Back to Frameworks
Frameworks

CPRA (California Privacy Rights Act)

Framework Name

California Privacy Rights Act (CPRA)

Type

Mandatory

Region / Jurisdiction

California, USA

Enforcing Body / Certifying Party

California Privacy Protection Agency (CalPrivacy), which CPRA itself created, together with the California Attorney General

Penalty / Consequence of Non-Compliance

Civil penalties of $2,500 per violation, rising to $7,500 for intentional violations or those involving a minor's data. CPRA specifically removed the 30-day period businesses previously had to fix a violation before being penalized, so enforcement can now be immediate

What It Is & Why It Matters

CPRA was a ballot measure California voters passed in November 2020, taking effect in 2023, that substantially expanded the original 2018 CCPA rather than replacing it. Its most structurally significant change was creating CalPrivacy, California's dedicated privacy enforcement agency, the first of its kind among US states, since previously the Attorney General's office was the only enforcer and had limited bandwidth to pursue privacy cases actively. CPRA also introduced real new obligations: a formal "sensitive personal information" category with its own extra protections, a right to correct inaccurate data, requirements for data minimization and limiting how long data is kept, and mandates for risk assessments and cybersecurity audits for higher-risk data processing.

It matters because it turned CCPA from a law that was, in its original form, seen as having real enforcement gaps, into one with a dedicated regulator actively writing new rules and bringing cases. The agency CPRA created is the same one behind the AI-related automated decision-making rules that took effect in 2026, which we covered in the CCPA entry, that expansion into AI governance territory only exists because CPRA built the regulatory infrastructure to make it possible in the first place.

Who Needs It

  • You already comply with the original CCPA and need to understand what specifically CPRA added on top of it
  • You handle what CPRA defines as sensitive personal information and need to understand the extra protections that category requires
  • You want to understand who actually enforces California privacy law today, and why CalPrivacy exists as a distinct agency from the Attorney General's office
  • You're tracking how California's automated decision-making and cybersecurity audit rules came to exist, since CPRA is the law that created the agency behind them
Book A Demo