California Privacy Rights Act
The California Privacy Rights Act (CPRA) is a California law that expands and strengthens the earlier California Consumer Privacy Act (CCPA), giving California residents additional rights over their personal information. It enhances consumer rights and introduces a defined category of sensitive personal data. Because it applies to California, its requirements differ from cookie consent rules in the EU, the UK, or other US states.
The CPRA is a California statute that amends and expands the CCPA, enhancing consumer rights and establishing a distinct category of 'sensitive' personal information subject to additional protections. Consistent with the broader US state privacy model, California generally follows an opt-out approach (for example, the right to opt out of the sale or sharing of personal information) rather than the prior opt-in consent standard characteristic of EU law under the ePrivacy Directive and GDPR. Practitioners should note that the evidence provided here establishes only high-level features of the CPRA; specific obligations, definitions, effective dates, enforcement positions, and how the CPRA interacts with cookie and tracking technologies (such as recognition of Global Privacy Control opt-out signals) are outside the scope of this definition and should be confirmed against the statute, applicable regulations, and current regulatory guidance.
Why it matters
For organizations that operate websites or serve users in California, the CPRA is significant because it expands and strengthens the earlier California Consumer Privacy Act (CCPA), enhancing the rights California residents have over their personal information and introducing a defined category of sensitive personal information subject to additional protections. Because cookies, pixels, SDKs, and similar tracking technologies frequently collect personal information, teams responsible for consent and tracking need to understand how California's framework applies to their data practices rather than assuming that EU or UK approaches transfer directly.
The CPRA matters particularly because it reflects a fundamentally different model from the EU regime. Rather than the prior opt-in consent standard characteristic of EU law under the ePrivacy Directive and GDPR, California generally follows an opt-out approach, including a right to opt out of the sale or sharing of personal information. Compliance programs built solely around EU-style prior consent may not, on their own, address California-specific obligations, and vice versa. Treating one jurisdiction's requirements as universal is a common source of compliance gaps.
Practitioners should be aware that the material summarized here establishes only high-level features of the CPRA. Specific obligations, definitions, effective dates, enforcement positions, and how the CPRA interacts with cookie and tracking technologies (such as the recognition of Global Privacy Control opt-out signals) are outside the scope of this definition and should be confirmed against the statute, applicable regulations, and current regulatory guidance before making compliance decisions.
Who it's relevant to
Inside CPRA
Common questions
Answers to the questions practitioners most commonly ask about CPRA.
