CCPA·9 min read

CCPA vs CPRA: What Changed and Which One Applies Now

The short answer to CCPA vs CPRA is that it is not a versus. The CPRA amended the CCPA rather than replacing it, so the law you comply with today is the California Consumer Privacy Act as amended — one statute, not two.

That distinction matters more than it sounds, because a lot of guidance still describes the pre-2023 version, and a compliance program built on it will be missing four consumer rights and an entire regulator.


The Timeline

  • June 2018 — The CCPA is signed into law as AB 375
  • January 1, 2020 — The CCPA takes effect
  • November 2020 — Voters pass Proposition 24, the California Privacy Rights Act (CPRA)
  • January 1, 2022 — The CPRA's data look-back period begins
  • January 1, 2023 — CPRA amendments take effect; employee and B2B exemptions expire
  • 2023 onward — The California Privacy Protection Agency issues and expands regulations, adding rules on cybersecurity audits, risk assessments, and automated decision-making with phased compliance dates

The practical upshot: any checklist, template, or vendor questionnaire written before 2023 is describing a law that no longer exists in that form.


What the CPRA Actually Changed

AreaOriginal CCPAAs amended by the CPRA
Consumer rightsKnow, delete, opt out of sale, non-discrimination, portabilityAdds correct and limit use of sensitive personal information
Data categoriesPersonal informationAdds sensitive personal information as a distinct category
Disclosure trigger"Sale"Adds "sharing" for cross-context behavioural advertising
Volume threshold50,000 consumers, households, or devices100,000 consumers or households; devices removed
RegulatorAttorney General onlyCPPA plus the Attorney General
Cure period30 days, automaticRemoved
Employee / B2B dataTemporarily exemptFully covered since January 1, 2023
Core obligationsNotice, access, deletionAdds data minimisation, purpose limitation, retention disclosure, and contract requirements
Breach liabilityCertain unencrypted personal informationExtends to email plus password or security question

The Changes That Matter Operationally

1. Sensitive personal information became its own category

The CPRA carved out a class of data requiring separate handling: government identifiers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of private communications, genetic and biometric data, and health, sex-life, or sexual-orientation data.

If you use sensitive personal information beyond a short list of permitted purposes — delivering the service, security, quality assurance — consumers can require you to stop. That means a "Limit the Use of My Sensitive Personal Information" link and a technical path behind it.

Most SaaS companies conclude they only use such data to deliver the product and therefore do not trigger the link. That conclusion is usually correct and almost never written down. Document it; the undocumented assumption is the exposure.

2. "Sharing" closed the advertising loophole

The original CCPA regulated the sale of personal information, and the ad tech industry argued at length that passing data to advertising partners was not a sale because no money changed hands.

The CPRA added sharing — disclosing personal information for cross-context behavioural advertising, whether or not for consideration. That resolved the argument. If you run third-party advertising pixels, you are almost certainly sharing, and the opt-out obligations apply.

The visible consequence is the required "Do Not Sell or Share My Personal Information" link, plus honouring Global Privacy Control browser signals automatically. Ignoring GPC is the most frequently cited technical failure in California enforcement, because it can be tested from outside your company in seconds.

3. A regulator with a full-time enforcement staff

The CPRA created the California Privacy Protection Agency, the first dedicated privacy regulator in the United States, with rulemaking and enforcement authority alongside the Attorney General.

This changed the enforcement posture more than any single substantive provision. An AG office allocates attention across every consumer protection issue in the state. A dedicated agency does privacy full time, and it writes the regulations it enforces.

4. The cure period is gone

Under the original CCPA, notice of an alleged violation started a 30-day clock to fix it. The CPRA removed the automatic entitlement.

Enforcers can still weigh voluntary corrective action in setting a penalty, so remediation is not pointless. But you can no longer treat "we would fix it if anyone complained" as a strategy, which is what the cure period effectively permitted.

5. Employee and B2B data came fully in scope

The temporary exemptions for employee, applicant, and business-contact data expired on January 1, 2023.

Your HR records, applicant tracking system, and sales prospect database are now subject to the same rights as consumer data — including access and deletion requests from current and former employees. Teams that scoped their privacy program to customer data alone are missing at least two systems.

6. Data minimisation and retention became substantive obligations

This is the quietest change and the one with the longest tail.

The original CCPA was fundamentally a disclosure law: tell consumers what you collect, let them opt out of its sale. It said little about whether you should have collected the data in the first place, or how long you could keep it.

The CPRA added three GDPR-flavoured constraints:

  • Data minimisation — collection, use, retention, and sharing must be reasonably necessary and proportionate to the purpose disclosed
  • Purpose limitation — you cannot process personal information for a purpose incompatible with the one you disclosed at collection, without giving fresh notice
  • Retention disclosure — you must tell consumers, at collection, how long you intend to keep each category, or the criteria you use to decide

That third one is the operational bite. "We retain data as long as necessary for business purposes" does not satisfy it. You need actual periods, per category, published — which means you first need a retention schedule that someone has thought about and engineering can enforce.

Most teams discover here that their real retention policy is "we have never deleted anything." Writing the disclosure honestly forces the cleanup, which is why this change generates more internal work than the headline rights do.

There is a useful side effect: a defensible retention schedule shrinks the blast radius of a breach, narrows the scope of every access request, and lowers storage cost. It is the rare compliance requirement that pays for itself.


Thresholds: Who Is Covered Now

A for-profit business doing business in California is covered if it meets any one of:

  • More than $25 million in gross annual revenue in the preceding calendar year
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually
  • Deriving 50% or more of annual revenue from selling or sharing personal information

Two subtleties. The CPRA raised the volume threshold from 50,000 to 100,000 and removed devices from the count, which pulled some smaller businesses out of scope. But the new sharing definition pulled others in, because ad-tech disclosures now count toward the third limb in ways they previously did not.

Run the calculation against the current definitions rather than assuming your 2021 scoping conclusion still holds.


Is the CCPA Only for California Residents?

The protected people are California residents. The regulated businesses are not California businesses.

There is no requirement for an office, employees, or infrastructure in the state. A company anywhere that does business in California and clears a threshold is covered. In practice, "does business in California" is read broadly — selling to California customers is generally sufficient.

Most SaaS companies that reach this conclusion stop trying to segment rights by user state. Building a workflow that grants deletion rights to Californians and refuses them to everyone else costs more to maintain than granting them universally, and it looks worse when a journalist tests it. Apply the strictest standard across your US user base and the operational problem disappears.


CPRA vs GDPR: Still Different Models

The CPRA borrowed visibly from the GDPR — data minimisation, purpose limitation, retention disclosure, a sensitive-data category, and mandatory contract terms with recipients all have European ancestry. The gap narrowed. It did not close.

What California still does not require:

  • A lawful basis before processing. The GDPR is a permission regime; California is disclosure-and-opt-out.
  • A Record of Processing Activities in the Article 30 sense.
  • International transfer mechanisms. Nothing in California law restricts sending data abroad.
  • A Data Protection Officer with statutory independence.

What California does that the GDPR does not:

  • Regulates the sale and sharing of personal information as a distinct category with a mandatory opt-out link.
  • Requires honouring an automated browser signal (GPC) as a valid request.
  • Grants a private right of action for certain breaches at $100–$750 per consumer per incident.

The engineering consequence: a GDPR-compliant consent banner does not satisfy California, because opt-in consent and an opt-out link are different mechanisms. Teams building for both should read our post on GDPR and CCPA compliance before duplicating the work.


What to Do With This

If your program predates 2023, five things need checking:

  1. Privacy policy — does it describe correction rights, sensitive personal information, sharing, and retention periods per category?
  2. Homepage links — is "Do Not Sell or Share" present, and does the sensitive-information limit link exist or is its absence documented?
  3. GPC handling — send a request with the Sec-GPC: 1 header and confirm tags actually suppress. Do not take the vendor's word for it.
  4. HR and B2B systems — are they inside the request workflow, or did scoping stop at customer data?
  5. Vendor contracts — do they carry the CPRA-required terms, and is each vendor classified as service provider, contractor, or third party?

Also watch the CPPA's newer regulatory work on cybersecurity audits, risk assessments, and automated decision-making. The compliance dates are phased by company size and have shifted during rulemaking, so confirm current deadlines with the agency directly rather than relying on a secondary summary — including this one.


For the step-by-step implementation work, see the CCPA compliance checklist and our breakdown of CCPA requirements. The CCPA service page covers how we scope California readiness, and the GDPR service page covers the EU side when both apply.


Frequently Asked Questions

Is CCPA the same as CPRA? They are one law. The CPRA is a 2020 ballot amendment to the CCPA, effective January 1, 2023. The operative statute is still the California Consumer Privacy Act, as amended.

What replaced CCPA? Nothing. The CPRA amended it in place. Documentation referring to "the CCPA" is not stale; documentation describing only pre-2023 obligations is.

What is the difference between GDPR and CPRA? GDPR requires a lawful basis before processing, plus a RoPA, transfer mechanisms, and sometimes a DPO. California requires disclosure and an opt-out from sale or sharing, plus GPC handling and a breach-related private right of action. Opt-in versus opt-out is the core divide.

Is the CCPA only for California residents? It protects California residents but binds businesses anywhere that do business in California and meet a threshold. No local office or servers required.

Did the CPRA remove the 30-day right to cure? Yes. There is no longer an automatic grace period, though voluntary remediation can still affect the penalty.

What are the CPRA thresholds for covered businesses? $25 million in gross annual revenue, or 100,000+ California consumers or households bought/sold/shared, or 50%+ of revenue from selling or sharing personal information. The volume threshold rose from 50,000 and devices were removed from the count.


Not Sure Which Obligations Apply to You?

ShieldKey Solutions runs California privacy scoping for SaaS companies: we confirm whether you meet a threshold under the current definitions, classify your data flows as sale, share, or neither, test your opt-out and GPC handling, and map the remaining gaps to owners and dates. If GDPR applies too, we build one program with both lenses rather than two.

Schedule a scoping call →