Loading

CCPA and CPRA

Knowledge Base | CCPA and CPRA | What is the difference between CCPA and CPRA?

What is the difference between CCPA and CPRA?

The CCPA introduced California’s main consumer privacy rules. The CPRA later strengthened these rules by expanding consumer rights and adding new responsibilities for businesses. Rather than replacing the CCPA, it updated and extended the existing law.

Comparison area

CCPA

CPRA

Legal role

Established California’s core consumer privacy law.

Amended and strengthened the existing CCPA framework.

Main effective date

Became effective on January 1, 2020.

Most amendments became effective on January 1, 2023.

Business threshold

Applied when a business processed data relating to at least 50,000 consumers, households or devices, among other criteria.

Raised the threshold to 100,000 consumers or households and removed devices from this calculation.

Consumer rights

Provided rights to know, access, delete and opt out of the sale of personal information.

Added the right to correct inaccurate information, opt out of sharing and limit certain uses of sensitive information.

Sale and sharing

Focused primarily on the sale of personal information.

Extended opt-out rights to sharing for cross-context behavioural advertising.

Sensitive information

Did not establish a separate sensitive personal information category.

Defined sensitive personal information and introduced a right to limit certain uses and disclosures.

Data collection and use

Required businesses to disclose their data practices.

Added clearer requirements for purpose limitation, data minimisation and proportionate use.

Data retention

Did not contain the same detailed retention disclosure requirements.

Requires businesses to disclose retention periods or the criteria used to determine them and avoid keeping data longer than reasonably necessary.

Third-party controls

Regulated service providers through contractual restrictions.

Added the contractor category and strengthened obligations for service providers, contractors and third parties.

Employee and B2B data

Temporarily exempted much employee and business-contact information from several requirements.

Allowed those temporary exemptions to expire, bringing more employee and B2B information within the framework.

Enforcement

Enforcement was primarily handled by the California Attorney General.

Created the California Privacy Protection Agency, which shares enforcement authority with the Attorney General.

Right to cure

Generally provided a 30-day period to correct an alleged violation before enforcement.

Removed the automatic 30-day cure period. Authorities may consider corrective action, but businesses are not guaranteed time to cure.

The current law is generally referred to as the CCPA as amended by the CPRA. Businesses should therefore assess compliance under the combined framework rather than treating the CCPA and CPRA as two separate privacy regimes.