8 min read

In May 2026, California announced a $12.75 million settlement with General Motors, the largest CCPA penalty in state history, over allegations that GM sold driving and location data to data brokers without adequate notice or consent. It was also the first enforcement action built specifically on the CPRA's data minimization and purpose limitation requirements, rules that didn't exist under the original CCPA at all.
That's the real-world stakes behind CCPA vs CPRA. The California Privacy Rights Act (CPRA) significantly amended the California Consumer Privacy Act (CCPA), expanding consumer rights, tightening business obligations, and creating an entirely new enforcement agency with the track record to prove it means business. Knowing the difference between the two laws matters most as the gap between a compliance program built for 2020's rules and one built for what CalPrivacy is actually enforcing in 2026.
| CCPA | CPRA | |
|---|---|---|
| Effective date | January 1, 2020 | January 1, 2023 |
| Enforcement | California AG | California Privacy Protection Agency (CPPA) |
| Applicability threshold | 50,000 consumers | 100,000 consumers |
| Data sharing | Not regulated | Regulated |
| 30 day cure period | Automatic | Discretionary |
| Private right of action | Limited | Expanded |
The California Consumer Privacy Act (CCPA) effective January 1, 2020, was the first comprehensive state-level consumer privacy law in the United States. It gave California residents new rights over their personal data, including the right to know what data businesses collect, the right to delete it, and the right to opt out of its sale.
The California Privacy Rights Act (CPRA), effective January 1, 2023, amended and significantly strengthened the CCPA. It introduced new consumer rights, expanded existing ones, added a new category of “sensitive personal information,” regulated data sharing rather than just data sale, and created the California Privacy Protection Agency as a dedicated enforcement body.
The CPRA amended the CCPA to add four new consumer rights: the right to correct inaccurate personal data, the right to limit how a business uses sensitive personal information, the right to access and opt out of significant decisions made through automated processing, and the right to opt out of profiling related to work performance, finances, health, location, or behavior, plus the right to data portability.
The CPRA also broadened three existing rights. The right to know now covers data a business shares, not just data it sells, with an extended lookback window under certain conditions. The right to opt out expanded from data sale to data sharing too, a critical distinction given how many businesses route data through ad-tech partners without a direct monetary exchange. And the right to delete now requires businesses to pass deletion requests downstream to any third party the data was shared or sold to.
The CPRA also added a specific protection for minors: if someone under 16 refuses the sale or sharing of their data, the business must wait 12 months before asking again.
The CCPA only defined “personal information,” broadly: anything that identifies, relates to, or could reasonably be linked to a specific consumer or household. The CPRA adds a narrower, higher-stakes category on top of that: sensitive personal information, covering Social Security and driver's license numbers, financial account credentials, precise geolocation, race, ethnicity, and religious beliefs, the content of emails and texts, biometric and genetic data, and health or sexual orientation information. Consumers can request that a business limit its use of this category specifically, a right that doesn't apply to personal information generally.
The CCPA largely governs data sale. The CPRA adds data sharing to that scope: disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. That closes a gap businesses had been using to route around sale restrictions by exchanging data without a direct payment. Consumers now get the right to opt out of, know about, and request deletion of shared data, not just sold data.
The CPRA created an entirely new enforcement body, the California Privacy Protection Agency (CPPA), known publicly as CalPrivacy. Before the CPRA, CCPA enforcement sat inside the California Attorney General's office as one responsibility among many. The CPPA is a dedicated agency empowered to audit for compliance, investigate violations, levy fines, and write new regulations.
That last power has been active. The CPPA's 2025 rulemaking finalized new regulations on automated decision-making technology (ADMT), cybersecurity audits, and risk assessments, which took effect January 1, 2026. The obligations phase in on a staggered timeline: full ADMT consumer-rights compliance is required starting January 1, 2027, and the first cybersecurity audit and risk assessment submissions aren't due until April 2028 for most businesses, on a schedule based on revenue. Compliance work for both starts well before those filing dates, since the underlying assessments have to cover activity from 2026 and 2027 onward.
Recent enforcement: GM's $12.75 million settlement in May 2026 is the clearest signal yet of how the CPPA and the Attorney General's office are using these expanded powers, and it followed prior settlements with Sephora, DoorDash, Disney, and several other companies. Data minimization and purpose limitation, requirements that didn't exist under the original CCPA, are now an active enforcement priority, not a theoretical one.
Under the CCPA, businesses got an automatic 30-day window to fix a violation before facing penalties. The CPRA made that cure period discretionary, granted case by case at the CPPA's judgment, not guaranteed. The CPRA also specifies that implementing “reasonable security” after a breach doesn't count as a cure. A company that under-secured sensitive data and then got breached is still liable, even if it patches the gap immediately afterward.
The CCPA already let consumers sue directly when a business failed to protect their unencrypted or unredacted data. The CPRA expanded that right to cover exposure of a consumer's email address paired with a password or security question, a combination common in credential-stuffing attacks. California remains one of the very few states offering any private right of action at all: Colorado, Virginia, and Utah don't provide it under any circumstance, per Transcend's state privacy law tracker.
The CPRA doubled the CCPA's applicability threshold from 50,000 to 100,000 consumers, which exempts many small and mid-sized businesses that would have qualified under the original law. That threshold isn't the only trigger, though: the CPRA also applies to any business with gross annual revenue over $25 million, or one that derives at least half its revenue from selling or sharing California residents' personal data, regardless of consumer volume.
The CPRA requires detailed contracts between a business and any third party it shares or sells data to. Those contracts must specify the purpose of the transfer, bind the third party to the same CPRA obligations the business has, give the business real enforcement power over how the third party actually uses the data, and require the third party to flag it if it can't meet those obligations. Learn more about service provider contract requirements under the CPRA.
Get the CPRA Do Not Sell or Share compliance guide to see exactly what these contract and disclosure requirements look like in practice.
Explore the Do Not Sell or Share Interactive GuideIs the CPRA the same as CCPA 2.0? Informally, yes. The CPRA amends the CCPA rather than replacing it. Every CCPA obligation still applies unless the CPRA specifically changed it, so the two laws have to be read together.
When did the CPRA take effect? The CPRA passed by ballot initiative in November 2020 and took full legal effect January 1, 2023, though its ADMT, cybersecurity audit, and risk assessment regulations didn't take effect until January 1, 2026.
Does the CPRA apply to my business? It applies if a business processes the data of 100,000 or more California consumers or households, has gross annual revenue over $25 million, or derives at least half its annual revenue from selling or sharing California residents' personal data. Meeting any one of these triggers CPRA obligations.
What are the penalties for CPRA violations? Civil penalties can reach $2,663 per violation, or $7,988 for intentional violations and those involving a consumer under 16, figures the CPPA adjusts for inflation periodically. As GM's $12.75 million settlement shows, penalties scale directly with the number of consumers affected.
How is the CPRA different from GDPR? The CPRA is opt-out by default for most data sales and sharing, while the GDPR requires opt-in consent for most processing. The CPRA also applies based on revenue and data-volume thresholds, while the GDPR applies to any organization processing EU residents' data regardless of size.
Does the CPRA cover employees? Yes. Since January 1, 2023, California employees and job applicants have the same CPRA rights as consumers, including the right to know what data an employer collects and to request its deletion, subject to certain employment-specific exceptions.
Managing CCPA and CPRA compliance, especially across dozens of internal systems and third-party vendors, takes more than spreadsheets and manual workflows. Transcend automates the work both laws require:
ZoomInfo cut DSR fulfillment from two days to 10 minutes after switching to Transcend. See the full case study.
Get a demo to see how Transcend keeps CCPA and CPRA compliance current as CalPrivacy's enforcement priorities keep evolving.
Contact us