Privacy Laws
What is CPRA (California Privacy Rights Act)?
The California Privacy Rights Act (CPRA) is the 2020 ballot initiative (Proposition 24) that amended and strengthened the CCPA — adding the rights to correct data and limit sensitive-data use, defining 'sharing' for behavioral advertising, and creating the California Privacy Protection Agency — with most provisions operative January 1, 2023.
The CPRA is not a separate statute so much as CCPA 2.0: it amends the same code sections, and 'CCPA as amended by the CPRA' is the law actually in force. Voters approved it as Proposition 24 in November 2020, and its principal provisions became operative on January 1, 2023, applying to personal information collected from January 1, 2022.
Its substantive additions map closely to GDPR concepts. It created the category of 'sensitive personal information' — government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, biometric and health data, sexual orientation, and message contents — with a consumer right to limit its use. It added the right to correct inaccurate information, and imported principles of data minimization, purpose limitation, and storage limitation into California law. Most consequentially for marketers, it defined 'sharing' as disclosure for cross-context behavioral advertising, extending the opt-out beyond monetary 'sales' to ordinary ad-tech data flows.
Institutionally, the CPRA created the California Privacy Protection Agency (CPPA) — the first US regulator dedicated to privacy — with rulemaking and administrative enforcement power alongside the Attorney General. It also removed the CCPA's automatic 30-day cure period, so businesses can no longer fix violations after notice as a matter of right, and it extended obligations to service providers and contractors through mandatory contract terms.
For consent design, one CPRA definition does outsized work: consent obtained through dark patterns 'does not constitute consent.' California regulators now review interface design itself, screenshotting banners and opt-out flows as evidence.
Why it matters for eCommerce
The CPRA is why your Do Not Sell link became 'Do Not Sell or Share,' why sensitive data like precise geolocation needs its own handling, and why interface tricks in consent flows are legally void. With the CPPA actively enforcing and the cure period gone, California compliance is no longer something to fix after the warning letter arrives.
Frequently asked questions
- What is the difference between CCPA and CPRA?
- The CPRA amends the CCPA rather than replacing it. It added the rights to correct and to limit sensitive-data use, defined 'sharing' for behavioral advertising, created the CPPA as a dedicated enforcement agency, removed the automatic 30-day cure period, and tightened rules on consent and dark patterns.
- What is the California Privacy Protection Agency?
- The CPPA is the regulator the CPRA created — the first US agency dedicated solely to privacy. It writes CCPA regulations and enforces the law administratively, alongside the California Attorney General's civil authority.
- What counts as sensitive personal information under the CPRA?
- Categories including Social Security and other government identifiers, account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric identifiers, health data, sex life or sexual orientation, and the contents of mail, email, and text messages.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Test your CPRA readiness