California Privacy Rights Act
The California Privacy Rights Act (CPRA) is a 2020 amendment to the California Consumer Privacy Act (CCPA) that strengthens privacy protections for California consumers. Among other changes, it adds a right for consumers to request that a business correct inaccurate personal information the business holds about them. It also established a dedicated regulator, the California Privacy Protection Agency, to help implement and enforce California's consumer privacy rules.
The CPRA is a ballot-initiative amendment to the CCPA, enacted in 2020, that expands and modifies California's consumer privacy regime rather than replacing it. It introduces additional consumer rights, including a right to request correction of inaccurate personal information maintained by a business, and it created the California Privacy Protection Agency (CalPrivacy) as the body responsible for implementing and enforcing California consumer privacy law, alongside related obligations such as those imposed on data brokers under the Delete Act. The evidence indicates the framework applies to businesses meeting certain thresholds, including entities that buy, sell, or share the personal information of large numbers of California consumers, though the precise threshold figures and applicability criteria should be confirmed against the current statutory and regulatory text. This entry defines scope and origin only; it does not detail the full set of consumer rights, business obligations, exemptions, cross-border or interstate applicability, enforcement mechanics, or penalty provisions, and CPRA treatment is specific to California and is not interchangeable with the EU GDPR, UK GDPR, or other US state privacy laws.
Why it matters
The CPRA matters because it reshaped California's consumer privacy landscape in two structurally significant ways: it expanded the substantive rights available to consumers and it created a dedicated enforcement body. Prior to the CPRA amendment, the CCPA framework did not include a standalone right for consumers to request correction of inaccurate personal information; the CPRA introduced that right, meaning businesses must now be prepared to receive, evaluate, and act on correction requests as part of their consumer rights handling processes. For compliance and privacy teams, this changes operational requirements beyond access and deletion workflows.
Equally important is the institutional change. The CPRA established the California Privacy Protection Agency (CalPrivacy) as a regulator responsible for implementing and enforcing California's consumer privacy rules, including the CCPA as amended and the Delete Act, which imposes additional requirements unique to data brokers. The existence of a dedicated agency signals sustained regulatory attention and rulemaking activity specific to California, which organizations must monitor rather than treating the framework as static.
Finally, the CPRA's applicability is scoped to businesses meeting certain thresholds, including entities that buy, sell, or share the personal information of large numbers of California consumers. Because the CPRA is a California-specific instrument and is not interchangeable with the EU GDPR, the UK GDPR, or other US state privacy laws, organizations operating across jurisdictions cannot assume that compliance with one regime satisfies another. The precise threshold figures and applicability criteria should be confirmed against the current statutory and regulatory text.
Who it's relevant to
Inside CPRA
Common questions
Answers to the questions practitioners most commonly ask about CPRA.