Author: Rimsha Zafar
September 24, 2026

CPRA Compliance Requirements Every Business Must Follow

Are you confident your business meets every obligation under California privacy law? With the California Privacy Rights Act now fully enforced and penalties increasing each year, uncertainty is no longer an option. Businesses that collect, process, or share personal data from California residents face a growing list of obligations that demand immediate attention.

 

This guide breaks down the full scope of CPRA compliance requirements. It covers who needs to comply, what rights consumers hold, how sensitive personal information must be handled, and what enforcement actions look like. Whether you manage compliance operations, lead a legal team, or oversee data governance, 

this blog gives you a clear, structured understanding of every major obligation under the CPRA.

By the end, you will know exactly what your business must do to stay compliant, avoid penalties, and build a privacy framework that holds up under regulatory scrutiny.

What Is the CPRA and Why Does It Matter

The California Privacy Rights Act (CPRA) reshaped data privacy obligations for businesses operating in or serving California residents.

Origins of the CPRA

California voters approved the CPRA through Proposition 24 in November 2020. It amended and expanded the California Consumer Privacy Act (CCPA), which had been in effect since January 2020. The CPRA introduced stronger protections for personal data. It also established a dedicated enforcement body to oversee compliance.

 

The law took full effect on 1 January 2023, with enforcement beginning on that same date. Its provisions apply to personal information collected on or after 1 January 2022. This retroactive scope means businesses must account for data collected well before the enforcement date.

The California Privacy Protection Agency

One of the most significant changes under the CPRA was the creation of the California Privacy Protection Agency (CPPA). This independent regulatory body has full authority to investigate complaints, conduct audits, and issue fines. Before the CPRA, enforcement sat solely with the California Attorney General. The CPPA now operates as a standalone agency with dedicated resources and rulemaking power.

Why Compliance Matters Now

Enforcement has accelerated sharply. In 2025 and 2026, the CPPA issued several high-profile penalties, including a $2.75 million settlement against Disney and a $1.35 million fine against Tractor Supply. These actions signal that the agency is actively pursuing violations. Businesses that delay compliance risk financial penalties and reputational damage that far outweigh the cost of getting compliant.

Who Must Comply with CPRA Compliance Requirements

Not every business falls under the CPRA, but the thresholds are broader than many expect.

Revenue and Data Processing Thresholds

A for-profit business must meet CPRA compliance requirements if it satisfies any one of three criteria. First, annual gross revenue exceeding $26,625,000 (adjusted for inflation). Second, processing personal information of 100,000 or more California consumers or households each year. Third, deriving 50% or more of annual revenue from selling or sharing consumer personal information.

 

Meeting just one of these triggers full compliance obligations. The revenue threshold is based on global revenue, not just California-specific income. This means international companies serving Californian consumers may also fall within scope.

Applicable Data Categories

The CPRA applies to personal information across all relationships, not just customer data. Employee records, contractor information, and job applicant data all fall under its scope. This expanded coverage was a significant shift from the original CCPA, which had temporary exemptions for employee and B2B data. Businesses must now treat sensitive personal information from every source with the same level of protection.

Geographic Reach

The CPRA applies regardless of where a business is physically located. If a company collects or processes personal data from California residents, CPRA compliance requirements apply. A business headquartered in London, Berlin, or New York must still comply if it meets any of the thresholds and handles data belonging to Californians.

Core CPRA Compliance Requirements for Businesses

Meeting CPRA compliance requirements involves several operational and legal obligations that businesses must build into their data practices.

Data Mapping and Inventory

Every business subject to the CPRA must know exactly what personal information it collects, where it stores that data, how it flows through internal systems, and who has access to it. Data mapping is the foundation of compliance. Without a clear inventory, businesses cannot respond to consumer requests, conduct risk assessments, or demonstrate compliance during an audit.

 

Data maps should cover all collection points, processing purposes, retention periods, and third-party sharing arrangements. They must be updated regularly as business operations change.

Data Minimisation and Retention

The CPRA introduced a data minimisation principle that did not exist under the original CCPA. Businesses must limit data collection to what is reasonably necessary for the disclosed purpose. They must also define and disclose retention periods for each category of personal information. Once the stated purpose is fulfilled, the data must be deleted.

 

This requirement forces businesses to justify every piece of data they collect. Collecting information “just in case” is no longer acceptable under the law.

Updated Privacy Notices

Privacy policies must clearly disclose specific categories of personal information collected, the purposes of processing, retention periods, and consumer rights. The CPRA also requires businesses to identify whether they sell or share personal data, and to provide a clear “Do Not Sell My Personal Information” link on their website.

Privacy notices must be reviewed and updated at least once every 12 months. Any material change in data practices must be reflected in the policy immediately.

Consumer Rights Under CPRA Compliance Requirements

The CPRA significantly expanded the rights available to California consumers over their personal data.

Right to Know and Access

Consumers can request details about what personal information a business has collected, the sources of that data, the business purposes for collection, and the categories of third parties with whom it has been shared. Under 2026 rules, businesses must extend historical access back to 1 January 2022 or earlier if data has been retained.

Right to Delete

Consumers may request deletion of their personal information. Businesses must comply within 45 days, with a possible 45-day extension if necessary. Crucially, the deletion obligation extends downstream. Businesses must notify all third parties and service providers who received the data and direct them to delete it as well.

Right to Correct

This right was new under the CPRA. Consumers can request corrections to inaccurate personal information held by a business. Businesses must make commercially reasonable efforts to correct the data upon a verified request. They must also instruct service providers and contractors to update their records.

Right to Opt Out

Consumers have the right to opt out of the sale or sharing of their personal information. The CPRA strengthened this right by requiring businesses to honour Global Privacy Control (GPC) signals. From 2026 onward, opt-out confirmation must be visible and immediate. Businesses must also ensure that opting out is as easy as opting in, with no manipulative design patterns.

Right to Limit Use of Sensitive Personal Information

Consumers can direct businesses to limit the use of their sensitive personal information to what is strictly necessary for the expected service. This includes restricting the use of data such as precise geolocation, financial credentials, health information, and biometric identifiers.

Sensitive Personal Information Under CPRA

One of the most consequential additions under the CPRA is the formal category of sensitive personal information (SPI).

What Qualifies as SPI

The CPRA defines a broad list of data types as sensitive personal information. These include government-issued identifiers such as Social Security numbers, driver licence numbers, and passport numbers. Financial account credentials, precise geolocation data, racial or ethnic origin, religious beliefs, biometric data, health information, and data about sexual orientation also fall under SPI.

 

In 2026, the CPPA expanded this category to include neural data. This covers information generated from measurements of central or peripheral nervous system activity, such as EEG readings. This addition reflects growing concerns around neurotechnology and brain-computer interfaces.

Obligations Around SPI

Businesses must provide notice at the point of collection when gathering sensitive personal information. They must offer consumers the right to limit the use and disclosure of SPI. They are also required to conduct risk assessments before processing SPI for purposes beyond what is necessary to provide the requested service.

Practical Steps for SPI Handling

Organisations should classify all data they hold and flag any categories that meet the SPI definition. Access controls must be tightened for SPI. Encryption and monitoring should be applied specifically to systems that store or process this category of data. Documentation of SPI processing activities is essential for demonstrating compliance during audits.

Risk Assessments and Cybersecurity Audits

The CPRA introduced mandatory risk assessments and cybersecurity audits as part of its compliance framework.

When Risk Assessments Are Required

Businesses must conduct risk assessments before engaging in processing activities that pose a significant risk to consumer privacy. The CPPA has identified six categories of activity that trigger this requirement:

 

  • Selling or sharing personal information
  • Processing sensitive personal information
  • Using automated decision-making technology for significant decisions
  • Training artificial intelligence or machine learning algorithms on personal data
  • Engaging in systematic observation or surveillance of consumers
  • Automated profiling that produces legal or similarly significant effects

 

Each assessment must weigh the benefits of the processing against the risks to consumer privacy. Businesses must submit these assessments to the CPPA upon request.

Cybersecurity Audit Requirements

Businesses that process personal information of 250,000 or more California consumers, or 50,000 or more sensitive information records, must undergo independent annual cybersecurity audits. Executive leadership must certify the results to the CPPA.

 

The phased timeline for audit submissions is structured by revenue tier. Businesses with revenue exceeding $100 million must submit by April 2028. Those between $50 million and $100 million by April 2029. Businesses under $50 million must submit by April 2030. Audit records must be retained for a minimum of five years.

Documentation and Record-Keeping

Beyond audits and assessments, the CPRA expects robust documentation of all compliance activities. This includes records of consumer requests received and fulfilled, data processing agreements with service providers, training logs for staff, and evidence of technical safeguards. Thorough documentation serves as the primary defence in any enforcement action.

Automated Decision-Making Technology (ADMT) Rules

New regulations around automated decision-making represent one of the most forward-looking elements of CPRA compliance requirements. Understanding these rules is essential for businesses relying on AI governance frameworks.

Pre-Use Notice Requirements

Starting 1 April 2027, businesses that use automated decision-making technology for decisions that produce legal or similarly significant effects must provide consumers with a pre-use notice. This notice must explain how the technology works, what data it uses, and how it influences the outcome. The notice must be provided before the decision is made, not after.

Consumer Rights Regarding ADMT

Consumers will have the right to request information about the methodology behind automated decisions. They can appeal decisions made through ADMT and request human review. They also have the right to opt out of automated decision-making processes entirely in most contexts. Certain narrow exceptions apply for fraud detection and security purposes.

Preparing for ADMT Compliance

Businesses should begin auditing their use of automated systems now. This includes customer scoring models, content personalisation algorithms, employment screening tools, and insurance underwriting systems. Mapping which systems qualify as ADMT under the CPRA definition is the first step toward compliance. Risk assessments for these systems must be completed and documented.

How CPRA Compliance Requirements Differ from CCPA

The CPRA is often described as an amendment to the CCPA, but the differences are substantial enough that businesses must treat it as a separate compliance framework. For a broader comparison of privacy laws, see our guide on GDPR vs CCPA.

New Rights and Categories

The CCPA gave consumers the right to know, delete, and opt out of the sale of personal information. The CPRA added the right to correct inaccurate data, the right to limit use of sensitive personal information, and rights related to automated decision-making. It also created the entirely new category of sensitive personal information, which carries its own set of obligations.

Stronger Enforcement Structure

Under the CCPA, enforcement was handled exclusively by the California Attorney General. The CPRA created the CPPA as an independent agency with its own budget, staff, and rulemaking authority. This shift dramatically increased enforcement capacity. The CPPA can initiate investigations on its own, without waiting for consumer complaints.

Data Minimisation and Purpose Limitation

The CCPA did not include data minimisation requirements. The CPRA introduced a clear obligation to collect only what is necessary for the stated purpose and to retain data no longer than reasonably required. This aligns California law more closely with the GDPR and marks a significant shift in how businesses must approach data collection.

Consent and Opt-Out Mechanisms

Proper consent handling is central to meeting CPRA compliance requirements and avoiding enforcement actions.

Global Privacy Control (GPC) Compliance

Businesses must detect and honour GPC signals transmitted by a consumer’s browser. This is now mandatory, not optional. The CPPA has specifically targeted companies that fail to respond to GPC signals. The Tractor Supply enforcement action in 2025 included GPC non-compliance as a key violation. Automating GPC detection through a consent management platform removes manual risk and ensures consistent compliance.

Symmetrical Consent Design

The CPRA requires that opting out must be as easy as opting in. Accept and reject buttons must have equal visual prominence. Closing a pop-up without clicking a button cannot count as consent. Pre-checked boxes and default opt-in settings are prohibited. Any interface that makes rejection harder than acceptance violates the symmetrical consent requirement.

Opt-Out Confirmation

From 2026, businesses must provide visible confirmation when a consumer opts out. Silent processing of opt-out requests is no longer acceptable. The confirmation must be clear, immediate, and accessible. This applies across all channels, including website interfaces, in-app controls, and email-based requests.

Vendor and Service Provider Obligations

Third-party relationships carry direct compliance obligations under CPRA compliance requirements.

Contract Requirements

Every agreement with a service provider, contractor, or third party that processes personal information must include specific CPRA-compliant clauses. These contracts must define the permitted purposes for data use, prohibit unauthorised selling or sharing, and require the vendor to assist with consumer requests. They must also mandate cooperation with cybersecurity audits and risk assessments.

Ongoing Vendor Monitoring

Signing a compliant contract is not enough. Businesses must actively monitor their vendors to ensure ongoing adherence to CPRA obligations. The Todd Snyder enforcement action highlighted how a malfunctioning third-party cookie banner led to a $345,178 penalty for the business, not the vendor. Responsibility for compliance sits with the data controller.

Downstream Deletion and Correction

When a consumer exercises their right to delete or correct data, the business must pass that request to every service provider and third party that received the data. This requires clear data flow documentation and established processes for forwarding and confirming downstream requests.

Penalties and Enforcement Under the CPRA

The enforcement landscape under the CPRA has become significantly more aggressive.

Civil Penalty Structure

Violations carry civil penalties of up to $2,663 per incident. Intentional violations increase to $7,988 per incident. These figures are adjusted for inflation in odd-numbered years. For violations involving children’s data (consumers under 16), the penalty is $7,500 per violation regardless of intent.

Private Right of Action

Consumers retain a private right of action for data breaches resulting from a business’s failure to implement reasonable security measures. Statutory damages range from $107 to $799 per consumer per incident. In a large-scale breach, these amounts accumulate rapidly and can result in multi-million dollar liability.

Recent Enforcement Actions

The CPPA has moved beyond warnings and into active enforcement. Key actions include the $2.75 million Disney settlement for failing to properly implement opt-out mechanisms across devices. The $1.35 million Tractor Supply fine addressed GPC non-compliance and vendor contract failures. A health publisher was fined $1.55 million for privacy notice inaccuracies. These cases establish clear precedent that the CPPA will pursue violations across industries and at significant financial levels.

Steps to Achieve CPRA Compliance

A structured approach to meeting CPRA compliance requirements reduces risk and simplifies ongoing operations.

Conduct a Data Inventory

Map every category of personal information your business collects, processes, stores, and shares. Identify all systems, databases, and third parties involved. This inventory forms the basis for every other compliance activity.

Update Privacy Policies and Notices

Review and revise your privacy policy to reflect all CPRA-mandated disclosures. Include specific categories of personal and sensitive personal information collected, processing purposes, retention periods, and consumer rights. Ensure the policy is accessible, current, and written in plain language.

Build Consumer Request Workflows

Establish documented procedures for receiving, verifying, and fulfilling consumer rights requests. This covers access, deletion, correction, opt-out, and limitation of SPI use. Centralise intake across all channels. Use proportionate verification methods. Automating data subject access requests can reduce processing costs from over $1,500 per request to under $300.

Implement Technical Safeguards

Deploy encryption, access controls, activity monitoring, and incident response protocols. Ensure systems that handle sensitive personal information have additional layers of protection. Conduct regular vulnerability assessments and penetration testing.

Train Staff and Assign Ownership

All employees who handle personal data must receive CPRA-specific training. Assign a privacy lead or data protection officer to oversee compliance activities, manage consumer requests, and serve as the point of contact for the CPPA.

Schedule Ongoing Reviews

Compliance is not a one-time project. Schedule regular reviews of data practices, vendor contracts, privacy notices, and technical controls. Regulatory updates from the CPPA should trigger immediate review of affected processes.

Final Thoughts

CPRA compliance requirements set a high standard for how businesses collect, process, and protect personal data from California residents. From sensitive personal information handling to mandatory risk assessments and cybersecurity audits, the obligations are detailed and enforceable. Businesses that invest in compliance now protect themselves from penalties, build consumer trust, and create a data governance framework that scales with evolving regulations.

Stay CPRA Compliant with Seers AI

Meeting CPRA compliance requirements takes the right tools and a clear framework. Seers.ai provides automated consent management, GPC signal detection, and privacy policy generation to help your business stay compliant without operational disruption. Simplify your compliance workflow and reduce regulatory risk.

Start Free Today

Frequently Asked Questions (FAQs)

What is the difference between CPRA and CCPA?

The CPRA expanded the CCPA by adding new consumer rights, creating the sensitive personal information category, introducing data minimisation obligations, and establishing the California Privacy Protection Agency as an independent enforcement body. It also removed the 30-day cure period for most violations and introduced mandatory risk assessments and cybersecurity audits for qualifying businesses.

Does the CPRA apply to non-profit organisations?

The CPRA applies only to for-profit businesses that meet at least one of the three qualifying thresholds. Non-profit organisations and government entities are exempt from CPRA compliance requirements. However, non-profits that operate for-profit subsidiaries meeting the thresholds should assess whether those subsidiaries are independently subject to the law.

How does the CPRA define sensitive personal information?

Sensitive personal information under the CPRA includes government identifiers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, health information, sexual orientation data, and contents of private communications. The CPPA expanded this list in 2026 to include neural data, covering brain activity measurements from devices like EEG monitors.

What penalties can businesses face for CPRA violations?

Civil penalties reach $2,663 per unintentional violation and $7,988 per intentional violation. Violations involving children carry a $7,500 fine per incident. Consumers also have a private right of action for data breaches, with statutory damages between $107 and $799 per consumer per incident. Recent enforcement actions have resulted in settlements exceeding $2 million.

What is the difference between CCPA and CPRA training?

Businesses processing personal information of 250,000 or more California consumers, or 50,000 or more sensitive information records, must undergo annual independent cybersecurity audits. Executive certification of audit results to the CPPA is mandatory. The requirement is phased by revenue tier, with the first submissions due in April 2028 for businesses exceeding $100 million in revenue.

What is the Global Privacy Control and how does it relate to CPRA?

Global Privacy Control is a browser-level signal that communicates a consumer’s preference to opt out of the sale or sharing of personal information. Under the CPRA, businesses must detect and honour GPC signals. Failure to do so is treated as a violation. The CPPA has already issued fines specifically for GPC non-compliance, making it a high-priority enforcement area.

How must businesses handle consumer data requests under the CPRA?

Businesses must acknowledge receipt of a consumer request within 10 business days and fulfil it within 45 calendar days, with a possible 45-day extension. Verification must be proportionate to the sensitivity of the request. For opt-out requests, minimal verification is required. For access to sensitive data, multi-factor identity verification is appropriate.

Businesses must obtain opt-in consent before selling or sharing personal information of consumers under 16. For children under 13, a parent or guardian must provide that consent. The penalty for violations involving minors is $7,500 per incident, the same as intentional violations. Businesses serving younger audiences must implement robust age verification mechanisms.

What are the CPRA requirements for automated decision-making?

From April 2027, businesses using automated decision-making technology for significant decisions must provide pre-use notices explaining the technology. Consumers will have rights to request information about the methodology, appeal decisions, and opt out of automated processing. Risk assessments must be completed for any system that qualifies as ADMT under the CPRA definition.

How often must businesses update their privacy policies under the CPRA?

Businesses must review and update their privacy policies at least once every 12 months. Any material change in data collection, processing, or sharing practices must be reflected in the privacy policy immediately. The policy must disclose all categories of personal and sensitive personal information collected, the purposes of processing, retention periods, and the full scope of consumer rights.

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn 

Unlock Accurate Insights with Google Consent Mode v2

Is Your Website at Risk of Losing Conversions?


Take our Free Cookie Audit and find out

Ready to Build Trust and Drive Business Growth?

Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.