Skip to main content
Category: Privacy Regulations

California Privacy Rights Act

Also known as: CPRA, CPRA, California Privacy Rights Act of 2020
Simply put

The California Privacy Rights Act (CPRA) is a 2020 amendment to the California Consumer Privacy Act (CCPA) that strengthens privacy protections for California consumers. Among other changes, it adds a right for consumers to request that a business correct inaccurate personal information the business holds about them. It also established a dedicated regulator, the California Privacy Protection Agency, to help implement and enforce California's consumer privacy rules.

Formal definition

The CPRA is a ballot-initiative amendment to the CCPA, enacted in 2020, that expands and modifies California's consumer privacy regime rather than replacing it. It introduces additional consumer rights, including a right to request correction of inaccurate personal information maintained by a business, and it created the California Privacy Protection Agency (CalPrivacy) as the body responsible for implementing and enforcing California consumer privacy law, alongside related obligations such as those imposed on data brokers under the Delete Act. The evidence indicates the framework applies to businesses meeting certain thresholds, including entities that buy, sell, or share the personal information of large numbers of California consumers, though the precise threshold figures and applicability criteria should be confirmed against the current statutory and regulatory text. This entry defines scope and origin only; it does not detail the full set of consumer rights, business obligations, exemptions, cross-border or interstate applicability, enforcement mechanics, or penalty provisions, and CPRA treatment is specific to California and is not interchangeable with the EU GDPR, UK GDPR, or other US state privacy laws.

Why it matters

The CPRA matters because it reshaped California's consumer privacy landscape in two structurally significant ways: it expanded the substantive rights available to consumers and it created a dedicated enforcement body. Prior to the CPRA amendment, the CCPA framework did not include a standalone right for consumers to request correction of inaccurate personal information; the CPRA introduced that right, meaning businesses must now be prepared to receive, evaluate, and act on correction requests as part of their consumer rights handling processes. For compliance and privacy teams, this changes operational requirements beyond access and deletion workflows.

Equally important is the institutional change. The CPRA established the California Privacy Protection Agency (CalPrivacy) as a regulator responsible for implementing and enforcing California's consumer privacy rules, including the CCPA as amended and the Delete Act, which imposes additional requirements unique to data brokers. The existence of a dedicated agency signals sustained regulatory attention and rulemaking activity specific to California, which organizations must monitor rather than treating the framework as static.

Finally, the CPRA's applicability is scoped to businesses meeting certain thresholds, including entities that buy, sell, or share the personal information of large numbers of California consumers. Because the CPRA is a California-specific instrument and is not interchangeable with the EU GDPR, the UK GDPR, or other US state privacy laws, organizations operating across jurisdictions cannot assume that compliance with one regime satisfies another. The precise threshold figures and applicability criteria should be confirmed against the current statutory and regulatory text.

Who it's relevant to

Privacy program leads and DPOs at businesses serving California consumers
Organizations that meet the applicable thresholds, including entities that buy, sell, or share the personal information of large numbers of California consumers, need to account for CPRA-added rights in their programs. The introduction of a right to correct inaccurate personal information means correction request handling must sit alongside existing access and deletion processes. Threshold applicability should be confirmed against the current statutory text rather than assumed.
Data brokers subject to the Delete Act
CalPrivacy's enforcement remit includes the Delete Act, which the evidence indicates creates additional requirements unique to data brokers. Entities that operate as data brokers under California law should treat these as distinct obligations layered on top of the broader CCPA-as-amended framework. This entry does not detail those specific requirements, which must be reviewed in the relevant statutory and regulatory sources.
Compliance and legal teams managing multi-jurisdiction obligations
Because the CPRA is specific to California and is not interchangeable with the EU GDPR, the UK GDPR, or other US state privacy laws, teams operating across jurisdictions cannot rely on compliance with one regime to satisfy another. Comparable rights, such as a right to correction or rectification, may exist elsewhere but are governed by their own instruments with different scoping, exemptions, and enforcement.
Governance, data quality, and records stewards
The right to request correction of inaccurate personal information intersects with data quality and stewardship functions, since responding to correction requests depends on knowing where personal information is held and being able to update it consistently. This overlaps with, but is distinct from, information security controls; correction handling is primarily a governance and data-management responsibility, supported by demonstrable evidence of how requests are processed.

Inside CPRA

Amendment to the CCPA
The CPRA is not a standalone statute but an amendment that revises and expands the California Consumer Privacy Act (CCPA). It should be read as modifying the existing CCPA framework rather than replacing it entirely, and its treatment differs from other regimes such as the EU GDPR, UK GDPR, and HIPAA.
Sensitive Personal Information category
The CPRA introduces a distinct category of sensitive personal information within California law, with associated consumer rights to limit its use and disclosure. This is a California-specific construct and should not be treated as equivalent to the special category data concept under the EU or UK GDPR.
Expanded consumer rights
The CPRA adds consumer rights beyond those in the original CCPA, generally including rights to correct inaccurate personal information and to limit the use of sensitive personal information, alongside the existing rights to know, delete, and opt out of sale.
Business obligations
Under the CPRA, obligations generally fall on businesses that meet applicable thresholds, with distinct roles defined for service providers, contractors, and third parties. The allocation of accountability depends on how each party processes personal information and on the contractual terms in place.
Enforcement authority
The CPRA establishes a dedicated California enforcement body for privacy matters. The scope of enforcement mechanics, penalties, and procedural detail is not covered in this entry and should be verified against the current statutory text and regulations.

Common questions

Answers to the questions practitioners most commonly ask about CPRA.

Did the CPRA replace the CCPA entirely?
No. The CPRA is generally understood as an amendment to and expansion of the California Consumer Privacy Act (CCPA) rather than a wholly separate statute. It revised and added to the existing framework, so references to CCPA obligations remain relevant as amended. Treating the CPRA as a standalone regime that supersedes the CCPA misstates their relationship. This answer does not address specific effective dates or enforcement timelines; consult the current statutory text and regulations for those particulars.
Is the CPRA essentially the same as the EU GDPR since both introduce concepts like sensitive data and data minimization?
No. While the CPRA introduced a category often described as sensitive personal information and referenced principles such as data minimization and purpose limitation, it is a distinct instrument from the EU GDPR and should not be treated as interchangeable with it. Definitions, scope, the rights afforded, the lawful basis structure, and the mechanisms for compliance differ between the two regimes. The GDPR's special category data and the CPRA's sensitive personal information are not equivalent categories. Do not assume that a control designed for GDPR compliance satisfies CPRA obligations, or vice versa.
How should an organization determine whether the CPRA applies to it?
Applicability generally turns on thresholds and criteria set out in the amended statute, which typically consider factors such as doing business in California and meeting defined thresholds relating to revenue, the volume of consumers or households whose personal information is processed, or deriving revenue from selling or sharing personal information. Because the precise thresholds are set by statute and regulation, an organization should map its activities against the current statutory criteria rather than relying on general summaries. This entry does not restate specific numeric thresholds; verify them against the authoritative text.
What does the CPRA's recognition of a category of sensitive personal information mean for handling practices?
The CPRA introduced a category commonly referred to as sensitive personal information and associated rights that generally allow consumers to limit certain uses of that information. In practice this typically requires organizations to identify which data elements fall within that category, distinguish the handling of those elements from other personal information, and support the applicable consumer rights. Note that classifying data as sensitive under the CPRA does not import the same obligations that apply under other regimes, and encryption or tokenization of such data does not remove it from scope as personal information.
How does the CPRA affect the relationship between a business and its service providers or contractors?
The CPRA framework generally distinguishes among businesses and other parties such as service providers, contractors, and third parties, and it typically conditions certain designations on contractual terms governing the processing of personal information. Practically, organizations should review and, where needed, update contracts to reflect the required commitments and limitations on use so that a vendor can properly be treated in the intended role. The specific contractual elements are defined by the statute and implementing regulations; this answer does not enumerate them, and stated contractual language alone does not by itself guarantee compliance without corresponding operational practice.
What implementation steps help demonstrate accountability under the CPRA?
Accountability under the CPRA generally requires demonstrable evidence rather than stated intent alone. Practical steps commonly include maintaining current records of the personal information collected and its purposes, mapping data flows to support consumer rights requests, implementing mechanisms to honor rights such as access, correction, deletion, opt-out of sale or sharing, and limits on the use of sensitive personal information, and documenting policies and vendor arrangements. The adequacy of these measures depends on context and implementation, and this entry does not address enforcement penalties, retention specifics, or cross-border transfer mechanics.

Common misconceptions

The CPRA is a completely new law that replaced the CCPA.
The CPRA amends and expands the existing CCPA rather than replacing it. Practitioners should interpret CPRA provisions as modifications layered onto the CCPA framework, not as a wholly separate regime.
The CPRA's sensitive personal information category is the same as special category data under the GDPR.
The CPRA sensitive personal information concept is defined within California law and carries California-specific rights and limits. It is not interchangeable with the EU or UK GDPR special category data, and the two regimes treat such data differently.
Any business handling data of California residents is automatically subject to the CPRA.
CPRA obligations generally apply to entities that meet defined applicability thresholds and criteria as a business, with different roles and duties for service providers, contractors, and third parties. Applicability depends on the specific facts and should be assessed against the statute.

Best practices

Map your data processing activities to CPRA roles, distinguishing whether your organization acts as a business, service provider, contractor, or third party, since accountability and obligations differ by role.
Identify and separately catalog sensitive personal information as defined under California law, and implement mechanisms to honor consumer requests to limit its use and disclosure.
Review and update contractual terms with service providers, contractors, and third parties to reflect CPRA requirements rather than relying on legacy CCPA agreements.
Establish processes to support the expanded consumer rights, including correction of inaccurate personal information, alongside existing rights to know, delete, and opt out.
Maintain demonstrable evidence of your compliance measures, as accountability requires documented proof rather than stated intent.
Verify CPRA applicability thresholds, enforcement details, and penalty provisions against the current statutory text and regulations, and do not assume alignment with other regimes such as the GDPR or HIPAA.