Author: Rimsha Zafar
September 4, 2026

CPRA vs CCPA: What Actually Changed and Why It Matters

Is your business still treating CCPA compliance as the finish line? The California Privacy Rights Act (CPRA) replaced and expanded the CCPA with stricter rules, broader consumer rights, and a dedicated enforcement agency. If your compliance framework has not been updated, you may already be at risk.

 

The CPRA is not a separate law sitting alongside the CCPA. It is a direct amendment that strengthens the original framework. This means businesses that were compliant under CCPA may no longer meet the new requirements. The gap between the two laws is where penalties, enforcement actions, and loss of consumer trust live.

 

This blog breaks down the real differences between CPRA vs CCPA. You will see exactly what changed, what stayed the same, and where your business needs to take action. Whether you are a compliance officer, a legal professional, or a business leader, this comparison will give you a clear path forward.

What Is the Relationship Between CPRA and CCPA?

Before jumping into the differences, it is worth understanding how these two laws connect to each other.

CCPA Was the Starting Point

The California Consumer Privacy Act (CCPA) took effect in January 2020. It was the first major state-level privacy law in the United States. The CCPA gave California residents the right to know what personal data businesses collected, the right to delete that data, and the right to opt out of data sales. It set the baseline, but it left gaps that businesses and regulators quickly noticed.

CPRA Expanded the Framework

California voters approved Proposition 24 in November 2020, which created the California Privacy Rights Act (CPRA). Rather than being an entirely new law, it amended and built upon the CCPA. The CPRA took full effect on 1 January 2023, with enforcement beginning on 1 July 2023. Every provision of the CCPA that the CPRA modified now follows the updated standard.

Why This Distinction Matters

Many businesses still reference CCPA compliance in their privacy policies and internal documentation. However, since the CPRA amended the CCPA, those references should reflect the current requirements. Operating under outdated standards creates both legal exposure and a false sense of security. 

CPRA vs CCPA: Side-by-Side Comparison Table

This table highlights the most significant differences between the two laws across key compliance areas.

CCPA vs CPRA Comparison Table
Compliance Area CCPA (Original) CPRA (Amended)
Enforcement Body California Attorney General California Privacy Protection Agency (CPPA)
Sensitive Personal Information No separate category defined Defined as a distinct category with extra protections
Consumer Rights Right to know, delete, and opt out of sale Added right to correct, limit SPI use, and opt out of automated decisions
Opt-Out Scope Opt out of data sale only Opt out of both data sale and data sharing
Data Minimisation No requirement Must limit collection to what is necessary for disclosed purposes
Data Retention No specific rules Must disclose retention periods and not retain data longer than necessary
Business Threshold 50,000+ consumers or households 100,000+ consumers or households
Penalties $2,500 per unintentional; $7,500 per intentional violation Up to $7,988 per violation; children's data violations treated as intentional
Contractor Obligations Limited third-party rules Expanded rules for contractors, service providers, and third parties
Cybersecurity Audits Not required Annual audits and risk assessments for high-risk processing
Private Right of Action Limited to data breaches Expanded to cover email plus password/security question breaches

Expanded Consumer Rights Under CPRA

One of the biggest shifts in the CPRA vs CCPA comparison is the expansion of what consumers can demand from businesses.

Right to Correction

Under CCPA, consumers could ask to see or delete their data, but they could not request corrections. The CPRA changed that. Consumers can now ask businesses to fix inaccurate personal information. This means your data management systems need to support correction workflows, not just deletion requests.

Right to Limit Sensitive Personal Information

The CPRA introduced a formal category of sensitive personal information (SPI). This includes data such as social security numbers, precise geolocation, biometric details, health records, and religious beliefs. Consumers can now direct businesses to limit the use of their SPI to only what is necessary to deliver the requested service. This is a significant operational change for any company that processes these data types.

Right to Opt Out of Automated Decision-Making

The CPRA gives consumers the right to know about automated decision-making processes and to opt out of them. If your business uses algorithms or AI to profile consumers, make credit decisions, or personalise pricing, you must now provide transparency and an exit option. The CCPA had no equivalent provision.

Enforcement Changes: From Attorney General to CPPA

The way California enforces its privacy law has changed fundamentally under the CPRA, and this shift carries real consequences.

A Dedicated Privacy Regulator

The CCPA relied on the California Attorney General for enforcement. Privacy was one responsibility among many. The CPRA established the California Privacy Protection Agency (CPPA), a standalone body with the sole focus of enforcing privacy regulations. This is the first agency of its kind in the United States. It has its own budget, rulemaking authority, and the power to conduct audits and investigations.

Faster Rulemaking and Updates

The CPPA has already issued multiple rounds of regulations, including amendments effective from 1 January 2026. These cover areas such as cybersecurity audits, automated decision-making rules, and opt-in vs opt-out mechanisms. A dedicated agency means rules will continue to evolve faster than they did under the CCPA.

Removal of the 30-Day Cure Period

Under the original CCPA, businesses received a 30-day window to fix violations before facing penalties. The CPRA removed this cure period entirely. When the CPPA identifies a violation, enforcement action can begin immediately. This makes proactive compliance far more important than reactive fixes.

Data Minimisation and Retention Rules

The CPRA introduced obligations that did not exist under the CCPA, bringing California closer to global standards like the GDPR.

Collect Only What You Need

Businesses must now limit data collection to what is reasonably necessary for the purpose disclosed at the point of collection. Under the CCPA, there was no such restriction. Companies could collect as much data as they wanted, as long as they disclosed it. The CPRA shifts this balance by requiring purpose limitation.

Retention Period Disclosures

The CPRA requires businesses to state how long they will retain each category of personal information. This must be communicated to consumers at the point of collection. Holding data indefinitely without a stated purpose is no longer compliant. Businesses need documented retention schedules that align with their privacy notices.

Impact on Data Governance

These requirements mean that compliance teams need to work closely with IT and data teams. Data mapping, classification, and lifecycle management are no longer optional exercises. They are regulatory requirements. Understanding the key updates in CCPA regulations for 2026 is essential for keeping your retention policies current.

How CPRA Affects Business Obligations

Beyond consumer rights, the CPRA places new operational demands on businesses that process California residents’ data.

Expanded Contractor and Vendor Rules

The CCPA drew a basic line between businesses and service providers. The CPRA goes further by adding contractors as a defined category. All three groups now have specific obligations around data handling. Contracts with service providers and contractors must include clauses that restrict how shared data is used, stored, and deleted.

Annual Cybersecurity Audits

Businesses whose data processing activities present significant risks to consumer privacy must now conduct annual cybersecurity audits. They must also perform regular risk assessments. These were not required under the CCPA. For many organisations, this means investing in audit frameworks or working with third-party assessors.

Stricter Penalties and No Grace Period

Penalties under the CPRA have increased to approximately $7,988 per violation. Violations involving children’s data are automatically treated as intentional, attracting the highest fine tier. Without the 30-day cure period, businesses cannot rely on fixing problems only after they are caught. This makes robust user consent management a non-negotiable part of your compliance stack.

What Stayed the Same Between CPRA and CCPA?

While the differences are significant, several core elements of the CCPA carried over into the CPRA without major changes.

 

  • The right to know what personal information is collected remains intact.
  • The right to delete personal information continues under the same framework.
  • The private right of action for data breaches still applies, though expanded slightly.
  • Revenue-based applicability thresholds ($25 million annual gross revenue) remain unchanged.
  • The requirement to provide a clear privacy policy and notice at collection persists.

 

These continuities mean that businesses already compliant with the CCPA have a strong foundation. But foundation is not the same as full compliance. The CPRA additions require concrete updates to processes, contracts, and consumer-facing mechanisms.

Steps to Close the CPRA vs CCPA Compliance Gap

If your business has been operating under CCPA standards alone, here is what needs attention now.

 

  • Audit your data inventory. Map every category of personal and sensitive personal information your business collects, processes, and shares.
  • Update consumer request workflows. Add correction capabilities and SPI limitation mechanisms alongside existing deletion and access processes.
  • Review vendor contracts. Ensure all service provider and contractor agreements include CPRA-compliant data protection clauses.
  • Implement retention schedules. Document how long each data category is retained and communicate this to consumers at collection.
  • Invest in a consent management platform. A reliable platform helps manage opt-out signals, consent-based marketing preferences, and regulatory updates in one place.
  • Prepare for audits. If your processing activities are high-risk, set up annual cybersecurity audits and document your risk assessment procedures.

Final Thoughts

The CPRA vs CCPA comparison is not about two separate laws. It is about how California’s privacy framework has matured. The CPRA closed gaps, strengthened consumer control, and created a dedicated enforcement body. Businesses that treat this as a minor update risk falling behind on compliance. Review your current practices against the CPRA standards, address the gaps, and build a privacy programme that holds up under scrutiny.

Stay CPRA Compliant with Seers

Managing CPRA compliance manually is complex and error-prone. Seers gives you automated consent management, real-time regulatory updates, and audit-ready documentation. Close your compliance gaps before they become enforcement actions.

START FREE TODAY

Frequently Asked Questions (FAQs)

Does the CPRA replace the CCPA entirely?

The CPRA amends and builds upon the CCPA rather than replacing it outright. The original CCPA framework remains the foundation, but every provision that the CPRA modified now follows the updated standard. Businesses should treat the CPRA-amended version as the current law and update their compliance documentation accordingly to reflect these changes.

What is sensitive personal information under the CPRA?

The CPRA defines sensitive personal information as a distinct category that includes social security numbers, financial account credentials, precise geolocation data, biometric and genetic information, health records, and data about religious beliefs or sexual orientation. Consumers can request businesses limit their use of this data to what is strictly necessary for the service provided.

How does the CPPA differ from the Attorney General in enforcement?

The California Privacy Protection Agency is a standalone regulatory body dedicated solely to privacy enforcement. Unlike the Attorney General, who handled privacy alongside many other responsibilities, the CPPA has focused authority to conduct audits, issue fines, and create new regulations. This specialisation means more consistent and targeted enforcement actions.

Are small businesses exempt from the CPRA?

The CPRA raised the data processing threshold from 50,000 to 100,000 consumers or households. This change exempts some smaller businesses that were previously covered under the CCPA. However, companies meeting any of the other thresholds, such as $25 million in annual gross revenue or earning 50% of revenue from selling personal data, are still subject to the law.

What happens if a business violates CPRA rules involving children's data?

Violations involving children’s personal information are automatically classified as intentional under the CPRA, regardless of whether the business acted knowingly. This means they attract the highest penalty tier, which currently stands at approximately $7,988 per violation. Businesses that collect or process minors’ data should implement additional safeguards and verification processes.

Can consumers still opt out of data sales under the CPRA?

The opt-out right remains intact and has been expanded under the CPRA. Consumers can now opt out of both the sale and the sharing of their personal information. Sharing is defined as transferring data to third parties for cross-context behavioural advertising. Businesses must honour these requests through clear opt-out mechanisms on their platforms.

Does the CPRA require businesses to conduct cybersecurity audits?

Businesses whose data processing activities pose significant risks to consumer privacy must perform annual cybersecurity audits under the CPRA. They are also required to conduct regular risk assessments. These obligations were absent from the original CCPA and represent a significant operational addition for companies that handle large volumes of personal information.

What is the data minimisation requirement under the CPRA?

The CPRA requires businesses to limit their data collection to what is reasonably necessary for the purpose disclosed to consumers at the point of collection. This principle also applies to data retention. Businesses cannot hold personal information longer than reasonably needed. Documented retention schedules and clear privacy notices are now essential compliance components.

How should businesses update their vendor contracts for CPRA?

The CPRA requires that agreements with service providers, contractors, and third parties include specific data protection clauses. These contracts must define how shared personal information is used, stored, and deleted. Businesses should review all existing vendor agreements to verify they meet the CPRA standard, particularly around data minimisation and deletion obligations.

Is the 30-day cure period still available under the CPRA?

The CPRA removed the 30-day cure period that existed under the original CCPA. Under the previous law, businesses had 30 days to correct a violation before facing penalties. This window no longer applies. The CPPA can begin enforcement actions immediately upon identifying a violation, making proactive compliance programmes far more critical. 

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn 

Unlock Accurate Insights with Google Consent Mode v2

Is Your Website at Risk of Losing Conversions?


Take our Free Cookie Audit and find out

Ready to Build Trust and Drive Business Growth?

Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.