Compared to many other US states, California privacy laws are some of the most comprehensive and forward-looking. However, the relationship between the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) is not always clear for businesses who need to comply. The CCPA and CPRA are often referred to together when discussing California privacy law, so it's important to understand how they interact.
The CCPA was the first comprehensive privacy law in California, and of any US state. It was effective from 1 January 2020. The CPRA later expanded and strengthened the CCPA, with new rules effective from 1 January 2023. Together, the CCPA/CPRA govern how businesses collect, use, and share the personal information of consumers. Throughout this article, references to the CCPA/CPRA mean "the CCPA as amended by the CPRA".
The CPRA amendments included a new definition of "sensitive data", new rights for consumers including rights to correct, opt-out of sharing data, rights about automated decision-making technology (ADMT) and the right to limit the use of sensitive data. The CPRA established the California Privacy Protection Agency (CPPA), and increased restrictions on businesses holding personal data for longer than necessary.
The CCPA as amended by the CPRA aims to protect the privacy rights of consumers, particularly the sale and sharing of personal data. For-profit businesses doing business in California must comply when they meet certain thresholds for revenue, data volume collected, or volumes of data sold or shared.
This article explains what the CCPA/CPRA is, who needs to comply, key definitions. This article also covers consumer rights and business obligations, penalties, and how to comply, including within the greater US-state-law context. You'll find a Privacy Policy template, enforcement examples, a compliance checklist, and a FAQ at the end.
CCPA/CPRA compliance requires several documents, including a Privacy Policy. TermsFeed helps businesses with this, using the TermsFeed Privacy Policy generator. Policies can be generated for specific laws, including the CCPA/CPRA.
Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:
-
At Step 1, select the Website option or App option or both.
-
Answer some questions about your website or app.
-
Answer some questions about your business.
-
Enter the email address where you'd like the Privacy Policy delivered and click "Generate."
You'll be able to instantly access and download your new Privacy Policy.
- 1. What is the CCPA?
- 2. What is the CPRA?
- 3. Does the CPRA Replace the CCPA?
- 4. CCPA vs CPRA at a Glance (Comparison Table)
- 5. Who Must Comply With the CCPA/CPRA?
- 5.1. CCPA Applicability Thresholds
- 5.2. CPRA Applicability Thresholds
- 5.3. Employee, B2B, and Health Data (Exemptions Removed)
- 6. Key Definitions You Need to Know
- 6.1. Personal Information
- 6.2. Sensitive Personal Information (SPI)
- 6.3. 'Sale' of Personal Information
- 6.4. "Sharing" of Personal Information (Cross-Context Behavioral Advertising)
- 6.5. The Four Regulated Entities: Business, Service Provider, Contractor, Third Party
- 7. Consumer Rights Under the CCPA/CPRA
- 7.1. Core Consumer Rights Under the Original CCPA
- 7.2. New Rights Added by the CPRA
- 7.3. Expanded Rights Under the CPRA
- 7.4. New Rights Added Through Later CPRA Regulations
- 7.5. Rights of Minors Under the CCPA/CPRA
- 8. Data Subject Access Requests (DSARs)
- 9. Business Obligations Under the CCPA/CPRA
- 9.1. Notice at Collection
- 9.2. Privacy Policy Requirements
- 9.3. Data Minimization, Purpose Limitation, and Storage Limitation
- 9.4. Reasonable Security, Cybersecurity Audits, and Risk Assessments
- 9.5. Vendor, Contractor, and Service-Provider Contracts
- 9.6. The "Do Not Sell or Share" and "Limit the Use of My SPI" Links
- 10. Consent Under the CCPA/CPRA
- 11. Enforcement: The CPPA and the Attorney General
- 12. Penalties and the Private Right of Action
- 13. How to Comply With the CCPA/CPRA (Step-by-Step)
- 14. CCPA/CPRA Compliance Checklist
- 15. How to Write a CCPA/CPRA-Compliant Privacy Policy
- 15.1. Information you collect
- 15.2. What purposes you collect information for
- 15.3. Who you share the information with
- 15.4. How long you keep the information you collect
- 15.5. How consumers can contact you
- 15.6. How you keep personal information secure
- 16. CCPA/CPRA Privacy Policy Template
- 17. Where to Display Your CCPA/CPRA Privacy Policy
- 17.1. Website footer
- 17.2. App download page
- 17.3. Checkout page
- 17.4. Account creation and login forms
- 17.5. Within California-specific privacy notices or supplements
- 18. How to Implement "Do Not Sell or Share" and Global Privacy Control
- 19. CCPA/CPRA vs Other US State Privacy Laws
- 20. CCPA/CPRA Enforcement Examples and Fines
- 21. CPRA vs CCPA: Frequently Asked Questions
- 22. Summary and Key Takeaways
What is the CCPA?
The California Consumer Privacy Act (CCPA) is the first comprehensive state-level consumer privacy law in the US. It was signed into law on 28 June, 2018, and was effective from 1 January 2020.
The CCPA gave California residents new rights over their data. These rights include the right to know what data is being collected, the right to delete data, the right to opt out of the sale or sharing of their data, and the right to receive equal services (non-discrimination).
It imposes obligations on businesses, service providers, and third parties who deal with personal data, to ensure that these privacy rights are respected and upheld.
The CCPA was originally enforced by the Attorney General alone. The CCPA is often compared to the GDPR, as a California law that reflects the principles and approach of the GDPR privacy protections.
What is the CPRA?
The California Privacy Rights Act (CPRA) is an amendment to the CCPA, which significantly strengthened the existing law. Often referred to as CCPA 2.0, the CPRA originated as a ballot proposition, Proposition 24, which California voters approved on November 3, 2020. Rather than replacing the CCPA, the CPRA amended it, so the two work together as one law.
The CPRA introduced a number of additional rights for consumers, including the right to correct inaccurate information that a business has about them, and the right to limit the use and disclosure of sensitive information about them.
Part of the approach to strengthening privacy rights under the CPRA included incorporating GDPR-style principles. These principles include data minimization, purpose limitation, storage limitation, and the establishment of a new, additionally protected category of "sensitive personal information".
The CPRA introduced new regulations for data sharing, rather than only data selling. This means even if no money is exchanged, the rules of the CPRA still apply. Data sharing includes data that is shared during targeted advertising and setting cookies.
The CPRA established the California Privacy Protection Agency (CPPA), the agency that investigates and enforces the rules in the CCPA as amended by the CPRA. Provisions became operative from 1 January 2023, and enforcement by the CPPA began from 1 July 2023.
Does the CPRA Replace the CCPA?
No, the CPRA amends and expands the CCPA. It does not replace it.
The CPRA added new provisions to the CCPA and amended existing ones. This means that CCPA provisions unaffected by the CPRA simply stayed in force, and still need to be complied with.
Legally, the CPRA is more like an amendment than a completely new law. The result is that the law is considered as one unified piece of legislation.
California agencies like the CPPA refer to the law as the CCPA, or "the CCPA as amended".
CCPA vs CPRA at a Glance (Comparison Table)
The table below shows how the original CCPA changed after it was expanded and amended by the CPRA.
| Dimension | CCPA | CPRA |
| Effective date | Jan 1, 2020 | Jan 1, 2023 |
| Enforcement | Attorney General | CPPA and Attorney General |
| Applicability threshold | 50,000 consumers | 100,000 consumers |
| Revenue test | Selling data | Selling or sharing data |
| Sensitive personal information | Doesn't exist as a category | Established as a new category, highly regulated |
| Data "sharing" | Not regulated | Newly regulated |
| Consumer rights | Rights to know, delete, and opt out of the sale of data | Rights to know, delete, and opt out of the sale of data, as well as the right to correct data, limit the sale and sharing of sensitive personal information, the right to opt out of ADMT, the right to access information about ADMT, and the right to data portability |
| Data minimization and retention | Not required | Required |
| Cure period | 30-day automatic cure period before regulatory enforcement action | 30-day cure period is no longer automatic, but rather discretionary for regulator enforcement action. Still applies to private right of action for consumers |
| Private right of action | Limited to data breaches of non-encrypted and non-redacted personal information, of specific data types such as SSN, government ID, medical information | Expanded to breaches of login credentials when an email address is revealed along with a password or security question answer |
| Penalties | $2,500/$7,500 | $2,663/$7,988 (inflation adjusted), with the higher tier of fines for violations against minors |
Who Must Comply With the CCPA/CPRA?
If you do business in California and meet certain thresholds, the CCPA as amended by the CPRA applies to you.
The initial thresholds for the CCPA were changed by the CPRA. You must now comply with the thresholds set out in the CCPA as amended by the CPRA.
The CCPA as amended by the CPRA has extraterritorial reach. This means your business doesn't need to be based in California to meet these thresholds and for the CCPA to apply to you.
There are three threshold tests:
- The gross revenue test
- The data volume test
- The revenue from selling or sharing test
Meeting any one of them means you need to comply. These tests are described in further detail in the section below.
The CPRA amendment increased the data volume test from 50,000 to 100,000 California households or consumers, and removed "devices" from this test. It also expanded the 50% annual revenue test to include "sharing" data, rather than just selling.
There were initial exemptions for employee and B2B data under the CCPA. However, these exemptions expired on 1 January 2023 when the CPRA came into force.
CCPA Applicability Thresholds
The original CCPA applied to for-profit businesses that met any one of three thresholds.
Meeting any one of these three thresholds meant you needed to comply with the original CCPA:
- Having an annual gross revenue exceeding $25 million in the previous calendar year
- Buying or selling the data of 50,000 or more California consumers, households, or devices in the past year
- Deriving 50% or more of your annual revenue from selling data of California residents in the past year
Essentially, the law applies to for-profit entities that collect and process, sell or share the personal information of California consumers.
CPRA Applicability Thresholds
The CPRA raised the thresholds that trigger compliance. The following are the thresholds that now apply under the CCPA/CPRA. Meeting any one of these three thresholds requires you to comply with the CCPA, as amended by the CPRA:
- Having an annual gross revenue exceeding $26.625 million (inflation adjusted) in the previous calendar year
- Buying, selling, or sharing the data of 100,000 or more California consumers or households in the past year (doubled from 50,000, and the CPRA removed devices)
- Deriving 50% or more of your annual revenue from selling OR sharing data of California residents in the past year
The effect of this is that some small- and medium-size businesses are no longer captured by the CCPA, because they do not deal with more than 100,000 California consumers or households. However, data sharing and selling businesses are newly required to comply.
Employee, B2B, and Health Data (Exemptions Removed)
The CPRA removed the temporary exemptions for employee and B2B data under the CCPA.
Employee (HR) data and B2B communication were temporarily exempt under the CCPA. The CPRA removed those exemptions from 1 January 2023. This means that employee data and B2B communication are now also covered by the CCPA and have the same protections as consumer data.
As a result, the CPRA effectively expanded the definition of "consumer" to include "employee", as HR data is now captured by the law.
Data covered by the Health Insurance Portability and Accountability Act (HIPAA) is partially exempt from the CCPA. However, the CPRA added stricter data-sharing requirements that also apply to other health data.
For example, health data collected by consumer health apps, wearable devices, or wellness tracking websites, may not be covered by HIPAA but will be covered by the CCPA. This information is likely classified as "sensitive personal information", and consumers have the right to limit the use and disclosure of this data.
Key Definitions You Need to Know
The CCPA as amended by the CPRA turns on a few defined terms. These definitions are important as the compliance burden for your business depends on what counts as personal information, sensitive information, and who is a regulated entity. The definitions of sharing and selling are important to understand, so you know what activities will be captured by the law.
Personal Information
Personal information is information that identifies, relates to, describes, or links to a particular consumer or household.
It includes information that is "reasonably capable" of doing these things. For example, this means that if data can be combined to identify a household, it will be personal information.
Personal information includes data such as:
- Name, online nickname or aliases
- Physical address or email address
- Online identifiers including cookies
- IP address
- Account name
- Social security number (SSN)
- Photo ID such as drivers' license or passport
- Purchasing history
- Internet activity including browsing and search history, ad interactions
- Geolocation data
- Biometric data
- Professional or employment data
- Education data
- Inferences or profiles
Information that is not considered "personal information" is information that is publicly available, deidentified, or aggregate data.
Sensitive Personal Information (SPI)
Sensitive personal information (SPI) is a subset of personal information that receives extra protection under the CCPA as amended by the CPRA.
SPI is data that is considered to cause greater potential harm if it is misused. This includes data such as:
- Government identification including SSN, drivers' license, state ID, or passport number
- Financial data including account logins, financial account details, debit or credit card numbers, security codes, passwords, or credentials
- Geolocation data when this data is precise (within 1,850 feet or 563 meters)
- Personal details such as race or ethnicity, citizenship or immigration status, religious or philosophical beliefs, union membership
- Genetic or biometric data when processed to uniquely identify an individual
- Health data, including data on sex life or sexual orientation
- Contents of mail, email, and text messages, unless the business is the intended recipient
Publicly available SPI is not considered to be SPI. Consumers have rights under the CCPA as amended by the CPRA to limit the use of SPI.
You need to have a "Limit the Use of My Sensitive Personal Information" link on your website or app, if you use SPI beyond the permitted or necessary purposes. You must have internal processes for deleting or changing the information you process, when asked.
'Sale' of Personal Information
A sale is any transfer of a consumer's personal information to another business or third party for monetary or other valuable consideration.
A sale includes renting, releasing, disclosing, transferring, making available, or otherwise communicating personal information, from one party to a "third party"
This is a sale regardless of whether the data is exchanged for money, advertising exposure, analytics, or some other valuable services.
A data transfer in exchange for value won't be considered a sale, if a customer has intentionally directed your business to disclose information to a third party or uses your business to interact with a third party.
However, the third party must not sell the data themselves, and the customer must be clearly shown to have taken "one or more deliberate actions" to indicate their intention to interact with (or for you to interact with) the third party. You must provide a "Do Not Sell or Share my Personal Information" link on your website for consumers, if you sell their data. More about the "Do Not Sell or Share my Personal Information" link is provided in the article below, as well as implementation steps.
"Sharing" of Personal Information (Cross-Context Behavioral Advertising)
Sharing means disclosing, renting, releasing, transferring, making available, or otherwise communicating consumer personal information to a third party for cross-context behavioral advertising. This is the case whether or not money changes hands.
Cross-context behavioral advertising is when advertising is targeted at particular consumers based on a profile that has been made about them from different websites and services.
Using third-party cookies, tracking pixels, or ad-tech tools is potentially also considered "sharing" of data and will be captured by the CCPA/CPRA. However, this is not automatically sharing, as it depends on whether the technology is used to share information to a third-party for cross-context behavioral advertising.
You need to provide consumers on your website or app with a mechanism or way to opt out of the sale or sharing of personal information, such as a "Do Not Sell or Share my Personal Information" link. This should be obvious to the user and simple for them to use. More about the "Do Not Sell or Share my Personal Information" link is provided in the article below, as well as implementation steps.
The Four Regulated Entities: Business, Service Provider, Contractor, Third Party
The four regulated entities under the CCPA as amended by the CPRA are businesses, service providers, contractors, and third parties. The CCPA/CPRA applies different rules to these different types of entities.
- Businesses are for-profit entities that do business in California, and meet at least one of the thresholds to be covered by the CCPA/CPRA. They collect personal information from consumers and determine the processing purposes and means.
- Service providers are organizations that process personal information on behalf of a business, governed by a written contract that restricts reuse of the data. Stripe, PayPal, or DHL shipping are examples of service providers.
- Contractors are organizations that process personal information on behalf of a business, governed by a written contract. Contractors were newly added as a regulated entity under the CPRA. They are like service providers, but must certify that they understand and will comply with the restrictions set out in the contract.
- Third parties are entities that are not service providers or contractors, and receive personal information from a business. Third parties have different obligations when compared to contractors and service providers. Businesses must provide consumers with the choice to opt out of the business selling or sharing data to a third party.
Consumer Rights Under the CCPA/CPRA
The rights contained in the CCPA/CPRA are sometimes counted by different sources differently. This is because some sources consider all rights together as "core rights", while others see the rights for minors and private right of action as more "specific" or "limited" rights. Some sources count all the rights that were added later by the CPRA under any regulation, while some count only the rights from the original CPRA text.
This article presents all of the rights under the CCPA/CPRA chronologically.
Core Consumer Rights Under the Original CCPA
The CCPA was enacted in 2018, creating a new framework of rights for California consumers. The original CCPA gave California consumers several core rights, including:
- The right to know what personal information is being collected, whether it is being sold or shared, and if so, to whom
- The right to delete their personal information
- The right to opt out of the sale of personal information
- The right to non-discrimination, meaning that consumers receive equal services at the same price, and can't be discriminated against, just because they exercise their rights
The CCPA gave California consumers specific rights for minors and for private cause of action:
- The right to initiate a private cause of action for data breaches
- The right to opt in to the sale or sharing of data relating to minors, meaning that selling or sharing data from minors is strictly prohibited, unless the minor or their parent (depending on the age of the minor) consents.
When a user says they want to exercise one of their privacy rights, such as the right to have their data deleted, or to know what information you hold on them, you need to verify their identity to a reasonable degree of certainty, to make sure they were an actual user of your service. When consumers make these requests they are known as data subject access requests (DSARs) or verifiable consumer requests.
You are obligated to provide records for at least the 12-month period prior to the user request. This was originally limited to 12 months under the CCPA, and then extended by the CPRA.
New Rights Added by the CPRA
The CPRA first added new rights effective 1 January 2023, for California consumers to correct information, and limit the use of information, specifically:
- The right to correct inaccurate personal information that a business holds on them.
- The right to limit the use and disclosure of sensitive personal information to what is reasonably necessary and expected for the provision of goods and services
- The right to data portability, meaning transmitting personal information to another entity in machine-readable form. This was already recognised under the CCPA, but it was made explicit under the CPRA
In the Privacy Policy from Conjointly, the rights of the consumer are laid out in a section as a list, as shown in the image below:
These rights strengthened the CCPA and gave consumers greater ability to protect their personal information and its use.
Expanded Rights Under the CPRA
The CPRA expands the existing rights to know, delete, and opt out that came from the CCPA.
The CPRA expanded the right to know by allowing consumers to ask for data that goes further back than the initial 12-month lookback requirement. This is only not required if finding this data would be impossible or would create a disproportionate burden on the business.
The right to delete data was expanded to include service providers, contractors, and third parties. This means when your business receives a request to delete data, you must delete it from your own systems, but also tell the other entities you work with to delete it as well.
The CPRA expanded the right to opt out by allowing consumers to request to opt out of data being shared, not just data being sold. You must create links on your website for consumers that state "Do Not Sell or Share My Personal Information". More about these links as well as implementation is explained in this article below.
New Rights Added Through Later CPRA Regulations
Regulations made under the CPRA added more new rights later, effective 1 January 2026, particularly with regard to ADMT. These regulations included:
- The right to access information about automated decision-making technologies, including their logic and outcomes
- The right to opt out of automated decision-making technologies, including profiling
- New rules on privacy risk assessments and cybersecurity audits
Businesses using ADMT need to be compliant with these provisions by 1 January 2027.
The Conjointly Privacy Policy includes these new rights in the rights section for consumers, as shown in the image below.
By explaining these rights in your Privacy Policy, you help to ensure that consumers see a clear, conspicuous explanation of what their rights are and how to exercise them.
Rights of Minors Under the CCPA/CPRA
The CPRA strengthened protections for the personal information of minors.
Businesses have an obligation to get opt-in consent, or "affirmative authorization" before they sell or share the personal information of a consumer, if they know that a consumer is under 16 years old. You have to get this authorization from their parent or guardian if the consumer is under 13. Children between 13 and 16 can provide their own consent.
You need to wait 12 months before asking again, if authorization is declined.
Violations relating to the data of minors have higher penalties, so it's important to be particularly careful when dealing with personal information from minors.
You can set up mechanisms on your website to verify the age of a user before you collect their personal information, and determine whether you need to ask for consent.
Data Subject Access Requests (DSARs)
A consumer request or Data Subject Access Request (DSAR) is the name for when a consumer exercises their rights to know, correct, or delete data held by your business. The CCPA as amended by the CPRA gives California consumers these rights, and your business must be ready to respond to them.
Your business must provide ways for consumers to make a DSAR. The process for consumers to make a DSAR should be obvious and simple. You must verify the consumer's identity before you tell them what information you have about them, or make corrections or deletions.
When a consumer makes a DSAR, you must respond within 45 days. With prior notice, your business is able to extend this by another 45 days. Opt-out requests are an exception to this, which must be honored within 15 business days.
Make sure you keep detailed records about DSARs that you receive, when you receive them, your process for responding to them, and your resolution timelines. This is useful if you are audited or if a regulator investigates.
Business Obligations Under the CCPA/CPRA
If you are a covered business, the law imposes a set of affirmative duties. This means that you have obligations that you must comply with, relating to how you collect, use, sell, share, disclose, retain, and protect the personal information of consumers.
You will need to:
- Notify consumers of their rights at the point of collection
- Maintain a CCPA/CPRA compliant Privacy Policy that you regularly update
- Honor requests that consumers make to exercise their rights, such as deleting data when a request for deletion is made
- Practice data privacy principles like data minimization, purpose limitation, and storage limitation
- Implement reasonable security measures such as encryption and physical data protection, and conduct cybersecurity audits and risk assessments on a regular basis
- Use CCPA/CPRA compliant contract with service providers, contractors, and third parties
- Provide the required opt-out or opt-in links (for minors) on your website, app, or service
The sections below explain these obligations in more detail.
Notice at Collection
The notice at collection is an obligation you have to tell consumers what you collect and why, at or before the point of collection.
Before or immediately when you want to collect personal information from a consumer, businesses must inform consumers about the categories of personal information that will be collected, the purposes for collection, and whether this personal information will be sold or shared.
For each category of personal information, including SPI you must include this same information, as well as telling the consumer how long their information will be retained for. You should include information about how consumers can exercise their CCPA/CPRA rights.
A "notice at collection" and a Privacy Policy are two different things. The notice at collection is in some cases a pop-up or banner.
On the Troutman Pepper Locke LLP website a banner appears that provides a link to a "CA Notice at Collection", which leads to a full document explaining what data is collected, why, and information on selling, sharing, SPI, and how to contact them. This banner is shown in the image below.
In other cases, you can include the relevant information for the notice at collection inside your Privacy Policy. Then, you must provide a link to that section at the point of collection.
However you decide to set up this Notice at Collection, it must be clear and conspicuous. That means you can't hide it or make it non-obvious to a typical visitor.
Privacy Policy Requirements
A compliant Privacy Policy contains a specific set of disclosures. You must have a Privacy Policy that is compliant with the CCPA/CPRA, if you are subject to this law. The Privacy Policy must explain your privacy practices and the rights that consumers have.
Your Privacy Policy must generally include:
- A description of what personal information is being collected or the categories of information collected
- The business or commercial purpose for each category of information
- The categories of third parties that personal information will be disclosed to
- The categories of personal information that will be sold or shared, who it will be sold or shared to, and information about the right to opt out
- The categories of SPI collected and information about the right to limit the use of SPI
- Retention periods for each category of personal information
- A description of consumer rights under the CCPA/CPRA, and how to exercise them
- Information about the use of cookies and trackers (you can also include this in a separate Cookie Policy)
This Privacy Policy should be regularly updated, at least every 12 months. If any of your business processes relating to personal information collection, sharing, selling, or retention change, you must update your Privacy Policy.
Later in the article you can find a full Privacy Policy template which illustrates the main sections and how they should appear in your policy.
Data Minimization, Purpose Limitation, and Storage Limitation
The CPRA codifies three GDPR-style principles: data minimization, purpose limitation, and storage limitation.
These principles were newly added by the CPRA, and were not present in the original CCPA.
- Data minimization means that the personal information that is collected, used, retained, or shared, should be relevant and limited to what is necessary for the purposes. Additional information shouldn't be collected.
- Purpose limitation means that the personal information collected, used, retained, or shared, should be only used for the stated purposes. Incompatible secondary uses are not permitted without notifying the consumer.
- Storage limitation means that personal information must only be kept as long as reasonably necessary for the disclosed purposes. The retention period, or the criteria used to determine the retention period, should also be disclosed to consumers.
The purpose of these principles is to encourage businesses to deal with data in a more privacy-respectful way.
Reasonable Security, Cybersecurity Audits, and Risk Assessments
Businesses must implement reasonable security and, for high-risk processing, conduct annual cybersecurity audits and risk assessments.
The security practices that you implement should be reasonable and appropriate, considering the personal information that you collect and process. This means that you will need to implement higher security measures for more sensitive data.
In this Privacy Policy from Zycus, reasonable security measures are described in a "Data Protection" section, as shown in the image below.
You need to conduct an annual cybersecurity audit, if your processing of personal information presents a "significant risk" to the privacy or security of consumers. Businesses must submit a certificate of completion to the CPPA, and provide the full cybersecurity audit and risk assessment documents if asked.
You must also conduct regular risk assessments weighing up the benefits of data collection, use, sharing or retention, compared to the privacy risks to consumers, if your processing of personal information presents a "significant risk" to consumers. This is especially the case if you collect SPI, use automated decision-making technologies, carry out profiling, or sell or share consumer information. These risk assessments must also be submitted to the CPPA.
The CPPA created these new rules about cybersecurity audits and risk assessments as part of new regulations in 2024-2025. You need to determine the level of risk in your own business, and assess whether these rules apply to you.
Vendor, Contractor, and Service-Provider Contracts
The CPRA requires written contracts with every service provider, contractor, and third party that receives personal information.
Contracts with service providers and contractors must bind these parties to the same CCPA/CPRA obligations as your business. Contractors must certify that they understand and will comply with the contract.
You must also specify the purpose of disclosure, sale, or sharing of personal information, in the contract. The contract should include restrictions on selling, sharing, use, retention, and further disclosure of personal information.
The contract must also specify how service providers, contractors and third parties are able to notify you if they can no longer comply.
This example from Parseable includes CCPA compliance sections in the Service Provider Contract, as shown in the image below.
This example shows restrictions on uses of Personal Information for the Service Provider, and outlines the expected behaviour in relation to CCPA compliance.
These contracts give you the right to monitor the other contractual party and stop the unauthorized use of personal information. This monitoring potentially includes manual reviews, automated scans, or annual audits. You have the right to take "reasonable steps" to ensure the recipient of personal information complies with the contract.
Review your contractual agreements regularly and make sure that they are up to date.
The "Do Not Sell or Share" and "Limit the Use of My SPI" Links
The CCPA/CPRA requires a clear way for consumers to exercise their rights to opt out. This is usually done through two clear and conspicuous links on your homepage, one for opting out of the sale or sharing of personal information, and the other for limiting the use of SPI.
For limiting the sale or sharing of personal information, you must include a link on your website like "Do Not Sell or Share My Personal Information". This lets consumers opt out of the sale and sharing of their personal information when clicked.
The other link should state "Limit the Use of My Sensitive Personal Information". This lets consumers restrict the use of SPI to what is necessary, when clicked.
Both links must be clear and conspicuous on your website homepage. A standard position for these links is in the website footer. On apps you can include these links in the menu.
Businesses that sell or share personal information must honor opt-out preferences that are set through the browser, such as Global Privacy Control (GPC). The implementation steps for opt-out banners and GPC are covered in more detail below.
Consent Under the CCPA/CPRA
The CCPA as amended by the CPRA defines consent in a GDPR-aligned way. Consent must be freely given, specific, informed, and unambiguous. The consent mechanism must indicate that the consumer has definitively agreed to the processing of their personal information.
Consent is obtained through a statement or a clear affirmative action of consent. This is something like clicking a checkbox, clicking an "Accept" button after being required to scroll through a Privacy Policy explaining data collection, or signing a written agreement alongside the provision of the Privacy Policy.
The CCPA also states that consent cannot be obtained through dark patterns. Dark patterns are deceptive interface designs or other techniques that make it unclear for the consumer what they are agreeing to. Dark patterns impair the ability of the consumer to make an informed and freely-given choice.
The CCPA does not require businesses to obtain consent before collecting or processing personal information. That is because the CCPA is an opt-out regime. However, consent applies to the following situations:
- Collection of data from minors under 16
- Secondary use of SPI after consumer has exercised their right to limit use and disclosure of SPI
- Selling or sharing personal information after the consumer has already opted-out (after 12 months have passed, the business can ask again to sell or share)
- Consumers opting in to financial incentive programs
- When personal information is collected for research purposes
When consent is required, make sure you use a specific, understandable, affirmative, and non-manipulative design, like a simple (not pre-checked) checkbox with the Privacy Policy or disclosure included conspicuously alongside.
Enforcement: The CPPA and the Attorney General
Two bodies can enforce the CCPA as amended by the CPRA. These two bodies are the CPPA and the Attorney General.
Under the CCPA, the Attorney General was the sole enforcer. The CPRA created the CPPA, or "CalPrivacy". This is the first US agency that is dedicated solely to data privacy.
The CPPA has full power to enforce the CCPA/CPRA. This includes making rules, investigating potential violations, carrying out audits, and handing down fines for violations. At the same time, the Attorney General retains enforcement power. However, businesses can't be fined by both enforcement bodies for the same violation.
The CPPA took over rulemaking from the Attorney General from 21 April, 2022 onwards. The CPPA made new rules in 2024-2025 that covered automated decision-making technology, cybersecurity audits, and risk assessments.
Penalties and the Private Right of Action
Noncompliance with the CCPA/CPRA potentially results in civil penalties, consumer lawsuits, or both. Penalties include:
- Civil penalties. The Attorney General and the CPPA can hand down civil penalties of $2,663 (inflation adjusted) for unintentional violations, and $7,988 (inflation adjusted) for intentional violations or violations against minors. The penalties are per violation, which means if you have many customers, this can become a large amount very quickly.
- Penalties for violations of the rights of minors. Violating the rights of minors results in the higher tier of penalties, at $7,988 per violation. This is regardless of whether the violation is intentional or unintentional.
- Statutory damages for breaches. Consumers are entitled to damages when a breach occurs that results in the theft or disclosure of, or unauthorised access to, their data. The amount is between $100 - $750 per incident per consumer, or actual damages, whichever is higher.
- Private right of action. This only applies to an actual data breach, not other CCPA/CPRA violations like a non-compliant Privacy Policy. There are certain combinations of breached information that can result in a private right of action, such as the breach of a name combined with an SSN, or an email address combined with a password.
The CCPA originally gave businesses a 30-day cure period to fix violations after being notified. The CPRA removed this requirement when it comes to regulator enforcement, effective from 1 January 2023. However, the 30-day cure period still applies to the private right of action and statutory damages. This means that a consumer must give you 30 days to cure the violation. However, implementing reasonable security after a breach does not count as a cure.
You must:
- Cure the violation within 30 days; and
- Provide the consumer with an express written statement that the violation is cured, and that no further violations will occur.
The consumer cannot pursue legal action if you have completed those steps. In many cases however, you will not be able to "cure" a data breach that has already occurred.
The following section outlines how to comply with the CCPA/CPRA, step-by-step.
How to Comply With the CCPA/CPRA (Step-by-Step)
Here is a practical path to compliance. Each of these concrete steps should be taken one by one.
- Determine if you are covered by the CCPA/CPRA. This means checking whether you meet the definition of a "business" and meet one of the CCPA/CPRA thresholds that require your compliance.
- Map your data. This process involves putting together a complete inventory of personal information that you collect or already hold in your business. Compliance is difficult if you don't know what data you hold.
- Update your Privacy Policy and Notice at Collection. These documents need to be updated to be compliant with the CCPA/CPRA, and updated regularly when your data collection, processing, sharing, selling, or retention approaches change.
- Add links for opting out. Include links on your website or app that say "Do Not Sell or Share My Personal Information", and "Limit the Use of My Sensitive Personal Information", so that consumers can exercise their rights easily.
- Set up a DSAR process. This means you need to set up a way for consumers to make formal requests to access, delete, correct, or make opt-out requests related to their data. Usually this is an email address, link, or phone number. This must be a simple process for consumers to exercise their rights.
- Establish compliant contracts with service providers, contractors, and third parties. This means you need to review any existing contracts or draft new ones that are CCPA/CPRA compliant.
- Implement reasonable security. This means you need to establish both technological measures like encryption and anonymization, organizational measures like having privacy practices within your business and access limitations, and physical measures, like locks on physical data storage locations.
- Train your staff. You must ensure that your staff also know what is expected of them under the CCPA/CPRA. Compliance doesn't work effectively when only some people within your business know what they need to do. You are more likely to have a data breach or data misuse if your staff are not clear about CCPA/CPRA requirements.
- Audit and assess your processes regularly. Compliance is an ongoing process. This means you need to review your CCPA/CPRA compliance processes regularly, and make required updates when you change your business practices or find an issue.
CCPA/CPRA Compliance Checklist
The compliance process for the CCPA/CPRA is complex, and regulations are continually updated.
Meeting these requirements involves multiple steps, from determining whether the law applies to your business and updating documents such as your Privacy Policy to implementing "Do Not Sell or Share My Personal Information" and other required links, reviewing supplier contracts, and conducting regular audits.
For easier review, the requirements are organized into five phases: Assess, Document, Implement Rights, Govern, and Secure and Audit. Keep this checklist as a reference as you work through your CCPA/CPRA compliance.
Assess:
☐ Confirm you meet a threshold ($26.625M / 100k / 50%)
☐ Determine if employee and B2B data now applies to you
☐ Run a data map (PI, SPI, sources, recipients, retention)
Document:
☐ Update notice at collection (categories, purpose, sale/share, SPI, retention)
☐ Update privacy policy annually (all required disclosures)
☐ Publish a cookie/consent policy
Implement Rights:
☐ Add "Do Not Sell or Share My Personal Information" link
☐ Add "Limit the Use of My Sensitive Personal Information" link
☐ Honor Global Privacy Control / opt-out preference signals
☐ Provide two request methods (phone/email/form); opt-outs within 15 business days, responses to requests within 45 days
☐ Honor minor opt-in (13-16) and parental consent (under 13)
Govern:
☐ Execute compliant contracts with all service providers/contractors/third parties
☐ Apply data minimization, purpose limitation, storage limitation
Secure and Audit:
☐ Implement reasonable security (incl. MFA, encryption)
☐ Conduct annual cybersecurity audit + risk assessments if high-risk (submit to CPPA)
☐ Re-scan and review regularly
Download the CCPA/CPRA Compliance Checklist as a PDF file.
Download the CCPA/CPRA Compliance Checklist.
How to Write a CCPA/CPRA-Compliant Privacy Policy
A compliant privacy policy is the backbone of CCPA/CPRA compliance. Your Privacy Policy should cover a number of specific sections, including the information you collect, the purposes you collect information for, who you share it with or sell it to, how long you keep information, how consumers can contact you, and how you keep data safe.
Each of these sections is described in more detail below, with examples.
Information you collect
Your Privacy Policy must explain what information you collect. This includes the categories of personal information, and any categories of SPI. Describe how this information is collected (such as directly, through cookies, or otherwise). The Privacy Notice from Amazon outlines the types of personal information that the company collects, as shown in the image below.
The Privacy Notice outlines information that customers give to Amazon directly, as well as automatically-collected information through cookies or other services. It explains at the end how information is gathered from other sources including third parties.
Your Privacy Policy should be detailed about the information you collect. The Parsons Privacy Notice informs users about the information collected in the last 12 months, and breaks down both categories and examples of types of data collected.
What purposes you collect information for
Your Privacy Policy must outline what you use personal information for. This includes direct purposes as well as indirect uses for the information. Data minimization principles mean that you must collect only what is necessary and relevant for the purposes you set out, and no more.
In the Deloitte Privacy Notice the below section explains how Deloitte uses personal information for improving its website, verifying user identity, data analysis, and marketing.
Who you share the information with
You must explain in your Privacy Policy who you will share personal information with. This includes service providers, contractors, and third parties. You must also distinguish between instances when you share data, and when you sell data.
The Google Privacy Policy outlines when Google shares personal information, as shown below. In this example, Google shares information when it is necessary to make bookings or reservations, and for using third-party services.
How long you keep the information you collect
You must also describe in your Privacy Policy how long you will keep personal information, or what criteria determines how long you will keep information.
The Qualcomm Privacy Policy explains that the company retains personal data while the user account is active, or when Qualcomm needs to provide Services, or retain data for legal obligations.
How consumers can contact you
Consumers must be able to find your contact information easily. You must include your contact details in your Privacy Policy. The Privacy Policy from Apple has information about a contact page for the Data Protection Officer , as well as a phone number for support.
How you keep personal information secure
Your Privacy Policy must outline how you keep personal information secure. This includes administrative, technical, and organizational safeguards, such as anonymization, access controls, or physical locks on data storage rooms.
In the data security section of the Infosys Privacy Statement, these specific technical protections are explained, as shown below.
Below you can see a complete template of a Privacy Policy that is compliant with the CCPA/CPRA.
CCPA/CPRA Privacy Policy Template
This template gives you fill-in-the-blank scaffolding for a CCPA/CPRA-compliant privacy policy.
This Privacy Policy template includes the key sections you need for compliance, such as what information you collect, the purposes for data collection, how you disclose, sell, or share data, how you store it and keep it safe, and how to contact you or what will happen when the policy is updated.
Before using the template Privacy Policy, check each section against your actual practices when dealing with personal information. Ensure that the Privacy Policy describes your activities accurately. Some sections are potentially inapplicable or require significant editing to suit your purposes.
You can download the Sample CCPA (CPRA) Privacy Policy Template as HTML code below. Copy it from the box field below (right-click > Select All and then Copy-paste) and then paste it on your website pages & app screens.
Where to Display Your CCPA/CPRA Privacy Policy
Your Privacy Policy only works if people can find it. There are several places you can put links to your Privacy Policy that are compliant, including in the website footer, app download page, checkout page, and account creation and login forms.
Place the link to your CCPA/CPRA Privacy Policy information within your California-specific privacy notices or supplements, if you have them.
Each of these placement options is described in more detail below, with examples.
Website footer
One of the most common and compliant places for your Privacy Policy is in the website footer. On its own however, this is not sufficient, especially for opt-in data sharing, sale, or the personal information of minors. In those cases, you must make sure you get explicit consent.
The footer on the Target website includes a general Privacy Policy, as well as a specific statement relating to California Privacy Rights, and a document about your rights and privacy choices in California.
App download page
For apps that are downloaded from the Apple Store or Google Play Store, you must include your Privacy Policy in the app download page.
The Snapchat app download page below shows the link to the Snapchat Privacy Policy, so that users can read the policy before they download the app. The Apple Store also highlights which data will be used to track users and which will be linked to the user, as shown in the image.
Checkout page
A very important location to place your Privacy Policy is on the checkout page when users make any purchases from your website. Using a checkbox with the policy on the checkout page is one way explicit consent is obtained.
In this example from Eventbrite, a checkbox is used with a link to the Eventbrite Terms of Service, Community Guidelines, and Privacy Policy. The checkbox is required to be ticked before the user proceeds with placing the order.
Account creation and login forms
Account creation and login forms are a location where checkboxes and links are provided, that makes it easy for the user to see them and agree to them using checkboxes if desired.
The example from Walmart shows a link to the Privacy Policy at the account creation stage, as shown in the image below.
A link to the Privacy Policy is provided under the "Continue" button, so that users see it as they progress through the sign-up process.
The Cisco account login page includes links to the Privacy Policy, Terms and Conditions, and Cookie Policy, as shown in the image below.
Placing links to your Privacy Policy in a wide range of places makes it more likely that a user will see it.
Within California-specific privacy notices or supplements
Your CCPA/CPRA Privacy Policy link is able to be placed in your California-specific privacy notices or supplements.
For example, Wells Fargo has a California Consumer Privacy Act Notice on its website. This lets users know how Wells Fargo handles the personal information of California residents, as shown in the image below.
The Supplemental Privacy Statement for California consumers from Thomson Reuters lets users know the steps it takes to honor the privacy rights of California consumers, as shown in the image below.
The Supplemental Privacy Statement is a document that supports the Privacy Statement of Thomson Reuters. It explains more information about the CCPA/CPRA. The link to the Privacy Policy is still provided within this document.
How to Implement "Do Not Sell or Share" and Global Privacy Control
The required opt-out links and honor GPC signals are implemented through several different steps, including website placement, request processing, and the use of GPC signals.
The opt-out link for "Do Not Sell or Share my Personal Information" is placed in the website footer, in pop-ups, and in the CCPA/CPRA section of the Privacy Policy.
The opt-out page must let consumers or authorized agents opt out without creating an account. These opt-out requests must be processed within 15 business days. You must then notify third parties who received personal information in the previous 90 days, so they can also start processing the request.
The same applies to the link that states "Limit the Use of My Sensitive Personal Information". This must be placed conspicuously and clearly in the footer, on a pop-up, and in relevant documents such as the Privacy Policy.
Some consumers use GPC signals to opt out automatically through the browser. Instead of using a link you honor opt-out requests through the GPC signal that the browser produces. This is done by configuring your website to detect the GPC signal. Processing the GPC signal is mandatory if you sell or share personal information.
You are allowed to rely on this signal instead of a "Do Not Sell or Share my Personal Information" link, but only if the GPC signal is processed in a "frictionless manner". This means without fees, logins, changing the consumer experience, or displaying extra prompts or steps.
Authorized-agent requests are permitted under the CCPA/CPRA. An authorized agent is someone (including a business) that a consumer gives permission to make privacy requests on their behalf. Ask authorized agents for proof of permission from the consumer. You must process opt-out requests from authorized agents within the same 15-business-day window as for individual consumers.
Common mistakes in implementation include hiding opt-out links or not making them conspicuous enough for the user, requiring a login to opt out, ignoring GPC signals, and not passing opt-out signals downstream to service providers, contractors, and third parties.
CCPA/CPRA vs Other US State Privacy Laws
California set the template, but it is no longer the only US privacy law.
More than 19 US states now have comprehensive privacy laws. This includes Virginia VCDPA, Colorado CPA, Connecticut, Utah, Texas, Oregon, Montana, and more coming online in 2025-2026 such as Indiana, Kentucky, and Rhode Island.
One of the key differences is that California is the only state with a private right of action. The CCPA/CPRA has the strictest sensitive-data and cure-period rules, while most others follow an opt-out model without a dedicated agency such as the CPPA to carry out enforcement and rulemaking.
Building your website or app to comply with the CCPA/CPRA means you'll also be compliant with most other US privacy laws, as many are not as strict. However, some have differing requirements that diverge from the CCPA/CPRA. Keep on top of new rulemaking that comes out from the CPPA, as additional regulations are created at any time.
CCPA/CPRA Enforcement Examples and Fines
Regulators are already enforcing the CCPA as amended by the CPRA with real fines.
You must take extra care with CCPA/CPRA compliance, as the 30-day cure period no longer applies to regulator enforcement (it still applies to the consumer private right of action). This means a violation results in immediate potential fines, rather than your business having time to make corrections. The CPPA takes enforcement action early.
| Regulator | Company | Year | Fine | Reason |
| Attorney General | Sephora | 2022 | $1.2 million | Failing to cure CCPA violations within the 30-day window (selling personal information without a "Do Not Sell" link and ignoring opt-out requests including through GPC signals) |
| Attorney General | DoorDash | 2024 | $375,000 | Failed to disclose that information would be sold to a third party for marketing, failed to provide an opportunity to opt out |
| CPPA | Todd Snyder | 2025 | $345,178 | Failing to process opt-out requests for 40 days, requiring consumers to provide more information than necessary for opt-outs, requiring consumers to verify their identity with a photo ID to opt out |
| CPPA | Honda | 2025 | $632,500 | Required excessive identity verification for opt-out requests, made it difficult for authorized agents to exercise privacy rights on behalf of consumers, failed to make opting out as easy as consenting, shared consumer information without appropriate contracts with third parties |
| Attorney General | Walt Disney | 2026 | $2.75 million | Opt-out processes failed to allow consumers to completely opt out and stop sale and sharing of data. Failure was over all devices and streaming services including Disney+, Hulu, ESPN+. |
| Attorney General, CPPA, and District Attorneys | General Motors | 2026 | $12.75 million | Sold personal information of consumers without knowledge or consent, despite statements assuring they would not do so. Retained driver information long after use for the original purpose it was collected for. This is the first legal action enforcing the data minimization principle under CCPA/CPRA. |
Each consumer affected by an issue counts as a separate violation, so penalties compound fast. In addition, the expanded private right of action raises your exposure to litigation after a breach. As a result, it's crucial to avoid violations of the CCPA/CPRA and make privacy a core business practice.
CPRA vs CCPA: Frequently Asked Questions
Here are answers to the most common questions about the CCPA as amended by the CPRA.
The CPRA does not replace the CCPA, but rather strengthens and updates it. The CCPA is still in force, as the CPRA is more like an amendment than a new law. The CCPA/CPRA are referred to together as the CCPA as amended by the CPRA, and many CCPA provisions remain valid, except where the CCPA has been updated by the CPRA.
Businesses must comply with the CCPA/CPRA if they meet one of the compliance thresholds. These include having an annual gross revenue more than $26.625 million (inflation adjusted); buying, selling, or sharing the data of 100,000 or more California consumers or households; or getting 50% or more of your annual revenue from selling or sharing data of California residents.
Sensitive personal information (SPI) is information that could cause greater potential harm if it is misused. It has higher protections than other types of information under the CCPA/CPRA. Consumers have rights to limit the use of SPI, and links to this effect (allowing consumers to limit the use of SPI) must be provided on your website or app.
Selling is transferring personal information to another business or third party for money, or other valuable consideration. Sharing is when personal information is disclosed to a third party, for the purposes of cross-context behavioural advertising. This is the case regardless of whether value changes hands.
The CPRA added new rights including the right to correct inaccurate personal information, the right to limit the use and disclosure of SPI, the right to access information about ADMT, the right to opt out of ADMT, and the right to data portability.
The CPPA is the agency that enforces the CCPA/CPRA, created by the CPRA. This is the first US agency dedicated to data privacy. The CPPA has the power to make rules, investigate potential violations, conduct audits, and issue fines. It works alongside the Attorney General and neither takes enforcement authority away from the other.
The CPRA removed the automatic 30-day cure period for regulator enforcement, effective 1 January 2023. The 30-day cure period still applies to the private right of action under the CCPA/CPRA if a consumer wants to claim statutory damages after a data breach.
Penalties are $2,663 (inflation adjusted) for unintentional violations, and $7,988 for intentional violations or violations against minors. Penalties apply per violation, which is usually "per consumer" but is potentially multiple violations against the same consumer. Consumers have the right to separately claim statutory damages of $100-750 per incident after a data breach.
Yes. The temporary exemptions for employee and B2B data ended on 1 January 2023. This means that employee and B2B data now have the same protections as consumer data, and you must treat them the same as other consumer data under the CCPA/CPRA.
Yes, if your business sells or shares personal information. You must provide a clear and conspicuous "Do Not Sell or Share My Personal Information" link on your website or app. Your business is able to rely on GPC signals instead of an opt-out link, as long as the GPC opt-out process is “frictionless” for the consumer.
Summary and Key Takeaways
Here are the key takeaways from this CPRA vs CCPA guide.
- The CPRA amended and expanded the CCPA. The operative law is described as the "CCPA as amended by the CPRA". The CPRA added new obligations for businesses, and new rights for consumers. It did not repeal the CCPA. You must consider the CCPA as amended by CPRA when thinking about your business obligations.
- The CPRA increased the data-volume threshold from 50,000 to 100,000 consumers or households. The revenue test now includes businesses that gain 50% or more of their annual revenue from sharing as well as selling personal data.
- Sensitive personal information (SPI) is a new protected category of data. This was introduced by the CPRA amendments to the CCPA. Consumers have the right to limit the use and disclosure of SPI and your business must provide a dedicated opt-out link.
- Consumers gained new rights (correct, limit SPI, ADMT, portability) and expanded rights (sharing opt-out, broader access, propagated deletion) through the CPRA amendment of the CCPA.
- The CPPA now enforces the CCPA/CPRA alongside the Attorney General. The automatic 30-day cure is no longer in effect for regulatory actions, and is rather discretionary. It still applies in relation to the private right of action that consumers have.
- Penalties are as high as $7,988 per intentional violation (or for violations against minors). Separately from this, consumers have a private right of action when data breaches occur and are able to claim statutory damages.
- Take steps in your business planning to comply with the California standard of the CCPA/CPRA. Do this by maintaining a compliant privacy policy and the required opt-out links on your website or app.
The TermsFeed Privacy Policy Generator provides you with a CCPA/CPRA-compliant Privacy Policy, so you can ensure compliance for your business without hassle.
The first step to compliance: A Privacy Policy.
Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.