AuditXYZ

Lesson 4 of 5

CPRA Amendments: What Changed and Why It Matters

13 min readIntermediate

CPRA Amendments

The California Privacy Rights Act (CPRA) — Proposition 24 — was passed by voters in November 2020 and became operative on January 1, 2023, with a lookback to data collected from January 1, 2022. It did not replace the CCPA; it rewrote it, closing the loopholes businesses had exploited in the law's first years and converting a transparency statute into something much closer to a GDPR-style regime with substantive limits and a dedicated regulator. Enforcement of the amended provisions is fully underway, and the CPPA's rulemaking continues to add obligations.

If your compliance program was built for "CCPA 1.0" — a privacy policy, a Do Not Sell link, a request inbox — this lesson is the delta you need to close.

Summary of Changes

ChangeBefore CPRAAfter CPRA
Sensitive PINo special categorySPI defined, with notice and limit-use obligations
Behavioral advertisingDebated whether "sale" covered it"Sharing" explicitly covers cross-context behavioral ads
EnforcementAttorney General onlyCPPA as dedicated agency, plus AG
Cure periodAutomatic 30-day cure before penaltiesDiscretionary — no guaranteed cure
Consumer rightsKnow, delete, opt out of saleAdds correct, limit SPI use, opt out of sharing
Data practicesTransparency-focusedPurpose limitation, minimization, retention limits
Thresholds50,000 consumers/households/devices100,000 consumers/households; devices dropped
Employee & B2B dataTemporarily exemptFully covered from January 1, 2023
Vendor categoriesService providersAdds contractors; mandatory terms for third parties
Audits/assessmentsNoneCybersecurity audits and risk assessments for high-risk processing (via CPPA regulations)
Contract lookthroughWeakDue diligence expectations for downstream recipients

Sensitive Personal Information

CPRA's most operationally significant addition. SPI includes: government identifiers (SSN, driver's license, passport), financial account or card numbers with access credentials, precise geolocation (within roughly 1,850 feet), racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail, email, and text messages where the business is not the intended recipient, genetic data, biometric information processed for unique identification, health data, and data concerning sex life or sexual orientation.

Obligations attach in two layers. First, notice: your notice at collection and privacy policy must separately disclose SPI categories, purposes, and retention. Second, the right to limit: if you use or disclose SPI for purposes beyond a permitted list (delivering the requested services, security and integrity, short-term transient use, order fulfillment, service quality), consumers can restrict you to those purposes via a "Limit the Use of My Sensitive Personal Information" link, effective within 15 business days and propagated to your vendors. Many businesses use SPI only to provide their service and thus avoid the link — but that conclusion requires an actual inventory of SPI flows, especially precise geolocation in mobile SDKs and health-adjacent signals in wellness products, which are the two categories companies most often discover late.

The California Privacy Protection Agency

CPRA created the CPPA — the first dedicated privacy regulator in the United States — with three powers that change the risk calculus:

  • Rulemaking: the agency writes and updates the CCPA regulations, an ongoing process that keeps adding obligations (opt-out signal rules, dark-pattern standards, and the audit/risk-assessment/ADMT package).
  • Administrative enforcement: investigations, hearings, and fines of up to $2,500 per violation ($7,500 for intentional violations or those involving minors) — alongside, not replacing, Attorney General civil enforcement.
  • Audit authority: the agency can audit businesses' compliance on its own initiative.

Equally important: CPRA removed the automatic 30-day cure period. Cure is now discretionary, weighed against factors like good-faith compliance efforts. The practical message from early CPPA activity — enforcement sweeps on GPC honoring, dark patterns, and data broker registration, plus its first monetary orders — is that documented, operational compliance before the knock matters far more than a rapid fix afterward.

New and Expanded Consumer Rights

  • Right to correct inaccurate PI (commercially reasonable efforts).
  • Right to limit SPI use, as above.
  • Opt-out expanded to "sharing" — cross-context behavioral advertising is now unambiguously covered, regardless of whether money changes hands. This is why the required link now reads "Do Not Sell or Share."
  • Access beyond 12 months — consumers can request information predating the 12-month window for data collected after January 1, 2022.
  • Regulations built on CPRA also cemented the duty to honor opt-out preference signals (GPC) and banned dark patterns: a consent or opt-out flow that is confusing, asymmetrical (one click to accept, five to decline), or manipulative does not produce valid consent.

Data Minimization and Retention

CPRA imported substantive limits: collection, use, retention, and sharing must be reasonably necessary and proportionate to disclosed purposes; you must disclose retention periods or criteria for each PI category at collection; and you may not retain PI or SPI longer than reasonably necessary. Operationally this means a data inventory tied to purposes, a retention schedule, and deletion jobs that actually run — detailed in the business obligations lesson.

Contractors, Third Parties, and Contract Terms

CPRA added the contractor category alongside service providers and imposed mandatory contract terms on all three recipient categories — including third parties, which previously escaped contractual requirements. It also introduced due-diligence expectations: a business that never verifies its recipients' compliance may not be able to claim ignorance of their violations. If your DPAs predate 2023, assume they are missing required clauses and re-paper.

Cybersecurity Audits, Risk Assessments, and ADMT

CPRA directed the CPPA to issue regulations requiring businesses whose processing presents significant risk to consumers' privacy or security to:

  • Perform annual cybersecurity audits — independent, thorough, and not merely a penetration-test certificate; and
  • Submit risk assessments to the CPPA for high-risk processing — weighing benefits against risks to consumers, documenting purposes, and identifying safeguards, with the assessment logic echoing GDPR DPIAs.

The same rulemaking package covers automated decision-making technology (ADMT): access and opt-out rights around significant automated decisions and profiling. The CPPA finalized these regulations in 2025 with phased compliance deadlines running over the following years, scaled by business size. If you profile consumers, make consequential automated decisions, process SPI at scale, or sell/share PI, plan for this regime now: build the risk-assessment habit (a DPIA-style template works), and get your security program audit-ready — an existing SOC 2 or ISO 27001 program is a strong foundation but will need California-specific scoping.

A Prioritized Remediation Plan

If you are closing the CPRA delta today, sequence the work by enforcement probability and effort:

First 30 days — the externally testable items. Update the opt-out link wording to "Do Not Sell or Share," verify GPC signals are honored at the network level, and sweep your own site the way the CPPA would: click every privacy link, submit a test opt-out, watch the tags. These items are visible to regulators without a subpoena, which is why sweeps start there.

Days 30–90 — inventory and notices. Complete the SPI inventory (mobile SDK geolocation and health-adjacent signals first), document the limit-use analysis, refresh notices at collection including HR and applicant flows, and add retention disclosures to the policy.

Days 90–180 — contracts and populations. Re-paper vendor agreements with the mandated terms, stand up employee/B2B rights handling, and implement the correction right with vendor propagation.

Ongoing — the regulatory horizon. Build the risk-assessment template into product and vendor review now, so high-risk processing gets assessed as it launches rather than retroactively, and scope your security program against the cybersecurity audit requirements on their phased timeline.

The logic throughout: regulators find the cheap-to-check failures first, so fix in that order — even though the contracts and inventory work is ultimately the heavier lift.

CPRA Readiness Checklist

  • SPI inventory completed — including precise geolocation in mobile apps and health-adjacent data
  • "Limit the Use of My Sensitive Personal Information" analysis documented; link posted if required
  • Opt-out link updated to "Do Not Sell or Share"; sharing flows (ad pixels, retargeting) mapped
  • GPC honored automatically; consent flows audited for dark patterns and click symmetry
  • Correction right implemented with vendor propagation
  • Employee, applicant, and B2B contact data brought into the program (notices, rights handling)
  • Retention periods defined and disclosed per PI category; deletion enforced
  • All vendor contracts re-papered with CPRA-required terms (service provider, contractor, third party)
  • Downstream due diligence process established for data recipients
  • Risk assessment template adopted for high-risk processing; ADMT exposure assessed
  • Cybersecurity audit readiness evaluated against the CPPA requirements
  • Enforcement posture reviewed: no reliance on a cure period; evidence of good-faith compliance maintained

Frequently Asked Questions

Is CPRA a separate law we have to comply with in addition to CCPA?

No. CPRA amended the CCPA — there is one law, the CCPA as amended, plus the CPPA's regulations. When vendors sell "CPRA compliance," they mean compliance with the current CCPA. The distinction matters mainly for reading older guidance: anything analyzing "the CCPA" written before 2023 is describing a law that no longer exists in that form.

We do not sell data — did CPRA change anything for us?

Almost certainly. The "sharing" definition captures routine ad-tech (pixels, SDKs, retargeting) even without payment; the employee/B2B exemptions expired; minimization and retention duties apply to everyone; SPI obligations may apply; and all vendor contracts need updated terms. "We don't sell data" was a viable CCPA 1.0 posture; under the amended law it is usually the start of the analysis, not the end.

Broadly: performing the services the consumer requested, helping ensure security and integrity, short-term transient use (including some non-personalized advertising), performing services on behalf of the business (order fulfillment, payment processing), and verifying or maintaining quality and safety. If every SPI use fits those buckets — and you can document it — the limit-use link is not required. Using SPI to infer characteristics or for cross-context advertising takes you outside them.

How likely are we to face a CPPA audit or enforcement?

The CPPA has prioritized visible, testable failures: ignored GPC signals, missing or broken links, dark patterns, defective vendor terms, and data broker registration lapses — often via sweeps that check many companies at once. Connected vehicles, ad-tech, data brokers, and children's data have drawn focused attention. The realistic exposure for a typical company is a sweep letter about something externally observable on your website, which is why the mechanical items in the checklist above deserve first priority.

When do the cybersecurity audit and risk assessment requirements actually bite?

The CPPA finalized the regulations in 2025 with phased deadlines: risk assessments apply to high-risk processing with submission obligations following, and annual cybersecurity audits phase in over several years, largest businesses first. Exact dates depend on your size and processing; the planning posture is to treat risk assessments as current practice and audit readiness as a 12–24 month program, not a future problem.

Does CPRA apply retroactively?

Consumer rights under the amended law reach data collected on or after January 1, 2022 (the lookback), and access requests can now reach beyond a 12-month window for that data. Practically: your data inventory and retention program need to cover everything you currently hold, whenever collected.

In the next lesson, we will pull everything together into building a CCPA compliance program.


Tracking CPPA rulemaking and keeping controls current is an ongoing job. AuditXYZ helps you compare compliance automation platforms and find auditors to keep pace without building everything by hand.