The California Privacy Rights Act of 2020, known as CPRA, strengthens consumer privacy by amending the California Consumer Privacy Act. It establishes the California Privacy Protection Agency and creates new rules for sensitive personal information and data minimization.
CPRA introduces stricter requirements for businesses that collect personal data, focusing on transparency, choice, and enforcement. These changes reshape how organizations handle data across California and often influence practices nationwide.
| Feature | Description | Impact on Consumers | Impact on Businesses |
|---|---|---|---|
| Enforcement Agency | California Privacy Protection Agency (CPPA) | Dedicated regulator for privacy complaints | Oversight, audits, and enforcement actions |
| Sensitive Personal Information | New category with heightened protections | More control over precise geolocation, race, religion, health data | Requires separate opt-in and stricter security |
| Contractor Liability | Service providers treated as shared responsibility | Broader accountability across the data chain | Due diligence and contractual obligations |
| Automated Decision-Making | Profiling that produces legal or similarly significant effects | Right to correction and explanation | Risk assessments and record-keeping required |
| Data Retention | Reasonable and necessary time only | Less indefinite data storage | Policy updates and lifecycle management |
Consumer Rights Under CPRA
CPRA expands the rights introduced by CCPA, giving California residents greater control over their personal information. These enhanced rights reflect evolving expectations about privacy in digital services.
Consumers can now request that businesses disclose and delete their personal information, and they can opt out of the sale and targeted use of their data. The law also allows consumers to correct inaccurate information and limit the use of sensitive personal data.
These rights apply to businesses that meet specific thresholds, such as handling the personal information of 100,000 or more consumers, or deriving more than half of annual revenue from selling personal information. The scope is designed to cover large-scale data handlers and service providers.
Enforcement through the CPPA ensures that violations can be addressed with penalties and corrective actions. This dedicated oversight reinforces compliance and provides a structured process for handling consumer complaints related to data practices.
New Data Categories and Definitions
CPRA introduces a precise definition of sensitive personal information, which includes identifiers that reveal race, religion, health, precise geolocation, and certain biometric data. Businesses must treat this category with additional safeguards.
Data minimization principles require organizations to collect, use, retain, and share only the data that is reasonably necessary for specified purposes. This encourages leaner data practices and reduces exposure in the event of a breach.
The classification of service providers as contractors or independent processors clarifies obligations. Shared responsibilities mean businesses must verify that downstream partners adhere to CPRA standards and do not extend the data use beyond authorized purposes.
Age-based consent rules provide protections for minors by requiring opt-in consent for the sale of their personal information. These rules acknowledge the heightened privacy risks facing younger users online.
Key Compliance Obligations
Organizations must update privacy notices to describe categories of personal information collected, the purposes of use, and the rights available to consumers. Clear communication supports informed decision-making and reduces confusion.
Consent management mechanisms are essential for handling sensitive personal information and targeted advertising. Systems must record and honor user preferences reliably over time.
Data security standards under CPRA emphasize risk assessments and reasonable safeguards. Companies are expected to implement technical and organizational measures tailored to the sensitivity of the data they handle.
Training and accountability within organizations ensure that teams understand CPRA requirements and integrate privacy into product design and operations. Governance structures support long-term compliance and cultural alignment.
Comparison with CCPA
CPRA builds upon the foundation of CCPA by closing gaps and addressing modern data practices. The table below outlines key differences between these landmark privacy frameworks.
| Aspect | CCPA | CPRA | Significance |
|---|---|---|---|
| Definition of Sale | Broad, including data exchanges for value | Narrower, clarified opt-out for targeted advertising | Reduces ambiguity for consumers and businesses |
| New Data Category | Not present | Sensitive Personal Information | Triggers specific consent and control requirements |
| Enforcement Body | California Attorney General | California Privacy Protection Agency | Dedicated, specialized oversight and rulemaking |
| Contractor Rules | General obligations | Detailed duties and audits for service providers | Strengthened accountability across the data supply chain |
| Data Retention | Reasonable and related purpose | Explicitly aligned with use and necessity | Curtails indefinite retention and reduces risk |
Strategic Data Governance
CPRA compels organizations to rethink how they collect, process, and protect data. A strategic approach aligns privacy practices with business objectives while reducing regulatory risk.
Governance frameworks should map data flows and identify where sensitive personal information is stored or shared. Visibility into data lifecycle enables teams to apply appropriate controls at each stage.
Technology investments in consent management, data discovery, and audit logging support scalable compliance. Automation reduces manual effort and improves accuracy in responding to consumer requests.
Regular reviews of vendor relationships and data transfer mechanisms ensure continued adherence to CPRA standards. Documentation and policies act as evidence during assessments by the CPPA.
Next Steps for Organizations
Businesses preparing for CPRA should focus on practical measures that align operations with the regulation and demonstrate accountability to regulators and consumers.
- Map personal and sensitive data flows across systems and vendors
- Update privacy notices and preference controls to reflect CPRA rights
- Implement procedures for verifying age and obtaining opt-in consent where required
- Conduct vendor assessments and update contracts to clarify responsibilities
- Train staff on data minimization, security, and response workflows
FAQ
Reader questions
Does CPRA apply to businesses located outside California?
Yes, CPRA applies to for-profit businesses that collect personal information of California residents and meet specific threshold criteria, regardless of where the business is physically located.
How does CPRA define sensitive personal information?
CPRA defines sensitive personal information to include precise geolocation, race, religion, genetic data, biometric information, health data, and other identifiers that require heightened protection and consent.
What changes did CPRA make to automated decision-making rules?
CPRA regulates profiling that produces legal or similarly significant effects by requiring transparency, the right to correction, and meaningful explanations, along with documented risk assessments.
Are small businesses exempt from CPRA requirements?
Small businesses are generally exempt if they do not meet the threshold of handling large volumes of personal information or deriving most revenue from selling personal information, but obligations may still apply depending on activities.