Skip to main content
The state of ai impact assessment
Category: Laws and Regulations

California Privacy Rights Act

Also known as: CPRA, California Privacy Rights Act of 2020
Simply put

The California Privacy Rights Act (CPRA) is a California law that expands and strengthens the earlier California Consumer Privacy Act (CCPA), giving California residents additional rights over their personal information. It enhances consumer rights and introduces a defined category of sensitive personal data. Because it applies to California, its requirements differ from cookie consent rules in the EU, the UK, or other US states.

Formal definition

The CPRA is a California statute that amends and expands the CCPA, enhancing consumer rights and establishing a distinct category of 'sensitive' personal information subject to additional protections. Consistent with the broader US state privacy model, California generally follows an opt-out approach (for example, the right to opt out of the sale or sharing of personal information) rather than the prior opt-in consent standard characteristic of EU law under the ePrivacy Directive and GDPR. Practitioners should note that the evidence provided here establishes only high-level features of the CPRA; specific obligations, definitions, effective dates, enforcement positions, and how the CPRA interacts with cookie and tracking technologies (such as recognition of Global Privacy Control opt-out signals) are outside the scope of this definition and should be confirmed against the statute, applicable regulations, and current regulatory guidance.

Why it matters

For organizations that operate websites or serve users in California, the CPRA is significant because it expands and strengthens the earlier California Consumer Privacy Act (CCPA), enhancing the rights California residents have over their personal information and introducing a defined category of sensitive personal information subject to additional protections. Because cookies, pixels, SDKs, and similar tracking technologies frequently collect personal information, teams responsible for consent and tracking need to understand how California's framework applies to their data practices rather than assuming that EU or UK approaches transfer directly.

The CPRA matters particularly because it reflects a fundamentally different model from the EU regime. Rather than the prior opt-in consent standard characteristic of EU law under the ePrivacy Directive and GDPR, California generally follows an opt-out approach, including a right to opt out of the sale or sharing of personal information. Compliance programs built solely around EU-style prior consent may not, on their own, address California-specific obligations, and vice versa. Treating one jurisdiction's requirements as universal is a common source of compliance gaps.

Practitioners should be aware that the material summarized here establishes only high-level features of the CPRA. Specific obligations, definitions, effective dates, enforcement positions, and how the CPRA interacts with cookie and tracking technologies (such as the recognition of Global Privacy Control opt-out signals) are outside the scope of this definition and should be confirmed against the statute, applicable regulations, and current regulatory guidance before making compliance decisions.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance programs need to understand that the CPRA imposes California-specific obligations that differ from the EU, the UK, and other US states. They should map where California residents' personal information is collected, including through cookies and similar technologies, and confirm current requirements against the statute and applicable regulations rather than relying on EU-style consent alone.
Legal counsel
Counsel advising on multi-jurisdictional operations should note that California generally follows an opt-out model rather than the opt-in standard of EU law, and that the CPRA introduces a defined category of sensitive personal information. Specific obligations, definitions, and enforcement positions should be verified against the statute and current guidance, as several details lie outside the scope of this high-level definition.
Marketing compliance teams
Teams managing advertising, analytics, and tracking technologies should recognize that data collected via cookies, pixels, and SDKs may fall within the CPRA's scope, potentially triggering rights such as the ability to opt out of the sale or sharing of personal information. How these rights map to specific tracking practices depends on regulatory detail that should be confirmed with counsel.
Web developers and CMP implementers
Developers configuring consent management platforms and preference mechanisms should be aware that California's opt-out approach differs from EU-style prior consent, and that requirements such as recognition of Global Privacy Control opt-out signals may apply. Because these technical obligations depend on regulations and guidance not covered here, implementation choices should be confirmed against current requirements.

Inside CPRA

California Privacy Rights Act (CPRA)
A California statute that amends and expands the California Consumer Privacy Act (CCPA), strengthening consumer privacy rights and adding new obligations for businesses that meet its applicability thresholds. Its scope is limited to California and does not govern cookie practices in the EU or UK.
Sensitive Personal Information (SPI)
A category introduced or elaborated under the CPRA covering data such as precise geolocation, racial or ethnic origin, and certain other identifiers, for which consumers may direct businesses to limit use and disclosure. The precise categories are defined by the statute and its regulations.
Right to opt out of sale or sharing
A core CPRA consumer right allowing individuals to opt out of the sale of their personal information and, notably, the sharing of personal information for cross-context behavioral advertising. This is relevant to cookies, pixels, and similar tracking technologies used for targeted advertising.
Opt-out model
Under the CPRA, obligations generally rely on an opt-out approach rather than the prior opt-in consent standard common in most EU jurisdictions. Businesses may collect and use data unless and until a consumer exercises applicable opt-out rights, which differs materially from EU practice.
Global Privacy Control (GPC) signals
The CPRA framework contemplates recognizing opt-out preference signals, such as GPC, that communicate a consumer's choice to opt out of sale or sharing. Businesses within scope may be required to honor such signals, though implementation details depend on regulations and guidance.
California Privacy Protection Agency (CPPA)
An agency associated with administering and enforcing California privacy law under the CPRA framework, alongside other enforcement mechanisms. Its guidance and enforcement positions may evolve over time.
Additional consumer rights
The CPRA expands rights beyond the original CCPA, which may include rights related to correction of inaccurate personal information and to limit the use of sensitive personal information, in addition to existing rights of access and deletion.

Common questions

Answers to the questions practitioners most commonly ask about CPRA.

Does the CPRA introduce an opt-in consent requirement for cookies like the EU's regime?
Generally no. Unlike the EU's ePrivacy and GDPR framework, which typically requires prior opt-in consent before non-essential cookies are placed, the CPRA (which amends and expands the CCPA in California) primarily operates on an opt-out model for most consumers. Businesses are generally permitted to process personal information and set tracking technologies unless and until a consumer exercises rights such as the right to opt out of the sale or sharing of personal information. There are narrower opt-in requirements in specific contexts, such as for minors, but the CPRA's baseline should not be equated with the EU's affirmative-consent standard. Confirm current requirements against the applicable California regulations and guidance, as enforcement positions evolve.
Does complying with the CPRA mean a business is also compliant with the GDPR and EU cookie rules?
No. The CPRA is a California statute with its own scope and mechanisms, and compliance with it does not satisfy obligations under the EU GDPR, the ePrivacy Directive's national implementations, the UK regime, or other state privacy laws. The legal regimes differ in their consent standards, definitions, and enforcement structures. Organizations operating across jurisdictions generally need to assess each applicable framework separately rather than treating CPRA compliance as universal. Because obligations vary by jurisdiction and facts, legal judgment specific to each regime is typically required.
How should a business honor Global Privacy Control (GPC) signals under the CPRA?
Under the California framework, an opt-out preference signal such as GPC has generally been treated as a valid means for consumers to exercise the right to opt out of the sale or sharing of personal information. In practice, this typically means configuring web properties and consent tooling to detect the signal and apply the corresponding opt-out to the browser or, where identifiable, the associated consumer. Because the technical details of signal handling and the categories of processing affected depend on your specific implementation and current regulatory guidance, verify the operative requirements against the applicable California regulations rather than relying on a single tool's default behavior.
What role does a 'Do Not Sell or Share My Personal Information' mechanism play in a CPRA cookie setup?
The CPRA generally contemplates that businesses subject to it provide a clear method for consumers to opt out of the sale or sharing of their personal information, which can include tracking technologies used for cross-context behavioral advertising. In a cookie context, this typically means presenting an accessible opt-out choice and ensuring that, once exercised, the relevant cookies, pixels, SDKs, or similar technologies are no longer used for the sale or sharing of personal information. The precise placement, wording, and technical enforcement depend on the applicable regulations and your data flows, so this should be scoped with reference to current guidance rather than assumed uniform across sites.
Do consent management platforms (CMPs) handle CPRA obligations automatically?
A CMP can support CPRA-related tasks, such as surfacing opt-out choices, detecting opt-out preference signals, and helping record consumer requests, but it does not by itself guarantee compliance. The CPRA framework differs structurally from opt-in regimes, so a CMP configured primarily for EU-style consent may not be aligned with California's opt-out approach without adjustment. Tools support compliance; they do not replace the legal judgment needed to map your specific processing, categories of data, and consumer rights to the applicable requirements.
What record-keeping should a business consider for CPRA opt-out handling?
As a general practice, organizations subject to the California framework maintain records demonstrating how consumer requests, including opt-outs of sale or sharing, are received and honored, which supports accountability if questions arise. In a cookie context, this can include logging when an opt-out preference signal or manual opt-out was applied and how the associated tracking technologies were affected. The specific retention periods, formats, and content of such records depend on the applicable regulations and your internal policies, so confirm the operative requirements against current California guidance rather than treating any single logging approach as sufficient everywhere.

Common misconceptions

CPRA requires opt-in cookie consent like the EU.
The CPRA generally operates on an opt-out model, allowing certain data collection and use unless a consumer exercises applicable opt-out rights. This differs from the opt-in, prior-consent standard applied in most EU jurisdictions under the ePrivacy Directive and GDPR. Complying with one framework does not automatically satisfy the other.
The CPRA governs cookie consent everywhere a business operates.
The CPRA is a California law and its obligations are limited to its defined territorial and applicability scope. It does not set requirements for the EU, the UK, or other US states, each of which may have distinct rules. Claims about cookie obligations should always specify the applicable jurisdiction.
The CPRA only applies to literal HTTP cookies.
The rights around sale and sharing for cross-context behavioral advertising can extend to a range of tracking technologies, such as pixels, SDKs, and similar identifiers, not just cookies. The relevant question is generally the underlying data processing and advertising activity rather than the specific technology used.

Best practices

Determine whether your organization falls within the CPRA's applicability thresholds before designing California-specific compliance measures, and treat California obligations separately from EU or UK requirements rather than assuming a single global approach.
Implement mechanisms to recognize and honor opt-out preference signals such as Global Privacy Control for consumers within scope, and confirm the technical configuration works across cookies, pixels, and similar tracking technologies used for cross-context behavioral advertising.
Provide clear, accessible methods for consumers to exercise applicable rights, including opting out of sale or sharing and directing limits on the use of sensitive personal information, and document how these requests are handled.
Inventory the tracking technologies on your properties, distinguishing those used for cross-context behavioral advertising, and map them to the corresponding opt-out and disclosure obligations.
Maintain records of consumer choices and opt-out signals to demonstrate how requests were received and actioned, recognizing that tools and CMPs support compliance but do not replace legal judgment.
Monitor evolving regulations and enforcement guidance from the relevant California authority, since interpretations and requirements may change over time and specific details depend on the current regulations.
Promotional banner for the Penetration Report Template Kit