The California Consumer Privacy Act (CCPA) reached its final legislative form on September 6, 2019. Soon after, the California Privacy Rights Act (CPRA) arrived in 2020, creating a critical decision point for your privacy program. You must decide which framework governs your compliance obligations.
This decision is not just theoretical. It impacts your data mapping, consumer rights infrastructure, and disclosure language. If you choose incorrectly, you risk over-engineering unnecessary controls or missing requirements that could lead to enforcement actions.
The Decision You Are Facing
You need to determine whether your organization operates under CCPA (as amended through 2019), CPRA (effective January 1, 2023), or both during a transition period. This choice affects:
- Which consumer rights you must honor
- How you handle sensitive personal information
- Your vendor contract terms and data processing agreements
- Your annual revenue thresholds and applicability triggers
- Your enforcement risk profile and penalty exposure
The California Attorney General enforces CCPA violations, while the California Privacy Protection Agency enforces CPRA violations. Knowing which authority has jurisdiction over your activities is crucial for assessing regulatory risk.
Key Factors That Affect Your Choice
Revenue and data volume thresholds
CCPA applies if you meet one of three conditions: annual gross revenues over $25 million, buying or selling personal information of 50,000 or more California residents annually, or deriving 50% or more of annual revenues from selling California residents' personal information.
CPRA maintains the $25 million revenue threshold but changes the second trigger to 100,000 consumers or households. Under CPRA, a household of four counts as one unit, unlike CCPA's original standard where each individual counts separately.
Enforcement date and lookback period
CCPA became enforceable on July 1, 2020. CPRA's enforcement began on July 1, 2023. The date of the processing activity determines which law applies and which enforcement authority has jurisdiction.
Sensitive personal information categories
CPRA introduced a "sensitive personal information" classification, including precise geolocation, racial or ethnic origin, religious beliefs, genetic data, private communications, and account credentials. If you process these categories, CPRA's right to limit use and disclosure applies, requiring a separate consumer control beyond opt-out.
Contractor vs. service provider definitions
CPRA created a "contractor" category distinct from "service provider." Contractors process personal information on behalf of the business but aren't subject to the same contractual restrictions as service providers. Your vendor agreements need to reflect which category applies, depending on whether CCPA or CPRA governs the relationship.
Path A: You Operate Under CCPA (Original Framework)
Choose this path if:
- Your last relevant processing activity occurred before January 1, 2023
- You're conducting a historical audit or investigating pre-2023 violations
- You're a small business that met CCPA's original triggers but fall below CPRA's revised thresholds
What this means for compliance:
You must honor four consumer rights: right to know, right to delete, right to opt out of sale, and right to non-discrimination. You don't need to implement CPRA's right to correct or right to limit use of sensitive personal information.
Your notice at collection must describe the categories of personal information you collect and the purposes for which you use them. CPRA's retention period disclosure or sensitive personal information notice isn't required.
Your vendor contracts need service provider language per Civil Code Section 1798.140(ag), restricting the service provider from retaining, using, or disclosing personal information for any purpose other than performing the services specified in the contract.
Path B: You Operate Under CPRA (Current Framework)
Choose this path if:
- You process California residents' personal information on or after January 1, 2023
- You meet CPRA's applicability thresholds, particularly the 100,000 consumer/household trigger
- You handle sensitive personal information as defined in Civil Code Section 1798.140(ae)
What this means for compliance:
You must honor six consumer rights: the original four from CCPA plus the right to correct inaccurate personal information and the right to limit use and disclosure of sensitive personal information.
Your notice at collection must include retention periods for each category of personal information or the criteria used to determine those periods. If you process sensitive personal information, you need a separate notice and opt-out mechanism.
Your vendor agreements must distinguish between service providers and contractors. Service providers need the restrictive contract terms from CCPA. Contractors need terms that reflect their more limited processing but don't require the same restrictions.
You must conduct regular cybersecurity audits if you process significant volumes of personal information. CPRA's Section 1798.150(c) creates a private right of action for data breaches resulting from failure to implement reasonable security procedures.
Path C: You're Transitioning Between Frameworks
Choose this path if:
- You have ongoing processing activities that span the January 1, 2023 effective date
- You're managing consumer requests submitted under CCPA but requiring CPRA-level responses
- You have multi-year vendor contracts that predate CPRA
What this means for compliance:
Apply the more protective standard. If a consumer submitted a request in 2022 under CCPA but you're fulfilling it in 2023, honor CPRA rights even if they weren't technically available when the request arrived.
Amend your vendor contracts to reflect CPRA's contractor/service provider distinction. You can't wait for renewal cycles. Civil Code Section 1798.140(j) requires that service provider contracts include specific provisions, and operating without them creates direct liability.
Implement both CCPA and CPRA disclosures during the transition. Your privacy notice should explain which framework governed historical processing and which governs current activities. This transparency reduces confusion when consumers exercise rights and expect specific outcomes.
Summary Matrix
| Factor | CCPA Path | CPRA Path | Transition Path |
|---|---|---|---|
| Applicability trigger | 50,000+ individuals | 100,000+ consumers/households | Apply both tests |
| Consumer rights count | 4 core rights | 6 rights (adds correction, limit SPI) | Honor all 6 |
| Vendor contracts | Service provider only | Service provider + contractor | Amend existing contracts |
| Sensitive PI handling | No separate category | Separate opt-out required | Implement SPI controls |
| Enforcement authority | Attorney General | Privacy Protection Agency | Coordinate with both |
| Retention disclosure | Not required | Required in notice | Add to all notices |
| Cybersecurity audit | Not mandated | Required for high volume | Implement now |
The choice isn't always clear. Many organizations will operate under CPRA for new processing while managing CCPA obligations for historical activities. The key is documenting which framework governs each processing operation and ensuring your consumer-facing disclosures match your actual compliance posture.
When Governor Gavin Newsom signed the final CCPA amendments, he set a compliance clock that's still ticking. Whether you're operating under the original framework or its expanded successor, the requirement is the same: match your controls to the law that actually applies.



