CCPA vs CPRA
Last reviewed: · By Victor Humenhuk (CIPP/US certified)
The CPRA is not a separate statute. Approved by California voters as Proposition 24 in November 2020 and operative from January 1, 2023, it amended and expanded the CCPA, so the law now in force is the CCPA as amended by the CPRA. The amendments added a sensitive personal information category with a right to limit its use, a right to correction, an opt-out of sharing for cross-context behavioral advertising, purpose limitation and retention duties, risk assessments and cybersecurity audits, and a dedicated regulator, the California Privacy Protection Agency. Citing the CPRA as though it were a standalone law is a common and avoidable error.
Is the CPRA a separate law from the CCPA?
No, and this is the single most useful thing to fix. The CCPA was signed in June 2018 and took effect on January 1, 2020, with Attorney General enforcement beginning that July. The CPRA was a ballot initiative passed in November 2020 that rewrote large parts of the same title of the California Civil Code. Most of its provisions became operative on January 1, 2023, with a lookback to personal information collected from January 1, 2022. The topic on California as first mover sets out the sequence.
So there is one operative statute, usually cited as "the CCPA, as amended by the CPRA." When a question asks what the CPRA does, it is asking what the 2020 amendments changed, not what a rival law says.
The amendments also allowed the temporary carve-outs for employee and applicant data and for business-to-business contact data to expire on January 1, 2023. Since then, California's comprehensive privacy law has applied in full to employees and job applicants, while the other state comprehensive laws continue to exempt data processed in an employment context - a difference worth remembering.
CCPA vs CPRA: what the amendments changed
| CCPA as enacted (2020) | As amended by the CPRA (from 2023) | |
|---|---|---|
| Applicability thresholds | Annual gross revenue over $25 million; or buying, receiving, selling or sharing personal information of 50,000 or more consumers, households or devices; or 50% of annual revenue from selling personal information | Revenue over $25 million in the preceding calendar year; or buying, selling or sharing personal information of 100,000 or more consumers or households (devices dropped); or 50% of annual revenue from selling or sharing |
| Sensitive data | No separate category | Sensitive personal information defined, with a right to limit its use and disclosure to what is necessary to provide the service |
| Consumer rights | Know, delete, opt out of sale, non-discrimination | Adds correction, the right to limit sensitive data use, an opt-out of sharing, and access beyond the 12-month window for data collected from January 1, 2022 |
| Ad-tech disclosures | Covered only if they met the definition of a sale | "Sharing" for cross-context behavioral advertising is separately regulated whether or not consideration changes hands |
| Business duties | Notice, response to requests, service provider contracts | Adds purpose limitation, data minimization, storage limitation with published retention periods, and prescribed contract terms for service providers, contractors and third parties |
| Risk and security | Not addressed | Authorizes regulations requiring cybersecurity audits, risk assessments for high-risk processing, and rules on automated decision-making technology |
| Regulator | Attorney General only | The California Privacy Protection Agency, a five-member body with rulemaking and administrative enforcement power; the Attorney General retains civil enforcement |
| Cure period | Mandatory 30-day cure before an AG enforcement action | Mandatory cure removed; any opportunity to cure is discretionary |
| Minors | Opt-in required before selling the personal information of consumers under 16 | Extended to sharing, with the higher penalty tier applying to violations involving consumers under 16 |
| Employee and B2B data | Temporarily exempt | Exemptions expired on January 1, 2023 |
How enforcement and penalties changed
Under the original CCPA, the Attorney General had to give a business 30 days to cure an alleged violation before bringing an action. The CPRA deleted that mandatory cure period, so a business no longer has a guaranteed second chance; the Agency and the Attorney General may take a good-faith cure into account, but they are not required to offer one.
Administrative penalties are set at up to $2,500 per violation and up to $7,500 for an intentional violation or a violation involving the personal information of a consumer the business knows is under 16. The $25 million revenue threshold, by contrast, is adjusted for inflation, so check the current figure before applying the applicability test rather than assuming the number in the original text.
The private right of action remains narrow and is the only route by which a consumer can sue directly. It applies to a breach of nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security, and it allows statutory damages of $100 to $750 per consumer per incident, or actual damages if greater. The CPRA extended the categories it covers to include an email address combined with a password or security question and answer that would permit access to the account.
The California Privacy Protection Agency issued its first substantial package of CPRA regulations in 2023, and adopted a further package in 2025 addressing automated decision-making technology, risk assessments and cybersecurity audits, with obligations phased in over the following years.
What does this mean for how you cite the law?
Three habits will keep you accurate:
- Refer to obligations as CCPA obligations. The correction right, the sharing opt-out and the sensitive data limit are rights under the CCPA as amended - the CPRA is the amending instrument, not a separate source of ongoing obligations.
- Watch the vocabulary that only California uses. "Sharing," "contractor," "cross-context behavioral advertising" and the right to "limit" sensitive data are Californian. Other states use "targeted advertising" and generally require opt-in consent for sensitive data rather than an opt-out.
- Do not treat the CPRA as the model for other states. Most state comprehensive laws follow the Virginia and Colorado pattern instead, which uses "personal data," a controller and processor structure, and opt-in consent for sensitive data.
The same care applies to the sensitive data category itself, covered in the topic on sensitive personal information: California gives a right to limit use, not a consent gate, and the two are frequently swapped in exam questions.
Related study notes
- California as First Mover - CCPA and CPRA
- Sensitive Personal Information
- Consumer Rights Overview and Response Timelines
- Enforcement - Penalties and Enforcers
- Cure Periods and the Private Right of Action
Frequently asked questions
Did the CPRA replace the CCPA?
No. The CPRA amended the CCPA. There is one statute in force, generally cited as the CCPA as amended by the CPRA, and the CPRA's changes became operative on January 1, 2023.
Do California employees have privacy rights over their own HR data?
Yes. The temporary exemptions for employee, applicant and business-to-business contact data expired on January 1, 2023, so employees and job applicants exercise the same rights as any other consumer, including access, deletion and correction.
What is the difference between selling and sharing?
A sale is a disclosure to a third party for monetary or other valuable consideration. Sharing is a disclosure to a third party for cross-context behavioral advertising, whether or not any consideration is exchanged. Both are covered by the same Do Not Sell or Share My Personal Information link.
Can consumers sue under the CCPA?
Only in one situation. The private right of action is limited to a breach of nonencrypted, nonredacted personal information resulting from a failure to implement reasonable security, with statutory damages of $100 to $750 per consumer per incident or actual damages if greater. All other violations are enforced by the Attorney General or the CPPA.
Test yourself
Try the free CIPP/US practice questions, or read the full CIPP/US study guide - free.