The California Consumer Privacy Act of 2018 (CCPA) is the statute's name. The California Privacy Rights Act of 2020 (), approved as Proposition 24, amended that statute. Most CPRA amendments became operative on January 1, 2023. For current compliance decisions, cite the relevant section of the CCPA as amended rather than treating CCPA and CPRA as two parallel laws.
Side-by-side comparison
Original CCPA vs CPRA amendments
The left column describes the original 2018 framework. The right column identifies material changes now incorporated into the CCPA.
The original CCPA covered a qualifying for-profit business doing business in California if it exceeded $25 million in annual gross revenue, handled personal information of at least 50,000 consumers, households, or devices, or earned at least 50% of annual revenue from selling consumers' personal information.
The amended test uses annual gross revenue above the statutory threshold, as adjusted under the law; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Affiliate, joint-venture, and voluntary-certification routes also require review.
The original CCPA provided rights to know, access, delete, opt out of sale, and receive equal service and price subject to the financial-incentive rules.
The added correction, extended opt-out to sharing, and created a right to limit certain uses and disclosures of sensitive personal information. The right to limit is conditional: it does not prohibit every use of sensitive personal information.
Update the privacy notice, request channels, response procedures, and downstream instructions. Do not describe the sensitive-information right as a blanket consent rule.
The amended law requires collection, use, retention, and sharing to be reasonably necessary and proportionate to a disclosed compatible purpose. Notice at collection must state the intended retention period for each category, or the criteria used to determine it.
Tie each data category to a specific purpose and retention rule. A privacy notice alone does not prove that systems delete or restrict data on schedule.
The amended law adds the contractor role and requires agreements with third parties, service providers, and contractors to state limited and specified purposes, require applicable privacy protection, support monitoring, require notice if the recipient can no longer comply, and permit the business to stop and remediate unauthorized use.
The California Attorney General enforced the original CCPA. Consumers had a limited private action for specified security incidents, not a general right to sue for every CCPA violation.
The created the California Privacy Protection Agency, which can investigate and bring administrative enforcement actions. The Attorney General also retains civil enforcement authority. The statute does not provide a general private action for all privacy violations.
Track regulator-facing evidence and security-incident exposure separately. Do not describe every noncompliance issue as creating a consumer damages claim.
The original CCPA covered a qualifying for-profit business doing business in California if it exceeded $25 million in annual gross revenue, handled personal information of at least 50,000 consumers, households, or devices, or earned at least 50% of annual revenue from selling consumers' personal information.
The amended test uses annual gross revenue above the statutory threshold, as adjusted under the law; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Affiliate, joint-venture, and voluntary-certification routes also require review.
The original CCPA provided rights to know, access, delete, opt out of sale, and receive equal service and price subject to the financial-incentive rules.
The added correction, extended opt-out to sharing, and created a right to limit certain uses and disclosures of sensitive personal information. The right to limit is conditional: it does not prohibit every use of sensitive personal information.
Update the privacy notice, request channels, response procedures, and downstream instructions. Do not describe the sensitive-information right as a blanket consent rule.
The amended law requires collection, use, retention, and sharing to be reasonably necessary and proportionate to a disclosed compatible purpose. Notice at collection must state the intended retention period for each category, or the criteria used to determine it.
Tie each data category to a specific purpose and retention rule. A privacy notice alone does not prove that systems delete or restrict data on schedule.
The amended law adds the contractor role and requires agreements with third parties, service providers, and contractors to state limited and specified purposes, require applicable privacy protection, support monitoring, require notice if the recipient can no longer comply, and permit the business to stop and remediate unauthorized use.
The California Attorney General enforced the original CCPA. Consumers had a limited private action for specified security incidents, not a general right to sue for every CCPA violation.
The created the California Privacy Protection Agency, which can investigate and bring administrative enforcement actions. The Attorney General also retains civil enforcement authority. The statute does not provide a general private action for all privacy violations.
Track regulator-facing evidence and security-incident exposure separately. Do not describe every noncompliance issue as creating a consumer damages claim.
Keep one California privacy program. Preserve original CCPA controls for notice, access, deletion, sale opt-out, non-discrimination, and reasonable security, then add the changes that apply to the business's facts.
The main additions are a right to correct inaccurate personal information; an opt-out from sharing for cross-context behavioral advertising; a right to limit certain uses and disclosures of sensitive personal information; purpose, proportionality, and retention limits; stronger contract requirements for recipients; and administrative enforcement by the California Privacy Protection Agency.
Recalculate business scope under the amended thresholds instead of relying on a pre-2023 CCPA assessment.
Map every disclosure as a sale, sharing, a business-purpose disclosure to a service provider or contractor, or another permitted disclosure.
Update request handling for correction and for deletion propagation to service providers, contractors, and relevant third parties.
State retention periods or the criteria used to set them, and keep personal information no longer than reasonably necessary for the disclosed purpose.
Test opt-out signals, notices, links, contracts, and downstream instructions with dated evidence.
How should a team update its California privacy controls?
Start with the entity and data-flow facts. Confirm that the entity is a covered business, identify the California consumers and households involved, and classify each recipient. A company can be a business for one activity and a service provider, contractor, or third party for another.
Then connect each legal trigger to an owner and evidence. Privacy or legal teams can interpret scope, but product, engineering, marketing, procurement, security, and customer-support owners must be able to change the affected system or process.
Scope evidence: revenue and consumer-or-household calculations, sale or sharing revenue, affiliate relationships, and any claimed exemption.
Rights evidence: intake methods, identity verification, response logs, correction workflows, deletion exceptions, extension notices, and downstream instructions.
Advertising evidence: sale and sharing classification, Global Privacy Control handling, opt-out testing, and records showing that suppressed data is not reintroduced.
Sensitive-data evidence: category and purpose mapping, whether the use falls within permitted purposes, limitation methods, and service-provider instructions.
Contract evidence: limited and specified purposes, required privacy protections, monitoring rights, notice of inability to comply, and stop-and-remediate rights.
Governance evidence: current notices, retention rules, security measures, training, approvals, and the applicable cybersecurity-audit, risk-assessment, or automated-decisionmaking analysis.