The California Privacy Rights Act (CPRA) has a set of requirements for the privacy policy that goes further than any other US state law.
This page covers one piece of the picture. For the full scope of the CPRA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CPRA and cookies.
It is not just about what the document must contain. It is about two specific links that must be visible on every page of the site. It is about specifying data retention periods. It is about an entirely new category of sensitive data with its own rules.
This article focuses exclusively on what the CPRA requires from the Privacy Policy, based on the official text of the law.
The law uses the term "privacy policy." In California, legal tradition requires this document to be accessible on the homepage and on any page where personal information is collected.
The CPRA significantly expands what the original CCPA required. If your privacy policy was written for the 2020 CCPA, it is likely outdated on several critical points.
The document must list the categories of personal information the business collects (Civil Code § 1798.100).
This includes: identifiers (name, email, IP), legally protected characteristics, commercial information, biometric data, geolocation data, internet activity data, audio or visual data, professional information, education information, and inferences used to create consumer profiles.
This is the CPRA's major innovation. The document must specifically identify whether the business collects sensitive personal information (Civil Code § 1798.121).
SPI includes: precise geolocation, financial account data with credentials, private communications, genetic data, biometric data, health data, sex life or sexual orientation, racial or ethnic origin, religious beliefs, and union membership.
If the business collects SPI, the policy must:
List the categories of SPI collected.
Describe the purposes for which SPI is used.
State whether use is limited to essential purposes or exceeds that.
Explain how the consumer can exercise the right to limit SPI use.
The document must describe the purposes for which categories of personal information are collected and used (Civil Code § 1798.100).
Purposes must be specific. "Improve our services" is not adequate. "Browsing behavior data collected via analytics cookies to identify pages with high abandonment rates and prioritize usability improvements" is the correct level of specificity.
This is a new requirement that the original CCPA did not have and that the CPRA explicitly introduced.
The document must inform how long each category of personal information is retained, or the criteria used to determine that period (Civil Code § 1798.130 a(5)(A)).
The CPRA prohibits retaining personal information beyond what is necessary for the disclosed purposes. This has direct impact on businesses that were simply accumulating data without a cleanup schedule.
The document must describe all rights guaranteed by the CPRA and how consumers can exercise them (Civil Code § 1798.130).
Rights under the CPRA include:
Right to know: categories and specific information collected, sources, purposes, and third parties.
Right to access: a copy of information collected in the past 12 months.
Right to deletion: request deletion, with exceptions.
Right to correct: correction of inaccurate personal information (new under CPRA).
Right to portability: data in a usable format.
Right to opt-out of sale and sharing: refuse sale and sharing for cross-context behavioral advertising.
Right to limit SPI use: limit use of sensitive information to essential purposes (new under CPRA).
Right to non-discrimination: no penalties for exercising rights.
For each right, the policy must describe the submission channel and the response process within 45 days.
The document must identify the categories of personal information disclosed to third parties for business purposes, and the categories of third parties to whom that information was disclosed (Civil Code § 1798.130).
This covers analytics platforms, advertising tools, CRMs, payment processors, and any external service receiving user data.
If the business sells or shares personal information, the policy must identify:
The categories of personal information sold or shared.
The categories of third parties to which information was sold or shared.
Whether the business sells or shares personal information of consumers under 16 (with confirmation that opt-in was obtained, where applicable).
"Sharing" under the CPRA means disclosing personal information for cross-context behavioral advertising even without direct payment. This includes sharing data with advertising networks via pixels, even if the business receives no money for that specific sharing.
Beyond the content of the policy, the CPRA requires two links that must be visible on the homepage and on any page where personal information is collected:
"Do Not Sell or Share My Personal Information": for opt-out of selling and sharing data for cross-context behavioral advertising.
"Limit the Use of My Sensitive Personal Information": for consumers to limit use of sensitive information to essential purposes.
These links may be combined into a single link if both opt-out options are available on the same destination page.
The privacy policy must describe these links and how they work.
The CPRA created a new layer of control for sensitive personal information that did not exist in the CCPA.
The business may use SPI only for essential purposes, unless the consumer has not exercised the limitation right. Essential purposes include: providing the requested service or product, security and integrity, debugging, reasonable internal research, and legal compliance.
If the business uses SPI for purposes beyond those, the policy must make that explicit and the consumer must have the option to limit that additional use.
The retention period for SPI must be specified. And sensitive information cannot be retained beyond what is necessary for the declared purpose.
The CPRA has specific minor protections that must be reflected in the privacy policy.
For consumers under 16: the business cannot sell or share personal information without active opt-in. The policy must describe how this opt-in is obtained.
For consumers under 13: consent must be given by parents or legal guardians. The policy must describe the parental consent process.
If a consumer under 16 declines consent for sale or sharing, the business must wait 12 months before requesting consent again. The policy must mention this rule.
Penalties for violations involving data of consumers under 16 are tripled and automatic. This should motivate special attention to this segment in the policy.
The CPRA expanded "selling" to include "sharing." This directly impacts how the privacy policy describes the use of advertising cookies.
If the site uses Meta Pixel, Google Ads, TikTok Pixel or any pixel that sends behavioral data to external advertising networks, this may constitute "sharing" of personal information under the CPRA, even if the business receives no direct payment for those specific data.
The policy must:
Identify the types of cookies and trackers used.
State whether data is shared with third parties for cross-context behavioral advertising.
Describe how the consumer can opt out of sharing (via the "Do Not Sell or Share" link or the GPC).
The site's cookie notice must align with what is described in the privacy policy.
The CPRA requires businesses to conduct periodic privacy risk assessments for high-risk activities, including processing of SPI, selling and sharing of data, and processing presenting significant risk to consumer rights.
Assessments do not need to be published in the policy, but the policy should state that the business conducts privacy risk assessments for high-risk activities as part of its compliance program.
The CPPA may request these assessments during investigations.
The CPRA prohibits discrimination against consumers who exercise their rights, including denying goods or services, charging different prices, or offering lower quality.
The exception is loyalty, rewards, premium features, or discount programs where the price or quality difference is reasonably related to the value the business derives from the consumer's data, provided the consumer participates voluntarily.
The privacy policy must describe this non-discrimination policy and any applicable exceptions.
AdOpt ensures that what is written in the policy has real correspondence with what actually happens on the site.
The automatic scan identifies all active technologies, feeding the list of data categories and third parties that must appear in the document. The consent management platform ensures that opt-out links work as described, the GPC is honored automatically, and opt-out records are available for audit.
Every interaction is logged. If the CPPA requests evidence, the record is available.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Want to build a Privacy Policy for your site that complies with the CPRA? Talk to our team.
Visible and accessible link on the homepage and on all pages where personal information is collected.
"Do Not Sell or Share My Personal Information" link visible on homepage (Civil Code § 1798.120).
"Limit the Use of My Sensitive Personal Information" link visible on homepage if SPI is collected (Civil Code § 1798.121).
Categories of personal information collected, with specific description of each category (Civil Code § 1798.100).
Categories of sensitive personal information (SPI) collected, if applicable (Civil Code § 1798.121).
Purposes of processing for each category, without vague descriptions.
Retention periods for each data category, or criteria used to determine retention (Civil Code § 1798.130 a(5)(A)).
All consumer rights listed with submission process and 45-day response deadline.
Free service for up to two requests per consumer per year (Civil Code § 1798.130 a(3)).
Categories of personal information sold or shared and categories of recipient third parties.
Protection for consumers under 16: mandatory opt-in for sale and sharing.
Protection for consumers under 13: parental consent.
12-month waiting rule after minors under 16 decline consent.
Non-discrimination policy for consumers exercising their rights.
Reference to privacy risk assessments for high-risk activities.
1. My privacy policy was written for the CCPA. What are the main updates needed for the CPRA?
The main updates are: add the sensitive personal information (SPI) category with its specific rules; describe the new right to correct data; describe the right to limit SPI use; include retention periods for each data category; update the "selling" section to include "sharing" for cross-context behavioral advertising; add the two mandatory links ("Do Not Sell or Share" and "Limit Use of SPI"); and reference the CPPA as the regulatory agency instead of the Attorney General.
2. What are the "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information" links?
These are two links the CPRA requires to be visible on the homepage and on any page where personal information is collected. The first ("Do Not Sell or Share My Personal Information") allows consumers to opt out of selling and sharing personal information for cross-context behavioral advertising. The second ("Limit the Use of My Sensitive Personal Information") allows consumers to restrict use of sensitive personal information to essential purposes. Both links may be combined into a single link if both options are on the same destination page.
3. Why does the CPRA require specifying data retention periods in the privacy policy?
The CPRA introduced an explicit prohibition on retaining personal information beyond what is necessary for the declared purposes. As a result, businesses must know how long they retain each data category and communicate that to consumers. Civil Code § 1798.130 a(5)(A) requires the policy to specify retention periods or criteria used to determine them. This rule closes a gap that existed under the CCPA, where businesses could accumulate data indefinitely.
4. What changes for data of teenagers aged 13 to 15 under the CPRA?
The CCPA already required opt-in for selling data of consumers under 16. The CPRA added a new rule: if a consumer under 16 declines consent for selling or sharing their data, the business must wait 12 months before making a new consent request. This prevents businesses from repeatedly re-presenting the consent request. Penalties for violations involving data of consumers under 16 are tripled and automatic.
5. Does the CPRA have a private right of action? In what situations can consumers sue the business directly?
Yes. The CPRA preserves and expands the private right of action introduced by the CCPA. Consumers can sue the business directly when there is an unauthorized data breach resulting in unauthorized access, theft, disclosure, use, modification, or destruction of unencrypted, unredacted personal information. Categories include Social Security numbers, financial account credentials, debit or credit card data with security codes, medical information, health insurance information, and other categories specified in the law. Minimum damages per consumer per incident are US$ 100 to US$ 750, or actual damages, whichever is greater. Class actions are permitted.
Ready to build a Privacy Policy for your site that complies with the CPRA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
23 Apr 2025
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications