๐ What We'll Cover
- CCPA vs CPRA โ what actually changed
- Who must comply (the thresholds are wider than you think)
- The 12 categories of personal information your policy must list
- "Sell" and "Share" under CPRA โ broader than you think
- The 8 consumer rights your policy must cover
- The "Notice at Collection" โ separate from your privacy policy
- Sensitive PI โ the new compliance burden
- Enforcement and penalties
CCPA vs CPRA โ What Actually Changed
The California Consumer Privacy Act (CCPA) took effect January 1, 2020. It was the first comprehensive US state privacy law, and it changed how businesses handle Californians' personal information.
Then came the California Privacy Rights Act (CPRA), approved by voters in November 2020 as Proposition 24. It went into effect January 1, 2023, with enforcement beginning July 1, 2023. The CPRA does not replace the CCPA โ it amends and expands it. Think of it as CCPA version 2.0.
Here is what the CPRA added or changed:
- Sensitive personal information โ a new category with its own set of rules and consumer rights (see section 7)
- Right to correction โ consumers can now request you fix inaccurate personal information
- Right to limit use of sensitive PI โ consumers can restrict how you use their sensitive data
- Purpose limitation โ you must collect, use, retain, and disclose PI only for the purposes disclosed at collection
- Data minimization โ you cannot collect more PI than is reasonably necessary for the stated purpose
- Expanded breach liability โ now covers email address combined with password or security question/answer (previously only name + SSN, driver's license, financial account, or medical info)
- New enforcement agency โ the California Privacy Protection Agency (CPPA) has its own budget, staff, and enforcement authority. The Attorney General's office is no longer the sole enforcer.
- Thresholds changed โ the 50,000 consumer threshold was raised to 100,000 (but this is not a relaxation; see section 2)
- "Sharing" defined โ cross-context behavioral advertising is explicitly covered, requiring a whole new opt-out mechanism
If your privacy policy was "CCPA compliant" in 2022, it is not compliant today. The CPRA added obligations that affect nearly every business that collects California consumer data. A 2022 policy is missing: sensitive PI disclosures, the right to correction, the "Limit Use" link, purpose limitation language, and the expanded "share" definition.
Who Must Comply (The Thresholds Are Wider Than You Think)
The CPRA applies to for-profit businesses that do business in California and meet any one of the following thresholds:
| Threshold | CCPA (2018-2022) | CPRA (2023+) |
|---|---|---|
| Annual gross revenue | Over $25 million | Over $25 million (unchanged) |
| PI of consumers/households bought, sold, or shared | 50,000+ | 100,000+ |
| Revenue from selling/sharing PI | 50%+ | 50%+ (unchanged) |
On paper, the 100,000 threshold looks like a relaxation. It is not. The CPRA added "sharing" (cross-context behavioral advertising) to the calculation, which sweeps in far more businesses.
Here is the trap small businesses fall into:
You run an e-commerce store doing $500,000/year in revenue. You think you are exempt because you are under the $25 million threshold. But you installed the Facebook/Meta Pixel on your website. Every time a visitor loads a page, Meta receives their IP address, browser fingerprint, and page activity. You are "sharing" personal information with Meta. If your site gets 100,000 unique California visitors in a year โ easy for even a modest e-commerce store โ you meet the threshold. You are now subject to the CPRA.
The CPRA also expanded the definition of "business" to include any entity that controls or is controlled by a covered business, and joint ventures or partnerships that are majority-owned by covered businesses. If your parent company meets the threshold, you do too.
The 12 Categories of Personal Information Your Policy Must List
The CCPA originally listed 11 categories of personal information. The CPRA added a 12th: sensitive personal information. Your privacy policy must identify which categories you collect, which you sell or share, which you disclose for business purposes, and the retention period for each category.
Here are all 12, with examples:
| Category | Code | Examples | Notes |
|---|---|---|---|
| Identifiers | (A) | Name, email, IP address, cookie IDs, device IDs, account name, phone number | This is the broadest category. Nearly every business collects at least a subset. |
| Customer records | (B) | Signature, phone number, bank account number, credit card number, employment history | Cal. Civ. Code ยง 1798.80(e). Overlaps with (A) and (L). If something appears in multiple categories, list it in each. |
| Protected classifications | (C) | Race, religion, gender, disability, sexual orientation, citizenship, veteran status | Sensitive under CPRA. Extra disclosure and opt-out requirements apply. |
| Commercial information | (D) | Purchase history, returns, products considered, loyalty program data, wish lists | Standard e-commerce data. Often shared with analytics or ad platforms. |
| Biometric information | (E) | Fingerprints, face scans, voice recordings, iris/retina scans, gait analysis | Less common for most businesses. If you use facial recognition or voice authentication, this applies. |
| Internet activity | (F) | Browsing history, search history, ad interactions, clickstream data | Collected by analytics tools, advertising pixels, session recording software. This is the category most businesses overlook. |
| Geolocation | (G) | Precise location (GPS-level), approximate location (city-level) | Precise geolocation is sensitive PI. Approximate is not โ but still must be disclosed. |
| Sensory data | (H) | Audio recordings (customer service calls), visual (CCTV footage, photos), thermal, olfactory | Customer support call recordings count. So do security cameras in your retail location. |
| Employment information | (I) | Job history, performance reviews, salary, benefits, disciplinary records | Applies to employee data as well as job applicants. |
| Education information | (J) | Transcripts, grades, enrollment records, student IDs | FERPA-protected records are excluded. Non-FERPA educational data is covered. |
| Inferences | (K) | "Likely to be interested in luxury goods," "churn risk score," "fraud likelihood score" | Derived from other data. If you build profiles or scoring models, you must disclose this. |
| Sensitive personal information | (L) | SSN, driver's license, financial account + password, precise geolocation, race/ethnicity, religion, union membership, biometric data, health data, sex life/orientation, citizenship status, mail/email contents, genetic data | NEW under CPRA. Subject to the right to limit use. Must be separately disclosed. |
Your privacy policy must, for each category you collect, state: whether you collect it, whether you sell or share it, whether you disclose it for a business purpose, and the retention period. A table format is the clearest way to present this.
"Sell" and "Share" Under CPRA โ Broader Than You Think
The CPRA defines "sell" and "share" differently from how most business owners use those words. Understanding the difference is critical to compliance.
Selling โ not just cash transactions
"Sell" means exchanging personal information for monetary or other valuable consideration. This includes:
- Sharing email lists with partners for cross-promotion
- Letting analytics providers (Google Analytics, Adobe, Amplitude) use your data for their own purposes, not just yours
- Participating in data co-ops where you contribute customer data and receive aggregated insights
- Allowing third-party retargeting pixels to capture visitor data
- Providing customer data to an advertising network for audience targeting
If there is any exchange of value โ even non-monetary, like getting analytics reports in exchange for letting the analytics provider use your data โ it may constitute a "sale."
Sharing โ cross-context behavioral advertising
"Share" is a new concept under CPRA. It specifically means sharing personal information for cross-context behavioral advertising โ targeting ads based on a consumer's activity across different websites, apps, or services.
This means:
- Facebook/Meta Pixel: sharing. Every time a page loads, Meta receives browsing data from multiple websites it can use to build profiles and serve targeted ads.
- Google Ads tracking (including Google Ads conversion tracking and remarketing): sharing.
- TikTok Pixel: sharing.
- Criteo, The Trade Desk, Amazon Ads, or any DSP that receives user data for ad targeting: sharing.
- Email retargeting (uploading email lists to Facebook for ad targeting): sharing.
The opt-out requirement applies to both selling and sharing. You can use a single link (the CPRA recommends "Do Not Sell or Share My Personal Information") that covers both, or separate links. Most businesses use the combined link for simplicity.
Exceptions โ not all data transfers count
The following are NOT considered selling or sharing:
- Disclosing PI to a service provider (contractor) who processes data on your behalf and cannot use it for their own purposes โ but your contracts must explicitly prohibit this, and the CPRA now requires detailed service provider agreements
- Disclosing PI to a third party at the consumer's direction
- Using or disclosing PI internally for the purpose the consumer expects
- Selling or sharing PI as part of a merger, acquisition, bankruptcy, or other business transfer โ but only if the buyer follows the same privacy practices
The 8 Consumer Rights Your Policy Must Cover
Your privacy policy must describe each of these rights and explain how consumers can exercise them. The CPRA recognizes eight distinct consumer rights:
| Right | Description | New in CPRA? |
|---|---|---|
| Right to Know | Request the categories and specific pieces of PI you have collected, used, shared, or sold. You must respond within 45 days (extendable by another 45 with notice). Free once per 12 months for the consumer. | Amended |
| Right to Delete | Delete PI you have collected, subject to exceptions (legal obligations, security, free speech, research, internal use consistent with consumer expectation). Must honor or explain the exception. | Amended |
| Right to Correct | Consumers can request correction of inaccurate PI. Requires a mechanism to submit and verify correction requests. | โ NEW |
| Right to Opt-Out of Sale/Sharing | Opt out of the sale of PI AND the sharing of PI for cross-context behavioral advertising. Requires a clear link on your homepage. | Amended (added "sharing") |
| Right to Limit Use of Sensitive PI | Restrict use of sensitive PI to only specified purposes: providing the service, security, fraud prevention, debugging, short-term transient use, customer service, and limited service improvement. | โ NEW |
| Right to Portability | Receive PI in a portable, machine-readable format (typically JSON or CSV). Must be structured, commonly used, and readily usable. | Amended |
| Right to Non-Discrimination | Cannot charge different prices, offer different quality of service, or deny goods/services because someone exercised a privacy right. Exception: you can offer financial incentives (loyalty programs) if the consumer opts in and the incentive is "reasonably related to the value of the consumer's data." | Amended |
| Right to Opt-Out of Automated Decision-Making | Right to opt out of profiling and automated decision-making that produces legal or similarly significant effects. The CPPA is actively writing regulations for this right (rulemaking 2024-2026). | โ NEW (regulations pending) |
How to implement these rights
Your privacy policy must include clear instructions for each right. The minimum requirements:
- A designated method for submitting requests (webform, email address, toll-free phone number, or physical address)
- A description of the identity verification process (you may need to request additional information to verify the consumer's identity, but you cannot require more than is reasonably necessary)
- The expected response timeline (45 days, plus possible 45-day extension)
- Whether the right is free or if a fee may apply (only for excessive, repetitive, or unfounded requests)
- An appeal process for denied requests (the CPRA requires a mechanism for consumers to appeal, and you must describe it in your policy)
privacy@yourcompany.com and a webform that maps to the same system. Track request dates religiously โ the 45-day clock starts when the request is received, not when you verify identity. If you cannot verify within 45 days, you can deny the request, but you must notify the consumer.The "Notice at Collection" โ Separate From Your Privacy Policy
This is one of the most commonly missed requirements. The CPRA requires a notice at or before the point of collection โ not just a link to your privacy policy. A privacy policy in your footer does not satisfy this requirement.
The notice at collection must include:
- The categories of personal information you are collecting
- The purposes for which you are collecting it
- Whether you sell or share the information
- A link to your full privacy policy
- If you collect sensitive PI: a link to "Limit the Use of My Sensitive Personal Information"
Where the notice must appear
| Collection Method | Notice Requirement |
|---|---|
| Website (landing/page load) | A popup, banner, or clearly visible inline notice when someone lands on your site. Not just a footer link. The notice should say something like: "We collect identifiers and internet activity to improve your experience and serve targeted ads. See our privacy policy for details." |
| Online form | The notice must be ON the form page, not linked from it. Include a brief notice near the submit button or at the top of the form. |
| Mobile app | Notice at first launch or at the point of data collection within the app. |
| Phone call recording | Verbal notice before recording begins (e.g., "This call may be recorded for quality assurance purposes"). |
| In-person collection (retail, events) | A physical sign at the entrance or point of interaction. For events: verbal notice or written notice on registration forms. |
| Employee/HR data | Notice at the time of application or onboarding. Employee privacy policies should be separate from customer-facing policies. |
Sensitive PI โ The New Compliance Burden
The CPRA created a new category of "sensitive personal information" (category L in the list above) with its own set of rules. This is arguably the biggest compliance change for most businesses.
What qualifies as sensitive PI
- Social Security number
- Driver's license or state ID number
- Financial account number + password/access code (e.g., bank account + PIN, credit card + CVV)
- Precise geolocation (GPS-level, not city or ZIP code)
- Racial or ethnic origin
- Religious or philosophical beliefs
- Union membership
- Biometric data used for identification (face scans, fingerprints, iris scans)
- Health data (physical or mental health conditions, medical records)
- Sex life or sexual orientation
- Citizenship or immigration status
- Email and mail contents (when the business is not the intended recipient)
- Genetic data
What your policy must say about sensitive PI
If you collect any of the above, your privacy policy must:
- Identify which categories of sensitive PI you collect
- Explain the business purpose for collecting each category
- State whether you sell or share sensitive PI (note: selling or sharing sensitive PI requires explicit consent under CPRA)
- Describe how consumers can exercise their right to limit use of sensitive PI
- Include a "Limit the Use of My Sensitive Personal Information" link on your homepage (if you use sensitive PI beyond permitted purposes)
The right to limit use โ how it works
Consumers have the right to direct you to limit the use of their sensitive PI to only those purposes that are "necessary" to provide the service. The permitted purposes (no opt-out needed) are:
- Providing the goods or services the consumer requested
- Security (preventing fraud, malicious activity, identity theft)
- Debugging (identifying and repairing system errors)
- Short-term transient use (e.g., ad impression measurement) โ but not building profiles
- Customer service (processing returns, handling complaints)
- Service improvement (limited, not for behavioral advertising)
- Compliance with legal obligations
Prohibited uses (require an opt-out mechanism):
- Behavioral advertising based on sensitive PI
- Profiling that produces legal or similarly significant effects (employment, credit, housing, insurance, education access)
- Any purpose not listed above
If you use sensitive PI for any prohibited purpose, you must provide a "Limit the Use of My Sensitive Personal Information" link on your homepage that directs to a mechanism for consumers to opt out. This link is separate from "Do Not Sell or Share My Personal Information."
Examples of how this plays out
A fitness app collects precise geolocation (to track runs) and health data (heart rate, workout history). If the app uses that data for behavioral advertising ("You run in wealthy neighborhoods โ here is a luxury car ad"), it must provide a limit-use link. If it uses geolocation only to map routes and health data only to display workout summaries, those are permitted purposes โ no opt-out link required.
A retail store that collects customer zip codes (approximate location, not sensitive) and purchase history (commercial information, not sensitive) does not need to worry about the sensitive PI rules. But if that same store starts collecting driver's license numbers for returns (some retailers do this for fraud prevention), driver's license is sensitive PI and triggers the disclosure and opt-out requirements.
Enforcement and Penalties
The CPRA created the California Privacy Protection Agency (CPPA), the first dedicated privacy enforcement agency in the United States. It has its own budget, its own staff, and its own enforcement authority โ independent of the Attorney General's office.
Penalty structure
| Violation Type | Penalty |
|---|---|
| Unintentional violation (per incident) | $2,500 |
| Intentional violation (per incident) | $7,500 |
| Data breach involving email + password or security question | Civil damages ($100-$750 per consumer per incident, or actual damages, whichever is greater) |
| Data breach involving name + SSN/driver's license/financial account/medical info | Civil damages ($100-$750 per consumer per incident, or actual damages, whichever is greater) |
"Per incident" can mean per affected consumer. A breach affecting 10,000 consumers could mean $25 million in unintentional penalties or $75 million in intentional penalties. The statutory damages for breach are capped only by the actual number of affected consumers.
Private right of action
Consumers have a private right of action ONLY for data breaches โ not for privacy policy violations, missing opt-out links, or failure to respond to consumer rights requests. However, the CPPA can investigate and penalize those violations on behalf of consumers, and class action lawyers are increasingly creative about finding breach-adjacent claims.
What the CPPA is actively enforcing (2024-2026)
The CPPA has signaled enforcement priorities through its investigation activity and rulemaking:
- Dark patterns โ deceptive design in opt-out flows (e.g., making the "opt out" button harder to find than "accept all")
- Cookies and tracking โ businesses claiming cookies are exempt from opt-out requirements when they are used for advertising
- Service provider agreements โ enforcement of the requirement that contracts with service providers explicitly limit data use
- Notice at collection โ businesses that skipped the point-of-collection notice requirement
- Sensitive PI โ businesses collecting sensitive PI without proper disclosures or limit-use links
- Automated decision-making โ new rulemaking on AI/profiling opt-out rights is expected to result in enforcement actions by late 2026 or 2027
Statute of limitations
The CPRA has a one-year statute of limitations for violations. The clock starts when the violation is discovered or should have been discovered through reasonable diligence. This means past violations are not automatically safe โ if you discover a 2023 violation in 2025, you still have one year to address it.
Compliance timeline โ what to do next
- Immediately: Audit your data collection. Map every touchpoint where you collect personal information from California residents. Include website forms, analytics, advertising pixels, email lists, customer support, HR records, and physical locations.
- This week: Add "Do Not Sell or Share My Personal Information" link to your homepage if you use any advertising technology.
- This month: Update your privacy policy to cover all 12 categories, the 8 consumer rights, sensitive PI disclosures, and your notice-at-collection practice.
- This quarter: Implement consumer rights request mechanisms (webform, email, verification process, appeal process). Review and update your service provider and contractor agreements to meet CPRA requirements.
- On an ongoing basis: Review the CPPA's rulemaking docket for new regulations. Automated decision-making and cybersecurity audit requirements are on the horizon.
Need a CPRA-compliant privacy policy?
Generate Your Privacy Policy โ
Further reading: General Privacy Policy Requirements ยท GDPR Privacy Policy Requirements