[Atomic Glue](atomicglue.co)
PRIVACY
Home › Glossary › Privacy· 69 ·

CCPA / CPRA

see-cee-pee-ay / see-pee-ar-aynoun
Filed underPrivacyLegal
In brief · quick answer

The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) are California state laws granting residents rights over their personal data. The CPRA expanded and amended the CCPA, effective January 2023.

§ 1 Definition

The CCPA (effective January 2020) was the first comprehensive US state privacy law, giving California residents the right to know what personal information is collected, the right to delete it, the right to opt out of its sale, and the right to non-discrimination for exercising these rights. The CPRA (Proposition 24, effective January 2023) amended and expanded the CCPA, adding rights to correct inaccurate data, limit use of sensitive personal information, and opt out of automated decision-making. The CPRA also established the California Privacy Protection Agency (CPPA) for enforcement. Together, they represent the most comprehensive data privacy regulation in the United States.

§ 2 Who Must Comply

A for-profit business that collects consumer personal information, does business in California, and meets one or more of: annual gross revenue over $25 million; buys, receives, or sells personal information of 100,000 or more California residents/households; or derives 50% or more of annual revenue from selling personal information. Unlike GDPR, CCPA/CPRA applies based on the business's characteristics, not just the consumer's location. However, the rights are only available to California residents.

§ 3 Consumer Rights

Right to know (CCPA): What personal information is collected, used, shared, or sold. Right to delete (CCPA): Request deletion of personal information. Right to opt out of sale/sharing (CCPA): Businesses must provide a clear 'Do Not Sell or Share My Personal Information' link. Right to correct (CPRA): Correct inaccurate personal information. Right to limit sensitive personal information (CPRA): Restrict use of sensitive data (e.g., precise geolocation, health data). Right to non-discrimination: Businesses cannot deny service or charge different prices to consumers who exercise their rights.

§ 4 CCPA vs CPRA Differences

The CPRA introduced the concept of sensitive personal information with opt-out rights distinct from general personal information. It created the California Privacy Protection Agency (CPPA) for enforcement, separate from the Attorney General's office. The CPRA also introduced contractual requirements for service providers and contractors, similar to GDPR's data processing agreements. The threshold for data volume changed from 50,000 to 100,000 consumers. The CPRA also introduced automated decision-making transparency and opt-out rights, and established a data minimization principle (collect only what is necessary).

§ 5 Note

Unlike GDPR, CCPA/CPRA does not require a cookie consent banner. It requires a 'Do Not Sell or Share My Personal Information' link. Many businesses combine both obligations with a single cookie consent tool. The CPRA expanded the definition of 'sale' to include sharing for cross-context behavioral advertising.

§ 6 Common questions

Q. Does CCPA/CPRA apply to my business outside California?
A. If you meet the revenue or data volume thresholds and do business in California or collect data of California residents, yes. The law applies to the processing of California residents' data regardless of where the business is headquartered.
Q. What are the penalties for non-compliance?
A. Fines of $2,500 per violation (intentional: $7,500) for CCPA. CPRA also created a private right of action for data breaches involving certain types of personal information, with statutory damages of $100 to $750 per incident per consumer.
Q. Is CCPA the same as GDPR?
A. Similar but not identical. CCPA/CPRA focuses on opt-out (not opt-in consent like GDPR for most processing), has different definitions of personal information, and does not have a right to data portability in the same form. Businesses must comply with both if they serve EU and California residents.
Key takeaways
  • CCPA/CPRA grants California residents rights over their personal data.
  • Requires 'Do Not Sell or Share My Personal Information' link on websites.
  • CPRA expanded CCPA with new rights: correct data, limit sensitive data use.
  • Fines: $2,500-$7,500 per violation plus private right of action for breaches.
How Atomic Glue helps

Atomic Glue implements CCPA/CPRA compliance features including Do Not Sell links, privacy notice generation, data subject request handling, and consent management integration. Get in touch.

Get in touch
# CCPA / CPRA

The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) are California state laws granting residents rights over their personal data. The CPRA expanded and amended the CCPA, effective January 2023.

Category: Privacy (also: Legal)

Author: Atomic Glue Security Team

## Definition

The CCPA (effective January 2020) was the first comprehensive US state privacy law, giving California residents the right to know what personal information is collected, the right to delete it, the right to opt out of its sale, and the right to non-discrimination for exercising these rights. The CPRA (Proposition 24, effective January 2023) amended and expanded the CCPA, adding rights to correct inaccurate data, limit use of sensitive personal information, and opt out of automated decision-making. The CPRA also established the California Privacy Protection Agency (CPPA) for enforcement. Together, they represent the most comprehensive data privacy regulation in the United States.

## Who Must Comply

A for-profit business that collects consumer personal information, does business in California, and meets one or more of: annual gross revenue over $25 million; buys, receives, or sells personal information of 100,000 or more California residents/households; or derives 50% or more of annual revenue from selling personal information. Unlike GDPR, CCPA/CPRA applies based on the business's characteristics, not just the consumer's location. However, the rights are only available to California residents.

## Consumer Rights

**Right to know** (CCPA): What personal information is collected, used, shared, or sold. **Right to delete** (CCPA): Request deletion of personal information. **Right to opt out of sale/sharing** (CCPA): Businesses must provide a clear 'Do Not Sell or Share My Personal Information' link. **Right to correct** (CPRA): Correct inaccurate personal information. **Right to limit sensitive personal information** (CPRA): Restrict use of sensitive data (e.g., precise geolocation, health data). **Right to non-discrimination**: Businesses cannot deny service or charge different prices to consumers who exercise their rights.

## CCPA vs CPRA Differences

The CPRA introduced the concept of **sensitive personal information** with opt-out rights distinct from general personal information. It created the **California Privacy Protection Agency (CPPA)** for enforcement, separate from the Attorney General's office. The CPRA also introduced **contractual requirements** for service providers and contractors, similar to GDPR's data processing agreements. The threshold for data volume changed from 50,000 to 100,000 consumers. The CPRA also introduced **automated decision-making** transparency and opt-out rights, and established a **data minimization** principle (collect only what is necessary).

## Note

Unlike GDPR, CCPA/CPRA does not require a cookie consent banner. It requires a 'Do Not Sell or Share My Personal Information' link. Many businesses combine both obligations with a single cookie consent tool. The CPRA expanded the definition of 'sale' to include sharing for cross-context behavioral advertising.

## Common questions

Q: Does CCPA/CPRA apply to my business outside California?

A: If you meet the revenue or data volume thresholds and do business in California or collect data of California residents, yes. The law applies to the processing of California residents' data regardless of where the business is headquartered.

Q: What are the penalties for non-compliance?

A: Fines of $2,500 per violation (intentional: $7,500) for CCPA. CPRA also created a private right of action for data breaches involving certain types of personal information, with statutory damages of $100 to $750 per incident per consumer.

Q: Is CCPA the same as GDPR?

A: Similar but not identical. CCPA/CPRA focuses on opt-out (not opt-in consent like GDPR for most processing), has different definitions of personal information, and does not have a right to data portability in the same form. Businesses must comply with both if they serve EU and California residents.

## Key takeaways

## Related entries


Last updated December 2024. Permalink: atomicglue.co/glossary/ccpa-cpra

Schedule a call

30 min · Video call

1
Date
2
Time
3
Details