California Privacy Regulation Act (CPRA): 2026 Explainer & Guide
Table of Contents
The CPRA (California Privacy Rights Act) is a 2020 initiative that amended the CCPA, California's main privacy law. It is not a separate law. It created the state data privacy regulator, the California Privacy Protection Agency (CPPA), added a sensitive-data category with its own consumer right, and extended the opt-out from data sales to data sharing.
The CPRA applies to for-profit businesses in California that clear any one of three thresholds: $25 million in revenue, personal information of 100,000 consumers or households, or half of revenue from selling or sharing data. Fines run up to $2,500 per violation, and $7,500 when intentional or involving minors' data, counted per consumer, per incident.
New rules under the CPRA continue to add deadlines: risk assessments apply as of January 1, 2026, and automated decision-making rules take effect on January 1, 2027.
This guide covers the current law in one place: what the CPRA is, exactly what it changed from the CCPA, who must comply, and the checklist with its 2026-2030 deadlines.
For California's place among all 20 state privacy laws, see our U.S. state law tracker.
What is the CPRA?
The California Privacy Rights Act is an amendment to the California Consumer Privacy Act (CCPA), passed by California voters as Proposition 24 in November 2020 and effective January 1, 2023. The state's own regulator is direct about this: the CPRA did not create a new law, it amended the existing one.
That's why the CPPA still calls the law "the CCPA." When you see "CCPA as amended" or "CCPA/CPRA," they all mean the same statute: California Civil Code § 1798.100 and following.
That framing matters practically. You don't comply with the CCPA and the CPRA separately. There is one law, and the CPRA is the reason it now has a dedicated regulator, a sensitive-data category, and a sharing opt-out.

What does the CPRA stand for?
CPRA stands for the California Privacy Rights Act. It is sometimes called Proposition 24, after the 2020 ballot measure that enacted it, or CPRA of 2020 in formal citations.
CPRA vs CCPA: What changed?
The CPRA changed who enforces the law, what counts as an opt-out, and how much grace you get when something breaks. Each CCPA vs CPRA change below is paired with what to do about it.
| What changed | CCPA (2020) | CCPA as amended by CPRA | What you must do |
|---|---|---|---|
| Legal status | The original law | Same law, amended | One compliance program, not two |
| Consumer threshold | 50,000 consumers, households, or devices | 100,000 consumers or households | Re-check applicability; some small businesses fell out of scope |
| Sensitive personal information | No separate category | New category with a right to limit its use | Inventory sensitive data; add the limit link |
| Opt-out scope | Sale of personal information | Sale OR sharing (cross-context behavioral advertising) | Your ad pixels now count; "we don't sell data" stopped being a defense |
| New rights | Know, delete, opt out, non-discrimination | Adds: correct, limit sensitive-data use, opt out of sharing | Extend your rights-request intake |
| Cure period | 30-day guaranteed grace to fix violations | Removed; cure is discretionary | Audit before the regulator does |
| Enforcement | Attorney general only | CPPA (dedicated regulator) plus the AG | Two agencies now bring cases, and both did in 2025 |
Who must comply with the CPRA?
CPRA applies to for-profit businesses that do business in California (from anywhere in the world) and meet any one of three thresholds:
1. Over $25 million in annual gross revenue in the preceding year.
2. Personal information of 100,000 or more California consumers or households bought, sold, or shared in a year.
3. Half or more of annual revenue from selling or sharing California consumers' personal information.
A consumer is any California resident, and the count is unique people, not sessions: someone who visits your store 200 times is one consumer, not 200. A good-faith estimate based on your customer records, email lists, and analytics from the prior year is sufficient. You don't have to reconcile identities perfectly across systems.
Nonprofits and government agencies are out of scope. HIPAA-covered health data, clinical trial data, and certain financial data under the GLBA are exempt at the data level.

What the CPRA requires from your website
Under this law your website needs working opt-out mechanics, notice at collection, consent in specific cases, and records that prove requests were honored. Every enforcement order so far has come from these mechanics failing, not from missing policy language.
The two links (or their GPC equivalent). A "Do Not Sell or Share My Personal Information" mechanism, and a "Limit the Use of My Sensitive Personal Information" mechanism if you use sensitive data beyond exempt purposes. California also requires honoring Global Privacy Control: a browser signal that broadcasts the visitor's opt-out automatically, which your site must treat as a valid request with no click required.
Notice at collection. What you collect, why, whether you sell or share it, and retention, presented at or before the point of collection.
An opt-out that actually executes. When someone opts out (by link or GPC signal), the ad and analytics tags that share their data have to stop. Todd Snyder's $345,178 order came after its portal silently dropped every opt-out request for 40 days; the regulator tested the plumbing, not the policy.
Consent where the law flips to opt-in. Selling or sharing data of consumers under 16 requires opt-in (parental consent under 13). Financial incentives tied to data need informed consent.
Rights-request intake with records. Know, delete, correct, portability, limit, opt out, all with a 45-day response clock, identity verification proportional to the request, and logs that prove what happened. Our DSAR guide covers the intake mechanics.
How Enzuzo handles this: Enzuzo's consent management platform serves California visitors the required links, honors GPC signals automatically, blocks sharing-classified tags until the consent state allows them, and keeps the timestamped records. Teams typically go live in one to three days. Book a demo to see how it keeps you compliant with the CPRA.
CPRA compliance checklist
Here's a step-by-step breakdown of how you need to be compliant with the CPRA.

| Step | What to do | Deadline |
|---|---|---|
| 1. Map your data | Inventory the personal information you collect, including sensitive categories. Neural data joined the sensitive list in January 2025. | In effect |
| 2. Re-check your thresholds | Re-test applicability against the current numbers, including B2B and employee data. | Ongoing |
| 3. Update your notices | Update your notice at collection and privacy policy for sharing, sensitive data, and retention. | Ongoing |
| 4. Ship the opt-out links | Add the two links (or a single alternative opt-out link) and honor GPC signals. | In effect |
| 5. Gate your tags | Make opt-outs actually stop ad-tech sharing. Test with a GPC-enabled browser. | In effect |
| 6. Extend your DSAR intake | Handle correction and limit requests, with proportional verification. (Todd Snyder was fined for demanding too much.) | In effect |
| 7. Fix your vendor contracts | Give service providers, contractors, and third parties the specific contract terms each requires. (Honda's fine was largely this.) | In effect |
| 8. Run risk assessments | Assess high-risk processing and document it. | Processing since Jan 1, 2026; file with the CPPA by Apr 1, 2028 |
| 9. Inventory your ADMT | If automated decision-making makes significant decisions about consumers, put notices and opt-outs in place. | By Jan 1, 2027 |
| 10. Check cybersecurity audit thresholds | Confirm whether your revenue triggers a required cybersecurity audit; certifications phase in by revenue band. | Phases in Apr 2028–Apr 2030 |
| 11. Mind minors' data | Get opt-in before selling or sharing under-16 data; parental consent under 13. | In effect |
| 12. Keep records | Retain consent logs, request logs, and assessment documents. The regulator asks for receipts, not intentions. | Ongoing |
CPRA deadlines: what's in force and what's coming
The CPRA regulations added three new obligations in 2025: risk assessments, automated decision-making rules, and cybersecurity audits. The CPPA finalized them in July 2025, the state approved them in September, and each arrived with its own deadline:
| Date | What | What you must do |
|---|---|---|
| Jan 1, 2023 | CPRA amendments effective; B2B and employee exemptions expire | Full compliance baseline, including workforce data |
| Jul 1, 2023 | Enforcement began | |
| Jan 1, 2025 | Neural data added to sensitive personal information (SB 1223); AI-output clarification (AB 1008) | Update your data inventory and sensitive-data handling |
| Sep 23, 2025 | ADMT, risk-assessment, and cybersecurity-audit regulations approved | Read them; the next four rows are the schedule |
| Jan 1, 2026 | Risk-assessment obligations apply to covered processing | Conduct and document assessments |
| Aug 1, 2026 | DROP live: data brokers must process deletion requests every 45 days | Data brokers only; check whether you meet the definition |
| Jan 1, 2027 | ADMT compliance deadline for significant decisions | Notices, opt-outs, and human-review paths in place |
| Apr 1, 2028 | First risk-assessment submissions due to the CPPA; cybersecurity audit certifications begin ($100M+ revenue) | Submit; certify |
| Apr 2029 / Apr 2030 | Audit certifications for $50–100M, then under $50M businesses | Staged by revenue |
Fines and enforcement
CCPA violations cost up to $2,500 each, or $7,500 when intentional or involving a minor's personal information, and each affected consumer can count as a separate violation. The guaranteed 30-day grace period is gone; whether you get time to fix a violation is now up to the regulator.
Enforcement runs through two bodies: the CPPA, with administrative fines, and the attorney general. Consumers can't sue over ordinary violations, but data breaches carry a private right of action at $100 to $750 per consumer per incident.
The fines are no longer theoretical. In 2025, the CPPA fined Honda $632,500 and Todd Snyder $345,178, and the attorney general settled with Healthline for $1.55 million, the AG's largest settlement under this law so far. All three cases came down to broken consent mechanics and missing vendor terms.

Consumer rights under the CPRA
California residents can:
1. Know and access what's collected about them
2. Correct inaccuracies
3. Delete their data
4. Take a portable copy
5. Opt out of sale and sharing, by link or GPC signal
6. Limit the use of sensitive personal information
7. Opt out of significant automated decision-making, and see how it's used
8. Exercise all of this without retaliation
Every request starts a 45-day response clock.
CPRA FAQs
What does CPRA stand for?
CPRA stands for the California Privacy Rights Act, the 2020 ballot initiative (Proposition 24) that amended the California Consumer Privacy Act effective January 1, 2023. It strengthened the CCPA rather than replacing it.
Is the CPRA a separate law from the CCPA?
No. The CPRA amended the CCPA; there is one law, officially still called the CCPA. The state regulator itself refers to "the CCPA, as amended." Compliance programs, notices, and contracts should treat CCPA and CPRA requirements as a single set.
What's the difference between the CCPA and the CPRA?
The CPRA added a dedicated regulator (the CPPA), a sensitive-personal-information category with a right to limit its use, an opt-out covering data sharing (not just sale), rights to correct data, a higher consumer threshold (100,000), and removed the guaranteed 30-day cure period.
Who enforces the CPRA?
The California Privacy Protection Agency and the attorney general, both actively: the CPPA fined Honda $632,500 and Todd Snyder $345,178 in 2025, and the AG settled with Healthline for $1.55 million. Consumers can sue only over data breaches, at $100 to $750 per consumer per incident.
What is sensitive personal information under the CPRA?
Categories including government identifiers like SSNs, precise geolocation, race or ethnicity, religion, union membership, genetic and biometric data, health and sex-life data, message contents, and, since January 2025, neural data. Consumers can limit its use to what's necessary to provide the service.
Does the CPRA require honoring Global Privacy Control?
Yes. California requires businesses to treat GPC browser signals as valid opt-outs of sale and sharing, applied automatically without a click. Regulators have tested this in enforcement, so a banner that ignores the signal is a live liability.
What are the CPRA compliance deadlines for 2026 and 2027?
Risk-assessment obligations apply to covered processing as of January 1, 2026, with documentation due to the CPPA by April 1, 2028. Automated decision-making (ADMT) compliance is due January 1, 2027. Cybersecurity audit certifications phase in by revenue tier from April 2028 through April 2030.
Osman Husain
Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.