Loading
Home / CPRA Privacy Management for Websites

CPRA Privacy Management for Websites

The California Privacy Rights Act (CPRA) expands consumer rights and website privacy obligations around personal information, sensitive data and consumer choice. Okito helps websites manage these requirements with privacy scanning, configurable controls and preference records across cookies, pixels and connected services.

Get Started
Powering we provide the latest solutions for website privacy compliance
garcia.png
suaryapi.png
blackstate.png
gulbenergen.png
reportage.png
sulax.png (1)
barbertrade.png
naksanyapi.png
byonhotels.png
atlastek.png
nexonya.png
uiduk.png
endemik.png
yediiklim.png
scotty.png
pehlivan.png
mintek.png
ader.png

How CPRA Shapes Website Data Practices

Sensitive Personal Information

Sensitive personal information may enter a website through forms, account areas, precise geolocation tools and connected services. Businesses should identify where this data is collected and, where applicable, allow consumers to limit certain uses and disclosures.

Sensitive Personal Information

Expanded Consumer Rights

By amending the original CCPA, CPRA expanded consumer control over personal information. California consumers may request correction, opt out of sale or sharing and restrict certain uses of sensitive personal information.

Expanded Consumer Rights

Purpose and Retention Limits

The purpose disclosed at collection should guide how personal information is later used and retained. Data practices must remain reasonably necessary and proportionate to that stated purpose, while businesses should establish and disclose applicable retention periods or criteria.

Purpose and Retention Limits

Build a Practical CPRA Website Workflow

01

Review the cookies, pixels, forms and third-party technologies that collect or transmit personal information.

02

Identify sensitive personal information and connect each data category with its collection, use and retention requirements.

03

Link opt-out and limit-use selections with the website technologies affected by each privacy choice.

04

Confirm that privacy signals work as intended, retain relevant preference records and revisit the configuration when the website changes.

Build a Practical CPRA Website Workflow

What CPRA Means for the Website Experience

Notice at Collection with Purpose and Retention Details

Consumers should know what personal information a website collects and why. Privacy notices should match the website’s actual data practices and explain how sensitive personal information is handled and how long data is kept.

  • Identify the categories of personal information collected

  • Explain why each type of data is collected and used

  • State whether personal information is sold or shared

  • Disclose sensitive personal information where applicable

  • Define how long personal information is retained

  • Update disclosures when data practices change

Okito connects website scan results with configurable notices and policy tools, making it easier to keep privacy information aligned with the website.

Notice at Collection with Purpose and Retention Details

From Privacy Choice to Website Action

The CCPA, as amended by CPRA, gives consumers different choices depending on how their personal information is used. These include opting out of sale or sharing and limiting certain uses of sensitive personal information.

  • Provide a clear way to opt out of the sale or sharing of personal information where applicable

  • Provide a way to limit the use and disclosure of sensitive personal information where the right applies

  • Recognize opt-out preference signals such as Global Privacy Control

  • Apply privacy choices to relevant advertising, analytics and third-party technologies

  • Obtain required affirmative authorization before selling or sharing information belonging to consumers known to be under 16, where applicable

Global Privacy Control communicates a consumer’s request to opt out of sale or sharing. Okito recognizes supported preference signals and applies the configured response across relevant website technologies.

Managing CPRA Consumer Privacy Rights

California consumers have several rights over the personal information a covered business holds about them. A privacy workflow should make these rights easy to exercise and connect each request with the appropriate internal process.

  • Request information about personal information collected, used, sold or shared

  • Access specific pieces of personal information

  • Request deletion, subject to applicable exceptions

  • Correct inaccurate personal information

  • Opt out of the sale or sharing of personal information

  • Limit certain uses and disclosures of sensitive personal information

  • Submit applicable privacy requests without creating an account solely for that purpose

  • Exercise privacy rights without discriminatory treatment

Okito keeps website preferences and consumer choices organized in a traceable digital workflow. Identity verification, legal assessment and the final response remain the responsibility of the business.

Keep Website Tracking Under Continuous Review

Cookies, pixels, SDKs and third-party services can create new data flows as a website changes. CPRA readiness therefore requires ongoing visibility into how tracking technologies collect and share personal information.

  • Scan digital properties for cookies, pixels and third-party scripts

  • Identify technologies by purpose, provider and data activity

  • Review technologies involved in sale, sharing or cross-context behavioral advertising

  • Apply opt-out requests and preference signals to relevant technologies

  • Keep records of how privacy choices were received and applied

  • Review the setup when vendors, campaigns or tracking technologies change

Okito brings recurring scans, privacy controls, GPC recognition and preference records into one central workspace.

Bring Your CPRA Website Controls into One Clear Workflow

1

Review Your Website

Tell us about your websites, digital services and the technologies used across them. The initial review helps identify the areas that need attention within your website privacy layer.

2

Configure the Relevant Controls

Set up collection notices, sale or sharing opt-outs, sensitive information choices and California-specific display rules according to your data practices.

3

Deploy, Test and Maintain

Install Okito using the deployment method that fits your website. Test privacy signals and tracking behavior before launch, then revisit the setup whenever the website changes.

Please use an email address that is not associated with an existing Okito account.

FAQ

Frequently Asked Questions

The California Privacy Rights Act (CPRA) is a 2020 ballot initiative that amended the California Consumer Privacy Act (CCPA). It did not create a separate privacy law.

The CPRA added rights to correct inaccurate information and limit certain uses of sensitive personal information. It also expanded opt-out rights to sharing, introduced clearer purpose and retention principles and established the California Privacy Protection Agency.

The CCPA created California’s main consumer privacy framework. The CPRA expanded that framework in several areas:

  • The right to opt out now covers both sale and sharing

  • Consumers can request correction of inaccurate information

  • Certain uses of sensitive personal information can be limited

  • Deletion obligations can extend to relevant third parties

  • Collection, use and retention are subject to clearer purpose and proportionality principles

  • The California Privacy Protection Agency has dedicated regulatory authority

The result is not a separate law but a broader version of the original CCPA.

No. The CPRA does not replace the CCPA. It amended and expanded the existing law. Businesses follow the CCPA as amended by the CPRA together with the regulations currently in effect. “CPRA compliance” is widely used in business and search contexts, but the official legal framework remains the amended CCPA.

Yes. The California Privacy Protection Agency (CPPA) implements and enforces the CCPA as amended by the CPRA. It can investigate possible violations, conduct administrative proceedings and impose fines.

The California Attorney General also retains enforcement authority and may bring civil actions.

Personal information generally includes information that identifies, relates to, describes or could reasonably be linked with a consumer or household. The definition also covers information that can reasonably be associated with a consumer or household directly or indirectly.

Examples include:

  • Names, addresses and email addresses

  • Online identifiers and IP addresses

  • Account and transaction records

  • Browsing and search activity

  • Geolocation and biometric information

  • Professional, employment and education data

  • Inferences used to create a consumer profile

Cookies may qualify when they can reasonably be linked to a consumer or household. Publicly available, deidentified and aggregate consumer information may be excluded when statutory conditions are met.

Violations of the CCPA as amended by the CPRA can lead to regulatory penalties. The inflation-adjusted amounts applicable in 2026 are:

  • Up to $2,663 for each violation

  • Up to $7,988 for each intentional violation

  • Up to $7,988 for each violation involving personal information of consumers known to be under 16

Consumers cannot sue for every privacy violation. A limited private right of action applies when certain personal information defined by statute is exposed in a qualifying data breach because the business failed to maintain reasonable security procedures.

In qualifying cases, statutory damages are not less than $107 and not greater than $799 per consumer per incident, or actual damages, whichever is greater.

The CPRA does not require prior consent for every cookie. The main question is whether a cookie, pixel, SDK or similar technology uses or discloses personal information in a way that qualifies as a sale or sharing.

Third-party advertising technologies and other tracking technologies may trigger sale or sharing obligations depending on how personal information is disclosed and used. Certain analytics arrangements may also require review. Where the law applies, the business must present relevant disclosures, offer an opt-out mechanism and honor valid Global Privacy Control signals.

CPRA compliance means aligning business practices with the CCPA as amended by the CPRA. A typical compliance process includes:

  • Determining whether the law applies

  • Mapping personal information and website trackers

  • Reviewing collection purposes and retention practices

  • Updating notices and privacy policies

  • Managing consumer rights requests

  • Implementing applicable sale, sharing and limit-use controls

  • Honoring Global Privacy Control

  • Reviewing vendor contracts and security measures

  • Monitoring changes in data practices and regulations

Technology can support these processes, but legal interpretation and final compliance responsibility remain with the business.

The CCPA generally applies to a for-profit business that does business in California, determines the purposes and means of processing personal information and meets at least one statutory threshold:

  • More than $26,625,000 in annual gross revenue

  • Buying, selling or sharing the personal information of 100,000 or more consumers or households in a calendar year

  • Earning 50% or more of annual revenue from selling or sharing consumers’ personal information

The gross revenue threshold is not limited to revenue from California consumers. Sale and sharing are assessed according to their specific meanings under the CCPA as amended by the CPRA.

The CCPA as amended by the CPRA gives California consumers the right to:

  • Know what personal information is collected, used, sold or shared

  • Access specific pieces of personal information

  • Request deletion subject to statutory exceptions

  • Correct inaccurate personal information

  • Opt out of sale or sharing

  • Limit certain uses and disclosures of sensitive personal information

  • Exercise their rights without discriminatory treatment

The regulations also establish rights and obligations concerning certain uses of automated decision-making technology (ADMT) involving significant decisions. Covered businesses must comply with the applicable ADMT requirements by January 1, 2027.

Sensitive personal information includes:

  • Social Security, driver’s license and passport numbers

  • Account login information combined with credentials that allow account access

  • Financial account, debit card or credit card information combined with credentials that permit access

  • Precise geolocation

  • Racial or ethnic origin, religious beliefs and union membership

  • Private mail, email and text content

  • Genetic and identifying biometric data

  • Health, sex life and sexual orientation information

Sensitive personal information does not automatically require consent. The right to limit applies only to specified uses and disclosures outside the purposes permitted by the law and regulations.

Covered businesses must issue appropriate notices, respond to consumer requests, honor applicable opt-outs, address sensitive personal information, maintain relevant contracts and use reasonable security measures.

The regulations effective January 1, 2026 introduced additional duties with separate timelines:

  • Certain businesses must conduct risk assessments for specified high-risk processing activities. The requirements apply beginning January 1, 2026. Covered processing already underway before that date must be assessed by December 31, 2027, and required information for assessments conducted in 2026 and 2027 must be submitted to the CPPA by April 1, 2028.

  • Businesses meeting the cybersecurity audit criteria have phased first-report deadlines between April 1, 2028 and April 1, 2030.

  • Businesses using ADMT for significant decisions must comply with the applicable ADMT requirements by January 1, 2027.

These additional duties apply only when the relevant regulatory criteria are met.