The CPRA amended the CCPA; it did not create a second privacy law for businesses to implement in parallel.
Use the comparison to understand the 2020 baseline and the changes operative from January 1, 2023. For present-day decisions, use the current CCPA statute and applicable regulations.
California voters approved Proposition 24, the California Privacy Rights Act (), in 2020. Its substantive amendments added rights and business duties to the California Consumer Privacy Act (CCPA), and most became operative on January 1, 2023. The California Privacy Protection Agency therefore refers to the present law as the CCPA or the CCPA as amended. This comparison is a change map, not a choice between two current regimes.
Historical change map
Original CCPA vs CPRA amendments
The left side summarizes the CCPA baseline operative in 2020. The right side shows material changes operative mainly from January 1, 2023. Current work must use the consolidated CCPA.
The CCPA as originally enacted established California consumer rights, business disclosures, a sale opt-out, contracting rules, and a limited private action for specified security breaches.
Second framework
CPRA amendments
Proposition 24 amended the CCPA's scope, definitions, rights, data-use limits, recipient contracts, and enforcement structure. These amendments now form part of the CCPA.
The original definition generally covered a qualifying for-profit entity doing business in California if it exceeded $25 million in annual gross revenue, annually handled personal information of at least 50,000 consumers, households, or devices, or derived at least 50% of annual revenue from selling consumers' personal information.
The amended definition uses an inflation-adjusted revenue threshold, raises the volume test to 100,000 consumers or households and removes devices from that test, and extends the revenue test to selling or sharing personal information. The CPPA states that the adjusted revenue threshold effective January 1, 2025 is $26.625 million.
Recalculate scope from current facts. A business can leave or enter scope because the volume, sharing, revenue, affiliate, joint-venture, or voluntary-certification rules differ from the original test.
The amendments added a right to correct inaccurate personal information, a right to opt out of sharing for cross-context behavioral advertising, and a right to limit specified uses and disclosures of sensitive personal information. The right to limit does not bar every use of sensitive information; the statute and regulations permit defined uses.
Update request intake, identity verification, response templates, propagation to service providers and contractors, and consumer-facing links. Do not present the sensitive-information right as a general deletion or consent right.
The amended CCPA requires collection, use, retention, and sharing to be reasonably necessary and proportionate to disclosed or compatible purposes. It also requires disclosure of retention periods or criteria and prohibits retaining personal information longer than reasonably necessary for the disclosed purpose.
Connect each data category to a disclosed purpose, necessity analysis, retention rule, deletion process, and change review. A generic privacy-policy statement does not replace this operational mapping.
The original law centered the opt-out on sale and used the service-provider role to support disclosures for a business purpose under a written contract.
The amendments added sharing for cross-context behavioral advertising, a contractor role, and more detailed contract restrictions for service providers, contractors, and third parties. A disclosure can be sharing even when no money changes hands.
Classify each recipient and purpose separately. Record whether the transfer is a sale, sharing, a business-purpose disclosure under a qualifying contract, a consumer-directed disclosure, or another statutory exception.
Temporary provisions limited many CCPA duties for employment-related information and personal information exchanged in specified business-to-business communications.
Those temporary exemptions became inoperative on January 1, 2023. California residents' rights now include employees, job applicants, and contacts for business customers, vendors, and independent contractors, subject to other applicable exemptions.
The original CCPA authorized California Attorney General enforcement and a limited private action for certain security breaches involving specified personal information.
The created the California Privacy Protection Agency with rulemaking, audit, investigation, and administrative enforcement powers while preserving Attorney General authority. It did not create a general consumer right to sue for every CCPA violation.
Prepare for CPPA and Attorney General inquiries, but assess private claims under Section 1798.150's specific security-breach conditions rather than assuming a general privacy cause of action.
The original definition generally covered a qualifying for-profit entity doing business in California if it exceeded $25 million in annual gross revenue, annually handled personal information of at least 50,000 consumers, households, or devices, or derived at least 50% of annual revenue from selling consumers' personal information.
The amended definition uses an inflation-adjusted revenue threshold, raises the volume test to 100,000 consumers or households and removes devices from that test, and extends the revenue test to selling or sharing personal information. The CPPA states that the adjusted revenue threshold effective January 1, 2025 is $26.625 million.
Recalculate scope from current facts. A business can leave or enter scope because the volume, sharing, revenue, affiliate, joint-venture, or voluntary-certification rules differ from the original test.
The amendments added a right to correct inaccurate personal information, a right to opt out of sharing for cross-context behavioral advertising, and a right to limit specified uses and disclosures of sensitive personal information. The right to limit does not bar every use of sensitive information; the statute and regulations permit defined uses.
Update request intake, identity verification, response templates, propagation to service providers and contractors, and consumer-facing links. Do not present the sensitive-information right as a general deletion or consent right.
The amended CCPA requires collection, use, retention, and sharing to be reasonably necessary and proportionate to disclosed or compatible purposes. It also requires disclosure of retention periods or criteria and prohibits retaining personal information longer than reasonably necessary for the disclosed purpose.
Connect each data category to a disclosed purpose, necessity analysis, retention rule, deletion process, and change review. A generic privacy-policy statement does not replace this operational mapping.
The original law centered the opt-out on sale and used the service-provider role to support disclosures for a business purpose under a written contract.
The amendments added sharing for cross-context behavioral advertising, a contractor role, and more detailed contract restrictions for service providers, contractors, and third parties. A disclosure can be sharing even when no money changes hands.
Classify each recipient and purpose separately. Record whether the transfer is a sale, sharing, a business-purpose disclosure under a qualifying contract, a consumer-directed disclosure, or another statutory exception.
Temporary provisions limited many CCPA duties for employment-related information and personal information exchanged in specified business-to-business communications.
Those temporary exemptions became inoperative on January 1, 2023. California residents' rights now include employees, job applicants, and contacts for business customers, vendors, and independent contractors, subject to other applicable exemptions.
The original CCPA authorized California Attorney General enforcement and a limited private action for certain security breaches involving specified personal information.
The created the California Privacy Protection Agency with rulemaking, audit, investigation, and administrative enforcement powers while preserving Attorney General authority. It did not create a general consumer right to sue for every CCPA violation.
Prepare for CPPA and Attorney General inquiries, but assess private claims under Section 1798.150's specific security-breach conditions rather than assuming a general privacy cause of action.
Apply the current CCPA as amended, using the statute and regulations in force for the activity and date at issue.
Use the original CCPA only to interpret pre-2023 conduct or to identify why a legacy control, notice, contract, or scope decision may now be incomplete.
Do not combine the columns into a 'stricter rule' test. The column consists of amendments to the same statute, so current requirements supersede or add to the earlier baseline.
Use the original CCPA column to interpret controls, notices, contracts, and request records built for the law that became operative on January 1, 2020. Use the column to identify what those controls needed after the amendments became operative on January 1, 2023.
For new or current processing, start with the consolidated CCPA. Confirm current business thresholds, covered data and exemptions, the entity's role, each consumer right, and the regulations that apply to the activity. A document labeled ' compliant' is not enough unless its controls map to the current statute and regulations.
Retest scope: the amended threshold counts 100,000 consumers or households and includes buying, selling, or sharing; the current gross-revenue threshold is adjusted for inflation.
Retest data and people: employment-related and business-to-business personal information no longer has the temporary exemptions that expired on December 31, 2022.
Retest user controls: add correction, sale-or-sharing opt-out, sensitive-personal-information limitation where applicable, and valid opt-out preference signal handling.
Retest governance: document purpose limitation, data minimization, retention, recipient contracts, and the California Privacy Protection Agency enforcement route.
Assign each control to the team that can change it: privacy or legal for interpretation, product and marketing for notices and ad-tech choices, engineering for request and signal handling, procurement for recipient contracts, and records owners for deletion and retention. Case-specific legal review is still needed when an exemption, entity relationship, or data use changes the result.
The review record should show the facts and source behind each decision, not only a policy label. Preserve the scope calculation, data-flow inventory, role classification, notice versions, request tests, opt-out preference signal tests, sensitive-information purposes, retention schedule, and executed contract terms.
Date legacy artifacts and state whether they implement the original CCPA or the CCPA as amended.
For every gap, name the affected data flow, statutory or regulatory requirement, owner, implementation ticket, evidence, and retest date.
Test exceptions at the data or processing level; an exemption for specified information does not necessarily exempt the whole organization.
Reassess after material changes to data collection, purposes, advertising partners, vendors, California market activity, or the governing law.