CCPA vs CPRA: What Businesses Need to Know
CCPA vs CPRA : If you’ve spent any time researching California privacy law, you’ve run into both “CCPA” and “CPRA” used constantly — sometimes in the same sentence, sometimes as if they’re competitors. Compliance checklists reference one or the other inconsistently, vendor security questionnaires ask about both, and it’s genuinely unclear to most operators whether they need to comply with one, the other, or somehow both.
Here’s the part that resolves most of that confusion: there is only one law. The California Privacy Rights Act didn’t repeal or replace the California Consumer Privacy Act — it amended it. Proposition 24, passed by California voters in November 2020, rewrote large sections of the existing statute, added new consumer rights, created a new enforcement agency, and raised the bar on what businesses have to do. The law is still officially titled the California Consumer Privacy Act of 2018. What most people mean when they say “CPRA” is simply the current, amended version of that same law.
This guide walks through exactly what changed between the original 2020 version and today’s CPRA-amended version, why that gap matters if your compliance program hasn’t been updated since 2023, and what the newest 2026 regulations add on top of all of it.
�� Quick Answer – CCPA vs CPRA are not two separate laws — the CPRA (Proposition 24) amended the existing CCPA, with those amendments taking effect January 1, 2023. The current law is properly called “the CCPA, as amended by the CPRA,” and it added two new consumer rights (to correct inaccurate data, and to limit use of sensitive personal information), created a new category of sensitive personal information, expanded opt-out rights to cover data “sharing” and not just “sale,” established a dedicated enforcement agency (the CPPA), removed the automatic 30-day cure period, raised the applicability threshold from 50,000 to 100,000 consumers, and — as of January 1, 2026 — added mandatory risk assessments, cybersecurity audits, and rules for automated decision-making technology.
The Relationship, Not the Rivalry
Understanding the actual relationship between these two names matters more than memorizing their differences point by point. The California Consumer Privacy Act became law in 2018 and took effect January 1, 2020 — the first comprehensive state-level consumer privacy law in the United States, giving residents rights to know, delete, and opt out of the sale of their personal information. Then, in November 2020, California voters approved the California Privacy Rights
Act as a ballot initiative. Rather than starting a new statute from scratch, the CPRA amended the CCPA directly, and those amendments became enforceable on January 1, 2023.
Practically, this means when someone asks whether they need to comply with “CCPA or CPRA,” the honest answer is that there’s only one law to comply with — the current, amended version — and one regulator actively enforcing it. Treating them as competing frameworks, or assuming an old CCPA-only compliance program is still sufficient, is the single most common gap auditors and regulators find in 2026.
What the CPRA Actually Changed
The amendments touch nearly every part of the original statute, but five changes account for most of the practical compliance work.
- A dedicated enforcement agency. The CPRA created the California Privacy Protection Agency (CPPA) — the first US agency built solely to enforce a consumer privacy law. Before this, only the California Attorney General could bring enforcement action. Today both regulators are active, and the CPPA has already imposed fines exceeding $4 million in 2026 alone.
- A new “sharing” concept, not just “sale.” The original CCPA only let consumers opt out of the sale of their data. Some businesses argued that passing data to ad-tech partners wasn’t a “sale” because no money changed hands. The CPRA closed that loophole by adding “sharing” — making data available to a third party for cross-context behavioral advertising — as an equally opt-outable activity, regardless of payment.
- Sensitive personal information as its own category. The CPRA introduced eleven defined categories of sensitive personal information — Social Security numbers, precise geolocation, financial account credentials, health data, and others — each carrying its own disclosure obligations and a new consumer right to limit its use.
- Two new consumer rights. The right to correct inaccurate personal information, and the right to limit the use and disclosure of sensitive personal information — neither existed under the original 2020 law.
- Removal of the automatic cure period. Under the original CCPA, businesses had a guaranteed 30 days to fix a violation after notice, with no fine if they did. The CPRA made that cure period discretionary rather than automatic, meaning regulators are no longer required to give a business a free pass on a first offense.
CCPA vs CPRA Before and After, Side by Side
Seeing the original law next to its current, amended form makes clear why a compliance program built in 2020 and never revisited is very likely out of date.
The Six Consumer Rights Today
The California Privacy Protection Agency itself uses a simple memory aid for the rights added or expanded by the CPRA: Limit, Opt-out, Correct, and Know — “L.O.C.K.” Combined with the two rights that existed from the beginning, Delete and Non-Discrimination, California residents now hold six distinct rights over their personal information.
CCPA vs CPRA Who Has to Comply — Today's Thresholds
The CCPA vs CPRA also changed who the law applies to. A for-profit business doing business in California and collecting residents’ personal information must comply if it meets at least one of three current thresholds:
- Annual gross revenue above $26,625,000 — a figure adjusted for inflation every odd-numbered year, up from the original $25 million threshold.
- Annually buys, sells, or shares the personal information of 100,000 or more consumers or households — raised from 50,000 under the original CCPA.
- Derives 50% or more of annual revenue from selling or sharing consumers’ personal information.
⚠️ Common Trap – Assuming your business is too small to be in scope because it doesn’t sell data for money. The CPRA’s “sharing” concept was written specifically to close that loophole — routing personal information to an ad-tech partner, analytics provider, or data broker for cross-context behavioral advertising counts even when no payment changes hands. Many businesses that correctly concluded they didn’t “sell” data under the original CCPA vs CPRA are in scope today because of “sharing” alone.
What Changed CCPA vs CPRA on January 1, 2026
The CCPA vs CPRA didn’t just amend the statute directly — it also directed the CPPA to write detailed regulations on several topics the ballot initiative only outlined. The CPPA finalized a major package of these regulations in September 2025, and they took effect January 1, 2026, adding a further layer of obligations on top of the 2023 amendments.
- Mandatory risk assessments for any processing activity that presents a significant risk to consumer privacy, weighing the benefits of the processing against the risks — with attestations and summaries due to the CPPA by April 1, 2028.
- Mandatory cybersecurity audits for businesses whose processing presents significant risk, assessing whether security practices are appropriate for the nature and volume of personal information handled.
- New rules governing automated decision-making technology (ADMT), including disclosure and opt-out requirements where automated systems make significant decisions about consumers.
- Mandatory confirmation of honored opt-outs, including for opt-out preference signals like Global Privacy Control (GPC) sent automatically by browsers and extensions — no longer optional to acknowledge.
Penalties: What Non-Compliance Actually Costs
The per-violation numbers look modest next to headline-grabbing GDPR fines, but CCPA penalties stack per violation and per affected consumer — which is what turns a single systemic failure into an eight-figure settlement.
| Violation Type | Maximum Penalty (2026) | Who Enforces It |
|---|---|---|
| Unintentional violation | $2,663 per violation | CPPA and/or California Attorney General |
| Intentional violation, or one involving a minor's data | $7,988 per violation | CPPA and/or California Attorney General |
| Consumer private right of action (certain data breaches) | $107–$799 per incident, or actual damages | Individual consumers, via civil suit |
Real enforcement actions show how quickly per-violation figures compound. General Motors’ $12.75 million settlement, announced in May 2026 and brought jointly by the Attorney General, the CPPA, and local district attorneys over the sale of driving and location data, is the largest CCPA fine to date. Disney was fined $2.75 million in a separate February 2026 Attorney General action. Ignoring opt-out requests from just 10,000 California residents, even at the lower unintentional rate, reaches $26.6 million in theoretical exposure — the stacking is what matters, not the headline per-violation number.
A consistent pattern runs through nearly every major settlement since the CPRA took effect: an opt-out mechanism or Global Privacy Control signal that didn’t fully work. Honda and Ford were both fined for requiring identity verification before processing a simple opt-out request. Disney’s opt-out applied on one device but not another. These aren’t novel legal theories — they’re basic mechanism failures that a straightforward technical audit would catch.
A Practical Compliance-Gap Workflow
For a business whose privacy program was built for the original 2020 CCPA and hasn’t been substantially revisited, the fastest path to closing the gap follows a specific order — start with what regulators can check simply by visiting your website.
Common Mistakes
- Treating CCPA vs CPRA as alternative or competing frameworks instead of understanding that CPRA is simply the current, amended version of the same law.
- Leaving the footer link reading “Do Not Sell My Personal Information” instead of the current “Do Not Sell or Share My Personal Information” language, or the unified “Your Privacy Choices” pattern.
- Assuming a 30-day cure period still applies to regulatory enforcement — it was removed for CPPA and Attorney General actions effective January 1, 2023, and only survives in a narrower form for the separate consumer private right of action.
- Not building a correction workflow, and underestimating how much data-lineage work “correct” actually requires once information has been shared with third parties who also need to be notified.
- Ignoring Global Privacy Control and other opt-out preference signals, or displaying that an opt-out was processed without actually stopping the underlying data flow — the single most common thread across 2025–2026 enforcement actions.
- Missing the new 2026 obligations entirely — risk assessments, cybersecurity audits, and ADMT rules are recent enough that many otherwise CPRA-compliant programs haven’t accounted for them yet.
Competitor Content Analysis
A look at what currently ranks for “ccpa vs cpra” shows heavy coverage from legal-tech and consent-management vendors, with a fairly consistent factual core but some recurring gaps.
- Legal and consent-management platforms (Termly, Transcend, Bastion) correctly emphasize that CPRA amended rather than replaced CCPA, but many still structure the content as a side-by-side “law vs law” comparison, which reinforces the exact misconception the content is trying to correct.
- The CPPA’s own FAQ page is the authoritative source and introduces the useful “L.O.C.K.” rights mnemonic, but like most regulator content, it’s dense and not built for a business audience trying to find a practical action list.
- Coverage of the January 2026 regulations (risk assessments, cybersecurity audits, ADMT) is thin on most comparison-focused pages, which tend to freeze the story at the 2023 CPRA amendments and miss the most recent operative changes.
- Penalty figures are inconsistently updated — several competing articles still cite the pre-2025 $2,500/$7,500 caps instead of the current inflation-adjusted $2,663/$7,988 figures, which is a small but meaningful accuracy gap.
- Very few articles visualize the actual timeline of amendments or use the regulator’s own rights mnemonic as a visual anchor — both are clear differentiation opportunities in a heavily text-based competitive field.
Search Intent: What People Are Actually Asking
- Primary intent is clarifying, not comparing: most searchers for this exact phrase are trying to resolve confusion about whether these are one law or two, not seeking a feature-by-feature comparison of rival statutes.
- “Is CPRA a separate law from CCPA” and similar phrasing form a large adjacent cluster, reinforcing that the naming confusion is the dominant pain point driving this search term.
- Compliance-currency queries trail closely — “CCPA 2026 changes” and “CPRA new rules” suggest a meaningful share of searchers are specifically checking whether their existing program accounts for the newest regulations.
- Penalty and enforcement queries (“CCPA fines,” “CCPA lawsuit”) are common secondary intent, often from businesses assessing risk exposure after a specific incident or vendor question, not from pure research.
ACCPA vs CPRA I Overview
If this topic were condensed into an AI-generated search summary, it would likely read: CCPA and CPRA are not two separate privacy laws — the California Privacy Rights Act (CPRA), approved by voters in November 2020 as Proposition 24, amended the existing California Consumer Privacy Act (CCPA) rather than replacing it. Those amendments took effect January 1, 2023, adding two new consumer rights (to correct data and to limit use of sensitive personal information), creating the California Privacy Protection Agency as a dedicated enforcement body, expanding opt-out rights to cover data sharing in addition to sale, and removing the automatic 30-day cure period for regulatory violations. As of January 1, 2026, further CPPA regulations took effect requiring risk assessments, cybersecurity audits, and new rules for automated decision-making technology. The current law is properly referred to as “the CCPA, as amended by the CPRA,” and 2026 penalties reach up to $2,663 per unintentional violation and $7,988 per intentional violation, with fines stacking per affected consumer.
�� Worth Remembering – An AI overview or quick search answer will correctly tell a reader that CPRA amended CCPA rather than replacing it — but it won’t tell them whether their own privacy notice, opt-out mechanism, and intake forms were actually updated to reflect those amendments, or whether their processing activities now trigger the risk assessment and cybersecurity audit rules that took effect in January 2026. That’s a program-specific gap analysis, not a naming-history question, and it’s where the real compliance risk — and the real enforcement pattern seen in recent settlements — actually lives.
A Practical Compliance Checklist
- Confirm your privacy notice and footer link use current language — “Do Not Sell or Share My Personal Information” — not the pre-2023 “Do Not Sell” wording.
- Verify your opt-out mechanism actually stops the underlying data flow, and test that it recognizes Global Privacy Control and other browser opt-out preference signals.
- Confirm your business meets or falls under the current thresholds: $26,625,000 in annual revenue, 100,000+ consumers/households, or 50%+ of revenue from selling or sharing data.
- Build (or verify) intake and fulfillment workflows for the two CPRA-era rights: correction and limiting the use of sensitive personal information.
- Inventory sensitive personal information across all systems against the eleven defined categories, and add the required separate disclosures.
- Update vendor contracts to reflect the CPRA’s service provider and contractor categories, including flow-down restrictions on selling or sharing data.
- Determine whether your processing activities trigger the January 2026 risk assessment and cybersecurity audit requirements, and begin scoping them now rather than waiting for the 2028 attestation deadline.
How B4Q Assurance Helps
B4Q Assurance helps businesses audit an existing CCPA program against the current CPRA-amended statute, identify gaps in opt-out mechanisms and sensitive-data handling before they become enforcement findings, and scope the new 2026 risk assessment and cybersecurity audit requirements before the attestation deadlines arrive.
CCPA vs CPRA Resources
- California Privacy Protection Agency — Official FAQs — https://cppa.ca.gov/faq.html
- California Privacy Protection Agency — Official Website — https://cppa.ca.gov
- California Attorney General — CCPA Official Page — https://oag.ca.gov/privacy/ccpa
- California Privacy Protection Agency — Regulations — https://cppa.ca.gov/regulations/
CCPA vs CPRA FAQs
Do we need to comply with CCPA or CPRA?
There is only one law to comply with — the CCPA as amended by the CPRA. If your business meets the current applicability thresholds, you’re subject to the full current version of the statute, not a choice between two different laws.
If we were CCPA-compliant in 2020, are we still compliant today?
Almost certainly not fully. The CPRA added rights, a new data category, a new enforcement agency, and — as of January 2026 — mandatory risk assessments and cybersecurity audits, none of which existed under the original 2020 law. A program that hasn’t been revisited since 2020 very likely has real gaps.
What's the difference between "selling" and "sharing" personal information?
“Selling” involves an exchange of personal information for monetary or other valuable consideration. “Sharing” — a concept the CPRA added — covers making personal information available to a third party for cross-context behavioral advertising, regardless of whether money changes hands. Consumers can opt out of both.
Does the 30-day cure period still exist under CPRA?
Not automatically for regulatory enforcement. The CPRA removed the guaranteed 30-day cure period for CPPA and Attorney General actions effective January 1, 2023; regulators may still consider good-faith efforts to fix a violation, but businesses no longer have a statutory right to a fine-free cure window. A separate, narrower cure period still applies to the consumer private right of action for certain data breaches.
What are the new 2026 requirements exactly?
Regulations that took effect January 1, 2026 require risk assessments for high-risk processing activities (with attestations due to the CPPA by April 1, 2028), cybersecurity audits for businesses whose processing presents significant risk, new disclosure and opt-out rules for automated decision-making technology, and mandatory confirmation of honored opt-outs including Global Privacy Control signals.