display a separate link on their website titled ‘Limit the Use of My Sensitive Personal Information.’ This must be distinct from the general opt-out link.
Organisations collecting sensitive personal information must clearly disclose this in their privacy policies. They must specify the categories of sensitive data collected, the purposes for which it is used, and whether it is shared with third parties.
Failure to handle sensitive data properly is treated as a higher severity violation. Fines for violations involving children’s data, which is classified as sensitive, are automatically set at the maximum of $7,500 per violation.
The CPRA introduces GDPR style principles around data minimisation and purpose limitation, a significant shift from the CCPA.
Businesses may only collect personal information that is reasonably necessary and proportionate to the disclosed purpose. Over-collection, such as gathering data ‘just in case’ or for undefined future use, is a direct violation.
This principle also extends to data retention. Businesses must not keep personal data longer than reasonably necessary to fulfil the stated purpose. Privacy policies must include retention schedules or criteria for determining retention periods.
Personal information collected for one purpose cannot be used for a materially different purpose without providing new notice to the consumer. If a business collects email addresses for order confirmations, it cannot later use those addresses for marketing without separate disclosure and, where applicable, consent.
This requirement forces businesses to think carefully about data collection at the point of intake. Vague or overly broad privacy notices no longer provide adequate legal cover.
These principles require organisations to conduct thorough data mapping exercises. Businesses must understand what data they collect, why they collect it, where it is stored, and how long they keep it. Companies without a structured data inventory will struggle to demonstrate compliance during audits or investigations.
Enforcement of the California Privacy Rights Act (CPRA) has intensified since 2024, with several major actions signalling a more aggressive regulatory posture. To stay informed, review the Key Updates in CCPA enforcement for 2026.
The CPRA authorises fines ranging from $2,500 per unintentional violation to $7,500 per intentional violation. Violations involving children’s data are automatically set at the higher $7,500 threshold, regardless of intent.
Unlike the GDPR, there is no statutory cap on total penalties. Each affected consumer record counts as a separate violation. A data breach affecting 10,000 consumers could result in penalties reaching $75 million.
The automatic 30-day cure period that existed under the CCPA has been removed. Enforcement agencies now have full discretion on whether to allow time for remediation before pursuing penalties. Post-breach improvements are not considered adequate remediation.
This shift means businesses must be compliant before an issue arises, not after. Reactive compliance strategies carry significant financial risk.
Meeting the requirements of the CPRA demands a structured approach across legal, technical, and operational areas of your business.
Start by identifying every category of personal information your business collects, processes, stores, and shares. Document the source, purpose, retention period, and any third parties involved. A comprehensive data inventory is the foundation of every other compliance step.
Your privacy policy must reflect all CPRA requirements. This includes disclosing data retention periods, listing categories of sensitive personal information collected, explaining consumer rights, and providing clear instructions on how to submit data requests. The policy must be reviewed and updated at least annually.
Set up verified processes for handling consumer requests, including access, deletion, correction, and opt-out. Response timelines must be met: 45 days standard, with a possible extension to 90 days. For automated decision-making technology, the response window is 15 business days.
Your website must also honour Global Privacy Control (GPC) signals and display confirmation that opt-out requests have been processed.
The CPRA places clear obligations on third parties that process data on behalf of businesses.
Every contract with a service provider or contractor must specify the purpose of data processing, prohibit use of data beyond that purpose, and require compliance with all CPRA provisions. Contracts must also give the business the right to audit the vendor’s practices.
If a service provider determines it can no longer meet its CPRA obligations, it must notify the business immediately. This requirement creates a chain of accountability that extends well beyond the primary data collector.
Obligations must flow down to subcontractors. If a service provider engages another company to process data, that subcontractor must be bound by the same restrictions and requirements. Businesses are ultimately responsible for ensuring this chain remains intact.
Businesses should conduct regular due diligence on their vendors. This includes reviewing privacy practices, verifying contractual compliance, and ensuring that data sharing arrangements are properly documented. A failure at the vendor level can result in penalties for the primary business.
The CPRA introduced formal requirements for risk assessments and cybersecurity audits, adding a new layer of compliance responsibility.
Businesses must conduct risk assessments for six categories of significant risk processing activities. These include selling or sharing personal information, processing sensitive data beyond disclosed purposes, using automated decision-making technology, training automated decision-making systems, systematic observation through technology, and automated profiling.
These assessments must weigh the benefits of the processing activity against potential risks to consumer privacy. Documentation must be maintained and made available to the CPPA upon request.
Cybersecurity audits are being phased in based on business revenue:
From January 2027, businesses using ADMT must provide pre-use notices, offer consumers the right to opt out, and establish appeal processes. This applies to automated systems that make decisions about employment, finance, health, housing, or education. The 15-business-day response window for consumer requests related to ADMT is shorter than the standard timeline.
The California Privacy Rights Act (CPRA) is not just an update to the CCPA. It represents a fundamental shift in how businesses must approach consumer data. With stronger rights, a dedicated enforcement agency, and penalties that scale with each violation, compliance is no longer optional. The time to act is now, and building a privacy-first approach will serve your business well beyond just meeting legal requirements.
Managing compliance with the California Privacy Rights Act (CPRA) does not have to be complicated. Seers.ai provides the tools you need to handle consent, manage data requests, and stay ahead of regulatory changes, all from one platform. Start building trust with your users and reduce compliance risk today.
START FREE TODAYThe CPRA applies to for-profit businesses meeting specific thresholds: $25 million in annual revenue, processing data of 100,000 or more consumers, or earning 50% of revenue from data sales. Small businesses below all three thresholds are generally exempt. However, those selling personal data should still evaluate their obligations carefully.
Personal information includes any data that identifies or can be linked to a consumer, such as names, emails, and browsing history. Sensitive personal information is a narrower category covering higher-risk data like social security numbers, biometrics, precise geolocation, and health information. Consumers have additional rights to limit how sensitive data is used.
The CPRA treats sharing personal data for cross-context behavioural advertising the same as a data sale. Consumers must be given the option to opt out of this type of sharing. Businesses must display a ‘Do Not Sell or Share My Personal Information’ link and honour browser signals like Global Privacy Control.
Businesses must respond within 45 days, with a possible 90-day extension if notice is provided. Failing to meet these deadlines is a violation that the CPPA can investigate. Repeated failures to respond could result in enforcement action and fines of up to $7,500 per intentional violation.
The temporary exemptions for employee data and B2B contact data that existed under the CCPA have expired. The CPRA now covers both categories. Businesses must extend the same privacy protections, including access, deletion, and opt-out rights, to employees and B2B contacts whose data they collect.
The CPPA is the first dedicated state-level privacy enforcement agency in the United States. It has authority to investigate complaints, conduct audits, issue subpoenas, and impose fines. It operates independently from the Attorney General and has been actively pursuing enforcement actions since 2024.
Businesses must detect and honour GPC browser signals as valid opt-out of sale and sharing requests. From 2026, businesses must also display visible confirmation that opt-out requests have been processed. Silent processing of these signals is no longer acceptable under the updated regulations.
The CPRA enforcement provisions apply to personal information collected from 1 January 2022 onwards. Consumers can request access to historical data going back to that date. Businesses that did not prepare for this retroactive scope may face challenges in responding to older data requests.
Data brokers must register with the California Attorney General and participate in the DELETE Act’s DROP platform. From August 2026, brokers must access the DROP system every 45 days to process consumer deletion and opt-out requests. Non-compliance carries additional penalties beyond standard CPRA fines.
The private right of action under the CPRA is limited to data breaches resulting from a business’s failure to implement reasonable security measures. Consumers can sue for breaches involving personal information like email addresses and passwords. Other CPRA violations are enforced by the CPPA and the Attorney General, not through private lawsuits.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.