EnglishEspañol
California flag

California

CCPA vs CPRA: Key Differences Explained (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

CCPA vs CPRA: Key Differences Explained (2026)

Frequently Asked Questions

Is the CPRA a separate law from the CCPA?

No. The CPRA (Proposition 24) amended the existing CCPA rather than creating a new statute. The official law is still titled the California Consumer Privacy Act of 2018. References to 'CCPA' now include all the changes the CPRA introduced, which took effect January 1, 2023.

When did the CPRA take effect?

The CPRA amendments to the CCPA took effect on January 1, 2023, and apply to personal information collected on or after January 1, 2022. The CPPA began enforcing these provisions on July 1, 2023. Additional regulations covering cybersecurity audits, risk assessments, and ADMT took effect January 1, 2026.

What new rights did the CPRA give consumers?

The CPRA added the right to correct inaccurate personal information and the right to limit a business's use of sensitive personal information. It also expanded the existing opt-out right to cover 'sharing' for cross-context behavioral advertising, not just 'sale' of personal information.

What is the California Privacy Protection Agency (CPPA)?

The CPPA is a state agency created by the CPRA to implement, interpret, and enforce the CCPA. It is the first government agency in the U.S. dedicated exclusively to consumer privacy. The CPPA shares enforcement authority with the California Attorney General and has primary rulemaking power for CCPA regulations.

Do businesses still get a 30-day cure period for violations?

It depends on who is bringing the claim. The CPRA eliminated the 30-day cure period for government enforcement, so the Attorney General and the CPPA can act and impose fines without first giving the business a chance to fix the problem. A 30-day cure period still applies to private lawsuits: under Civ. Code Sec. 1798.150(b), a consumer suing for statutory damages after a data breach must give the business 30 days' written notice first, and if the business cures within that window and confirms it in writing, the statutory damages claim cannot proceed.

What are opt-out preference signals under the CPRA?

Opt-out preference signals are browser-based settings (like Global Privacy Control) that automatically communicate a consumer's choice to opt out of the sale and sharing of their personal information. Businesses must treat these signals as valid opt-out requests, just like a consumer clicking the 'Do Not Sell or Share' link.

What is the difference between a service provider and a contractor under the CCPA?

Both are entities that process personal information on behalf of a business under a written contract. The key difference is in the contractual relationship: contractors must certify they understand and will comply with CCPA restrictions. Both are prohibited from selling or sharing the data and must assist with consumer rights requests.

Are cybersecurity audits now required under the CCPA?

Yes, for certain businesses. Regulations finalized in September 2025 (effective January 1, 2026) require businesses whose processing presents significant risk to consumer privacy to conduct annual cybersecurity audits and submit attestations to the CPPA by April 1, 2028.

Updates

Corrected the cure-period discussion to note that the CPRA eliminated the 30-day cure period only for Attorney General and CPPA enforcement, and added coverage of the data-breach private right of action under Civil Code 1798.150, which still carries a 30-day notice-and-cure requirement and which the CPRA expanded to breached email-and-password credentials.

We corrected a mislinked citation for the original CCPA bill, added the CPRA's updated 100,000-consumer/household applicability threshold, added a note on the December 2022 expiration of the CCPA's temporary employee and B2B data exemptions, and added citizenship or immigration status to the sensitive personal information list.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. CCPA Full Text (Cal. Civ. Code 1798.100-1798.199.100)(leginfo.legislature.ca.gov).gov
  2. CPPA Law & Regulations Portal(cppa.ca.gov).gov
  3. CCPA Overview (California Attorney General)(oag.ca.gov).gov
  4. CPPA FAQ(cppa.ca.gov).gov
  5. CCPA Statute Effective January 1, 2026(cppa.ca.gov).gov
  6. CPI-Adjusted Monetary Thresholds(cppa.ca.gov).gov
  7. CCPA Updates: Cybersecurity Audits, Risk Assessments, ADMT(cppa.ca.gov).gov
  8. CPPA Finalizes Privacy Regulations (Sept 2025)(cppa.ca.gov).gov
  9. Global Privacy Control (GPC)(oag.ca.gov).gov
  10. AG Sephora Settlement ($1.2M)(oag.ca.gov).gov
  11. CPPA Honda Settlement ($632,500)(cppa.ca.gov).gov
  12. Joint Investigative Sweep: CA, CO, CT (Opt-Out Compliance)(cppa.ca.gov).gov
  13. CPPA Consumer Privacy Act Regulations(cppa.ca.gov).gov
  14. DELETE Act: Drop Platform(cppa.ca.gov).gov
  15. SB 1223 (Neural Data)(leginfo.legislature.ca.gov).gov
  16. Cal. Civ. Code 1798.150 (Private Right of Action for Data Breaches)(leginfo.legislature.ca.gov)
  17. Proposition 24 (CPRA), Official Text of Proposed Law, SEC. 16 amending Civ. Code 1798.150(vig.cdn.sos.ca.gov)
  18. AB 375 (2018), California Consumer Privacy Act as chaptered (original Civ. Code 1798.150 text)(leginfo.legislature.ca.gov)
Share: