CPRA vs CCPA: Unpacking the Differences [Updated 2024] (2024)

CPRA vs CCPA: At a glance

  • The California Privacy Rights Act (CPRA) amended the California Consumer Privacy Act (CCPA)–modifying its scope, expanding consumer rights, and adding additional regulations around commercial data collection and processing.
  • For businesses operating in California, understanding the difference between CPRA and CCPA is critical—the CPRA modified regulations have been finalized and California Privacy Protection Agency is actively able to purse CPRA enforcement.
  • Read on learn about the differences between CCPA vs CPRA, plus how these updates will affect your business in the future.

Table of contents

  • New consumer rights
  • Expanded consumer rights
  • Sensitive personal information
  • Data “sharing”
  • California Privacy Protection Agency
  • 30 day cure period
  • Private right of action
  • Data processing thresholds
  • Third-party contract requirements

CPRA vs CCPA: New consumer rights

The CPRA amended the CCPA to add four new consumer rights.

Right to correction

Consumers have the right to correct inaccuracies in their own personal data held by an organization.

Right to limit sensitive personal information

If a business collects a consumer’s sensitive personal data, theconsumer can requestthat the business limit that data’s use to what’s “necessary to perform the services or provide the goods reasonably expected by an average consumer.”

Right to access and opt-out of automated decision making

Businesses must respond to consumer requests for information about the logic behind automated decision-making and the likely outcome of those processes.

Consumers may opt-out of automated decision-making, includingprofiling, in regards to their “performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.”

Right to data portability

Consumers can ask a business to transmit their personal data to another business.

CPRA vs CCPA: Expanded rights

Right to know

Under the CCPA, consumers may request information about thepersonally identifiable information(PII), as well as the categories of PII a business collects and sells. The CPRA expands this right to include the data a business shares.

It also expands the timeframe for which a consumer can request that information. A consumer may request information beyond the standard 12 months prior window withtwo caveats:

  • The data was collected on or after January 1, 2022
  • Fulfilling the request is possible and doesn’t require “disproportionate” effort.

Businesses are not obligated to keep data for a set period of time, so though a consumer may make requests, the data may not be available.

Right to opt out

The CPRA allows consumers to opt out of both data sale and data sharing. Under the CCPA, they could only opt out of data sale. The CPRA definesdata sharingas:

“sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party”

An action counts as sharing whether or not money was exchanged.

Right to delete

Though the CPRA maintained the same basic ‘Right to delete’ framework, it added additional guidance about moving these requests downstream.

Under the CPRA, after receiving a consumer data deletion request, businesses must pass the request to any third parties to whom the consumer’s data was shared or sold—instructing they delete the data as well.

The CPRA does offer a few exceptions to this rule, including if the consumer’s data is necessary for completing a requested transaction, part of a security incident, or part of a server log necessary for debugging an error.

Opt-in rights for minors

TheCCPAalready required businesses get opt-in consent from any minor under 16. Expanding this requirement, the CPRA states that if a minor refuses the sale or sharing of their personal data, the business must wait 12 months to request consent again.

CPRA vs CCPA: Sensitive personal information

Under the CPRA, sensitive personal information (SPI) includes:

  • Identifying information like social security and driver’s license numbers
  • Credit and debit card numbers
  • Log-in credentials for financial accounts
  • Precise geolocation data
  • Information about a consumer’s race, ethnicity, and religious beliefs
  • Content from a consumers emails, mail, and texts
  • Uniquely identifying biometric data, including genetic data
  • Information about a consumers health, sex life, or sexual orientation

In contrast, the CCPA only defined requirements around “personal information,” which was defined as:

“information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”

Put simply, personal information could identify you or your household. And sensitive personal information builds on that definition by including the data types listed above.

Learn more about how to handle sensitive personal information under CPRA.

CPRA vs CCPA: Data "sharing"

While the CCPA largely only governs data sale, the CPRA places new requirements on data sharing. Data sharing isdefinedas:

“sharing, renting, releasing, disclosing, disseminating, making available, [or] transferring [...] a consumer’s personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration”

In other words, if you allow an external party access to consumer information for the purpose of cross-context behavioral advertising, in any form, it’s considereddata sharing––even if no money was exchanged.

Data sharing is regulated under the CPRA, which gives consumers the right to opt-out, know, and request deletion for any personal data that’s been shared with a third-party.

This new level of scrutiny stems from the fact that, to circumvent data sale regulations under the CCPA, many businesses were exchanging data without a direct monetary transaction.

CPRA vs CCPA: California Privacy Protection Agency

The CPRA established theCalifornia Privacy Protection Agency (CPPA), an entirely new agency tasked with enforcing California’s growing canon of privacy regulation.

Headed by Ashkan Soltani, the CPPA will be responsible for auditing CPRA compliance, evaluating potential violations, levying fines, and implementing new privacy laws.

The CPPA worked on finalizing the CPRA's requirements through 2022, havingrequested feedbackon topics including cybersecurity audits and risk assessments, automated decision-making, CPPA auditing, and the particulars of certain consumer rights.

As of March 2023, the CPRA modified regulations were finalized and approved by the California Office of Administrative Law.

Read theNew York Times profileon Mr. Soltani and his novel approach to building out the CPPA.

CPRA vs CCPA: 30 day cure period

Businesses will no longer have an automatic 30 day cure period, which previously allowed a window where organizations could attempt to address violations. The CPRA made this cure period discretionary, meaning it can be granted by theCPPAon a case-by-case basis.

The CPRA also clarifies that implementing “reasonable security”aftera breach does not count towards a meaningful cure.

In other words, if a company fails to provide enough security for sensitive data and then experiences a breach–they will still be held accountable even if they implement additional security measures after the fact.

CPRA vs CCPA: Private right of action

The CCPA offered consumers a private right of action in cases when an organization failed to protect their unencrypted or unredacted data. The CPRA expanded this scope to include a users email address, password, or security question,stating:

“Any consumer whose nonencrypted and nonredacted personal information[…] is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices[may]institute a civil action”

In light of steadily increasing cyberattacks and high-profile security breaches, organizations should be especially mindful of this scope expansion. A breach that results in exposure of these credentials could lead to significant, consumer-initiated legal action.

Notably, the CCPA and CPRA are the only US state privacy laws that afford the private right of action–Colorado,Virginia, andUtahdon’t provide this right under any circ*mstance.

CPRA vs CCPA: Data processing thresholds

Under the California Privacy Rights Act, businesses must process the personal data of at least 100,000 consumers–doubling the CCPA’s 50,000 threshold.

Impact:Many small and medium sized businesses may end up exempt.

To be clear, the data processing threshold is not the only way an entity can trigger theCPRA. The CRPA also applies to any business which:

  • Has a gross annual revenue exceeding $25 million
  • Buys, sells, or shares personal data for 100,000 or more California residents
  • Derives 50% or more of annual revenue from selling or sharing California residents’ personal data

If a business meets any of these criteria, the CPRA applies.

CPRA vs CCPA: Contract requirements for third-parties

The CPRA requires comprehensive contracts between businesses and any third parties with whom data is being shared or sold. More than that, thesecontracts must:

  • Specify the purpose for which the data is being sold or shared
  • Place the third party under the same CPRA obligations as the business, meaning the third party must comply with CPRA privacy protection requirements
  • Give the business enough power to enforce their CPRA obligations throughout the third-party’s data processing activities
  • Require notice if the third party feels unable to meet their obligations as defined by the contract
  • Enable the business to effectively address inappropriate use of consumer data

These new requirements are intended to ensure better data governance and security throughout any third-party processing, so it’s important that businesses consider these contracts carefully.

Learn more about third party and service provider contracts under CPRA.

About Transcend

Has your organization has been impacted by the California Privacy Rights Act or other consumer privacy laws? Transcend, an all-in-one platform for modern privacy and data governance, can help you ensure compliance.

Encoding privacy at the code layer, we provide solutions for any privacy challenge your teams may be facing—including getting you ready forstate privacy lawscoming online in 2024.

FromConsent Management, to automatedDSR Fulfillment, to a full suite of data mapping solutions (Data Inventory,Silo Discovery,Structured Discovery, and more), Transcend has you covered as your company grows and evolves in a swiftly changing regulatory environment.

Additional CPRA resources

  • The Complete Guide to CPRA Compliance
  • 5 key takeaways from the CPRA modified regulations
  • 9 step CPRA compliance guide
  • Managing employee DSAR under CPRA
  • Handling sensitive personal information under CPRA and VCDPA
  • The Complete Guide to CPRA Do Not Sell or Share [Updated 2023]
CPRA vs CCPA: Unpacking the Differences [Updated 2024] (2024)
Top Articles
Understanding International Capital Markets
CVS HEALTH STOCK FORECAST 2024 - 2025
Katie Pavlich Bikini Photos
Safety Jackpot Login
Spn 1816 Fmi 9
Skamania Lodge Groupon
Jennifer Hart Facebook
Mrh Forum
Summit County Juvenile Court
Wellcare Dual Align 129 (HMO D-SNP) - Hearing Aid Benefits | FreeHearingTest.org
Jesus Calling December 1 2022
Craigslist Free Stuff Appleton Wisconsin
Irving Hac
biBERK Business Insurance Provides Essential Insights on Liquor Store Risk Management and Insurance Considerations
Find The Eagle Hunter High To The East
Facebook Marketplace Charlottesville
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
The Superhuman Guide to Twitter Advanced Search: 23 Hidden Ways to Use Advanced Search for Marketing and Sales
Www Craigslist Com Phx
Craftology East Peoria Il
Kirksey's Mortuary - Birmingham - Alabama - Funeral Homes | Tribute Archive
*Price Lowered! This weekend ONLY* 2006 VTX1300R, windshield & hard bags, low mi - motorcycles/scooters - by owner -...
18889183540
Daytonaskipthegames
Pokemon Unbound Shiny Stone Location
THE FINALS Best Settings and Options Guide
Netwerk van %naam%, analyse van %nb_relaties% relaties
Bleacher Report Philadelphia Flyers
Tottenham Blog Aggregator
Healthy Kaiserpermanente Org Sign On
Reserve A Room Ucla
+18886727547
Flaky Fish Meat Rdr2
Gideon Nicole Riddley Read Online Free
Smartfind Express Henrico
24 slang words teens and Gen Zers are using in 2020, and what they really mean
Breckie Hill Fapello
Giantess Feet Deviantart
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
Muziq Najm
craigslist: modesto jobs, apartments, for sale, services, community, and events
Karen Wilson Facebook
US-amerikanisches Fernsehen 2023 in Deutschland schauen
Best Suv In 2010
Theater X Orange Heights Florida
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
The Machine 2023 Showtimes Near Roxy Lebanon
Cara Corcione Obituary
9294027542
King Fields Mortuary
Www Extramovies Com
Latest Posts
Article information

Author: Sen. Ignacio Ratke

Last Updated:

Views: 6155

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Sen. Ignacio Ratke

Birthday: 1999-05-27

Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

Phone: +2585395768220

Job: Lead Liaison

Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.