AuditXYZ

Compliance Framework

California Privacy Rights Act of 2020 (CPRA)

The CPRA amends and expands the CCPA, introducing new consumer rights, the concept of sensitive personal information, the California Privacy Protection Agency, and mandatory cybersecurity audits for high-risk businesses.

$10,000–$150,0002–8 monthsAudit Required2020 (enforced January 1, 2023)
Issuing BodyCalifornia Voters (Ballot Proposition 24) / California Privacy Protection Agency
First Published2020-11-03
Latest Version2020 (enforced January 1, 2023)
Typical Cost$10,000–$150,000
Typical Timeline2–8 months
Audit RequiredYes
Audit FrequencyAnnual cybersecurity audits required for businesses whose processing presents significant risk to consumer privacy. Risk assessments required for high-risk processing.
Geographyus-california

CPRA: The Complete Guide

The California Privacy Rights Act, passed by California voters as Proposition 24 in November 2020, significantly strengthens and amends the CCPA. Effective January 1, 2023, the CPRA introduces new consumer rights, creates a dedicated enforcement agency, and imposes obligations that more closely align California's privacy regime with the GDPR. For organizations already navigating the CCPA, the CPRA represents the most significant expansion of California consumer privacy law since the original act.

What the CPRA Is and Who Enforces It

The CPRA created the California Privacy Protection Agency (CPPA) — the first dedicated state privacy enforcement body in the United States — and vested it with rulemaking authority and independent enforcement power. The CPPA operates alongside the California Attorney General, who retains civil enforcement authority for violations of the underlying CCPA as amended.

The CPPA has been actively exercising its authority since its inception. In 2023-2024, it issued regulations on automated decision-making technology, risk assessments, and data broker registration. In 2025, the CPPA issued its first formal enforcement action — against a data broker for failure to register with the California data broker registry — and has indicated a broader enforcement agenda targeting algorithmic advertising and sensitive personal information handling.

What the CPRA Adds to the CCPA

The CPRA introduces several important concepts absent from the original CCPA:

Sensitive personal information (SPI) — A new category covering Social Security numbers, driver's license and passport numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, biometric data processed for the purpose of uniquely identifying a consumer, personal communications, and genetic data. Consumers gain the right to limit the use and disclosure of their SPI to purposes necessary for providing goods or services.

Right to correct — A new right allowing consumers to request correction of inaccurate personal information about them.

Right to opt out of automated decision-making — Consumers may opt out of automated decision-making technology — including profiling — that produces decisions that have significant effects on them. The CPPA finalized regulations on this right in 2024, creating detailed requirements for pre-use notices and opt-out mechanisms.

Data minimization and purpose limitation — The CPRA codifies obligations to collect, use, and retain personal information only to the extent reasonably necessary for disclosed purposes. This brings California's approach significantly closer to GDPR proportionality requirements.

Extended lookback period — Consumer requests may cover personal information collected up to 12 months before the request (with earlier data available upon request if technically feasible).

Sharing — The CPRA extends the opt-out right to cover "sharing" of personal information — defined as disclosure to third parties for cross-context behavioral advertising — even when no money changes hands. This was designed to close a gap where some businesses argued that ad tech data flows were not "sales."

Applicability Thresholds

The CPRA modifies the CCPA's applicability thresholds. It applies to for-profit businesses that collect personal information from California residents and meet one of three criteria:

  • Annual gross revenue over $25 million in the preceding calendar year.
  • Buying, selling, or sharing the personal information of 100,000 or more consumers or households during the preceding calendar year (note: the original CCPA also counted households separately; under CPRA, only consumers are counted for this threshold).
  • Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.

Cybersecurity Audits and Risk Assessments

The CPRA introduces two new assessment obligations that go beyond anything in the original CCPA:

Annual cybersecurity audits — Businesses whose processing activities present a significant risk to consumer privacy or security must submit to an annual cybersecurity audit by an independent auditor. The CPPA is developing regulations specifying which businesses are covered and the audit scope.

Risk assessments — Before undertaking processing activities that present significant risk, businesses must conduct and document risk assessments analyzing benefits versus privacy risks. Categories include selling personal information, processing SPI, profiling for automated decisions, and other activities the CPPA designates by rule.

These requirements are the most substantial new operational obligation introduced by the CPRA and signal the direction of California privacy law toward continuous compliance rather than one-time certification.

Contractor, Service Provider, and Third-Party Regime

The CPRA created a new three-way classification of data recipients:

  • Service providers — Receive personal information under contract for specified business purposes.
  • Contractors — A new CPRA category for entities receiving personal information for business purposes where the business does not "sell" or "share" the data.
  • Third parties — All other recipients; sharing with third parties for advertising purposes triggers opt-out rights.

Contracts with service providers and contractors must now include expanded provisions: a right to audit, acknowledgment that consumers' CPRA rights apply, prohibition on use for the recipient's own advertising, and in the case of service providers, prohibition on further sharing with contractors.

Enforcement and Penalties

Enforcement rests with both the CPPA (administrative enforcement) and the California Attorney General (civil enforcement). Penalties remain at $2,500 per unintentional violation and $7,500 per intentional violation, with a tripled penalty ($22,500) for intentional violations involving minors. The private right of action from the CCPA for data breaches is preserved.

The cure period under the original CCPA was eliminated for most violations after January 1, 2023. The CPPA may offer cure in some circumstances but is not obligated to do so.

CPRA vs. GDPR and US State Laws

The CPRA achieves approximately 65% conceptual overlap with the GDPR — the highest of any US state law. Key points of convergence include data minimization, purpose limitation, sensitive data protections, and risk assessment obligations. Key differences remain: GDPR requires a lawful basis before processing begins; CPRA operates on an opt-out default for most processing.

Among US state privacy laws, the CPRA (85% overlap with CCPA) is the direct predecessor. The VCDPA and CPA share broadly similar consumer rights structures. The CTDPA includes loyalty program provisions. All three are modeled partly on CPRA's approach to sensitive data and risk assessments, making CPRA compliance a strong foundation for multi-state US compliance.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
Gap assessmentCPRA requirements beyond CCPA baseline, SPI mapping2-4 weeks
DesignCorrection rights, opt-out of automated decisions, SPI limitation3-6 weeks
ImplementationVendor contract updates, audit program setup, risk assessment docs4-8 weeks
OngoingAnnual audits, risk assessments, CPPA rule monitoringContinuous

Key compliance steps:

  1. Gap assessment — Identify CPRA requirements beyond existing CCPA compliance, focusing on SPI, data minimization, and automated decision-making.
  2. Sensitive data inventory — Map all sensitive personal information processing and evaluate whether any use can be limited without business impact.
  3. Consumer rights updates — Implement correction request workflows and automated decision-making opt-out mechanisms meeting CPPA regulations.
  4. Data minimization review — Evaluate collection practices against the necessity and proportionality standard.
  5. Vendor agreements — Update contracts with service providers, contractors, and third parties to include all CPRA-required provisions.
  6. Cybersecurity audit program — Establish annual cybersecurity audit procedures if processing presents significant risk.
  7. Risk assessments — Conduct and document assessments for all high-risk processing activities before they commence.
  8. Data broker registry — If applicable, register with the California data broker registry maintained by the CPPA.

How Privacy Automation Helps

Managing CPRA's expanding obligations — SPI handling, automated decision-making opt-outs, annual audits, risk assessments, and state-level reporting — creates real operational complexity. TruePrivacy automates the data discovery and DSR management layer that underpins CPRA compliance, covering CPRA alongside CCPA, GDPR, and 12-plus other frameworks. Its AI-powered data discovery across 128-plus sources helps maintain the current data inventory that CPRA's data minimization obligations require.

At $5,000 per year with 24-hour onboarding, TruePrivacy is an efficient entry point for organizations building or expanding California privacy programs. AuditXYZ rates it 88/100. See best privacy management tools and the TruePrivacy vs OneTrust comparison for a fuller picture.

Frequently Asked Questions

What is sensitive personal information under the CPRA and how is it different from "sensitive data" under the GDPR? CPRA's SPI is a specific list including geolocation, biometrics, SSN, and certain communications. The GDPR's special category data includes health, racial origin, religious beliefs, and similar data focused on characteristics that could lead to discrimination. There is meaningful overlap but not identity — precise geolocation and login credentials are SPI under the CPRA but not GDPR special categories. Biometrics appear in both.

Does the right to limit use of SPI require an opt-in or opt-out mechanism? It is an opt-out right. Businesses may use SPI for specified business purposes without consent, but consumers can direct the business to limit use to only what is necessary to provide goods and services. Businesses must provide a "Limit the Use of My Sensitive Personal Information" link, which can be combined with the opt-out of sale link.

What must a risk assessment include under the CPRA? CPPA regulations specify that assessments must describe the processing, articulate the purpose and business rationale, identify categories of personal information involved, enumerate privacy risks, document measures taken to mitigate those risks, and weigh the benefits of processing against the risks. Assessments must be reviewed at least annually or when the processing materially changes.

If we are already compliant with the CCPA, how long will CPRA remediation take? For organizations with mature CCPA programs, incremental CPRA work typically takes 2-4 months. The primary work involves SPI identification and limitation mechanisms, correction right workflows, automated decision-making opt-out infrastructure, updated vendor contracts, and documenting the risk assessment program. Cybersecurity audit requirements may take longer if audit infrastructure does not already exist.

Do the CPRA's automated decision-making regulations apply to B2B uses? The CPRA and CPPA regulations on automated decision-making apply to processing of California consumers' personal information. The term "consumer" in the CPRA includes California residents in their employment and business contexts as well as their personal capacity. B2B companies that process California-resident employee or end-user data through algorithmic systems should evaluate whether those systems fall within the opt-out right scope.

Request a CPRA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

CCPAHigh85%
GDPRMedium65%

Related frameworks

Get matched with a CPRA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools