What CPRA actually requires
The CPRA amends and expands the CCPA. It adds the concept of 'sensitive personal information', new rights around correction and limiting the use of sensitive data, and creates the California Privacy Protection Agency (CPPA) to enforce the law.
Key requirements
- All CCPA requirements continue to apply
- Provide a 'Limit the Use of My Sensitive Personal Information' link where applicable
- Honour requests to correct inaccurate personal information
- Implement data minimisation and purpose limitation principles
- Sign updated contracts with service providers that include the new CPRA terms
- Conduct risk assessments for high-risk processing
At a glance
Full name
California Privacy Rights Act
Region
California, USA
Status
In force since January 2023
Who it affects
Same scope as the CCPA, with the threshold for 'data on consumers' raised to 100,000 consumers or households (sharing alone is no longer a qualifier).
Penalties
Up to $2,500 per violation, $7,500 per intentional violation, and $7,500 per violation involving minors. The CPPA has dedicated enforcement powers.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
