- Aug 06, 2026
- 8 min read
CCPA vs. CPRA: Understanding California's Data Privacy Laws
See the key differences between California's privacy laws, compliance duties, and consumer rights businesses must follow in 2026.

California has some of the strictest data privacy laws in the United States, and businesses that collect personal information from California residents face increasing scrutiny from regulators. Since the California Privacy Rights Act (CPRA) amended and expanded the California Consumer Privacy Act (CCPA), organizations subject to these laws face expanded consumer rights, additional compliance obligations, and increased enforcement.
In February 2026, the California Attorney General secured a $2.75 million settlement with Disney over allegations that consumer opt-outs were not fully applied across linked devices and streaming services, at the time the largest CCPA settlement California had reached. That record stood only for a few months. On May 8, 2026, the California Attorney General announced that General Motors agreed to pay $12.75 million to settle allegations that it illegally collected and sold driving and location data from hundreds of thousands of OnStar subscribers, making it the largest CCPA settlement in history.
These enforcement actions highlight the importance of understanding California's privacy laws and keeping up with their evolving requirements. Businesses that fail to comply face both regulatory scrutiny and significant financial and reputational consequences.
This guide explains the key differences between the CCPA and the CPRA, how the CPRA changed California's privacy framework, and what organizations need to do to comply in 2026.
What are the CCPA and CPRA?
The California Consumer Privacy Act (CCPA) provided California residents with certain rights regarding the personal information businesses collect about them. It introduced rights to know, delete, and opt out of the sale of personal information, while requiring covered businesses to provide privacy notices and process consumer requests regarding their data.
The California Privacy Rights Act (CPRA) amended the CCPA. It added rights to correct information and limit certain uses of sensitive data, extended opt-outs to sharing for cross-context behavioral advertising, and created the California Privacy Protection Agency (CalPrivacy).
CCPA and CPRA timeline
- 2018: CCPA passed: California enacted the CCPA, which became operative on January 1, 2020.
- 2020: CPRA approved: California voters approved the CPRA through Proposition 24.
- 2023: CPRA enforcement begins: Most CPRA amendments took effect on January 1, with statutory enforcement beginning on July 1.
The CCPA: Core consumer rights
The original CCPA consumer rights remain central to the amended California Consumer Privacy Act:
- Right to know and access: Consumers can request the data collected about them, its sources and uses, and the categories of third parties receiving it.
- Right to delete: Consumers can request deletion of information collected from them, subject to statutory exceptions.
- Right to opt out of sale: Consumers can stop businesses from selling their information. A “sale” may involve benefits other than direct payment.
- Right to non-discrimination: Businesses cannot penalize consumers for exercising their rights.
Businesses must provide notice at or before collection describing the categories of personal information collected and the purposes for which they are collected.
Which businesses need to comply with the CCPA?
Current CCPA compliance requirements apply to for-profit entities that do business in California, determine the purposes for which personal information is processed, and meet at least one of the following thresholds:
- Gross annual revenue of at least $26.625 million in the preceding calendar year.
- Buying, selling, or sharing the information of at least 100,000 California consumers or households annually.
- Deriving at least 50% of annual revenue from selling or sharing California consumers’ information.
A company need not be based in California. Certain related entities, joint ventures, service providers, and contractors may also have obligations. Nonprofit organizations and government agencies are generally outside the CCPA’s scope. Certain types of information governed by sector-specific laws, including some health and financial data, may also qualify for exemptions.
Suggested read: Californians Sue Healthcare Providers Over AI Recordings of Medical Visits
The CPRA: What’s new?
The California Privacy Rights Act introduced additional privacy obligations relating to consumer rights, data governance rules, and enforcement for breaches of CPRA requirements.
Who needs to comply with the CPRA?
CPRA compliance applies to for-profit businesses that operate in California, determine how and why personal information is processed, and meet at least one CCPA threshold. The CPRA changed the scope by increasing the processing threshold from 50,000 consumers, households, or devices to 100,000 consumers or households, removing devices from the count, and adding “sharing” to the revenue-from-data threshold.
Depending on the circumstances, affiliated entities, service providers, and contractors may also have obligations under the amended law.
Clarified definition of selling and sharing data
The CCPA defines a ‘sale’ broadly as exchanging personal information for money or another valuable benefit. The CPRA added “sharing” as a separate concept, covering the disclosure of personal information to a third party for cross-context behavioral advertising, whether or not money changes hands.
This means advertising cookies and similar tracking technologies, depending on how they are implemented, may be considered sharing under the CPRA. Businesses must offer an accessible opt-out, usually through a clearly labeled “Do Not Sell or Share My Personal Information” link or permitted alternative, and recognize valid opt-out preference signals such as Global Privacy Control.
Expanded consumer rights under the CPRA
The CPRA added or extended several protections:
- Employees and B2B contacts: Temporary exemptions expired at the end of 2022, bringing employee, applicant, vendor, and business contact data within the practical scope.
- Correction: Consumers can request correction of inaccurate information.
- Sensitive data: Consumers can limit specified uses and disclosures of sensitive personal information where the statutory requirements apply.
- Sharing: Consumers can opt out of sharing for cross-context behavioral advertising, a common form of targeted advertising.
- Portability: Information must be supplied in a structured, commonly used, machine-readable format when technically feasible.
❗Businesses subject to this law are generally required to include disclosures in their privacy policies about these rights and how to exercise them. Policies should also identify the personal information collected, its sources and purposes, the categories of third parties to whom it is sold or shared, relevant retention periods, and the categories of third parties receiving it. These disclosures must be reviewed and updated at least annually.
Stronger data governance requirements
The CPRA requires businesses to collect, use, retain, and share personal information only to the extent reasonably necessary and proportionate for the disclosed purposes.
It also created a category of sensitive personal information, which includes government identifiers, financial credentials, precise geolocation, private communications, genetic and neural data, certain biometrics, and information about health, ethnicity, immigration status, religion, union membership, sex life, or sexual orientation. Consumers can limit specified uses and disclosures beyond permitted purposes.
California’s 2026 regulations also address risk assessments, cybersecurity audits, and automated decision-making technology (ADMT), including transparency and consumer rights requirements applicable in certain circumstances. The regulations define ADMT as technology that processes personal information and uses computation to replace or substantially replace human decision-making. Businesses using it for significant decisions must meet notice, opt-out, and access requirements beginning January 1, 2027.
The CPRA also created the California Privacy Protection Agency (CPPA, now known as CalPrivacy), with powers to investigate, audit, regulate, and impose administrative fines.
Violations can lead to CCPA and CPRA penalties of up to $2,663 per violation or $7,988 for intentional violations and violations involving consumers known to be under 16.
Suggested read: Social Security Number Verification: Methods, Legality, and Best Practices in 2026
CCPA vs CPRA: Key differences at a glance
The most significant changes, including revised thresholds, additional rights, and changes to CCPA exemptions, are summarized below.
| Original CCPA | CCPA as amended by the CPRA | |
| Threshold | Covered businesses processing data from at least 50,000 consumers, households, or devices | Threshold increased to 100,000 consumers or households; devices no longer count |
| Revenue threshold | More than $25 million in annual gross revenue | Adjusted for inflation to $26.625 million for 2026 |
| Data revenue | 50% from selling data | 50% from selling or sharing data |
| Consumer rights | Rights to know, delete, opt out of sale, and receive equal treatment | Adds rights to correct inaccurate data, limit certain uses of sensitive personal information, and opt out of sharing |
| Consumers covered | Temporary employee and B2B exemptions | Employee and B2B exemptions expired on December 31, 2022 |
| Data governance | Focused on notices, requests, and sales | Adds explicit purpose-limitation, data-minimization, and retention requirements |
| Sensitive data | No dedicated category or limitation right | Defines sensitive personal information and lets consumers limit certain uses |
| Enforcement | Enforced by the California Attorney General, with an automatic 30-day cure period | Also enforced by CalPrivacy; removes the automatic cure period |
| Continuing exemptions | Included exemptions for certain regulated information and organizations | Many health, financial, and credit-reporting exemptions remain |
Why California privacy laws matter for businesses
If an organization does business in California, processes residents’ personal information, and meets a statutory threshold, California’s consumer data privacy laws may apply.
Compliance can affect advertising, analytics, customer accounts, recruitment, vendor relationships, data retention, cybersecurity, and automated decision-making.
The California Privacy Protection Agency can investigate suspected violations, audit businesses, and impose administrative fines, while the California Attorney General retains civil enforcement authority. Because there is no longer a guaranteed 30-day period to cure violations, businesses cannot assume they will receive a warning before facing regulatory action.
How the CPRA and CCPA impact your business
Marketing, HR, product development, procurement, cybersecurity, and customer service may all process covered information. Businesses subject to the CPRA and CCPA typically implement coordinated privacy controls that align their privacy notices with their actual practices.
Changes in marketing and targeted advertising
Consumers generally have the right to opt out of the sharing of personal information for cross-context behavioral advertising, including where certain advertising cookies or similar tracking technologies are used. Not every form of targeted advertising is considered sharing. Advertising based only on activity within a business’s own services is generally outside this scope.
Marketing teams should identify third-party tracking technologies, classify their role, honor Global Privacy Control, and implement applicable opt-out mechanisms across relevant accounts, devices, services, and partners. Businesses must also obtain the required opt-in consent before selling or sharing information about consumers known to be under 16, with parental authorization for children under 13.
New CPRA risk assessment requirements
Under California’s regulations effective from January 1, 2026, covered businesses must conduct a CPRA risk assessment before beginning processing that presents a significant risk to consumers’ privacy. Qualifying activities include:
- Selling or sharing personal information
- Processing sensitive personal information, subject to limited exceptions
- Using automated decision-making technology for significant decisions
- Using personal information to train certain decision-making, facial-recognition, emotion-recognition, or identification technologies
The assessment must document the processing purpose, data involved, sources, retention periods, recipients, expected benefits, potential negative effects, and safeguards. The business must then determine whether the benefits outweigh the privacy risks and whether the processing should proceed.
Assessments must be reviewed periodically and updated within 45 days of a material change.
Data mapping for CCPA and CPRA compliance
Data mapping records how personal information moves through an organization. A data map should identify the information collected, people concerned, sources, purposes, storage systems, retention periods, recipients, and any activity that may constitute selling, sharing, or high-risk processing.
Without an accurate data inventory, businesses may struggle to answer access requests, correct inaccurate records, apply opt-outs, or identify processing that requires a risk assessment. The map should be reviewed whenever the business introduces a new vendor, data source, product, or processing purpose.
Suggested read: From Alchemy to Algorithms: A History of Fraud
CCPA and CPRA compliance checklist
- Confirm scope and any applicable exemptions
- Inventory and classify personal and sensitive information
- Document sources, purposes, systems, recipients, and retention periods
- Apply purpose limitation and data minimization
- Provide notices at or before collection and review the privacy policy annually
- Provide required sale-and-sharing opt-outs and recognize Global Privacy Control
- Implement timely processes for access, deletion, correction, limitation, and opt-out requests
- Review cookies, pixels, SDKs, analytics tools, and advertising partners
- Review and update vendor contracts where appropriate and periodically test vendor compliance
- Complete required risk assessments and prepare for applicable cybersecurity audits
- Monitor developments relating to ADMT requirements
- Maintain reasonable security and a tested incident-response plan
- Train relevant staff, retain evidence, and monitor CPPA developments
CCPA and CPRA vs other US state privacy laws
As of August 2026, more than 20 states have enacted comprehensive consumer privacy laws. Most provide similar rights to access, correct, delete, and obtain personal data, but important differences remain.
| California | Common approach in other states | |
| Scope | Includes a standalone revenue threshold (in addition to data-volume and data-revenue thresholds) and covers employee, applicant, and B2B contact data | Many laws rely on data-volume thresholds |
| Advertising | Treats cross-context behavioral advertising as “sharing” and provides an opt-out right | Many states allow consumers to opt out of targeted advertising, data sales, and some profiling |
| Risk assessment | Triggers include selling or sharing data, processing sensitive information, and uses of automated technology | Often required for targeted ads, sales, sensitive data, or risky profiling |
| Enforcement | Enforced by both CalPrivacy and the Attorney General; limited private right of action for certain data breaches | Usually Attorney General enforcement only |
How Sumsub supports CCPA and CPRA compliance
Sumsub provides privacy controls that can support CCPA and CPRA compliance programs. Whether an organization complies, however, depends on its own processing activities and implementation. Customers remain responsible for determining the applicability of the CCPA and CPRA to their processing activities and for complying with their obligations under those laws.
- Privacy notices and consent. Customers are responsible for providing any applicable privacy notices before submitting personal information for verification. When configured by the customer, Sumsub’s SDKs can facilitate notice and consent flows, while API integrations require customers to implement these mechanisms themselves.
- Data security. Sumsub implements technical and organizational measures designed to protect personal information, including encryption, security testing, and industry-recognized certifications, such as ISO standards and SOC 2 Type II, where applicable.
- Sensitive personal information. Identity verification may involve the processing of sensitive personal information, including government-issued identification documents and biometric information. Sumsub processes such information in accordance with applicable law, its contractual commitments, and applicable privacy documentation.
- Service provider role. In many verification scenarios, Sumsub acts as a Service Provider under the CCPA (or as a processor under other applicable privacy laws), processing personal information on behalf of customers in accordance with their documented instructions. Certain processing activities may instead be carried out by Sumsub as an independent business or controller where permitted by applicable law and described in the applicable contractual documentation or privacy notice.
- Supporting consumer rights. Sumsub provides product functionality and documentation that may assist customers in responding to applicable consumer rights requests where supported by the relevant service. Customers remain responsible for assessing and fulfilling their obligations under the CCPA and CPRA.
- Trust Center. Sumsub’s Trust Center provides customers with relevant security and compliance documentation, including certifications and audit reports, to support vendor due diligence.
FAQ: CCPA vs CPRA
-
What is the difference between CCPA and CPRA?
The CCPA created California’s core consumer privacy rights, including rights to know, delete, and opt out of data sales. The CPRA amended it by adding further rights, stricter governance requirements, protection for sensitive information, and a dedicated enforcement agency.
-
What is CCPA and CPRA?
The CCPA is the California Consumer Privacy Act, a privacy law passed in 2018 that became operative in 2020. The CPRA is the California Privacy Rights Act, a voter-approved measure that expanded and amended the CCPA in 2023.
-
Does CPRA replace CCPA?
No, the CPRA does not replace the CCPA or operate as a separate privacy regime. It amends the CCPA, so references to current CCPA requirements mean the CCPA as amended by the CPRA.
-
What is sensitive personal information?
In California, sensitive personal information includes data such as government identifiers, financial credentials, precise geolocation, private communications, genetic or neural data, certain biometric information, and details about health, ethnicity, religion, or sexual orientation.
Relevant articles
- Article
- Jul 10, 2026
- 11 min read
Learn how to spot fake IDs across US states with key red flags, state-specific security features, and advanced verification techniques for 2026.

- Article
- 3 weeks ago
- 10 min read
Learn how to create an AML compliance policy covering CDD, MLRO duties, SAR filing, and audits, and get a free FINRA template to help you get started.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


