When the California Consumer Privacy Act (CCPA) came into effect on January 1, 2020, the United States still had no federal privacy law. California decided not to wait and passed the most comprehensive data protection law in the country, which became the reference for virtually everything that followed.
Two years later, California voters went to the polls and approved Proposition 24, which created the California Privacy Rights Act (CPRA). And this is where things get a little confusing for outsiders.
This guide explains what each one is, what changed, and what the current California law requires from anyone handling data of state consumers.
Good question, and the answer is not simple.
The CCPA (California Consumer Privacy Act) is the original law. It was passed as AB 375 in 2018 and came into effect on January 1, 2020. It is codified at California Civil Code § 1798.100 to § 1798.199.100.
The CPRA (California Privacy Rights Act) is Proposition 24, passed by popular vote on November 3, 2020, with most provisions operative starting January 1, 2023. The CPRA did not create a separate law. It amended and expanded the CCPA. In other words: what exists today is the CCPA with the CPRA amendments incorporated.
The 2020 CCPA guaranteed California consumers basic rights: knowing what was collected, requesting deletion of their data, and refusing the sale of their data. It was a pioneering and important law, but with significant gaps.
The CPRA made deep changes:
Created the California Privacy Protection Agency (CPPA): an independent regulatory agency with full administrative power to implement and enforce the law. Before, it was the Attorney General who enforced compliance. Now the CPPA has its own structure, investigative powers, authority to impose administrative fines, and a guaranteed budget.
Added new rights: the right to correct inaccurate data and the right to limit the use and disclosure of sensitive personal information.
Created the "sharing" category: separated "sale" from "sharing" for cross-context behavioral advertising. This means sharing data with advertising platforms for targeting, even without receiving money directly, now requires an opt-out.
Expanded the definition of sensitive data: added genetic data, neural data, health information, sexual orientation, and sex life.
Required the "Limit the Use of My Sensitive Personal Information" link: in addition to the existing "Do Not Sell or Share My Personal Information."
Imposed data minimization and proportionate retention requirements.
| Aspect | CCPA (2020) | CCPA + CPRA (2023) |
|---|---|---|
| Enforcement | Attorney General | CPPA (independent agency) + AG |
| Consumer rights | 5 rights | 7 rights |
| Required links | "Do Not Sell My Personal Information" | "Do Not Sell or Share" + "Limit Sensitive PI" |
| Sensitive data | Basic category | Expanded (includes neural data) |
| Private right of action | Security breaches only | Security breaches only |
| Full effect | Jan 2020 | Jan 2023 |
In the California articles on this blog, we cover the current law: CCPA as amended by the CPRA. For the specific CPRA changes, we have a dedicated guide on the California CPRA.
The California Consumer Privacy Act, as amended by the CPRA, is the most comprehensive data protection law in the United States. It guarantees broad rights to California consumers and creates detailed obligations for businesses that handle their data.
Enforcement today is shared between the California Privacy Protection Agency (CPPA) and the California Attorney General, with distinct and complementary powers.
The original CCPA came into effect on January 1, 2020.
The CPRA amendments became operative on January 1, 2023.
The current version of the law, with all rights and obligations in effect, has applied since January 2023.
Under § 1798.140(d), the law applies to for-profit businesses that do business in California, collect personal information from consumers, and meet at least one of the following thresholds:
Annual gross revenues in excess of US$ 25 million in the preceding calendar year.
Annually buys, sells, or shares the personal information of 100,000 or more consumers or households.
Derives 50% or more of annual revenues from selling or sharing consumers' personal information.
The US$ 25 million threshold is the lowest among all US state privacy laws, making the CCPA the law with the broadest reach in terms of businesses affected.
Understanding the distinction between controller and processor is fundamental to defining responsibilities in the processing chain.
Exempt from most obligations:
Protected health information under HIPAA and data of covered entities.
Data regulated by the California Confidentiality of Medical Information Act.
Consumer credit information regulated by the Fair Credit Reporting Act.
Financial data regulated by the Gramm-Leach-Bliley Act or the California Financial Information Privacy Act.
Data regulated by the Driver's Privacy Protection Act.
Academic or public health research data with appropriate safeguards.
Employee and job applicant data when used in that capacity.
Under § 1798.140(v), personal information is any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
This includes identifiers such as name, address, IP address, email, Social Security number, driver's license, and passport number. It also includes commercial information, browsing history, geolocation data, audio and visual information, employment data, education data, and inferences drawn to create consumer profiles.
De-identified data and publicly available information are excluded.
The CCPA, after CPRA amendments, has an expanded category of "sensitive personal information" (§ 1798.140(ae)):
Social Security number, driver's license, state identification card, or passport number.
Account login, financial account, debit or credit card number in combination with any required security code or password.
Precise geolocation (radius of 1,850 feet or less).
Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership.
Contents of a consumer's mail, email, and text messages, unless the business is the intended recipient.
Genetic data.
Neural data: information generated by measuring the activity of a consumer's central or peripheral nervous system.
Processing of biometric information for unique identification.
Health information collected and analyzed.
Information about sex life or sexual orientation.
The inclusion of neural data is exclusive to the CCPA/CPRA among US state privacy laws.
The law guarantees seven main rights:
Right to know and access: confirming whether the business processes their data and obtaining specific information collected, including categories of data, sources, purposes, third parties, and the specific pieces of personal information. The request covers the preceding 12 months (§ 1798.110, 1798.115).
Right to deletion: requesting deletion of personal data collected by the business, with the obligation to notify service providers, contractors, and third parties to also delete (§ 1798.105).
Right to correction: requesting correction of inaccurate personal data, added by the CPRA (§ 1798.106).
Right to opt-out of sale and sharing: directing the business not to sell or share personal data, exercisable at any time (§ 1798.120).
Right to limit use of sensitive personal information: restricting use of sensitive personal information to what is necessary to provide the products or services reasonably expected. Added by the CPRA (§ 1798.121).
Right of non-discrimination: exercising any right without being discriminated against by the business (§ 1798.125).
Private right of action for security breaches: filing a civil lawsuit for damages of US$ 100 to US$ 750 per consumer per incident. Unique among US state privacy laws (§ 1798.150).
The business has 45 days to respond. The deadline can be extended by another 45 days when reasonably necessary, with notification within the initial period. Service is free. The business is not obligated to provide information to the same consumer more than twice in a 12-month period (§ 1798.130(b)).
The CCPA/CPRA requires specific links on the business's homepage (§ 1798.135):
"Do Not Sell or Share My Personal Information": a clear and conspicuous link to a page where the consumer can opt out of sale and sharing of their data.
"Limit the Use of My Sensitive Personal Information": a link allowing the consumer to limit the use of sensitive personal information to what is necessary to provide the products or services.
The business may use a single combined link for both purposes, as long as it clearly allows exercising both options.
Both links need somewhere to land. In practice that destination is a privacy portal where the consumer submits and tracks the request — the same channel that receives access, deletion, and correction requests within the statutory deadline.
It is also possible to comply by honoring the opt-out preference signal of the Global Privacy Control (GPC) when sent by the user.
This distinction created by the CPRA is fundamental.
Sale (§ 1798.140(ad)): transfer of data for monetary or other valuable consideration to third parties.
Sharing (§ 1798.140(ah)): transfer of data to third parties for cross-context behavioral advertising, whether or not for monetary consideration.
Cross-context behavioral advertising (§ 1798.140(k)): targeting ads based on personal information obtained from consumer activity across businesses, distinctly branded websites, applications, or services other than where the consumer is currently interacting.
In practice: if your site passes data to an advertising platform so it can display personalized ads to the user on other sites, that is "sharing" under the CCPA/CPRA, even if you receive no money directly.
Cookies that collect personal information or allow user identification fall directly within the scope of the CCPA/CPRA.
Before firing any non-essential cookie, the site must display a clear cookie notice, offer opt-out of sale and sharing, block non-consented trackers, and honor the GPC.
Correct tag categorization is what makes it possible to identify which cookies constitute sale or sharing and which require the opt-out links.
That same inventory is what you publish to visitors: a CCPA cookie policy needs to list each category of tracker, its purpose, its retention period, and whether it results in sale or sharing of personal information.
§ 1798.120(c) prohibits the sale or sharing of data of consumers under 16 without affirmative authorization:
For consumers between 13 and 15: the consumer's own authorization.
For consumers under 13: authorization from a parent or legal guardian.
A business that willfully disregards the consumer's age is deemed to have actual knowledge of it.
The CPPA (§ 1798.199.10) is governed by a five-member board with terms of up to eight years. It has power to:
Impose administrative fines of up to US$ 2,500 per violation and up to US$ 7,500 for intentional violations or violations involving minors.
Investigate businesses on its own initiative or based on complaints.
Conduct audits.
Issue and revoke regulations.
The Attorney General retains power to seek civil penalties of up to US$ 2,500 per violation and US$ 7,500 for intentional violations or violations involving minors.
There is no guaranteed cure period before CPPA actions. The agency has discretion to investigate and act without any obligation to grant advance notice.
§ 1798.130(a)(1) requires two or more designated methods for submitting requests. One of those methods must be, at minimum, a toll-free telephone number.
Businesses that operate exclusively online with a direct consumer relationship may limit themselves to an email address.
§ 1798.130(a)(5) requires the business to update the privacy notice at least once every 12 months, including lists of the categories of data collected, sold, shared, and disclosed for business purposes in the preceding 12 months.
This is the annual review that keeps a CCPA privacy policy valid — an outdated notice is, in practice, a notice out of compliance.
AdOpt records every consent and opt-out interaction, honors the GPC when sent by the user, blocks trackers before acceptance, and generates the auditable log needed in a CPPA or Attorney General investigation.
The automatic scan identifies all active trackers on the site, feeding the data inventory. And when the law changes, the platform updates automatically.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Ready to bring your website into compliance with the CCPA? Talk to our team.
| Law | State | Threshold | Penalty | Enforcer | Effective Date |
|---|---|---|---|---|---|
| CCPA/CPRA | California | US$ 25M OR 100K consumers OR 50% revenue | Up to US$ 7,500/violation | CPPA + AG | Jan 2020/Jan 2023 |
| VCDPA | Virginia | 100K or 25K + 50% revenue | Up to US$ 7,500/violation | AG | Jan 2023 |
| FDBR | Florida | US$ 1B+ global revenue | Up to US$ 50K/violation | Dept. Legal Affairs | Jul 2024 |
| NHDPA | New Hampshire | 35K or 10K + 25% revenue | Up to US$ 10K/violation | AG | Jan 2025 |
| CPA | Colorado | 100K or 25K + 50% revenue | Up to US$ 20K/violation | AG | Jul 2023 |
To understand how these privacy laws compare in structure and practical impact, our comparative guide goes deeper.
The CCPA is the starting point, not the whole picture. To see what changed when Proposition 24 took effect, read our guide to the CPRA and cookies. And to compare California's approach with the European and Brazilian models, see how the GDPR, LGPD, and CCPA differ in practice.
Compliance with the CCPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.
1. What is the difference between the CCPA and the CPRA?
The CCPA is California's original privacy law, in effect since January 1, 2020. The CPRA (Proposition 24) was passed by voters in November 2020 and amended the CCPA with full effect from January 2023. The CPRA is not a separate law: it modified and expanded the CCPA. The most important changes were the creation of the California Privacy Protection Agency (CPPA), the addition of rights to correct data and limit use of sensitive personal information, the separation of "sale" from "sharing," and the expanded definition of sensitive personal information.
2. Who needs to comply with the CCPA?
For-profit businesses that do business in California and meet at least one threshold: annual revenues exceeding US$ 25 million; buying, selling, or sharing personal information of 100,000 or more consumers or households per year; or deriving 50% or more of annual revenues from selling or sharing personal data (§ 1798.140(d)).
3. What is the difference between "sale" and "sharing" under the CCPA/CPRA?
"Sale" is the transfer of data for monetary or other valuable consideration to third parties. "Sharing" is the transfer for cross-context behavioral advertising, with or without monetary consideration. The distinction ensures that advertising targeting practices are also subject to opt-out, even without direct payment to the site.
4. What are the "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information" links?
These are mandatory links on the business's homepage (§ 1798.135). The first allows the consumer to opt out of sale and sharing of their data. The second allows limiting the use of sensitive personal information. They can be two separate links or a single combined link that clearly allows exercising both options.
5. What is the private right of action under the CCPA and why is it unique?
§ 1798.150 grants consumers the right to file a civil lawsuit when unencrypted and unredacted data is exposed in a security breach due to the business's failure to implement reasonable security measures. The consumer can recover US$ 100 to US$ 750 per incident or actual damages when greater. This private right of action is exclusive to the CCPA among US state privacy laws.
Ready to bring your website into compliance with the CCPA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
Here is a step-by-step explanation of how consent registration works in AdOpt.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
23 Jul 2024
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications