CPRA vs CCPA: what's the difference?
The CPRA is not a separate law; it amended the CCPA. California voters passed it in 2020, and its changes took effect January 1, 2023. It added the right to correct data, limits on sensitive personal information, and created the California Privacy Protection Agency to enforce the law.
Applies to: Businesses subject to the California Consumer Privacy Act; the CPRA amendments apply the same $25M-revenue, 100,000-consumer, or 50-percent-data-revenue thresholds and added new obligations from January 1, 2023.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
People search for CPRA versus CCPA expecting two rival laws. There is only one. The California Privacy Rights Act, passed as Proposition 24 in 2020, did not replace the California Consumer Privacy Act; it amended it. The California Attorney General's office is explicit that the CPRA amended the CCPA rather than creating a separate law, which is why the combined statute is usually called the CCPA, as amended. What changed is the substance, and those changes have been in force since January 1, 2023.
Are the CPRA and CCPA the same law?
Effectively, yes. The CCPA became operative on January 1, 2020. In November 2020 California voters approved Proposition 24, the CPRA, and its amendments took effect on January 1, 2023. So a business does not choose between the two: it complies with the current, amended statute. The applicability test also did not change in shape. Under Cal. Civ. Code 1798.140(d), a for-profit business that handles California residents' personal information is covered if it has over $25 million in gross annual revenue, buys, sells, or shares the personal information of 100,000 or more consumers or households, or derives 50 percent or more of its revenue from selling or sharing that information.
What did the CPRA change?
The CPRA expanded the law in four ways that matter operationally. It added a new consumer right to correct inaccurate personal information, in Cal. Civ. Code 1798.106. It created a category of sensitive personal information and a right to limit its use and disclosure, in 1798.121, with a Limit the Use of My Sensitive Personal Information control. It added the concept of sharing, meaning cross-context behavioral advertising, so opt-outs now cover more than an outright sale. And it raised the consumer-volume threshold to 100,000 consumers or households while dropping the earlier device count.
Who enforces the amended law?
This is the structural change. The original CCPA was enforced by the Attorney General alone. The CPRA created the California Privacy Protection Agency, in Cal. Civ. Code 1798.199.10, a dedicated five-member board with rulemaking and enforcement power over the statute. The CPRA also removed the CCPA's automatic 30-day right to cure, so a business can no longer count on a grace period to fix a violation before enforcement. Administrative fines under 1798.155 run to $2,500 per violation, or $7,500 for an intentional violation or one involving a minor's data.
What this means for your business
If you were already compliant with the original CCPA, the CPRA did not reset your obligations, but it did add to them. The pieces to check are the correction right, the sensitive-data limit, the broader opt-out that now covers sharing, and the fact that a standing regulator can act without giving you a cure period. For the applicability test itself, see does California's CCPA apply to your business and does the CCPA apply if you are based outside California. The US state privacy laws hub shows how California compares with the other states.
Next step
If you are not sure whether the amended CCPA reaches you or which of the new duties you owe, run the free 2-minute Obligation Scan. It checks the 1798.140(d) thresholds against your business and flags the correction, sensitive-data, and opt-out obligations the CPRA added, so you work from the current law rather than the 2020 version.
Compliance checklist
- Treat the CCPA and CPRA as one law: the CPRA amendments have applied since January 1, 2023.
- Confirm you meet a threshold in Cal. Civ. Code 1798.140(d): over $25 million in revenue, 100,000 consumers or households, or 50 percent of revenue from selling or sharing data.
- Add a documented process to honor the new right to correct inaccurate personal information.
- Identify the sensitive personal information you process and offer a Limit the Use of My Sensitive Personal Information choice.
- Update opt-outs to cover sharing for cross-context behavioral advertising, and expect enforcement by the California Privacy Protection Agency.
Sources
- Cal. Civ. Code 1798.140(d) (business thresholds; sells or shares; 100,000), California Legislative Information
- Cal. Civ. Code 1798.106 (right to correct) and 1798.121 (right to limit sensitive personal information)
- Cal. Civ. Code 1798.199.10 (California Privacy Protection Agency)
- California Attorney General, CCPA (CPRA amended the CCPA; operative January 1, 2023)
Last verified: 2026-08-03
Informational, not legal advice.