Tell us about your websites, digital services and the technologies used across them. The initial review helps identify the areas that need attention within your website privacy layer.
CPRA Privacy Management for Websites
The California Privacy Rights Act (CPRA) expands consumer rights and website privacy obligations around personal information, sensitive data and consumer choice. Okito helps websites manage these requirements with privacy scanning, configurable controls and preference records across cookies, pixels and connected services.
How CPRA Shapes Website Data Practices
Sensitive Personal Information
Sensitive personal information may enter a website through forms, account areas, precise geolocation tools and connected services. Businesses should identify where this data is collected and, where applicable, allow consumers to limit certain uses and disclosures.
Expanded Consumer Rights
By amending the original CCPA, CPRA expanded consumer control over personal information. California consumers may request correction, opt out of sale or sharing and restrict certain uses of sensitive personal information.
Purpose and Retention Limits
The purpose disclosed at collection should guide how personal information is later used and retained. Data practices must remain reasonably necessary and proportionate to that stated purpose, while businesses should establish and disclose applicable retention periods or criteria.
Build a Practical CPRA Website Workflow
Review the cookies, pixels, forms and third-party technologies that collect or transmit personal information.
Identify sensitive personal information and connect each data category with its collection, use and retention requirements.
Link opt-out and limit-use selections with the website technologies affected by each privacy choice.
Confirm that privacy signals work as intended, retain relevant preference records and revisit the configuration when the website changes.
What CPRA Means for the Website Experience
Notice at Collection with Purpose and Retention Details
Consumers should know what personal information a website collects and why. Privacy notices should match the website’s actual data practices and explain how sensitive personal information is handled and how long data is kept.
Identify the categories of personal information collected
Explain why each type of data is collected and used
State whether personal information is sold or shared
Disclose sensitive personal information where applicable
Define how long personal information is retained
Update disclosures when data practices change
Okito connects website scan results with configurable notices and policy tools, making it easier to keep privacy information aligned with the website.
From Privacy Choice to Website Action
The CCPA, as amended by CPRA, gives consumers different choices depending on how their personal information is used. These include opting out of sale or sharing and limiting certain uses of sensitive personal information.
Provide a clear way to opt out of the sale or sharing of personal information where applicable
Provide a way to limit the use and disclosure of sensitive personal information where the right applies
Recognize opt-out preference signals such as Global Privacy Control
Apply privacy choices to relevant advertising, analytics and third-party technologies
Obtain required affirmative authorization before selling or sharing information belonging to consumers known to be under 16, where applicable
Global Privacy Control communicates a consumer’s request to opt out of sale or sharing. Okito recognizes supported preference signals and applies the configured response across relevant website technologies.
Managing CPRA Consumer Privacy Rights
California consumers have several rights over the personal information a covered business holds about them. A privacy workflow should make these rights easy to exercise and connect each request with the appropriate internal process.
Request information about personal information collected, used, sold or shared
Access specific pieces of personal information
Request deletion, subject to applicable exceptions
Correct inaccurate personal information
Opt out of the sale or sharing of personal information
Limit certain uses and disclosures of sensitive personal information
Submit applicable privacy requests without creating an account solely for that purpose
Exercise privacy rights without discriminatory treatment
Okito keeps website preferences and consumer choices organized in a traceable digital workflow. Identity verification, legal assessment and the final response remain the responsibility of the business.
Keep Website Tracking Under Continuous Review
Cookies, pixels, SDKs and third-party services can create new data flows as a website changes. CPRA readiness therefore requires ongoing visibility into how tracking technologies collect and share personal information.
Scan digital properties for cookies, pixels and third-party scripts
Identify technologies by purpose, provider and data activity
Review technologies involved in sale, sharing or cross-context behavioral advertising
Apply opt-out requests and preference signals to relevant technologies
Keep records of how privacy choices were received and applied
Review the setup when vendors, campaigns or tracking technologies change
Okito brings recurring scans, privacy controls, GPC recognition and preference records into one central workspace.
Bring Your CPRA Website Controls into One Clear Workflow
Frequently Asked Questions
The California Privacy Rights Act (CPRA) is a 2020 ballot initiative that amended the California Consumer Privacy Act (CCPA). It did not create a separate privacy law.
The CPRA added rights to correct inaccurate information and limit certain uses of sensitive personal information. It also expanded opt-out rights to sharing, introduced clearer purpose and retention principles and established the California Privacy Protection Agency.
The CCPA created California’s main consumer privacy framework. The CPRA expanded that framework in several areas:
The right to opt out now covers both sale and sharing
Consumers can request correction of inaccurate information
Certain uses of sensitive personal information can be limited
Deletion obligations can extend to relevant third parties
Collection, use and retention are subject to clearer purpose and proportionality principles
The California Privacy Protection Agency has dedicated regulatory authority
The result is not a separate law but a broader version of the original CCPA.
No. The CPRA does not replace the CCPA. It amended and expanded the existing law. Businesses follow the CCPA as amended by the CPRA together with the regulations currently in effect. “CPRA compliance” is widely used in business and search contexts, but the official legal framework remains the amended CCPA.
Yes. The California Privacy Protection Agency (CPPA) implements and enforces the CCPA as amended by the CPRA. It can investigate possible violations, conduct administrative proceedings and impose fines.
The California Attorney General also retains enforcement authority and may bring civil actions.
Personal information generally includes information that identifies, relates to, describes or could reasonably be linked with a consumer or household. The definition also covers information that can reasonably be associated with a consumer or household directly or indirectly.
Examples include:
Names, addresses and email addresses
Online identifiers and IP addresses
Account and transaction records
Browsing and search activity
Geolocation and biometric information
Professional, employment and education data
Inferences used to create a consumer profile
Cookies may qualify when they can reasonably be linked to a consumer or household. Publicly available, deidentified and aggregate consumer information may be excluded when statutory conditions are met.
Violations of the CCPA as amended by the CPRA can lead to regulatory penalties. The inflation-adjusted amounts applicable in 2026 are:
Up to $2,663 for each violation
Up to $7,988 for each intentional violation
Up to $7,988 for each violation involving personal information of consumers known to be under 16
Consumers cannot sue for every privacy violation. A limited private right of action applies when certain personal information defined by statute is exposed in a qualifying data breach because the business failed to maintain reasonable security procedures.
In qualifying cases, statutory damages are not less than $107 and not greater than $799 per consumer per incident, or actual damages, whichever is greater.
The CPRA does not require prior consent for every cookie. The main question is whether a cookie, pixel, SDK or similar technology uses or discloses personal information in a way that qualifies as a sale or sharing.
Third-party advertising technologies and other tracking technologies may trigger sale or sharing obligations depending on how personal information is disclosed and used. Certain analytics arrangements may also require review. Where the law applies, the business must present relevant disclosures, offer an opt-out mechanism and honor valid Global Privacy Control signals.
CPRA compliance means aligning business practices with the CCPA as amended by the CPRA. A typical compliance process includes:
Determining whether the law applies
Mapping personal information and website trackers
Reviewing collection purposes and retention practices
Updating notices and privacy policies
Managing consumer rights requests
Implementing applicable sale, sharing and limit-use controls
Honoring Global Privacy Control
Reviewing vendor contracts and security measures
Monitoring changes in data practices and regulations
Technology can support these processes, but legal interpretation and final compliance responsibility remain with the business.
The CCPA generally applies to a for-profit business that does business in California, determines the purposes and means of processing personal information and meets at least one statutory threshold:
More than $26,625,000 in annual gross revenue
Buying, selling or sharing the personal information of 100,000 or more consumers or households in a calendar year
Earning 50% or more of annual revenue from selling or sharing consumers’ personal information
The gross revenue threshold is not limited to revenue from California consumers. Sale and sharing are assessed according to their specific meanings under the CCPA as amended by the CPRA.
The CCPA as amended by the CPRA gives California consumers the right to:
Know what personal information is collected, used, sold or shared
Access specific pieces of personal information
Request deletion subject to statutory exceptions
Correct inaccurate personal information
Opt out of sale or sharing
Limit certain uses and disclosures of sensitive personal information
Exercise their rights without discriminatory treatment
The regulations also establish rights and obligations concerning certain uses of automated decision-making technology (ADMT) involving significant decisions. Covered businesses must comply with the applicable ADMT requirements by January 1, 2027.
Sensitive personal information includes:
Social Security, driver’s license and passport numbers
Account login information combined with credentials that allow account access
Financial account, debit card or credit card information combined with credentials that permit access
Precise geolocation
Racial or ethnic origin, religious beliefs and union membership
Private mail, email and text content
Genetic and identifying biometric data
Health, sex life and sexual orientation information
Sensitive personal information does not automatically require consent. The right to limit applies only to specified uses and disclosures outside the purposes permitted by the law and regulations.
Covered businesses must issue appropriate notices, respond to consumer requests, honor applicable opt-outs, address sensitive personal information, maintain relevant contracts and use reasonable security measures.
The regulations effective January 1, 2026 introduced additional duties with separate timelines:
Certain businesses must conduct risk assessments for specified high-risk processing activities. The requirements apply beginning January 1, 2026. Covered processing already underway before that date must be assessed by December 31, 2027, and required information for assessments conducted in 2026 and 2027 must be submitted to the CPPA by April 1, 2028.
Businesses meeting the cybersecurity audit criteria have phased first-report deadlines between April 1, 2028 and April 1, 2030.
Businesses using ADMT for significant decisions must comply with the applicable ADMT requirements by January 1, 2027.
These additional duties apply only when the relevant regulatory criteria are met.
Türkçe
English