Artifact GuideUSCCPA vs CPRA

US CCPA CCPA vs CPRA

The CPRA amended the CCPA; it did not create a second privacy law for businesses to implement in parallel.

Use the comparison to understand the 2020 baseline and the changes operative from January 1, 2023. For present-day decisions, use the current CCPA statute and applicable regulations.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

California voters approved Proposition 24, the California Privacy Rights Act (), in 2020. Its substantive amendments added rights and business duties to the California Consumer Privacy Act (CCPA), and most became operative on January 1, 2023. The California Privacy Protection Agency therefore refers to the present law as the CCPA or the CCPA as amended. This comparison is a change map, not a choice between two current regimes.

Historical change map

Original CCPA vs CPRA amendments

The left side summarizes the CCPA baseline operative in 2020. The right side shows material changes operative mainly from January 1, 2023. Current work must use the consolidated CCPA.

Review all sources
First framework
Original CCPA baseline

The CCPA as originally enacted established California consumer rights, business disclosures, a sale opt-out, contracting rules, and a limited private action for specified security breaches.

Second framework
CPRA amendments

Proposition 24 amended the CCPA's scope, definitions, rights, data-use limits, recipient contracts, and enforcement structure. These amendments now form part of the CCPA.

Comparison row 2

Business scope thresholds

Original CCPA baseline

The original definition generally covered a qualifying for-profit entity doing business in California if it exceeded $25 million in annual gross revenue, annually handled personal information of at least 50,000 consumers, households, or devices, or derived at least 50% of annual revenue from selling consumers' personal information.

CPRA amendments

The amended definition uses an inflation-adjusted revenue threshold, raises the volume test to 100,000 consumers or households and removes devices from that test, and extends the revenue test to selling or sharing personal information. The CPPA states that the adjusted revenue threshold effective January 1, 2025 is $26.625 million.

Operational implication

Recalculate scope from current facts. A business can leave or enter scope because the volume, sharing, revenue, affiliate, joint-venture, or voluntary-certification rules differ from the original test.

Comparison row 3

Consumer rights

Original CCPA baseline

The original CCPA gave consumers rights to know, delete, opt out of sale, and receive equal treatment, subject to statutory conditions and exceptions.

CPRA amendments

The amendments added a right to correct inaccurate personal information, a right to opt out of sharing for cross-context behavioral advertising, and a right to limit specified uses and disclosures of sensitive personal information. The right to limit does not bar every use of sensitive information; the statute and regulations permit defined uses.

Operational implication

Update request intake, identity verification, response templates, propagation to service providers and contractors, and consumer-facing links. Do not present the sensitive-information right as a general deletion or consent right.

Comparison row 4

Purpose, minimization, and retention

Original CCPA baseline

The original CCPA required notice at collection and reasonable security, but it did not contain the 's express proportionality and retention language.

CPRA amendments

The amended CCPA requires collection, use, retention, and sharing to be reasonably necessary and proportionate to disclosed or compatible purposes. It also requires disclosure of retention periods or criteria and prohibits retaining personal information longer than reasonably necessary for the disclosed purpose.

Operational implication

Connect each data category to a disclosed purpose, necessity analysis, retention rule, deletion process, and change review. A generic privacy-policy statement does not replace this operational mapping.

Comparison row 5

Sale, sharing, and recipient contracts

Original CCPA baseline

The original law centered the opt-out on sale and used the service-provider role to support disclosures for a business purpose under a written contract.

CPRA amendments

The amendments added sharing for cross-context behavioral advertising, a contractor role, and more detailed contract restrictions for service providers, contractors, and third parties. A disclosure can be sharing even when no money changes hands.

Operational implication

Classify each recipient and purpose separately. Record whether the transfer is a sale, sharing, a business-purpose disclosure under a qualifying contract, a consumer-directed disclosure, or another statutory exception.

Comparison row 6

Employee and business contact data

Original CCPA baseline

Temporary provisions limited many CCPA duties for employment-related information and personal information exchanged in specified business-to-business communications.

CPRA amendments

Those temporary exemptions became inoperative on January 1, 2023. California residents' rights now include employees, job applicants, and contacts for business customers, vendors, and independent contractors, subject to other applicable exemptions.

Operational implication

Bring workforce and business-contact systems into the data inventory, notices, request workflow, retention review, and exemption analysis.

Comparison row 7

Regulator and private claims

Original CCPA baseline

The original CCPA authorized California Attorney General enforcement and a limited private action for certain security breaches involving specified personal information.

CPRA amendments

The created the California Privacy Protection Agency with rulemaking, audit, investigation, and administrative enforcement powers while preserving Attorney General authority. It did not create a general consumer right to sue for every CCPA violation.

Operational implication

Prepare for CPPA and Attorney General inquiries, but assess private claims under Section 1798.150's specific security-breach conditions rather than assuming a general privacy cause of action.

Practical decision rule

Which law should a team apply now?

  • Apply the current CCPA as amended, using the statute and regulations in force for the activity and date at issue.
  • Use the original CCPA only to interpret pre-2023 conduct or to identify why a legacy control, notice, contract, or scope decision may now be incomplete.
  • Do not combine the columns into a 'stricter rule' test. The column consists of amendments to the same statute, so current requirements supersede or add to the earlier baseline.
Section 1

How should teams use a CCPA vs CPRA comparison?

Use the original CCPA column to interpret controls, notices, contracts, and request records built for the law that became operative on January 1, 2020. Use the column to identify what those controls needed after the amendments became operative on January 1, 2023.

For new or current processing, start with the consolidated CCPA. Confirm current business thresholds, covered data and exemptions, the entity's role, each consumer right, and the regulations that apply to the activity. A document labeled ' compliant' is not enough unless its controls map to the current statute and regulations.

  • Retest scope: the amended threshold counts 100,000 consumers or households and includes buying, selling, or sharing; the current gross-revenue threshold is adjusted for inflation.
  • Retest data and people: employment-related and business-to-business personal information no longer has the temporary exemptions that expired on December 31, 2022.
  • Retest user controls: add correction, sale-or-sharing opt-out, sensitive-personal-information limitation where applicable, and valid opt-out preference signal handling.
  • Retest governance: document purpose limitation, data minimization, retention, recipient contracts, and the California Privacy Protection Agency enforcement route.
Section 2

What evidence should a migration review produce?

Assign each control to the team that can change it: privacy or legal for interpretation, product and marketing for notices and ad-tech choices, engineering for request and signal handling, procurement for recipient contracts, and records owners for deletion and retention. Case-specific legal review is still needed when an exemption, entity relationship, or data use changes the result.

The review record should show the facts and source behind each decision, not only a policy label. Preserve the scope calculation, data-flow inventory, role classification, notice versions, request tests, opt-out preference signal tests, sensitive-information purposes, retention schedule, and executed contract terms.

  • Date legacy artifacts and state whether they implement the original CCPA or the CCPA as amended.
  • For every gap, name the affected data flow, statutory or regulatory requirement, owner, implementation ticket, evidence, and retest date.
  • Test exceptions at the data or processing level; an exemption for specified information does not necessarily exempt the whole organization.
  • Reassess after material changes to data collection, purposes, advertising partners, vendors, California market activity, or the governing law.
Primary sources

References and citations

Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.