Artifact GuideUSCCPA vs CPRA

California privacy law CCPA vs CPRA

The CPRA did not replace the CCPA. It amended and expanded it, so current programs should apply the CCPA as amended by the CPRA.

Use the comparison to identify which original controls still apply, what changed on January 1, 2023, and which records need updating.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The California Consumer Privacy Act of 2018 (CCPA) is the statute's name. The California Privacy Rights Act of 2020 (), approved as Proposition 24, amended that statute. Most CPRA amendments became operative on January 1, 2023. For current compliance decisions, cite the relevant section of the CCPA as amended rather than treating CCPA and CPRA as two parallel laws.

Side-by-side comparison

Original CCPA vs CPRA amendments

The left column describes the original 2018 framework. The right column identifies material changes now incorporated into the CCPA.

Review all sources
First framework
Original CCPA

The 2018 law created baseline notice, access, deletion, sale opt-out, non-discrimination, security, and enforcement requirements.

Second framework
CPRA amendments

Proposition 24 changed scope and expanded rights, duties, recipient controls, and regulatory enforcement within the same statute.

Comparison row 2

Covered-business thresholds

Original CCPA

The original CCPA covered a qualifying for-profit business doing business in California if it exceeded $25 million in annual gross revenue, handled personal information of at least 50,000 consumers, households, or devices, or earned at least 50% of annual revenue from selling consumers' personal information.

CPRA amendments

The amended test uses annual gross revenue above the statutory threshold, as adjusted under the law; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Affiliate, joint-venture, and voluntary-certification routes also require review.

Operational implication

A pre-2023 scope result may be wrong. Recalculate the current thresholds and document which route covers the entity.

Comparison row 3

Consumer rights

Original CCPA

The original CCPA provided rights to know, access, delete, opt out of sale, and receive equal service and price subject to the financial-incentive rules.

CPRA amendments

The added correction, extended opt-out to sharing, and created a right to limit certain uses and disclosures of sensitive personal information. The right to limit is conditional: it does not prohibit every use of sensitive personal information.

Operational implication

Update the privacy notice, request channels, response procedures, and downstream instructions. Do not describe the sensitive-information right as a blanket consent rule.

Comparison row 4

Collection, use, and retention

Original CCPA

The original CCPA centered on notice at collection and disclosure of categories, purposes, sales, and business-purpose disclosures.

CPRA amendments

The amended law requires collection, use, retention, and sharing to be reasonably necessary and proportionate to a disclosed compatible purpose. Notice at collection must state the intended retention period for each category, or the criteria used to determine it.

Operational implication

Tie each data category to a specific purpose and retention rule. A privacy notice alone does not prove that systems delete or restrict data on schedule.

Comparison row 5

Recipients and contracts

Original CCPA

The original CCPA distinguished businesses, service providers, and third parties and used contracts to support business-purpose disclosures.

CPRA amendments

The amended law adds the contractor role and requires agreements with third parties, service providers, and contractors to state limited and specified purposes, require applicable privacy protection, support monitoring, require notice if the recipient can no longer comply, and permit the business to stop and remediate unauthorized use.

Operational implication

Classify the recipient before choosing contract language. Calling every vendor a service provider does not make the statutory conditions true.

Comparison row 6

Enforcement and private claims

Original CCPA

The California Attorney General enforced the original CCPA. Consumers had a limited private action for specified security incidents, not a general right to sue for every CCPA violation.

CPRA amendments

The created the California Privacy Protection Agency, which can investigate and bring administrative enforcement actions. The Attorney General also retains civil enforcement authority. The statute does not provide a general private action for all privacy violations.

Operational implication

Track regulator-facing evidence and security-incident exposure separately. Do not describe every noncompliance issue as creating a consumer damages claim.

Practical decision rule

How to use this comparison

  • For current conduct, apply the CCPA as amended and the operative regulations.
  • Use the original-law column to identify legacy controls and historical differences, not as a separate present-day compliance program.
  • Record the exact section, factual trigger, owner, system change, exception, and evidence for each applicable requirement.
Section 1

What is the practical answer to CCPA vs CPRA?

Keep one California privacy program. Preserve original CCPA controls for notice, access, deletion, sale opt-out, non-discrimination, and reasonable security, then add the changes that apply to the business's facts.

The main additions are a right to correct inaccurate personal information; an opt-out from sharing for cross-context behavioral advertising; a right to limit certain uses and disclosures of sensitive personal information; purpose, proportionality, and retention limits; stronger contract requirements for recipients; and administrative enforcement by the California Privacy Protection Agency.

  • Recalculate business scope under the amended thresholds instead of relying on a pre-2023 CCPA assessment.
  • Map every disclosure as a sale, sharing, a business-purpose disclosure to a service provider or contractor, or another permitted disclosure.
  • Update request handling for correction and for deletion propagation to service providers, contractors, and relevant third parties.
  • State retention periods or the criteria used to set them, and keep personal information no longer than reasonably necessary for the disclosed purpose.
  • Test opt-out signals, notices, links, contracts, and downstream instructions with dated evidence.
Section 2

How should a team update its California privacy controls?

Start with the entity and data-flow facts. Confirm that the entity is a covered business, identify the California consumers and households involved, and classify each recipient. A company can be a business for one activity and a service provider, contractor, or third party for another.

Then connect each legal trigger to an owner and evidence. Privacy or legal teams can interpret scope, but product, engineering, marketing, procurement, security, and customer-support owners must be able to change the affected system or process.

  • Scope evidence: revenue and consumer-or-household calculations, sale or sharing revenue, affiliate relationships, and any claimed exemption.
  • Rights evidence: intake methods, identity verification, response logs, correction workflows, deletion exceptions, extension notices, and downstream instructions.
  • Advertising evidence: sale and sharing classification, Global Privacy Control handling, opt-out testing, and records showing that suppressed data is not reintroduced.
  • Sensitive-data evidence: category and purpose mapping, whether the use falls within permitted purposes, limitation methods, and service-provider instructions.
  • Contract evidence: limited and specified purposes, required privacy protections, monitoring rights, notice of inability to comply, and stop-and-remediate rights.
  • Governance evidence: current notices, retention rules, security measures, training, approvals, and the applicable cybersecurity-audit, risk-assessment, or automated-decisionmaking analysis.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Sections 1798.106, 1798.120, and 1798.121 establish correction, sale-or-sharing opt-out, and the conditional right to limit.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.