What is California Privacy Rights Act?
Definition
The California Privacy Rights Act (CPRA) is a ballot initiative approved by California voters in November 2020 that significantly amended and expanded the CCPA. It created the California Privacy Protection Agency, introduced new consumer rights, and established requirements for sensitive personal information, effective January 1, 2023.
In Depth
CPRA represents the most significant expansion of CCPA since its original enactment. Key changes include the creation of the California Privacy Protection Agency (CPPA), a dedicated enforcement body with rulemaking authority that replaces the Attorney General as the primary regulator. CPRA introduced several new consumer rights: the right to correct inaccurate information, the right to limit use of sensitive personal information, and expanded the right to opt-out to cover "sharing" for cross-context behavioral advertising in addition to "sales." The law also established new business obligations including mandatory risk assessments for high-risk processing, annual cybersecurity audits for businesses whose processing presents significant risk, and enhanced requirements for contracts with service providers and contractors. CPRA's enforcement provisions include administrative fines of $2,500 per unintentional violation and $7,500 per intentional violation or violation involving minors, with the CPPA having independent authority to investigate and enforce. Organizations should note that CPRA also extended the lookback period for consumer requests, added data minimization and purpose limitation principles, and introduced the concept of "contractors" as a new data recipient category.
Related Frameworks
Related Terms
Right to Delete
The right to delete under CCPA/CPRA allows California consumers to request that a business delete any personal information it has collected about them. Businesses must comply within 45 days, with limited exceptions for legal obligations, security, and completing transactions.
Right to Know
The right to know under CCPA/CPRA grants California consumers the right to request that a business disclose what personal information it has collected, the sources of that information, the business purposes for collecting it, and the third parties with whom it has been shared or sold.
Right to Opt-Out
The right to opt-out under CCPA/CPRA allows California consumers to direct businesses to stop selling or sharing their personal information with third parties. Businesses must honor opt-out requests and provide a clear "Do Not Sell or Share My Personal Information" link on their website.
Sensitive Personal Information
Sensitive personal information under CPRA includes specific categories requiring heightened protections: government IDs, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, mail/email/text content, genetic data, biometrics, health data, and sex life or orientation.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free